The Small-Business AI Policy Toolkit

The AI policy your cyber insurer, your board, and your biggest clients will ask for. Adaptable to a Canadian small business or nonprofit in a weekend.

Why this matters in 2026

Through 2025, cyber insurers watched losses from AI-driven attacks and from employees pasting client data into public AI tools. Chubb, Beazley, and Travelers 2026 policies now include Condition Precedent clauses that void coverage if a forensic audit shows regulated data was sent to a third-party AI without redaction. Renewal questionnaires now ask "do you have a signed AI acceptable-use policy?" on page one.

This toolkit hands you the structure and clauses to answer "yes" — honestly.

What's inside

  1. Purpose & scope — covers company devices, personal devices, and shadow-AI usage
  2. Approved tools list — template for Microsoft 365 Copilot, ChatGPT Team, GitHub Copilot, with permitted data categories
  3. Prohibited data categories — PII, PHI, financial, credentials, source code — the list the Condition Precedent clauses ask about
  4. Prompt disclosure rules — verify facts, disclose AI involvement, do not misrepresent AI-generated work
  5. Record-keeping requirements — the evidence your insurer will ask to see
  6. Incident handling playbook — a 6-step process for when AI is misused
  7. Technical controls checklist — DLP rules, tenant-level data protection, audit log retention, EDR coverage
  8. Insurer Q&A crib sheet — how to answer the 5 common renewal questions, with evidence

Built from the actual clauses showing up on 2026 Canadian cyber insurance questionnaires. Ready to drop into a Word document, fill in your company name, and get signed.

Download the toolkit

Instant download. We keep your name and email so we know who we're helping — we don't spam or share your details.

Direct download — no waiting. Opting into the newsletter is optional and separate from the download.

Who should use this

If any of these are on your calendar, this toolkit is for you:

  • Cyber insurance renewal in the next 6 months
  • Vendor-risk questionnaire asking about AI governance
  • Board or executive committee asking for an AI policy
  • Staff already using ChatGPT, Copilot, or Gemini without rules in place
  • Regulated data (health, legal, financial) that shouldn't leave your tenant

What makes it different

Built from the clauses showing up on real 2026 Canadian cyber insurance applications — not a generic template lifted from a U.S. SaaS blog. The technical controls section pairs every policy clause with the Microsoft 365 or third-party control that makes it enforceable.

Need help turning this into a signed, enforceable policy?

DVG Systems tailors this toolkit to your business, wires up the DLP and audit-log controls in Microsoft 365, and provides the training records your insurer will ask to see. Most small businesses are up and running inside two weeks.

Ask AI

Accessibility