Securing Copilot and ChatGPT at a Small Business: A One-Page AI-Use Policy
The fastest way to secure Copilot and ChatGPT at a small business is a one-page AI-use policy that names which tools are approved, bans pasting regulated or customer data into consumer chatbots, and tightens who can see what inside Microsoft 365 before you turn Copilot on. You don't need a 40-page governance manual. You need a single page everyone actually reads, plus two or three technical controls behind it.
I run a cybersecurity-first MSP, and over the last year almost every client conversation has started the same way: "Half my team is already using ChatGPT and I have no idea what they're putting into it." That's the real problem. Not the technology. The fact that it's already in the building and nobody wrote down the rules.
Shadow AI is already in your building
Shadow AI is the use of AI tools your company never approved or even knows about. A dispatcher pastes a rate confirmation into ChatGPT to clean up the wording. An office manager drops last quarter's P&L into a free "summarize my spreadsheet" tool. A salesperson runs the customer list through an AI email writer. None of them think they're doing anything wrong, and that's exactly why it spreads.
The reason this matters for a small business: you have fewer controls than an enterprise and the same data worth stealing. Customer records, banking details, payroll, contracts. When that data goes into a consumer AI tool, you lose track of where it lives and who can read it. The free tiers of many tools reserve the right to use what you type to train their models, which means your data can resurface in someone else's answer.
The fix is not to ban AI. Bans push usage further into the shadows, where you have zero visibility. The fix is to give people a short list of approved tools that are safe to use, and a clear line they must not cross. People follow rules they understand and that don't slow them down.
Where the data actually leaks
The leak is almost always the prompt. Whatever a person types or pastes into the chat box, that's the exposure. Three patterns cause most of the damage I see.
First, copy-paste of sensitive documents: contracts, financials, medical or HR records, anything with personal data. Second, using AI to "fix" a real file that contains customer or employee information, so the whole file goes up. Third, connecting an AI tool or browser extension to a company mailbox or drive with broad permissions, which quietly gives a third party standing access to everything in there.
The cost when this goes wrong is not theoretical. IBM tracks the global average cost of a data breach in its annual Cost of a Data Breach Report, and the figure runs into the millions, with smaller organizations often hit harder relative to their size because they have less margin to absorb it. For a 30-person logistics shop, even a fraction of that average is an extinction-level event.
Build the approved-tool list first
Before you write a single rule, decide which tools are in bounds. This is the most useful thing you'll do, because it turns a vague "be careful" into a concrete "use these, not those."
A workable list for most small businesses has three tiers. Approved for business data: paid, enterprise-grade tools where your data is contractually excluded from model training and stays in your tenant. Microsoft 365 Copilot and ChatGPT Enterprise or Team plans usually qualify, because the business agreement changes how your data is handled. Approved for general use only: free or personal AI tools, fine for public information like drafting a generic blog intro, never for anything customer- or company-confidential. Not approved: everything else, including random browser extensions and AI features baked into apps you haven't vetted.
Put the actual product names on the page. "Use approved tools" means nothing. "Use Microsoft 365 Copilot for anything involving our files; never paste customer data into free ChatGPT" means something a driver or a dispatcher can follow at 6 a.m.
Microsoft 365 Copilot inherits your permission mess
Here's the part that surprises owners. Microsoft 365 Copilot doesn't create new access. It surfaces what a user can already reach. If your SharePoint and OneDrive permissions are sloppy, and in most small businesses they are, Copilot becomes a very efficient way to find the payroll file someone left in a shared folder years ago.
This is permission sprawl: over years of "just share it with everyone so we stop emailing versions," half the company can open files they were never meant to see. Nobody noticed because finding those files was tedious. Copilot makes it effortless. Ask it "what do we pay our drivers" and if the permissions allow it, you get an answer.
So the work before switching Copilot on is unglamorous and essential: review who can access what, lock down sensitive sites, remove "everyone" and "all company" sharing on anything confidential, and apply sensitivity labels to the documents that matter. We pair this with Microsoft Purview data-loss-prevention rules and Conditional Access so the tool can't be reached from an unmanaged personal laptop. Do this once and Copilot becomes a genuine productivity gain instead of an internal search engine for your worst-kept secrets.
Anchor the policy to NIST AI RMF
You don't need to invent a governance framework. The federal government already published a sensible one. The NIST AI Risk Management Framework is voluntary, written in plain language, and built around four functions: govern, map, measure, and manage. For a small business that translates cleanly into: decide who owns AI decisions, know where AI is used, watch for problems, and respond when something goes wrong.
Citing NIST in your policy does two things. It gives your one-pager credibility with clients, insurers, and partners who ask how you handle AI. And it keeps you aligned with a US standard rather than chasing whatever framework is trending. For most Chicago-area SMBs and the trucking and logistics firms we serve, a NIST-aligned posture is exactly what a shipper's vendor questionnaire is looking for.
The one-page AI-use policy
Here's the structure I hand clients. It fits on a single page and a new hire can read it in two minutes.
Purpose: one sentence on why this exists, that AI is allowed and encouraged with guardrails. Approved tools: the three-tier list above, with real product names. The hard rule: never enter customer data, financial records, personal or health information, passwords, or anything you wouldn't post publicly into an AI tool that isn't on the approved-for-business-data list. Verify before you trust: AI makes confident mistakes, so a human checks anything that goes to a customer or into a contract. No unapproved connections: don't grant AI tools or extensions access to company email, calendars, or files without IT sign-off. Who to ask: a name and an email for "is this tool okay?" Reporting: if you pasted something you shouldn't have, tell us immediately, no blame, because a fast report limits the damage.
Have everyone sign it, review it twice a year, and pair it with a short training session. A signed policy plus 20 minutes of training stops far more incidents than any tool, because most AI leaks are honest mistakes by people who never knew the line existed.
Getting this right is a small project, not a big one, and it pays for itself the first time it stops a customer list from landing in a free chatbot. If you want help drafting the policy, fixing Copilot permissions before you flip it on, or mapping the whole thing to a US standard, that's the work we do every day. Start with the EFROS AI governance page to see how we build a practical, NIST-aligned AI program for small and mid-size businesses.
Frequently Asked Questions
What should a small business AI-use policy actually include?
At minimum: an approved-tool list with real product names, a hard rule banning customer, financial, and personal data from non-approved tools, a requirement that a human verifies AI output before it reaches a customer or contract, and a named person to ask when someone is unsure. Keep it to one page so people read and follow it. Anchoring it to the NIST AI Risk Management Framework adds credibility with clients and insurers.
Is Microsoft 365 Copilot safe to turn on right away?
Not until you clean up your permissions first. Copilot only surfaces files a user can already access, so if your SharePoint and OneDrive sharing is loose, it will quickly find sensitive documents people forgot were exposed. Review access, remove company-wide sharing on confidential files, apply sensitivity labels, and add Conditional Access and data-loss-prevention rules before you enable it.
What is shadow AI and why is it a risk for small businesses?
Shadow AI is the use of AI tools your company never approved, like an employee pasting a contract into free ChatGPT. It's risky because small businesses hold the same valuable data as larger ones but with fewer controls, and many free AI tools may use what you type to train their models. The answer is an approved-tool list and clear rules, not an outright ban, since bans just push usage out of sight.
Can we just ban ChatGPT and other AI tools entirely?
You can, but it usually backfires. Bans push employees to use AI on personal phones and accounts where you have zero visibility or control. A better approach is to approve safe, paid tools where your data is excluded from training, and draw a clear line on what can never be entered into anything else. People follow rules that let them keep working.
How does the NIST AI Risk Management Framework apply to a small company?
The NIST AI RMF is voluntary and built around four plain-language functions: govern, map, measure, and manage. For a small business that means deciding who owns AI decisions, knowing where AI is used, watching for problems, and responding when something goes wrong. It gives you a recognized US standard to point to when a client or insurer asks how you handle AI, without requiring a large compliance program.
About the author

Stefan Efros
CEO & Founder, EFROS
Stefan founded EFROS in 2009 after 15+ years in enterprise IT and cybersecurity. He sees how the pieces connect before others see the pieces themselves. Focus: security-first architecture, operational rigor, and SLA accountability.
Related articles
More from the EFROS blog on ai governance and adjacent topics.
AI Vendor Risk Assessment: What Goes in the DPA
What a real AI vendor DPA looks like in 2026: training data carve-outs, sub-processor disclosure, model-update notification, and the deletion clauses every mid-market US company should be insisting on.
AI Policy Templates for Mid-Market US Companies
Three foundational AI policies every mid-market US company should have in place: an acceptable-use policy, a vendor policy, and an incident response policy. The exact clauses we use with EFROS clients.
AI Incident Response: What's Different from Cyber
AI incidents aren't traditional security incidents. They have different triggers, different forensics, different stakeholders, and different remediation paths. Here's what changes, and what doesn't.