// in this post
About a quarter of UK businesses were using some form of AI by the end of 2025, up from roughly one in ten two years earlier, according to the Office for National Statistics. Almost none of them have a policy that's kept pace. That gap, not the technology itself, is where the real risk sits.
This is a practical AI usage policy for a UK small business: what to actually put in it, and what UK regulators expect, without wading through five overlapping regulatory regimes to work it out yourself.
Why "we'll just be careful" doesn't hold up
There's no single UK AI law to comply with. The government's approach is deliberately principles-based: existing regulators (the ICO for data protection, the FCA for financial services, the CMA for competition, and others in their own sectors) apply existing law to AI, guided by five cross-sector principles from the AI white paper: safety, transparency, fairness, accountability, and contestability. If you handle EU customers or their data, the EU AI Act can reach you too, regardless of where your business is based.
That sounds like room to improvise. In practice it means the burden sits with you to translate five abstract principles into something your team can actually follow, and "we trust people to use good judgement" is the absence of a policy, not a policy in itself. It's also exactly the gap the ICO's own internal AI use policy, published for its own staff, exists to close: approved tools, what can't go into them, and who's responsible. The regulator that would investigate you has already written down what it expects of itself.
What actually goes in the policy
Which tools are approved, and for what. Name them. "Use AI sensibly" isn't a rule anyone can follow or break. "Claude and Copilot are approved for drafting and internal analysis; personal ChatGPT accounts are not approved for anything containing client or employee data" is.
What data can and can't go into each one. A simple three-tier split covers most small businesses: public information (fine anywhere), internal business information (fine in approved tools only), and client, employee, or regulated data (needs a specific sign-off, or is banned outright from tools that haven't been checked). This is the single most common gap: people don't misuse AI maliciously, they just don't know where the line is until they've already crossed it.
Who owns the decision to approve a new tool. One named person or small group, not "IT" as an abstraction. When someone in the business finds a tool that would help, there needs to be an actual person to ask, and an actual answer within a reasonable time, or people will just use it anyway and stop asking.
A lightweight risk tier for anything higher-stakes. Not every use needs the same scrutiny. A tool drafting internal meeting notes is a different risk to one screening job applications or scoring customers, where the ICO's incoming guidance on automated decision-making requires documented human oversight of the outcome. If your team is building its own tools rather than just using off-the-shelf ones, the risk-tiering approach in our vibe-coding safety piece works the same way here: classify by what data's involved and what happens if it goes wrong, then scale the review to match.
What happens when something goes wrong. Who gets told, how fast, and what the fix looks like. This matters most for the specific failure modes that show up with autonomous AI agents rather than simple chat tools, covered in more depth in our piece on agent risks and guardrails: a tool left running after a project ends, or one that's been fed instructions it shouldn't have followed. A policy that only covers the moment of first use and not what happens afterward isn't finished.
The one thing most policies skip: knowing what's actually running
Keep a short register: what tools exist, who owns each one, what data they touch, what they're approved for. It sounds like paperwork, and it is, but it's the difference between answering a data subject access request in an afternoon and not being able to answer it at all. It's also the practical anchor for the lawful basis you need under UK GDPR: for most internal AI use, "legitimate interests" is the usual working basis, but it needs a documented assessment behind it, not just an assumption nobody wrote down.
None of this is theoretical. The incidents that actually happen tend to trace back to exactly these gaps: a tool nobody approved, data nobody classified, a decision nobody owned.
Where to start
Write the three-tier data split and the approved-tools list first, they're the two things that stop the most common mistakes and take an afternoon to draft. The risk-tiering and the register can follow once the basics are in place. If you'd rather work through this with someone who's built it for other organisations, that's the governance and policy strand of a Discovery engagement. Get in touch if you'd rather talk it through first.
FAQ
Does the UK have an AI law SMEs need to comply with?
Not a single one. The UK has taken a principles-based approach: existing regulators (the ICO, the FCA, the CMA and others) apply existing law, especially UK GDPR, to AI within their own sectors, guided by five cross-sector principles from the government's AI white paper: safety, transparency, fairness, accountability and contestability. If you handle EU customers or data, the EU AI Act can also apply regardless of where you're based.
What should an AI usage policy for a small business actually include?
Five things: which tools are approved and for what, what data can and can't go into each one, who owns the decision to approve a new tool, a lightweight risk tier for anything higher-stakes, and what happens when something goes wrong. It needs to be short enough that people actually read it, not a compliance document nobody opens.
Do I need a lawful basis under UK GDPR to use AI tools with personal data?
Yes, if the tool touches personal data at all. For most internal business use, 'legitimate interests' is the usual working answer, but it needs a documented Legitimate Interests Assessment behind it, not just an assumption. If the AI is making or shaping a decision about a real person, such as filtering job applications or scoring customers, the ICO's guidance on automated decision-making requires documented human oversight.
What is an AI register, and do I need one?
A simple log of what AI tools are actually running in your business, who owns each one, what data it touches, and what it's approved for. It sounds bureaucratic, but it's the thing that saves you when someone leaves, a tool has an incident, or a regulator asks what you're actually doing. Most UK SME governance frameworks that hold up in practice have one.