AI policy for UK SMEs
A good policy gives people a safe, workable answer at the point they need one. It should set boundaries, name responsibility and leave no doubt that human judgement still matters.
A good policy gives people a safe, workable answer at the point they need one. It should set boundaries, name responsibility and leave no doubt that human judgement still matters.
An AI policy for UK SMEs should be short enough to read before someone pastes text into a tool. Two pages of clear rules, backed by practical guidance, will do more than twenty pages of legal language stored in a forgotten folder. The policy is not a substitute for contracts, privacy work or specialist advice. It is the everyday instruction that stops well-meaning staff making an avoidable mistake.
Write it for the person preparing a client email, analysing a spreadsheet or drafting a job advert. Tell them which tools they may use, which data is off limits, when a human must check output and who can answer a difficult question. Link it to your approach to shadow AI, rather than pretending that a rule alone will stop it.
This is general information, not legal advice. Data protection, employment, sector rules and contracts may require advice tailored to your organisation and use case.
Name approved tools and explain why approval matters. A tool is not approved merely because an employee has created an account or because it is popular. Approval should consider its plan, contract, data settings, retention, connected services, access controls and the particular task. Keep a short register: tool name, permitted use, owner, data limits, contract status and review date.
The policy should state that staff must not put personal data, special category data, customer confidential information, passwords, API keys, legal advice, commercially sensitive bids or unpublished financial information into an unapproved tool. For approved tools, set narrower rules. “Approved” does not mean every document and every use is permitted.
Keep the register accessible, not just available on request. A one-screen table on the intranet is enough for most teams. It should make it obvious which account to use, what data limit applies and who can approve a new use. The aim is to remove the everyday uncertainty that sends people back to personal tools.
The policy needs one plain rule: the person using AI remains responsible for the work they submit, send or act upon. AI can draft, summarise, extract and suggest. It cannot accept a contractual risk, reassure an unhappy client or explain why a figure is correct. Require a human check that is proportionate to the consequence. A spelling suggestion is not a loan decision.
Be specific about what “check” means in your setting. It may mean opening the source document, recalculating a sample, checking a cited regulation, or asking a subject expert to approve a recommendation. For higher-risk work, record who reviewed it and what evidence they used. AI education for the team should teach this judgement, not just prompt-writing.
There is no useful blanket rule that every assisted sentence must carry a label. Decide disclosure by impact and expectation. A client should be told where AI materially shaped a deliverable, where a contract or professional rule requires it, or where the client would reasonably assume specialist human work. Do not use disclosure to excuse poor checking; it is a matter of honesty and context.
UK GDPR applies when AI use involves personal data, whether that data is used to train, test or operate an AI system. The ICO expects organisations to consider the normal data-protection principles, including a lawful basis, fairness, transparency, purpose limitation, data minimisation, accuracy, security and accountability. Your policy should direct staff to the privacy or data owner before a new use of personal data begins.
A useful rule is that a policy opens the right conversation; it does not approve processing by itself. The organisation still needs to understand the roles of supplier and customer, the contract and data-processing terms, international transfers where relevant, retention, security measures and how people will be informed. A DPIA may be required where processing is likely to result in high risk to people. Data readiness is therefore part of governance, not a later technical detail.
For ordinary office uses, this may mean that anonymised examples and approved templates are sufficient. For a proposal to analyse customer records, monitor employees, profile people or make recommendations that materially affect them, the question is different. Pause before the trial, describe the purpose and data flow, decide who is responsible for the processing, and involve the people who can assess privacy, security and fairness. A quick prototype is not a reason to skip the assessment.
The EU AI Act is not a general UK-only rule. It can be relevant to a UK organisation that places an AI system or general-purpose model on the EU market, deploys a system in the EU, or produces output used in the EU. The obligation depends heavily on the organisation’s role and the system’s use. A firm buying ordinary office software for UK-only internal work should not treat it as the centre of its policy.
It matters more where a UK firm sells an AI-enabled product into the EU, operates across borders, or uses AI in a sensitive area such as employment. Keep the policy practical: require escalation before any cross-border launch, product feature or automated decision that could affect people significantly. Obtain specific advice where the use case warrants it.
Give the policy an owner with enough authority to say yes, no or not yet. In a small organisation this may be an operations director supported by the person responsible for data protection and IT. The owner should maintain the approved-tool list, record exceptions, collect questions from staff and bring material changes to leadership. Avoid making one junior enthusiast responsible for governance without support.
Review the policy every six months and after a material incident, a new major tool, a new automated decision, or a change in the organisation’s data or client commitments. The review should use real questions people asked, not a ceremonial date change. AI consulting can help turn those questions into proportionate controls where the team is unsure.
Give staff a usable reporting route as well. They should know how to ask before using a new service, flag an output that looks wrong and report information entered into the wrong place. The first response should focus on containing the issue and learning what happened. Deliberate misuse is a separate management matter; ordinary uncertainty should not be driven underground. A short AI policy for UK SMEs should make that route clear.
A policy should help a busy team make sound decisions, not create theatre. If you need help turning current use into clear rules, start with the tools, data and decisions already in play.
A short policy is strongly advisable as soon as staff use AI for work, particularly where they handle client information or personal data. It gives employees clear boundaries and provides evidence that the organisation has taken responsible use seriously. The policy does not replace data-protection, employment, contractual or sector-specific obligations, which depend on the use case.
Possibly, but only after the organisation has assessed the specific tool, account, contract, processing role, data settings and purpose. The fact that a tool is on an approved list does not create a blanket permission for all personal data. Higher-risk processing may require a DPIA and additional controls before use.
Not for every low-impact use. Tell clients where AI materially contributes to work they reasonably expect to be done by a person, where a contract, professional rule or client instruction requires disclosure, or where the use could affect their interests. Set a clear internal escalation route for uncertain cases.
Review it at least every six months, and sooner when you introduce a significant new tool, connect a system to company data, change a customer commitment, discover unsafe use or begin a use case that affects people more directly. A review should update the actual rules and tool register, not just change the document date.
Keep reading
Talk to us about AI
A policy should help a busy team make sound decisions, not create theatre. If you need help turning current use into clear rules, start with the tools, data and decisions already in play.
Replies come from the person who would do the work, usually the same day.