Of the UK businesses adopting AI, only about a quarter have any rules governing how it’s used.

Which means in most businesses right now, the answers to three questions are “nobody decided”:

What data must never go into an AI tool? Nobody decided. What would catch an AI-written mistake before a customer sees it? Nobody decided. If something goes wrong involving AI — who’s responsible? Nobody decided, which means it lands on the owner. Not by choice. By default.

I spent years at a lending business deciding exactly how much authority our automated models had — where software could act alone and where it stopped. So I’ll say this with some confidence: the absence of rules is not neutral. It’s a decision too. It’s just one you didn’t get to make.

Why is “policy” the wrong word?

Because it makes owners picture a forty-page document, a solicitor’s invoice, and a project that never starts. So it never starts — and the informal usage from last week’s article carries on with no guardrails at all.

But the risk you’re actually managing is narrow. For most small businesses it comes down to two scenarios: customer or company data pasted somewhere it shouldn’t go, and an AI-drafted mistake — a wrong price, a wrong promise, a tone-deaf reply — reaching a customer with your name on it. Both are cheap to prevent and expensive to unwind. Neither needs forty pages.

What goes on the one-pager?

Three lists and a sentence. Genuinely an afternoon’s work.

1. Three things that never go into public AI tools. Customer personal data. Supplier pricing and terms. Anything you’d mind a competitor reading. (Adjust for your business — but three memorable things beat twelve forgettable ones.)

2. The tools we use. A short approved list — which tools, which accounts. Not to be restrictive; so that when something better comes along, there’s a place to add it and a person to ask. If the amnesty conversation surfaced tools your team already rates, start with those.

3. One rule for anything customer-facing. A human reads it before it sends. That’s it. Internal drafts, brainstorming, summaries — use AI freely. Anything that reaches a customer carries your reputation, so it gets human eyes first.

“If something involving AI goes wrong, tell [name] — no blame, same day.”

That’s the sentence. Responsibility by decision, not by chaos.

Communicate it in the same twenty-minute meeting as the amnesty. Treat the people already using AI as your early adopters, not offenders, and this lands as permission with edges — which is what most teams actually want.

What does one page actually buy you?

In risk terms: the two most likely failure modes, closed, for the cost of an afternoon. If you handle customer data, it’s also the difference between explaining to the ICO that you had rules and someone slipped, versus explaining that you’d never thought about it.

But the quieter benefit is what it does to adoption. Ambiguity is what keeps AI use hidden. Clear edges — this is fine, this never, this gets checked — is what lets your team use these tools openly and get visibly better with them. The businesses pulling ahead aren’t the ones with the strictest rules or the loosest. They’re the ones where the rules are decided, known, and one page long.

You’re in the majority if you have nothing written down. But the majority is exposed. What’s actually stopping you writing the one-pager this week — time, or just that nobody’s asked the question out loud yet?

Stat: Cyber Security Breaches Survey 2025/26 — about 24% of AI-adopting businesses have any process governing AI risk.

Delphi Decide helps owners put decidable edges around AI before it becomes a problem to unwind. If you’d like to talk it through — get in touch.