Your First AI Policy: A Practical One-Page Framework for Singapore SMEs

Employees do not wait for a formal transformation programme before trying artificial intelligence. Someone uses an AI assistant to rewrite an email. Another person uploads meeting notes for summarisation. A manager asks a chatbot to compare proposals. A new hire experiments with an automated agent that can read files and create tasks.

Most of this activity begins with a sensible intention: save time and produce better work. The risk is that the business has not agreed on the boundaries. Staff may not know which tools are approved, what information may be entered, when an output requires checking, or who must be told when something goes wrong.

An SME does not need a forty-page governance manual to start addressing this. It needs a short policy that people can understand, remember and apply during ordinary work. The first version should make safe use easier, not bury employees under abstract principles.

This guide explains what a practical one-page AI policy should contain, how to introduce it and when the business needs more detailed controls.

Why a small business needs an AI policy now

Singapore SMEs are adopting AI quickly, often through off-the-shelf tools rather than custom systems. That makes experimentation accessible, but it also means adoption can spread across teams before management has a complete view of how the tools are being used.

The absence of a policy does not mean the absence of AI. It usually means each employee is making their own decisions about risk.

One person may assume that a paid account makes every type of upload acceptable. Another may believe that removing a customer’s name makes a document anonymous, even though other details still identify the person. A third may treat a fluent answer as a verified fact. These are not necessarily reckless employees. They are people working without a shared operating rule.

A first policy should solve five immediate problems:

  • make approved and unapproved uses visible;
  • protect confidential, personal and commercially sensitive information;
  • define where human judgement remains mandatory;
  • assign responsibility for tools, incidents and policy updates; and
  • give employees a clear route for questions and new ideas.

Singapore’s approach to AI governance is practical and risk-based. IMDA’s frameworks emphasise bounding system capabilities, maintaining meaningful human accountability, testing controls and educating users. The same logic can be scaled down for an SME: the greater the potential consequence, the stronger the controls and approval should be.

A policy is not the same as a ban

Some businesses respond to uncertainty by prohibiting all AI use. A blanket ban may be appropriate for a particular high-risk environment, but it is difficult to enforce when useful AI features are already appearing inside productivity, design, accounting and customer-service software.

An effective policy separates low-risk assistance from consequential decisions.

Asking an approved tool to improve the tone of a generic internal announcement is different from asking it to decide whether a customer deserves a refund. Summarising a public report is different from uploading an employee disciplinary record. Drafting a checklist is different from authorising a payment.

The policy should therefore describe what people may do, not only what they must avoid. Employees are more likely to follow a policy that supports legitimate work and explains the reason behind important boundaries.

The one-page AI policy framework

The following seven sections are sufficient for a useful first version.

One-page AI policy framework covering purpose, tools, data, human review, disclosure, incidents and ownership
One-page AI policy framework covering purpose, tools, data, human review, disclosure, incidents and ownership

1. Purpose and scope

Begin with one paragraph explaining why the policy exists and who it covers.

For example: “This policy supports the safe and productive use of AI tools in company work. It applies to employees, contractors and temporary staff using AI to create, analyse, summarise, recommend or act on behalf of the business.”

This prevents the policy from being interpreted as relevant only to the IT team. It also makes clear that using a personal account for company work does not place that activity outside the policy.

2. Approved tools and accounts

List the tools or categories currently approved. Require company work to be performed through company-managed accounts where these are available.

The rule might state that staff may use approved AI features within the organisation’s Microsoft 365 environment and one approved standalone assistant, while other tools require a short review by the policy owner.

Approval should consider more than brand recognition. Ask where data is processed, whether inputs are used to train models, what retention controls are available, how accounts are removed when staff leave, and whether the organisation can review usage or incidents.

Do not let the approved list become stale. Add a simple request route so an employee can propose a tool and explain the use case, information involved and expected benefit.

3. Information that must not be entered

This is the most important everyday section. Use categories and examples employees will recognise.

Unless specifically approved for the use case, prohibit entering:

  • customer or employee personal data;
  • passwords, access tokens and security details;
  • confidential contracts, pricing or negotiations;
  • unpublished financial information;
  • proprietary source code, business methods or internal investigations; and
  • information subject to a client, vendor or regulatory restriction.

Avoid the vague instruction “do not enter sensitive data” without defining sensitive. A sales employee and an IT administrator may interpret that phrase very differently.

The PDPA remains relevant when personal data is collected, used or disclosed through an AI-enabled process. Singapore organisations should understand the purpose of collection, provide appropriate notification, maintain reasonable protection and make reasonable efforts regarding accuracy where the data may affect an individual. An internal AI policy should therefore align with the organisation’s existing data-protection policies and its Data Protection Officer’s responsibilities.

4. Human review and prohibited decisions

State clearly that an employee remains responsible for work submitted under their name. AI output must be reviewed for accuracy, appropriateness, confidentiality and completeness before use.

Then identify decisions AI must not make independently. Common examples include:

  • hiring, discipline or termination decisions;
  • final credit, refund or eligibility decisions;
  • legal, medical, safety or regulatory advice;
  • commitments on price, scope, delivery or contract terms;
  • payments, account changes or access permissions; and
  • responses to serious complaints or vulnerable customers.

AI can sometimes prepare information for these activities, but an authorised person must decide and approve. The difference between “draft” and “decide” should be unmistakable.

5. Accuracy, disclosure and intellectual property

Require employees to verify important facts against reliable sources. Generated citations, quotations, calculations and summaries should be checked rather than trusted because they look convincing.

The policy should also address disclosure. A business may decide that internal drafting assistance does not normally require a label, while customer-facing AI interactions should clearly tell people that they are dealing with an automated system and provide a route to a person.

Employees should not ask a tool to imitate a named living artist, reproduce protected material or create content that the company does not have the right to use. When the ownership or licensing position is unclear, the output should not be published until it is reviewed.

6. Incident reporting

Give people a non-punitive way to report mistakes quickly. Examples include uploading restricted information, receiving an unsafe recommendation, discovering a false customer response or noticing that an automated tool performed an unexpected action.

The policy should name a contact and say what to preserve: the tool used, approximate time, information involved, output received, action taken and people affected. Employees should not delete evidence or attempt a complex technical fix on their own.

Fast reporting helps the business contain an incident. A culture that punishes every honest mistake encourages silence, which increases the eventual damage.

7. Ownership and review

Name one business owner for the policy and one supporting role, such as the DPO or IT administrator. The owner maintains the approved-tool list, coordinates questions and schedules reviews.

For a small firm, these responsibilities may sit with existing roles. The important point is that they are explicit. “Management” is not an owner.

Review the policy every six months, and sooner when the business adopts a materially different tool, connects AI to operational systems, experiences an incident or changes how personal data is used.

A copy-ready first policy

The following wording can be adapted onto one page:

Purpose. We use AI to support productivity while protecting customers, employees and company information. This policy applies to everyone using AI for company work.

Approved use. Use only approved tools and company-managed accounts. New tools require approval from [POLICY OWNER].

Data. Do not enter personal data, credentials, confidential commercial information, restricted client material or unpublished financial information unless the specific tool and use case have been approved.

Human responsibility. Check all output before use. AI may assist but must not independently make employment, payment, pricing, contractual, safety, legal or other high-impact decisions.

Transparency and rights. Do not misrepresent AI-generated material as verified fact. Respect intellectual-property obligations. Customer-facing AI must identify itself where appropriate and provide a route to a person.

Incidents. Immediately report accidental uploads, unexpected actions, harmful output or suspected data exposure to [INCIDENT CONTACT]. Preserve relevant details and follow instructions.

Ownership. [POLICY OWNER] maintains the approved-tool list, handles requests and reviews this policy at least every six months.

This template is an operational starting point, not a substitute for legal advice or sector-specific requirements. The business should adapt it to the information it handles and the consequences of its decisions.

How to introduce the policy without slowing the team

A document placed in a shared folder is not implementation. Introduce the policy through a thirty-minute working session using real examples from the business.

Ask employees to classify five scenarios: allowed, allowed with review, or prohibited. Include an email rewrite, a customer spreadsheet, a proposal summary, a recruitment shortlist and an automated refund. Discussion exposes ambiguity that the written policy can then address.

Next, demonstrate the approved tools and show how to ask for a new one. Make the incident route visible. Ask each team to identify one safe use case and one activity that requires human approval.

Managers must follow the same rules. A policy loses credibility when leaders upload restricted information while instructing junior staff not to do so.

When one page is no longer enough

The first policy is suitable for general productivity use. More detailed controls are needed when AI becomes part of a production process or receives access to systems and data.

Expand the framework when the organisation:

  • deploys a customer-facing chatbot at meaningful volume;
  • uses AI to recommend outcomes affecting individuals;
  • connects an agent to email, CRM, finance or file systems;
  • trains or customises a model using company data;
  • processes sensitive personal data or regulated information; or
  • relies on an AI-enabled process for a critical operation.

At that point, add a use-case register, documented risk assessment, test cases, approval matrix, access controls, monitoring measures, vendor responsibilities and an incident-response procedure.

The one-page policy remains useful as the employee-facing summary. Detailed procedures can sit behind it for the people who build, approve and operate higher-risk systems.

The practical goal is shared judgement

A first AI policy will not predict every tool or situation. Its purpose is to give employees a reliable way to think: use approved systems, minimise the information provided, keep people accountable for consequential work, verify important output and report problems early.

That is enough to move an SME from informal experimentation towards controlled adoption. The policy can mature as the business learns. What matters is that employees no longer need to invent the rules each time they open an AI tool.

Sources and further reading

Not sure where to begin?

Start with the process that is taking too much time or creating uncertainty. Discuss the problem with Syahmul Aziz

Scroll to Top