A DVG Systems Toolkit  ·  Edition 2026

The Small-Business AI Policy Toolkit

The AI policy your cyber insurer and your board will ask for — with the specific clauses 2026 renewal underwriters now treat as mandatory. Ready to adapt to a Canadian small business in a weekend.

www.dvgsystems.com   ·   (807) 700-0061
v2026.04

Why AI governance moved from "nice to have" to renewal blocker

Through 2025, cyber insurers watched losses from AI-driven attacks and from employees pasting client data into public AI tools. Coalition's 2026 Cyber Claims Report calls this the "Year of Technical Validation". Carriers responded with three things:

This toolkit hands you the structure, the clauses, and the technical controls you need to answer "yes" — honestly.

Part 1 — The policy (a plain-English template)

Copy the 8 sections below into a Word document. Fill in the placeholders. Have it reviewed by legal counsel if you handle regulated data (health, legal, financial). Get it signed by every employee and contractor, including owners.

1. Purpose and scope

Template

This policy governs the use of generative AI tools (including but not limited to ChatGPT, Microsoft Copilot, Google Gemini, Claude, Perplexity, GitHub Copilot, and any tool that processes prompts through a large language model) by all employees, contractors, and agents of Your Company while conducting company business.

It applies whether the tool is used on company devices, personal devices, company accounts, or personal accounts, when the work involves company or client information.

2. Approved tools

List the specific tools your staff are authorised to use and the category of data permitted in each. Anything not on the list is prohibited by default.

Template

The following AI tools are approved for business use, within the data categories listed:

Free or personal-tier AI accounts are not approved for any company data. Consumer ChatGPT, Gemini personal, and free Claude accounts may retain prompts for model training.

3. Prohibited data categories

Template

The following data types MUST NOT be entered into any AI tool (approved or otherwise) without prior written approval from CEO / Privacy Officer:

Why this matters for insurance: the Condition Precedent clauses in 2026 policies specifically call out "regulated or client-confidential data sent to a third-party AI tool without redaction." A documented prohibition is your first line of defence.

4. Prompt disclosure rules

Template

When AI tools produce output that is used in client-facing deliverables, staff must:

5. Record-keeping (your proof for insurers)

Template

For the purposes of insurance, audit, and incident response, the company maintains the following records:

6. Incident handling when AI is misused

Define what happens when a staff member pastes prohibited data, or when an AI tool produces harmful output used in a client deliverable.

Template
  1. Report within 24 hours to IT / Privacy Officer, even if no harm is apparent.
  2. Preserve evidence — screenshots, conversation exports, timestamps.
  3. Assess data exposure — what was sent, to which tool, under which account.
  4. Notify the insurer's breach hotline if any category of prohibited data was involved — do not wait for confirmation of harm.
  5. Notify affected clients as required by contract and applicable privacy law (PIPEDA, PHIPA, provincial laws).
  6. Debrief — close the policy gap that allowed the incident.

7. Review cadence

Template

This policy is reviewed at least annually by Owner / Privacy Officer, and additionally whenever:

8. Signature block

Template

I acknowledge that I have read this AI Acceptable Use Policy, understand it, and agree to comply with it as a condition of my employment or contract with Your Company.

Name:  

Role:  

Signature:      Date:  

Part 2 — The technical controls your insurer expects behind the policy

A signed policy without matching technical controls is a paper shield. Underwriters in 2026 are asking for the pairing.

A. Tenant-level data protection for Microsoft 365 Copilot

If staff use Copilot, confirm it runs under your commercial data protection boundary (Microsoft 365 Business Premium or E3/E5 with Copilot licences). Your prompts and outputs are not used for model training and are subject to your tenant's compliance controls. Personal Copilot (free tier) does not meet this bar.

B. DLP rules that watch for prompt pasting

Microsoft Purview DLP, Microsoft Defender for Cloud Apps, or equivalents from Proofpoint, Cloudflare, or Netskope can flag and optionally block pastes of sensitive data to AI tool domains (chat.openai.com, gemini.google.com, claude.ai, etc.). Start with alert-only, graduate to block for your strictest data categories.

C. Browser controls on unmanaged AI tools

If staff use personal AI accounts on work devices, either move them to approved enterprise accounts or use browser isolation / category blocking in your DNS filter (see the Cyber Insurance Readiness Checklist, item 4).

D. Audit log retention

Microsoft 365 Copilot usage logs flow to the unified audit log. Confirm log retention is at least 12 months (requires Audit Premium or E5) — short retention makes forensic work after an incident impossible.

E. EDR coverage on every device that uses AI tools

If an account is compromised and used to exfiltrate prompt history, EDR is what surfaces it. See item 2 of the Cyber Insurance Readiness Checklist.

Part 3 — How to answer the insurer questions

"Do you have a documented AI acceptable-use policy?"

Yes, dated  , reviewed annually, signed by all staff. Evidence: policy PDF + signature record.

"Do you restrict the AI tools staff may use for business data?"

Yes — section 2 of the policy lists approved tools. Non-approved tools are blocked at the DNS and DLP layer. Evidence: DNS filter rule export, DLP policy export.

"Do you prevent prohibited data (PII, PHI, source code) from being sent to third-party AI tools?"

Yes — section 3 prohibits by policy, and DLP monitoring flags attempts. Evidence: DLP alert log sample.

"Do you log and audit AI tool usage?"

Yes — Microsoft 365 Copilot usage is captured in the unified audit log with 12-month retention. Evidence: audit log sample query.

"Have you trained staff on AI risks?"

Yes — the policy is reviewed on hire and annually, supplemented by security awareness training. Evidence: training completion report.

Sources
  1. Coalition, 2026 Cyber Claims Report — coalitioninc.com/claims-report/2026
  2. Beazley Cyber Insurance Application (sub-$20M) — beazley.com
  3. Microsoft Learn, "Data, Privacy, and Security for Microsoft 365 Copilot" — learn.microsoft.com
  4. Office of the Privacy Commissioner of Canada, guidance on generative AI — priv.gc.ca
  5. Canadian Centre for Cyber Security, "Generative AI" guidance — cyber.gc.ca

Need help turning this into a signed, enforceable policy?

DVG Systems tailors this toolkit to your business, wires up the DLP and audit-log controls in Microsoft 365, and provides the training records your insurer will ask to see. Most small businesses are up and running inside two weeks.

Talk to us
(807) 700-0061
Email
solutions@dvgsystems.com
Book online
www.dvgsystems.com/contact