Small office team around a laptop reviewing a written policy

Artificial IntelligenceComplianceCybersecurity

ChatGPT and AI Governance: A Practical Guide for Small Businesses

ChatGPT governance starts with an admission: your staff have already made AI decisions for you. The office manager drafts client letters in ChatGPT, a partner records meetings with an AI note-taker, and someone in billing switched on the AI assistant in your practice management software last month. Each choice made sense to the person who made it. Nobody made them as an organization.

AI governance is how you make those decisions on purpose. It doesn’t need a committee or a 40-page policy. For most organizations with 10 to several hundred staff, it fits on a few pages and a short list of settings. If you’re still finding out which tools are in use, start with our guide to shadow AI, which covers what the policy should include. This guide covers the system around that policy.

The four decisions AI governance covers

DecisionWhat to settleWho usually owns it
ToolsWhich AI products and features are approved, and with which accountsThe owner or operations lead, with your IT provider
DataWhat information may and may not go into each toolWhoever owns compliance
ReviewWho checks AI output before it reaches a client, a patient or a decisionThe manager of each team using AI
OwnershipWho maintains the rules, approves new tools and handles mistakesOne named person with authority to say no

The policy is the written document employees follow. Governance is the system around it: who owns it, which tools are approved and configured, how new tools get vetted, and how the policy is reviewed.

ChatGPT governance starts with the account

The same product can be safe or risky depending on how someone signs in.

Person using a laptop at an office desk
Tool and accountWhat the vendor says
ChatGPT consumer accountsUsed to improve models unless the user opts out
ChatGPT Business (formerly Team), Enterprise and the APIOpenAI does not train on business inputs or outputs by default
Microsoft Copilot Chat with a work accountCovered by enterprise data protection under Microsoft’s Data Protection Addendum, and not used to train foundation models
Copilot and Copilot Chat in healthcareSupport HIPAA compliance for properly configured implementations, but web search queries are not covered by Microsoft’s business associate agreement

For most organizations already on Microsoft 365, Copilot Chat with a work sign-in is the simplest starting point because it sits inside an environment you already manage. Whatever you choose, confirm the vendor’s data use terms in writing before anyone puts client information into it. Business AI plans typically include admin consoles and logs that consumer plans lack, which you’ll want for the records below.

We do Copilot readiness work for clients, and much of it is cleaning up file permissions first. AI with broad access to email and SharePoint can surface files people technically had permission to see but never knew existed.

Write rules people can follow

  • Set boundaries before people start. Decide which tasks AI suits, such as drafting, summarizing, brainstorming and formatting, and which are off-limits, such as final legal or medical judgments, anything requiring a license, and decisions about individual people.
  • List the data that never goes into AI: client and patient records, financial account details, passwords, employee files and anything under an NDA.
  • Keep a human in the loop. Anything that leaves the building or drives a decision needs a named person to check it. In 2023 a federal court in New York sanctioned two lawyers who filed a brief citing cases ChatGPT had invented.
  • Keep a record of approved tools, who has access and when settings changed. Those records matter if a client, insurer or regulator asks how their information was handled.
  • Check whether a tool’s terms give the vendor rights to your content.

AI compliance under rules you already follow

No AI exemption exists from the rules you already follow, and AI tools make those rules easier to break by accident.

  • HHS says a covered entity or business associate that uses a cloud service to maintain electronic protected health information without a business associate agreement is in violation of the HIPAA Rules. An AI tool that processes patient information is a cloud service, so include approved AI tools in your HIPAA risk analysis. More on our healthcare IT page.
  • The FTC Safeguards Rule requires covered tax, accounting and financial firms to oversee the service providers that handle customer information. An AI vendor that receives client data belongs in your written information security program, vetted like a cloud backup or tax software vendor.
  • ABA Formal Opinion 512 (July 2024) applies lawyers’ duties of competence, confidentiality, client communication and reasonable fees to generative AI, including, in some cases, getting the client’s informed consent before putting confidential information into an AI tool.

Where AI law stands

AI-specific regulation in the U.S. is moving fast and in more than one direction. A December 2025 executive order directed the Justice Department to challenge state AI laws it considers overly burdensome, though only courts or Congress can actually overturn them. Colorado, which passed the first broad state AI law, replaced it in May 2026 with a narrower, notice-based law taking effect January 1, 2027, after a federal court blocked enforcement of the original.

Chasing each bill isn’t practical for a small organization. Anchor your program on the NIST AI Risk Management Framework, a free, voluntary framework organized around four functions (Govern, Map, Measure, Manage), and its Generative AI Profile published in July 2024. Pair that with the privacy and security rules you already follow, which our compliance guide covers.

A 30-day rollout

  1. Name an owner, often the owner or office manager working with your IT provider.
  2. Find out what is in use. Ask staff, and review apps connected to Microsoft 365 or Google Workspace, browser extensions and meeting note-takers.
  3. Pick approved tools and accounts, and move people off personal accounts onto business plans with training turned off.
  4. Write a short policy covering approved tools, forbidden data, review rules, how to request a new tool and how to report a mistake.
  5. Fix overshared file permissions and turn on the sensitivity labels and data loss prevention your licenses already include.
  6. Train staff with tasks they actually do.
  7. Put a review on the calendar every six months, or sooner if a vendor changes its terms.

We write AI use policies for clients, get Microsoft 365 ready for Copilot, and block or control AI tools that haven’t been approved, so the rules on paper match the settings in your tenant. Our AI services and compliance services pages have more.

Common mistakes

  • Writing a policy and never changing the settings to match it.
  • Approving a tool by brand without checking which account staff sign in with.
  • Rolling out Copilot before cleaning up file permissions.
  • Leaving AI tools out of the risk analysis and vendor list.
  • Banning AI outright, which pushes it onto personal phones.

A few decisions made this month will save a lot of cleanup later. Book a 20-minute call if you’d like help choosing tools and putting the rules in writing.

FAQ

Frequently asked questions

Is ChatGPT safe for business use?

It can be with a business account and clear rules. OpenAI doesn’t train on ChatGPT business or API data by default, while consumer accounts are used for training unless the user opts out.

How often should we update our AI policy?

At least twice a year, and whenever you add a new AI tool or a vendor changes how it handles data.

Sources: OpenAI: How your data is used to improve model performance; Microsoft Learn: Enterprise data protection in Microsoft 365 Copilot and Copilot Chat; HHS: Guidance on HIPAA and cloud computing; FTC: Safeguards Rule, what your business needs to know; American Bar Association: ABA issues first ethics guidance on a lawyer’s use of AI tools, July 2024; Paul Hastings: President Trump signs executive order challenging state AI laws, December 2025; McDermott Will & Schulte: Colorado AI law in flux, May 2026; NIST: AI Risk Management Framework; Goldberg Segalla: Fake cases, real consequences (Mata v. Avianca sanctions), 2023.

Talk to an advisor

Questions about your own environment?

Our team can walk through how this applies to your organization, with honest recommendations and no pressure.