An SMB AI policy that actually changes day-to-day behaviour fits on one page and contains exactly eight clauses — sanctioned tools, prohibited data, human-review gate, client disclosure rule, prohibited uses, incident-report path, review cadence, and signature line — each closing a failure mode currently surfacing in regulatory guidance, court records, and breach disclosures through 2025-2026.
Status set to Partial at publication because the IAPP-cited 'order of magnitude lower remediation cost' figure in clause 6's commentary is annotated as our-estimate; the IAPP 2024 AI Governance Profession Report characterises the remediation-cost gap as material but does not publish a precise multiple. All other clauses are anchored on cited primary sources (ABA Formal Opinion 512, IRS Circular 230, FINRA AI key topics, HHS/OCR HIPAA AI bulletin, FTC AI guidance, SEC AI-washing enforcement, EEOC AI-in-employment, NIST AI RMF, EU AI Act Article 4). REVIEW: Peter to confirm whether the IAPP-derived multiple is sourceable to a more precise published figure or whether the commentary should be tightened to remove the multiplier framing entirely.
Correction log
- 29 Apr 2026Initial publication 29 Apr 2026. Status set to Partial at publication because clause 6 commentary references an order-of-magnitude remediation-cost gap derived from the IAPP 2024 AI Governance Profession Report; the report characterises the gap as material but does not publish a precise multiple, so the wording is annotated source: our-estimate. REVIEW: Peter to source a precise figure or amend the commentary.
/holding/OPS-036/Embed this claimiframe + oEmbed
The card auto-updates when the claim's status, last-reviewed date, or correction log changes. Embedders never need to refresh — the card is rendered live from the canonical record.