Governing AI in a small firm comes down to three questions: where it is used, who would notice a bad output, and what that output would cost. The people who can answer them already work for you.

How a UK Small Business Can Govern AI Without a Compliance Team

Guides

By James Cotton · Last updated · 6 min read

Part of our topic guides on AI Governance & Data Strategy and AI Skills for Business.

By James Cotton, Founder, iO-Sphere

A small firm's advantage is the short distance

In a large company, the person typing a prompt and the person who would spot a wrong answer usually work in different teams, joined by a policy and a handoff. In a small firm they are often the same person. Or they share a desk. That short distance is what a small firm governs with.

Small firms are also earlier in their use of the tools. The ONS article "Artificial intelligence in UK businesses: 2023 to 2026", published 20 July 2026 from June 2026 fieldwork, found 28% of businesses with 0 to 9 employees use at least one AI technology. Among those with 250 or more, the figure was 49%.

DSIT has come to a similar view about size. In its December 2025 government response on AIME, it said a size-agnostic tool "struggled to meet the diverse needs of different users" and that "SMEs and start-ups often lack the time, funding, and personnel to dedicate to AI governance". Its future guidance is meant "to specifically target SMEs".

Finding where AI is already in use

The usual starting position in a small firm is that nobody holds the full picture. The tools arrived one at a time. Some came as features inside software you already pay for, others through one person signing up to a free account, and nobody wrote any of it down.

You can build the list in a week. Send everyone one message asking which AI tools they used last week, and for what. Check subscriptions and card statements for AI services. Look through the settings of your main business software for AI features that are switched on.

For each entry, record three things. The tool. The task it does. Whose data goes into it, whether that is customers, job applicants, staff or nobody. Where someone is unsure whether a feature counts as AI, it goes on the list anyway.

Expect patchy answers. Only 11% of businesses with 10 or more employees told the ONS that more than half their workforce had received AI-related training, and the top barriers firms named were identifying use cases, cost and lack of expertise. A team that has never been shown what to look for will miss some of its own uses.

Naming who would notice a bad output

Go down the list and write a name next to each use: the person who sees the output before it reaches a customer or decides something about a person. In a small firm there is usually one obvious name. Sometimes there is none. Those blanks are where to start.

In a small team, being equipped to judge comes down to three things. The checker knows how the tool tends to fail, so they know what to look for. They know which outputs touch personal data. And they have the standing to stop something going out.

A regulator looking at your AI would work from the UK's five cross-sector principles, set out in DSIT's government response of 6 February 2024: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; contestability and redress. They are non-statutory and applied by existing regulators, and there is no UK AI Act. They also make a usable checklist for the person you named.

Naming a checker does not settle who answers for the output if it does harm. Who is responsible for AI governance maps where that accountability belongs in a business.

Matching the controls to what a mistake would cost

Not every use deserves the same care. A first draft that someone reads before sending already has its check built in. Three kinds of use need more: anything customer-facing, anything that makes or shapes a decision about a person, and anything that puts personal data into the tool.

For those, add one control each. A named reviewer before the output leaves. A record of why a decision about someone was made. A rule on what data may be pasted in. Everything else can stay light, and a right-sized AI governance framework shows how to write the controls down at small scale.

On security, few firms have caught up. Of the 2,112 businesses in DSIT's Cyber Security Breaches Survey 2025/26, surveyed between August and December 2025 and reported in April 2026, 31% were using, adopting or actively considering AI. Of those, 24% had cyber security practices or processes to manage AI risks.

More specific rules are on the way. SI 2026/425, the Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, came into force on 12 May 2026. It requires the ICO to prepare a code of practice on developing and using AI and on automated decision-making. No deadline is set.

Until that code exists, the ICO's guidance on AI and data protection is the reference point. It was last updated on 15 March 2023. It now carries a banner saying it is under review because of the Data (Use and Access) Act.

Building the judgement inside your own team

The first need in a small firm is a shared baseline: everyone who touches AI able to recognise a costly use when they meet one. Data & AI fluency training is built for that, and it reaches the whole team at once.

One person then has to own the list, the names and the controls, and that person can be grown from within. iO-Sphere's apprenticeship for the role is Data & AI Governance, built on the Level 4 Data Protection & Information Governance Practitioner standard.

In their first month, the owner can do the work this guide describes on your real tools. They build the list of uses, put a name against each one, and set a control on every use that touches customers, decisions about people or personal data. That record gives them live material to learn on from the first day of Data & AI Governance.

Frequently asked questions

Do we need an AI policy document?

Nothing covered in this guide makes a document with that title a legal requirement. A policy written before you know which tools are in use is a guess at your own business. Start with the record of what is used and who checks it, and turn it into a policy later if a client or insurer asks for one.

What goes on the one-page record?

One line per AI use, answering the three questions in turn. Where it is used: the tool, the task and whose data goes in. Who would notice: the named checker, or a blank you intend to fill. What a wrong output would cost: whether the use is customer-facing, shapes a decision about a person or takes in personal data, and, if so, the one control you added.

Do we need a data protection officer?

Only if your firm meets one of the three conditions the ICO sets, which most small firms outside the public sector do not; Building or buying AI governance gives the three conditions and what each means for who does the work.

Does the EU AI Act apply to us?

It can apply to a UK firm where an AI system's output is used in the EU or where the firm sells AI-enabled products or services there, and what AI governance is places the Act in the wider picture.

Want to own AI governance in your organisation?

Our Level 4 Data & AI Governance programme builds the frameworks that make data trustworthy and AI accountable, funded through the Growth & Skills Levy.