A page hangs by the kettle at eye level, in the one spot where somebody standing still has nothing else to look at.
One side of A4. Nine rules and a line at the bottom for a signature, in type big enough to read from arm's length, because the only time anybody reads it is while the urn is boiling.
There is a tea splash on it. That is a good sign.
The direct answer. An AI policy for a small business does not need to be a document. It needs to be one side of A4 that a Saturday casual can read in two minutes and follow for the rest of the shift, covering six things: what they may use AI for, what they must never type into it, what a person reads before anything goes to a client, where AI must never go at all, who to ask when they are unsure, and what happens if they get it wrong. The full text is further down this page, in a block you can copy into a document and print. Make the last of those six generous, because a policy that punishes mistakes gets mistakes hidden, and a hidden mistake is the expensive kind.
Take Steph, a two-groomer salon in Sydney's Inner West, with Priya on the bench four days a week and Deb on Saturdays. She is a worked example we follow through this series rather than a real client's books.
Your team is already using AI, with or without a page on the wall
Priya has asked a chatbot how to word a message about Peanut's muzzle. Not because anyone told her to, and not because she was being sneaky. She was in the car park at 4:50pm, the message was awkward, and the thing in her hand is good at awkward messages.
Deb has pasted a Google review into something to get a reply out of it. Somebody has typed a client's message in whole, header and all, because copying the lot is quicker than retyping the part that matters.
That is the real argument for writing a page, and it beats the compliance one. Not writing a policy does not mean there is no AI in your business. It means there is no rule on the AI already in it.
The compliance version fails on its own terms anyway. What gets sold as an AI policy for small business is usually a document about obligations, aimed at somebody who does not personally have any, in a register nobody on a shop floor reads. Your Saturday casual needs to know she can put a review in there and not a phone number, and that she can ask which is which without feeling stupid.
A page nobody reads is worse than no page
An unread policy is not neutral. It is worse than nothing, because it turns a live risk into a filed one. You have a policy now, so you stop thinking about it, and the person it was written for has never opened the folder it lives in.
Three things decide whether a page gets read, and all three are physical.
- One side of A4. If it runs to two sides, the second side is decoration.
- On the wall where people stop. By the kettle, above the bath, next to the roster. Not in an induction folder, not on a shared drive, not in an email from March.
- In the words you actually use. "Never put a client's phone number in there" beats "personal information must not be entered into third-party generative AI systems", and it beats it precisely because it is not a policy sentence.
And one test worth being strict about. Hand it to whoever on your team thinks about this least, and watch them read it. If they reach the bottom and ask you something, it works. If they say "yep, no worries", it does not.
What an AI policy for a small business needs, and nothing else
Six things, in this order, because that is the order somebody needs them in.
- What they may use it for. Permission before prohibition. A page that starts with bans reads as distrust, and never answers the question the reader arrived with: whether they are allowed to use it at all.
- What must never go into it. This is the never list, the same eight lines the rest of this series has used. Do not reword it. It is short so that it is memorable, and memorable because it never changes.
- What a person reads before it leaves. Everything going to a client or a pet owner. And say what they are reading for, because "check it" is not an instruction: a price not on your list, an offer you never ran, an award you never won.
- Where it must never go at all. Anything clinical, anything behavioural, and incident reports. One line each, no exceptions, and no argument on the page; the argument is where AI must never go in pet care.
- Who to ask, by name. Not "management". A name, and explicit permission to use it. Most of what goes wrong here goes wrong because somebody guessed instead of sending a two-line message.
- What happens if they get it wrong. The one everybody writes last and gets backwards.
Six things become nine rules on the page, because two of them carry a second line: the never list needs the habit that replaces it, and the reading rule needs to say what a person is reading for.
Make the mistake rule generous, or you will not hear about the mistakes
The reasoning here is not soft, it is arithmetic.
A policy with a penalty in it does not stop mistakes. It stops disclosure. Whoever pasted the wrong screenshot at 8pm on a Thursday now has two problems, the paste and the telling, and the second one is the one that can be put off. So it gets put off, and you find out three weeks later, from the client.
Nearly everything that goes wrong with these tools is fixable on the day and unfixable in a month. A message that went out with the wrong price can be followed by one with the right price that afternoon, while the client is still reading it.
So write the clause like this, and mean it. Tell me the same day. You are not in trouble for a mistake you bring to me. The only thing here that is a real problem is hiding it.
Then behave that way the first time it happens, because the page is not the policy. The first time somebody owns up is the policy. Everything after that is your team repeating what happened to whoever went first.
The page itself
Copy this into a document, replace the bracketed parts, print it, and put it where the kettle is. It is written for somebody on their third shift, so nothing in it is phrased the way a policy would phrase it.
Change the tone to yours, because a page in somebody else's voice reads as somebody else's rules. And if you add a line, take one off; the moment it needs a second side of paper it stops being the thing on the wall and becomes the thing in the folder.
Ten minutes on somebody's first shift
Printing it is not the job. The page works because of the ten minutes you spend on it once with each person, and it stops working the day you start handing it over instead.
Read it with them, out loud, standing at the wall. Stop on rule two and give one example from your own week, because an example gets remembered and a list does not. Stop on rule nine and say the sentence yourself: nobody is in trouble for telling me. Then have them sign the bottom, because signing is how a person remembers having read something.
Date it, and read it again when something changes: a new tool, a new starter, or somebody getting it wrong. That last one is the most useful revision you will make, because a real mistake shows you which line was not clear enough.
One thing the page cannot do, and this is where a rule wants a setting behind it. It tells your team what they should not export. It does not stop them. Whatever software holds your client list should decide who can pull the whole book out, and in Petboost that sits with roles and permissions: exporting client data is restricted to Admin and Owner Admin, so a Saturday casual cannot download it whether she has read the page or not.
Rule on the wall, permission in the software.
CLAUDE.md tells the software. This page tells the people.
If you have come up the ladder you already have a CLAUDE.md, where your prices, policies, and hard rules are written down once so Claude Code reads them at the start of every session.
They are not substitutes, and swapping one for the other is the mistake worth naming. The file governs a tool that will follow a clearly written rule and has no idea what the rule is for. The page governs a person who knows exactly what it is for, and who decides at 4:50pm in a car park whether it applies to her right now. You want both, and the never list belongs in both, because one of them stops the tool and the other stops the hand holding the phone.
If your business has grown past the point where one page and one name can carry it, the governance version is the operating manual a 10-person daycare runs on.
The legal part of an AI policy, kept short
The rules on that page are not there because a regulator demands them. Most Australian pet businesses sit under the Privacy Act's small business turnover threshold and are outside the Australian Privacy Principles altogether, and there is nothing unlawful about using AI. Australia's privacy regulator recommends against entering personal information into publicly available generative AI tools, and recommends is the honest word for it.
Three things sit outside that, one line each. Card numbers are governed by the card industry's own security standard rather than by privacy law, even when a client sends you one unasked. A published claim about your services has to be accurate and have reasonable grounds behind it whether or not anybody meant to mislead, which is what turns an AI-written service page from a typo into a live risk. And the statutory tort for serious invasions of privacy, which commenced on 10 June 2025, reaches businesses the Privacy Act does not, so exempt is not the same as safe.
The law behind the never list is post four's job, with every source linked in place. This is general guidance rather than legal advice. If something has already gone out that should not have, buy an hour of a real lawyer's time.
What this actually reclaims for you
Ten minutes, once, per person, and one sheet of paper. That is the entire cost.
Here is the countable half, as a worked example. Deb writes eight client messages a week that used to sit in Steph's phone until 9pm, because Steph was the only person allowed near anything that went out. Steph reads each one now instead of writing it, under a minute against the five it used to take her. Call it half an hour a week, from a page on a wall.
The other half is worth more. Steph was the bottleneck on purpose, because being the only person allowed near a client message was the only control she had. The page is a better control than she was, and it holds while she is on holiday.
That is the top of the ladder, and it is a duller destination than it sounds. Running on rails is not a business that runs itself. It is a business where the repeatable half is written down: your prices in a file the software reads, your recurring jobs in skills you never explain again, and your rules on one side of A4 by the kettle with a tea splash on it.
If you landed here first, the complete guide to AI for pet businesses is the front door. And if the part still working against you is the software holding the client book, Start your free trial and set the permissions to match the page.