A risk-based starting plan for UK SMEs covering acceptable use, data protection, supplier review, pilots and accountable ownership.
The risks that actually apply to a small business
Most AI safety writing is aimed at organisations with a legal department. For a UK SME, four risks account for nearly everything that realistically goes wrong.
| Risk | What it looks like in practice | How likely |
|---|---|---|
| Data leakage | Staff pasting customer data or contracts into a free consumer AI account | Very high — it is almost certainly happening already |
| Confidently wrong output | A quote, calculation or client answer that is plausible and incorrect | High |
| Regulatory exposure | Personal data processed with no lawful basis, DPA or record | Medium, rising with ICO attention |
| Over-reliance | Staff stop checking, quality degrades quietly | Medium |
Notice what is not on that list: existential AI risk, model bias in abstract, or anything requiring an ethics committee. For an SME, the practical exposure is mundane and manageable.
Shadow AI is the actual starting position
Almost every SME that thinks it has not adopted AI has, in fact, adopted AI — informally, through staff using free accounts on personal logins.
That is the worst of both worlds: the organisation gets none of the governance and all of the exposure, because consumer tiers typically use input for training and provide no data processing agreement.
The fix is not a ban. Bans reliably fail — staff use their phones instead, and you lose visibility entirely. The fix is to make an approved option available and easy, then close the unapproved one.
Five decisions that cover most of the risk
1. Buy business tier, block consumer tier
The single highest-value decision. Business and enterprise tiers contractually exclude your data from model training, provide a DPA, and give you admin controls and audit logging. Consumer tiers do none of that.
2. Write one page of rules
Not a policy document nobody reads. One page:
- Approved tools: [the ones you bought]
- Never put in: customer personal data unless the tool is approved for it, bank or payment details, passwords, unreleased commercial information, anything covered by a client NDA
- Always check before sending: anything going to a customer, anything with numbers in it, anything with a legal or contractual effect
- Ask [named person] if unsure
3. Keep humans on consequential decisions
Anything affecting a person's money, employment, service or rights gets human review. Quotes, invoices, contracts, hiring decisions, complaint responses, dismissals.
4. Record it
If you process personal data with AI, it belongs in your record of processing activities with a lawful basis, retention period and transfer mechanism. This is a small amount of paperwork that turns an unassessed risk into a documented decision.
5. Train people on failure modes, not features
Most staff training covers what the tool can do. The valuable training is what it gets wrong: fabricated citations and figures, outdated information, confident tone regardless of accuracy, and arithmetic that looks right.
Recruitment and HR need extra care
If you use AI anywhere in hiring or people management, that is a materially higher-risk activity — high-risk under the EU AI Act if you have any EU footprint, and the subject of specific ICO guidance in the UK. Human decision-making, candidate transparency and bias testing all become necessary rather than optional. See our guide on AI automation for recruitment agencies for the detail.
Where UK rules currently sit
The UK has not implemented an AI Act equivalent. It is pursuing a principles-based, regulator-led approach, so your existing obligations — UK GDPR, employment law, consumer protection, sector regulation — are the binding constraints.
Two practical implications:
- The ICO is the regulator that matters most for most SMEs, and its AI guidance is readable and specific.
- If you have EU customers or an EU entity, the EU AI Act may apply to you regardless of UK policy. Check this rather than assuming UK-only exposure.
A realistic first month
| Week | Action |
|---|---|
| 1 | Ask staff, without blame, what they are already using. You will be surprised |
| 2 | Choose and buy one approved business-tier tool |
| 3 | Publish the one-page rules; run a 45-minute session covering failure modes |
| 4 | Block consumer equivalents; add the tool to your ROPA |
That is genuinely sufficient for most small businesses to move from unmanaged exposure to a defensible position.
Frequently asked questions
Do we need an AI policy if we only use ChatGPT occasionally?
One page, yes. The effort is trivial and it is the document that demonstrates you thought about it.
Is UK GDPR really a problem for normal AI use?
Only if you process personal data without a basis, agreement or record. Using AI to draft a blog post raises no issues. Using it to analyse customer records does.
What if staff refuse to stop using their own accounts?
Usually a sign the approved tool is worse or harder to access. Fix that first — enforcement without a good alternative just moves the behaviour out of sight.

