You're viewing this in your browser. Use Print → Save as PDF to share or attach.
A DVG Systems Toolkit · Edition 2026
The Small-Business AI Policy Toolkit
The AI policy your cyber insurer and your board will ask for — with the specific clauses 2026 renewal underwriters now treat as mandatory. Ready to adapt to a Canadian small business in a weekend.
www.dvgsystems.com · (807) 700-0061
v2026.04
Why AI governance moved from "nice to have" to renewal blocker
Through 2025, cyber insurers watched losses from AI-driven attacks and from employees pasting client data into public AI tools. Coalition's 2026 Cyber Claims Report calls this the "Year of Technical Validation". Carriers responded with three things:
AI Security Rider — added by several carriers in 2026 — requires technical controls around generative AI use and treats failure as grounds to deny claims.
Condition Precedent clauses — now appearing in Chubb, Beazley and Travelers 2026 policies — void coverage if a forensic audit shows client or regulated data was sent to a third-party AI tool without redaction or approval.
Questionnaire expansion — application forms now ask "do you have an AI acceptable-use policy, and is it signed by all employees?" on the first page.
This toolkit hands you the structure, the clauses, and the technical controls you need to answer "yes" — honestly.
Part 1 — The policy (a plain-English template)
Copy the 8 sections below into a Word document. Fill in the placeholders. Have it reviewed by legal counsel if you handle regulated data (health, legal, financial). Get it signed by every employee and contractor, including owners.
1. Purpose and scope
Template
This policy governs the use of generative AI tools (including but not limited to ChatGPT, Microsoft Copilot, Google Gemini, Claude, Perplexity, GitHub Copilot, and any tool that processes prompts through a large language model) by all employees, contractors, and agents of Your Company while conducting company business.
It applies whether the tool is used on company devices, personal devices, company accounts, or personal accounts, when the work involves company or client information.
2. Approved tools
List the specific tools your staff are authorised to use and the category of data permitted in each. Anything not on the list is prohibited by default.
Template
The following AI tools are approved for business use, within the data categories listed:
Microsoft 365 Copilot (with tenant-level data protection) — internal documents, client communications, financial data.
ChatGPT Team or Enterprise — general research, drafting, internal documents. Not approved for client PII.
GitHub Copilot for Business — source code only. Not approved for customer data.
Add others relevant to your business.
Free or personal-tier AI accounts are not approved for any company data. Consumer ChatGPT, Gemini personal, and free Claude accounts may retain prompts for model training.
3. Prohibited data categories
Template
The following data types MUST NOT be entered into any AI tool (approved or otherwise) without prior written approval from CEO / Privacy Officer:
Personally identifiable information (PII) — SIN, date of birth, home address, driver's licence numbers
Protected health information (PHI) — medical records, diagnostic information, appointment details
Financial account data — credit-card numbers, bank account numbers, tax filings
Client-confidential material — contracts, legal matters, strategic plans marked Confidential
Authentication credentials — passwords, API keys, tokens, recovery phrases
Source code containing proprietary business logic (unless using an approved enterprise coding tool)
Anything covered by an NDA or client-specific data-handling agreement
Why this matters for insurance: the Condition Precedent clauses in 2026 policies specifically call out "regulated or client-confidential data sent to a third-party AI tool without redaction." A documented prohibition is your first line of defence.
4. Prompt disclosure rules
Template
When AI tools produce output that is used in client-facing deliverables, staff must:
Verify factual claims against primary sources before publication.
Disclose AI involvement to clients where material to the deliverable, or where the client's agreement requires it.
Not present AI-generated material as independent human analysis when doing so would mislead the client.
5. Record-keeping (your proof for insurers)
Template
For the purposes of insurance, audit, and incident response, the company maintains the following records:
A signed copy of this policy for every employee and contractor, retained for at least 3 years after separation.
A record of AI tool approvals, including business justification and data-category scope.
Tenant-level audit logs for Microsoft 365 Copilot and equivalent enterprise tools, retained for at least 12 months.
A log of exceptions granted to this policy, reviewed quarterly by Owner / Privacy Officer.
6. Incident handling when AI is misused
Define what happens when a staff member pastes prohibited data, or when an AI tool produces harmful output used in a client deliverable.
Template
Report within 24 hours to IT / Privacy Officer, even if no harm is apparent.
Assess data exposure — what was sent, to which tool, under which account.
Notify the insurer's breach hotline if any category of prohibited data was involved — do not wait for confirmation of harm.
Notify affected clients as required by contract and applicable privacy law (PIPEDA, PHIPA, provincial laws).
Debrief — close the policy gap that allowed the incident.
7. Review cadence
Template
This policy is reviewed at least annually by Owner / Privacy Officer, and additionally whenever:
A new AI tool is requested for business use.
A cyber insurance renewal introduces new questions or exclusions.
Regulatory or professional-body guidance on AI changes materially.
An incident reveals a gap in current rules.
8. Signature block
Template
I acknowledge that I have read this AI Acceptable Use Policy, understand it, and agree to comply with it as a condition of my employment or contract with Your Company.
Name:
Role:
Signature: Date:
Part 2 — The technical controls your insurer expects behind the policy
A signed policy without matching technical controls is a paper shield. Underwriters in 2026 are asking for the pairing.
A. Tenant-level data protection for Microsoft 365 Copilot
If staff use Copilot, confirm it runs under your commercial data protection boundary (Microsoft 365 Business Premium or E3/E5 with Copilot licences). Your prompts and outputs are not used for model training and are subject to your tenant's compliance controls. Personal Copilot (free tier) does not meet this bar.
B. DLP rules that watch for prompt pasting
Microsoft Purview DLP, Microsoft Defender for Cloud Apps, or equivalents from Proofpoint, Cloudflare, or Netskope can flag and optionally block pastes of sensitive data to AI tool domains (chat.openai.com, gemini.google.com, claude.ai, etc.). Start with alert-only, graduate to block for your strictest data categories.
C. Browser controls on unmanaged AI tools
If staff use personal AI accounts on work devices, either move them to approved enterprise accounts or use browser isolation / category blocking in your DNS filter (see the Cyber Insurance Readiness Checklist, item 4).
D. Audit log retention
Microsoft 365 Copilot usage logs flow to the unified audit log. Confirm log retention is at least 12 months (requires Audit Premium or E5) — short retention makes forensic work after an incident impossible.
E. EDR coverage on every device that uses AI tools
If an account is compromised and used to exfiltrate prompt history, EDR is what surfaces it. See item 2 of the Cyber Insurance Readiness Checklist.
Part 3 — How to answer the insurer questions
"Do you have a documented AI acceptable-use policy?"
Yes, dated , reviewed annually, signed by all staff. Evidence: policy PDF + signature record.
"Do you restrict the AI tools staff may use for business data?"
Yes — section 2 of the policy lists approved tools. Non-approved tools are blocked at the DNS and DLP layer. Evidence: DNS filter rule export, DLP policy export.
"Do you prevent prohibited data (PII, PHI, source code) from being sent to third-party AI tools?"
Yes — section 3 prohibits by policy, and DLP monitoring flags attempts. Evidence: DLP alert log sample.
"Do you log and audit AI tool usage?"
Yes — Microsoft 365 Copilot usage is captured in the unified audit log with 12-month retention. Evidence: audit log sample query.
"Have you trained staff on AI risks?"
Yes — the policy is reviewed on hire and annually, supplemented by security awareness training. Evidence: training completion report.
Microsoft Learn, "Data, Privacy, and Security for Microsoft 365 Copilot" — learn.microsoft.com
Office of the Privacy Commissioner of Canada, guidance on generative AI — priv.gc.ca
Canadian Centre for Cyber Security, "Generative AI" guidance — cyber.gc.ca
Need help turning this into a signed, enforceable policy?
DVG Systems tailors this toolkit to your business, wires up the DLP and audit-log controls in Microsoft 365, and provides the training records your insurer will ask to see. Most small businesses are up and running inside two weeks.