Small businesses already have an AI governance problem
Staff adoption can happen before formal approval
Team members often adopt AI tools to work faster before any policy exists. That is normal, but it means the first governance step is simply understanding what is already happening.
The same AI tool can create very different risks
One tool can be harmless for public research and risky for client data. Risk sits with the use case and the information involved, not the tool alone.
Start with the AI uses that actually exist
Before writing rules, list the real uses: who uses what, for which tasks, with what information. This short inventory makes every later control more accurate.
Five practical controls for an SME
Name an accountable owner
Give each significant AI use a named owner so responsibility is clear.
Maintain an AI use register
Keep a simple list of tools and use cases, updated as things change.
Set safe-use boundaries
Define what information may go into which tools, using the Green, Amber and Red boundaries.
Require human review where consequences matter
Keep a person in the loop before AI output drives a material decision or external action.
Keep enough evidence to review what happened
Retain light records of approvals and reviews so you can explain decisions later.
What should stay out of public AI tools?
Personal, confidential, privileged or regulated material should stay out of public AI tools unless a separately approved secure route exists. When in doubt, treat it as Red.
AI policy, AI register and AI risk register
What each artefact does
The AI policy sets rules, the use register records where AI is used, and the AI risk register records specific risks, owners and controls.
Why one document cannot replace the others
A policy without a register is hard to enforce; a register without risk assessment misses consequences. Together they form a workable system.
When lightweight governance is no longer enough
As AI touches higher-consequence decisions, regulated data or customer outcomes, add deeper assessment, testing and oversight. The AI Governance Starter Pack is a proportionate way to assemble these.