Small businesses already have an AI governance problem

Staff adoption can happen before formal approval

Team members often adopt AI tools to work faster before any policy exists. That is normal, but it means the first governance step is simply understanding what is already happening.

The same AI tool can create very different risks

One tool can be harmless for public research and risky for client data. Risk sits with the use case and the information involved, not the tool alone.

Start with the AI uses that actually exist

Before writing rules, list the real uses: who uses what, for which tasks, with what information. This short inventory makes every later control more accurate.

Five practical controls for an SME

Name an accountable owner

Give each significant AI use a named owner so responsibility is clear.

Maintain an AI use register

Keep a simple list of tools and use cases, updated as things change.

Set safe-use boundaries

Define what information may go into which tools, using the Green, Amber and Red boundaries.

Require human review where consequences matter

Keep a person in the loop before AI output drives a material decision or external action.

Keep enough evidence to review what happened

Retain light records of approvals and reviews so you can explain decisions later.

What should stay out of public AI tools?

Personal, confidential, privileged or regulated material should stay out of public AI tools unless a separately approved secure route exists. When in doubt, treat it as Red.

AI policy, AI register and AI risk register

What each artefact does

The AI policy sets rules, the use register records where AI is used, and the AI risk register records specific risks, owners and controls.

Why one document cannot replace the others

A policy without a register is hard to enforce; a register without risk assessment misses consequences. Together they form a workable system.

When lightweight governance is no longer enough

As AI touches higher-consequence decisions, regulated data or customer outcomes, add deeper assessment, testing and oversight. The AI Governance Starter Pack is a proportionate way to assemble these.