AI Self-Governance for Small Businesses: Part 2
Ben Johnson (BJ)
CEO and Founder of Freya Systems
Mary Kate Lo Conte (MKL)
CEO and Partner of Merz Branding
Part 2: Why an AI Policy Is Not Enough
In Part 1, the conversation focused on the risks and responsibilities small businesses need to understand as AI becomes part of everyday work, from confidentiality and copyright to client trust, brand consistency, and creative ownership. Part 2 turns to what business owners can do now.
The short answer: create a policy, but do not stop there. A policy tells people the rules. A framework helps teams make discerning decisions, protect information, review outputs, and use AI responsibly without slowing innovation.
If a small business has no formal AI governance yet, what should the owner do first?
BJ: Start. That sounds blunt, but it is the truth. Whether you like it or not, people are bringing AI into your business. The best time to put governance in place was yesterday. The second best time is today. Begin with the basics: what tools are approved, what information is off-limits, who reviews outputs, and when employees should ask before using AI.
MKL: I would add: create your AI usage talking points. Even if the full policy and framework are still being developed, your team needs consistent language now. Most people in a small business interact with clients in some way, so the owner cannot be the only person who knows how to answer, ‘How are you using AI?’
What is the difference between an AI policy and an AI framework?
MKL: The policy is what lives in your employee handbook. It is the official statement of what is allowed, what is not allowed, and what the company expects. The framework is what helps your team successfully integrate AI into everyday workflow and culture. That is the piece most businesses skip.
BJ: A policy should be concise and clear: do not use non-approved tools, do not put sensitive client data into open systems, do not publish AI-generated output without review. The framework is more practical. It helps employees decide which tool to use, what data can go in, how to check the result, when to escalate, and how to keep a human in the loop.
What should employees never paste into AI tools?
MKL: Employees should not enter confidential or proprietary information into an AI tool, including client names, logos, unreleased work, NDA-protected materials, private employee or customer data, company processes, or client-specific restrictions, unless the tool and use case have been approved.
BJ: A simple test is: would you be comfortable emailing this to an outside vendor you do not know? If the answer is no, do not paste it into a general AI tool. Use paid tools at a minimum, and where possible, use closed or siloed environments that do not train on your information. If you do not have cybersecurity guidance, do not start connecting AI to your email, calendar, files, or client systems just because the button is there. Treat the tool like an island until someone qualified has reviewed the bridge.
How do you encourage AI use without killing creativity or experimentation?
MKL: You cannot make AI governance feel like the Department of No. People will either avoid it entirely or quietly work around it. We use a tiered approach: a primary secure platform, integrated workspace tools, and then approved tools that can be used only with anonymized information. That gives people room to experiment while still protecting the business.
BJ: AI champions can help here. They do not need to be a huge committee or a group of technical experts. They need to be people who understand the policy, can translate it into real work, and can bring back examples of what is working. AI is so broad that someone will always find a use case the owner did not think of. You want that energy, but with guardrails.
MKL: We also like the idea of shared prompt sessions. What is working? What is not? What prompts are helping? Which ones are producing generic soup? When prompts and examples live somewhere everyone can access, AI becomes part of the culture instead of a secret side hustle.
How much human review is enough?
BJ: More than people think. Fact-checking AI output can be harder than creating something yourself, because the draft may sound confident even when it is wrong. Our process starts before the prompt: what is the goal, which tool is appropriate, what information is safe to use, and what must be checked before the work is shared?
MKL: For creative and branding work, review is not just about factual accuracy. It is about judgement. Does this sound like the client? Does it reflect the brand? Is it distinctive? Is it repetitive? We have seen AI generate ideas for very different types of clients that start to look suspiciously similar. That is when human discernment matters.
BJ: The framework should make the review step explicit. Do not hand off your fact-checking responsibility to the next person in the chain. If you used AI, you own the review before it goes to someone else.
What should businesses tell clients or prospects about AI use?
MKL: Use plain language. For example: we use AI to support research, ideation, planning, and efficiency, but human strategy, creative judgment, and final execution drive the work. Then explain how client information is protected. If you are not putting client data into open tools, say it. If you are using a closed environment, say it. If you require human review before anything is delivered, say it.
BJ: I always encourage our clients to be transparent with their clients about their use of AI. Transparency protects trust. On our reports, we’ve used language noting that the material was compiled with the support of AI. That’s not a magic legal shield, but it changes the conversation. It shows good faith if something ever gets questioned.
MKL: It also helps qualify the right clients. If a prospect is only interested in faster and cheaper, that tells you something. If they value thought, judgment, confidentiality, and originality, your AI governance approach can become a trust signal.
How should small businesses protect themselves from AI washing?
MKL: This reminds me of the early SEO days. Some clients did not know enough to evaluate the work, and bad vendors took advantage of that. AI has some of the same potential. There are already examples of companies being penalized for misleading claims about AI-powered services. Small business owners need to ask better questions before buying into a pitch.
BJ: Exactly. Not everything with ‘AI’ bolted onto the end is actually AI, and not every AI tool solves a meaningful business problem. Learn enough of the basics to ask: what does the tool do, what data does it need, how is the data protected, does it train on our information, what review controls exist, and how do we measure value? Sometimes the answer is that you do not need AI. You need a better workflow. Or frankly, a spreadsheet.
What should a small business owner do this week?
BJ: Take inventory. What AI tools are people using now? Which are paid, which are free, and which are connected to company systems? Then identify approved tools, prohibited uses, and the information that can never go into an open system. Appoint one or two AI champions and create a process for reviewing new tools or use cases.
MKL: Write the talking points. They do not need to be perfect. They need to be clear enough that your team can answer client questions consistently. Then work with HR on the policy and IT or cybersecurity support on the framework. This should not be a one-and-done initiative. AI governance is now part of how the business works.
BJ: The goal is not to slow the business down. The goal is to keep the business from walking into avoidable problems while still capturing the value of AI. Policy gives you the rules. Framework gives your team the discernment. You need both.
MKL: And the businesses that get this right will not be the ones shouting about AI the loudest. They will be the ones using it with enough intention that clients, employees, and partners can trust the work on the other side.
Ben Johnson is CEO and Founder of Freya Systems, a Media, Pennsylvania-based data analytics and AI solutions firm he established in 2009. For more than 15 years, Ben has helped organizations in aviation, utilities, manufacturing, defense, and energy make data more useful, actionable, and valuable. His work focuses on AI strategy, machine learning, workflow efficiency, predictive maintenance, and practical ways to balance automation with human judgment. A Goldman Sachs 10,000 Small Businesses alumnus, Ben leads Freya with a focus on curiosity, collaboration, and sustainable solutions that support both innovation and organizational well-being. Learn more about Freya Systems at freyasystems.com
Mary Kate Lo Conte is CEO and Partner of Merz Branding, where she helps healthcare, life sciences, and nonprofit organizations build brands that drive meaningful growth. With more than 30 years of experience, Mary Kate translates research and insights into clear strategy, compelling creative, and consistent execution. Her work focuses on positioning, messaging, brand strategy, and practical ways to help organizations build trust and show up with clarity across every touchpoint. She holds an MBA in Marketing from Drexel University and is a national conference speaker on branding, bringing a strategic, hands-on perspective to building brands with long-term impact. Learn more about Merz Branding at merzbranding.com


