AI governance for small business

AI Policy for Small Business NZ

What to decide before staff use AI

A practical AI policy helps a New Zealand business use AI tools without losing control of customer trust, private information, or public decisions.

An AI policy for a small business in New Zealand should define approved tools, prohibited data, staff responsibilities, approval points, privacy rules, use cases, and escalation steps. It should be simple enough for daily use and specific enough to guide work.

The policy does not need to be long. It needs to answer the questions staff face before they paste information into a chatbot, draft replies, generate copy, or connect an agent to systems. If the immediate issue is staff using ChatGPT, use the ChatGPT for Business NZ AI Policy Checklist as the tool-specific companion. If broader workflow decisions are unclear, use the $1,000 AI Agent Assessment to map tools, data, approval gates, and the first agent worth building.

What is an AI policy for a small business?

An AI policy is a short set of rules that tells staff how AI may be used, what information stays out of AI tools, which outputs need human review, and who owns the decision.

The short answer for New Zealand owners

For most owner-operated businesses, the first version can be one or two pages. It should name approved tools, restricted information, tasks AI can prepare, and actions needing approval before they reach customers, staff, suppliers, systems, or the public.

Policy vs AI strategy vs AI agent assessment

An AI strategy explains where the business wants to use AI. An AI policy explains the rules of use. An AI agent assessment identifies the workflow, source data, tool access, approval map, and roadmap for a controlled agent.

If staff only need drafting rules, start with policy. If you are connecting AI to CRM, inboxes, files, websites, or reporting systems, policy alone is not enough. The next step is to compare practical AI workflow automation examples for NZ businesses and the broader AI Governance Framework NZ before choosing what to build.

Why NZ businesses need AI rules before they need more tools

Many small businesses already use AI informally. The bigger risk is that no one has decided which mistakes matter, who checks them, and what information should never leave the business environment. If staff are already using tools outside approved rules, use the Shadow AI Policy NZ Business Guide to find and govern that hidden use before expanding access.

Staff may already be using AI informally

A team member might use AI to rewrite an email, summarise a customer conversation, outline a proposal, draft a social post, or turn notes into tasks. Those uses can help, but they should not depend on private judgment about safety.

Privacy, customer trust, and business information risks

Official New Zealand guidance encourages safe AI use, privacy, cybersecurity, transparency, and sound data handling. Business.govt.nz's safe and smart AI guidance and MBIE's responsible AI guidance are useful, but each business still needs daily operating rules.

A practical policy should make sensitive data visible: customer records, staff information, financial details, passwords, commercial strategy, unpublished IP, and confidential supplier or client material. If AI is already touching those areas, maintain an AI risk register for NZ businesses using AI agents alongside the policy so each workflow has an owner and approval point.

Why “do not use AI” is usually not a practical policy

A blanket ban may feel safe, but it often drives AI use into private accounts and unlogged workarounds. A better starting point is controlled permission: approved tools, acceptable tasks, restricted information, and outputs needing review.

Bounded access

What to include in a small-business AI policy

The policy should be written in plain English and organised around decisions staff actually make.

Approved AI tools and accounts

List the AI tools, accounts, and subscriptions staff may use for work. Include who owns each account, whether business data may be entered, and who can approve a new tool.

Information staff must not enter into AI tools

Name restricted information clearly. Common examples include passwords, API keys, bank details, health information, employment matters, legal correspondence, customer records, private contracts, pricing strategy, and confidential client material.

Acceptable use cases

Give staff safe starting uses: brainstorming, rewriting for clarity, summarising non-sensitive notes, preparing checklists, researching public information, comparing options, and drafting internal material for review.

The safer pattern is: AI prepares the work; a person checks the consequences.

Human approval before customers, publishing, pricing, legal, or sensitive records

Set approval gates before customer messages, proposals, quotes, public website copy, social posts, pricing recommendations, legal or privacy copy, finance actions, and important CRM fields. For more detail, read AI Approval Gates for Business Automation.

Logging, ownership, and escalation

Decide where AI-assisted work is recorded, who owns the final output, and what staff should do when they are unsure. The policy should make escalation normal, not embarrassing.

A simple AI policy checklist for owner-operated businesses

Use this checklist before you ask staff to rely on AI in daily work.

Tool list

Write down approved AI tools, account owners, allowed users, and whether business data can be entered. Remove tools no one can supervise.

Data rules

Create a red, amber, green list. Green information may be used. Amber information needs approval or anonymisation. Red information must not be entered into AI tools.

Approval map

For each common task, write whether AI may prepare, suggest, update, send, publish, or decide. Most small businesses should begin with preparation and require approval for external or sensitive actions.

Review rhythm

Review the policy at least quarterly, and sooner if the business adds a tool, connects an agent to a system, changes its offer, hires staff, or starts using AI for customer-facing work.

When an AI policy is not enough

A policy is a safety baseline. It is not a workflow design, integration plan, or implementation roadmap.

When staff want agents connected to CRM, inboxes, website, files, or finance systems

Once AI can access business systems, the questions become specific. What records can it read? What fields can it update? Which actions are logged? Who can revoke access? What must the agent never do alone?

That is the point where an AI Agent Implementation Plan NZ becomes useful.

When to run an AI Agent Assessment before implementation

Run an assessment when the workflow touches customers, sales, pricing, publishing, sensitive information, management decisions, or system changes. The AI Agent Assessment can recommend build, prepare, wait, or do not automate.

Example: turning policy into an approval-gated workflow

A policy becomes useful when it changes how work moves.

Sales follow-up draft

Policy rule: AI may prepare follow-up drafts from approved CRM notes, but it must not send outreach automatically. A human checks accuracy, tone, promises, timing, and whether to send. For sales-specific guidance, see AI CRM Automation for NZ Sales Teams.

Website update recommendation

Policy rule: AI may prepare page observations, internal-link suggestions, FAQ drafts, and metadata recommendations. A human approves public copy, pricing, claims, forms, tracking, and publishing. The AI Website Maintenance Checklist shows a recurring review queue.

Internal reporting summary

Policy rule: AI may summarise approved dashboards and notes for internal review. A manager checks conclusions before they influence staff decisions, client commitments, spending, or public reporting.

Frequently asked questions

What should a small-business AI policy include in New Zealand?

It should include approved tools, restricted information, use cases, approval gates, staff responsibilities, logging rules, escalation steps, and a review rhythm. Keep it useful.

Can staff use ChatGPT or other AI tools for business work?

They can if the business has approved the tool and set clear rules for data, review, and ownership. Staff should not use private AI accounts for sensitive business information unless the business has deliberately approved that use.

What information should never be entered into an AI tool?

Do not enter passwords, API keys, bank details, sensitive customer or staff records, confidential contracts, legal correspondence, private financials, or unpublished strategy unless the business has a controlled environment and explicit approval.

Does an AI policy replace an AI assessment?

No. A policy defines the rules for AI use. An assessment defines the workflow, business case, data sources, permissions, approval gates, and practical roadmap for an AI agent or automation project.

Who should approve AI-generated customer messages or website copy?

A named person with authority over the relationship, offer, risk, and brand should approve it. For many small businesses, that is the owner, sales lead, account manager, consultant, or marketing lead.

Next step

Write the first version before AI use becomes invisible. Start with approved tools, data rules, use cases, approval points, and escalation.

If you want to move from policy to a controlled workflow, book the $1,000 AI Agent Assessment. AI Agent Agency will map the workflow, tool access, source data, approval gates, and first agent worth building for your New Zealand business.