The Policy Gap Nobody’s Talking About
A 2025 survey from the U.S. Chamber of Commerce and Teneo found that 68% of small businesses now use AI tools regularly, for drafting emails, summarizing documents, building spreadsheets, even talking to customers. That part isn’t surprising to anyone who’s watched an employee paste a client email into a chatbot to get a faster reply. What’s surprising, or at least concerning, is the other number in that same survey: 77% of those businesses have no written policy governing how AI gets used.
That gap is where the actual risk lives. It’s not the AI tools themselves, it’s the complete absence of any rule about what goes into them and what comes back out.
Three Ways This Actually Goes Wrong
This isn’t a hypothetical, it’s already playing out in small businesses that never sat down to think it through:
- Data exposure. An employee pastes a customer contract, a patient record, or internal financials into a free AI tool to “clean it up,” and that information now lives on a server outside your control, subject to whatever terms of service that tool operates under.
- Hallucinated output reaching clients. AI tools generate confident, well formatted answers that are sometimes simply wrong, a made up statistic, a misquoted regulation, a policy that doesn’t exist. Without a review step, that output can land directly in front of a customer or regulator with your company’s name on it.
- Accidental vendor lock-in. Teams adopt whatever free or cheap AI tool is in front of them, department by department, with no coordination. A year later the business is paying for four overlapping subscriptions and nobody can say which one holds what data.
And here’s the part that should really get an owner’s attention: the same survey found only 15 to 20% of small businesses using AI are seeing measurable strategic value from it. Most of the risk is being taken on without most of the upside being captured, which is about the worst trade a business can make.
What a Workable AI Policy Actually Contains
A good policy here doesn’t need to be 40 pages, and it definitely shouldn’t take six months to write, most small businesses can put a usable first version in place in a few weeks. At minimum it needs to name which tools are approved for company use, spell out what categories of data can never be entered into an AI tool (client PII, financials, anything covered by a compliance framework your business follows), and require a human review step before AI generated content goes external.
It should also say who owns the decision when a new AI tool shows up, because one will, probably next quarter. Without an owner, “figure it out yourself” becomes the default policy by accident, and that’s how you end up back at the 77% with no policy at all.
This Belongs on the Roadmap, Not the Back Burner
This is exactly the kind of decision that should sit inside a business’s broader technology roadmap rather than get handled department by department. Its the same category of thinking that goes into any strategic planning work Cloud9 Tech Solutions does with clients: figure out where the business is exposed, set a clear direction, and put a plan in place before the gap turns into an incident.
AI adoption in small business isn’t slowing down, and it shouldn’t. The businesses that get real value out of it are the ones treating it as a deliberate decision instead of something that happened to them. If your business is somewhere in that 77% with no policy yet, now’s the moment to fix that, not after something goes wrong.
Let’s Build the Policy Before You Need It
Schedule a free security assessment with Cloud9 and we’ll help you figure out exactly where AI is already being used in your business, whether it’s creating risk, and what a policy that fits your size and industry should actually say.

