The Small-Business AI Policy Toolkit
The AI policy your cyber insurer, your board, and your biggest clients will ask for. Adaptable to a Canadian small business or nonprofit in a weekend.
Why this matters in 2026
Through 2025, cyber insurers watched losses from AI-driven attacks and from employees pasting client data into public AI tools. Chubb, Beazley, and Travelers 2026 policies now include Condition Precedent clauses that void coverage if a forensic audit shows regulated data was sent to a third-party AI without redaction. Renewal questionnaires now ask "do you have a signed AI acceptable-use policy?" on page one.
This toolkit hands you the structure and clauses to answer "yes" — honestly.
What's inside
- Purpose & scope — covers company devices, personal devices, and shadow-AI usage
- Approved tools list — template for Microsoft 365 Copilot, ChatGPT Team, GitHub Copilot, with permitted data categories
- Prohibited data categories — PII, PHI, financial, credentials, source code — the list the Condition Precedent clauses ask about
- Prompt disclosure rules — verify facts, disclose AI involvement, do not misrepresent AI-generated work
- Record-keeping requirements — the evidence your insurer will ask to see
- Incident handling playbook — a 6-step process for when AI is misused
- Technical controls checklist — DLP rules, tenant-level data protection, audit log retention, EDR coverage
- Insurer Q&A crib sheet — how to answer the 5 common renewal questions, with evidence
Download the toolkit
Instant download. We keep your name and email so we know who we're helping — we don't spam or share your details.
Who should use this
If any of these are on your calendar, this toolkit is for you:
- Cyber insurance renewal in the next 6 months
- Vendor-risk questionnaire asking about AI governance
- Board or executive committee asking for an AI policy
- Staff already using ChatGPT, Copilot, or Gemini without rules in place
- Regulated data (health, legal, financial) that shouldn't leave your tenant
What makes it different
Built from the clauses showing up on real 2026 Canadian cyber insurance applications — not a generic template lifted from a U.S. SaaS blog. The technical controls section pairs every policy clause with the Microsoft 365 or third-party control that makes it enforceable.