AI Governance for SMEs: What You Actually Need Before You Deploy
Not a framework. Four things on two sides of paper — an inventory, a never-list, a named human, and what happens when it is wrong.
Most AI governance advice is written for companies with a compliance function. If you have 30 staff, one person doing IT alongside their real job, and a director who has just been asked "are we doing anything about AI?", almost none of it applies.
Here is the honest version: before you deploy anything, you need four things written down. Not a framework. Four things, on about two sides of paper, that you could hand to a client, an insurer, or the ICO without wincing.
Why this comes before the tool, not after
The usual order is to buy something, use it for a few months, then write a policy when a client asks. That order is expensive, because by then the decisions have already been made by whoever happened to be using the tool.
Staff adopt AI faster than any firm approves it. By the time governance arrives, client data has already been pasted into three consumer accounts nobody knows about, and the policy becomes an amnesty rather than a control. Writing it first costs an afternoon. Writing it afterwards means finding out what happened, which is a different and much worse afternoon.
The other reason is that a documented position is increasingly what customers ask for. Tender questionnaires now ask how you use AI, and so do larger clients before they send you their data. A firm that can answer in one page wins time back on every one of those.
The four things
One: an inventory of what you actually use. Which tools, on whose accounts, paid or free, and what data goes into each. This is the one nearly everybody skips and the one that does the most work. You cannot govern a tool you do not know is running, and every AI project that stalls tends to be standing on top of this gap. Start it as a spreadsheet, ask people in a way that gets you the truth rather than the tidy answer, and accept that the first version will be wrong.
Two: a list of data that never goes in. Written as actual categories of thing, not as a principle. "Client bank details." "Anything from a claim in dispute." "Health information." Principles get interpreted at 4pm on a Friday by someone who wants to go home; a list does not need interpreting. Keep it short enough to remember without looking it up.
Three: a named human on anything that leaves the building. Not review-in-principle — a named role who signs off before AI-drafted text reaches a client, a candidate, or a regulator. The failure mode is not the model inventing something. It is the model inventing something plausible on a Tuesday when everyone is busy and nobody reads it properly.
Four: what happens when it is wrong. Who gets told, how the output is corrected, and where that gets recorded. Every firm already has this process for human mistakes. Most have never asked whether it covers a mistake nobody made on purpose.
That is the whole thing. If your AI policy runs longer than a page and a half, the length is not making you safer, and it makes it less likely anyone reads to the end.
Where the tier matters more than the tool
One technical point worth knowing, because it changes the risk more than any policy wording: the consumer tier and the business tier of the same product are not the same product. Business and enterprise tiers of the major assistants generally do not train on your inputs and sit under a data processing agreement. The free consumer tier may do neither.
So "is ChatGPT safe for client data?" is usually the wrong question. Which account, on which tier, under whose contract — that is the question. Moving your team from personal logins to a paid business tenancy removes more risk than most policies do, and it takes a morning.
What the rules actually require of you
Two regimes are worth tracking, and neither is as dramatic as the headlines.
Under UK GDPR, AI is not a special category. If you process personal data through a tool, you need a lawful basis, a record of the processing, and meaningful transparency with the people affected. If AI makes or heavily influences a decision about a person — hiring, credit, tenancy — you are into automated decision-making territory, and the ICO's updated guidance on that is due in winter 2026.
The EU AI Act follows the market rather than the company registration, so a UK firm whose AI output lands in the EU can be in scope. The transparency duties went live on 2 August 2026; the high-risk obligations moved to 2 December 2027.
Neither requires a governance department. Both assume you can say what you use and why, which brings you back to the inventory.
Governance is not the same as caution
The point of writing this down is not to slow anything down. It is to make the first deployment boring enough to approve. Firms with the four things above tend to move faster, because each new tool is a decision against an existing position rather than an argument from scratch.
For the board-level version — why controls written once stop matching a model that keeps changing — the briefing on static controls and live models goes deeper.
If you want to know where you actually stand before writing anything, the AI readiness scorecard takes about five minutes, scores you across the areas above, and shows the result immediately. No email required.
Ready to integrate AI into your business?
See how Model Context Protocol (MCP) can connect your AI assistant to all your business tools. Book a call with our team to discuss your specific needs.
Book a Call (opens in a new tab)