Policy Playbook

AI Policy Checklist for Small Businesses

Last updated: February 23, 2026

Most teams start with a generic policy template and stop there. The checklist below is designed to move from document-only policy to operational governance.

Core policy checklist

  1. Define approved, restricted, and prohibited AI tools.
  2. Define what data can never be entered into AI tools.
  3. Define disclosure rules for AI-assisted outputs.
  4. Assign ownership for approvals, exceptions, and incidents.
  5. Document review cadence and change-control process.
  6. Collect policy attestation from all employees.
  7. Keep an exportable evidence trail for external diligence.

Operational checks that close the gap

  • Discovery baseline refreshed on a recurring cadence.
  • Reminders sent automatically for unacknowledged policies.
  • Board/client-ready snapshot generated from real activity data.

Texas and Colorado policy updates (2026)

  • Texas HB 149 (TRAIGA): Effective January 1, 2026 and requires disclosures when AI is used to interact with consumers.
  • Colorado SB24-205: Effective date adjusted to June 30, 2026 through SB25B-004.

External policy references

Snapshot current as of February 23, 2026. Treat this as an operations guide, not legal advice.

Related guides

View all

EU AI Act for SMBs

What applies, which deadlines matter, and where to start operationally.

Read guide

Shadow AI Risk Guide

Top risk categories and concrete controls to reduce exposure quickly.

Read guide

Build your first draft in minutes

Start with a tailored policy draft now. After generation, request a launch invite for full governance workflows.