What should an AI policy for a small business include?
An AI policy for a small business should include a short mission statement, a plain disclosure of which AI tools you use and how, a confidentiality section explaining what happens to client data, and clear boundaries on AI-generated work coming from clients. Josh Hall lays out exactly that on the Web Design Business podcast, using the policy he wrote for his own business as a template. His advice is to get a draft published this week rather than waiting for a perfect version.
Lead with what you are, not what you're avoiding
Josh's policy opens with a mission statement, and it's worth copying the approach even if your wording differs. His is short: a human-first design experience that helps clients stand out. The point is to frame AI in terms of what your business stands for, so the rest of the policy reads as a set of principles rather than a list of restrictions.
From there he clarifies where AI actually sits in his business. Design, strategy, and customer experience are human-first. AI is used mostly internally to help with standardized workflows. That one sentence answers the question most clients are quietly asking, which is whether the thing they're paying for was generated by a machine.
If you run any kind of service business, this framing translates directly. Say what stays human, then say where AI helps behind the scenes.
"We are human-first in design, strategy and customer experience, using AI primarily internally to help with standardized workflows."
Name the tools you use
The second section is a tool stack disclosure. Josh lists the main AI tools his business currently uses, and he suggests you do the same. In his case that means things like Claude, ChatGPT, AI features inside page builders, Zoom AI, Figma AI, and Canva AI.
This feels exposing at first, but it does two useful things. It shows clients you've thought about this and aren't hiding anything. And it makes the next section, confidentiality, concrete, because now the client knows exactly which tools their information might pass through.
Keep the list current. Josh frames it as the tools you're using today, not a permanent commitment, so updating it every few months is expected.
Confidentiality: the section clients care about most
This is the part Josh treats as non-negotiable. Clients want to know whether their data, their content, and their business details are being fed into a model that learns from them or could surface them elsewhere.
His policy states that client data is not used to train any AI model and is not knowingly shared publicly through AI tools. Backing that up, he describes a practical step: in every AI tool the business uses, the setting that allows the provider to train on your inputs is turned off.
That's a good example of the whole document. It's not legal boilerplate. It's a plain description of a real setting you can actually go and change, and then tell clients you've changed.
"Your data is NOT being used to train any AI LLM model or intentionally or knowingly shared publicly via AI tools."
Boundaries on AI work coming the other way
Most AI policies only cover what the business does with AI. Josh's also covers what clients bring in. His policy says the business will not accept AI-generated content and designs and then revise, refine, or code them up to its standards. If a client shows up with a site that an AI tool spat out, that's a different engagement, and he has a separate, limited AI service for redesigning sites or design systems that were previously built with AI.
He also protects his own work in the other direction. Clients may not take his human-first designs, strategy, and copy and rework them in an AI tool without permission. His word for what happens to good work fed through a generator is "slopified."
The closing section confirms the team follows the same mission, tool stack, and principles, so the policy applies to everyone, not just the owner. Josh's last piece of advice is the most practical: get it up this week, even as a rough draft. It's a disclosure, and a rough disclosure beats none.
"Get this up this week, even just as an initial draft. This is more of a disclosure for you and your business."
What to remember
- Open with a mission statement that says what stays human in your business.
- Disclose the specific AI tools you use and keep the list current.
- State plainly that client data isn't used to train models, and disable training settings in every tool.
- Set boundaries on AI-generated work from clients and on clients reworking your work with AI.
- Publish a draft this week; the policy is a disclosure, not a legal masterpiece.
People also ask
Do I need to tell clients I use ChatGPT or Claude?
Josh's policy does exactly that, listing the main AI tools the business uses. His view is that disclosure builds trust and makes your confidentiality promises meaningful.
How do I keep client data out of AI training?
The episode describes turning off the setting in each AI tool that allows the provider to train on your inputs, then stating in the policy that client data isn't used for training or shared publicly.
Should I accept AI-generated designs from clients and fix them?
Josh's policy says no as part of standard work. He treats reworking AI-built sites as a separate, limited service rather than folding it into normal projects.
Based on the Web Design Business with Josh Hall episode "437 - Creating an AI Policy for Your Web Design Biz," released August 17, 2026, hosted by Josh Hall.