AI governance for a UK business means having a clear, proportionate framework for how your organisation uses AI — which tools are approved, how data is handled, where humans must review output, and who's accountable. For most UK SMEs, the EU AI Act applies if you have any EU customers, partners or staff, and a basic AI policy needs six things: scope, approved tools, data handling rules, human oversight, incident reporting, and named accountability. Good governance isn't bureaucracy — it's what lets you adopt AI with confidence rather than crossing your fingers.
Jake Whitford
Founder, Magnetic AI
Jake has run a manufacturing business and now helps UK SMEs adopt AI practically — process first, tools second. He works directly with every client from his Plymouth base.
What AI governance means in practice
AI governance is the framework that lets your business use AI deliberately rather than by accident. In practice, it means knowing which AI tools you use, what they're used for, what data goes into them, where a human checks the output, and who's responsible when something needs a decision.
The most common mistake is confusing an employee use policy with a governance framework. A use policy tells your team how to behave — and that's genuinely valuable. But it doesn't tell an auditor, a client, or a regulator that your organisation has thought seriously about AI risk and accountability. Those are two different jobs.
Think of it this way: a use policy is the highway code. A governance framework is the evidence that you have a roadworthy vehicle, a licensed driver, and a process for servicing the car. Both matter — but showing someone the highway code doesn't prove the rest.
For an SME, none of this needs to be complicated. The entire framework can live in a handful of documents. But it does need to exist as a system, not just a policy.
The EU AI Act obligations for UK businesses
The EU AI Act became law in August 2024 and takes a risk-based approach. It applies to any organisation that places AI systems on the EU market or puts them into service within the EU — which, for most UK businesses, means if you have any EU customers, partners, or staff, you're in scope. Brexit didn't remove that obligation.
The first thing the Act requires is classifying every AI system your business uses according to its risk level:
Prohibited
Systems the Act bans outright — social scoring, real-time biometric surveillance. Most SMEs won't be near this category.
High-risk
AI used in recruitment, HR decisions, credit scoring, education, healthcare. If you screen CVs or make consequential decisions about people, you may be here. Triggers conformity assessments, documentation, human oversight and logging.
Limited-risk
Chatbots and similar. Transparency obligations apply — if a customer interacts with an AI, they need to know.
Minimal-risk
Most general business productivity use of tools like ChatGPT or Claude. No specific obligations beyond basic good practice.
The Act also distinguishes between providers (organisations that develop or place AI systems on the market) and deployers (organisations that use AI built by others). If you're using Microsoft Copilot or ChatGPT, you're a deployer. If you build AI-powered products for clients, you may be a provider — and the obligations differ.
Full compliance for most systems is required by August 2026, with the picture continuing to develop. For UK-only businesses, the UK's principles-based approach applies through regulators like the ICO, FCA and CMA — but aligning with the EU framework now is a sensible hedge regardless of where your customers are.
What a basic AI policy should contain
A workable AI policy for an SME doesn't need to be long. It needs to cover six things clearly:
Scope
Which AI tools, systems and processes are covered by the policy, and which aren't. Without a defined scope, a policy is impossible to enforce.
Approved tools
A clear list of which AI tools are approved for use, and for what purposes. This stops shadow AI use and gives your team confidence they're doing the right thing.
Data handling rules
What data can and can't be entered into AI tools. Personal data, client information and commercially sensitive material need clear rules — a genuine UK GDPR consideration.
Human oversight
Where a human must review AI output before it's used or sent externally. For most SME use cases, AI should produce a first draft, not a final answer.
Incident reporting
A simple way for staff to flag when something goes wrong — a bad output, a data concern, a tool behaving unexpectedly. Early visibility prevents small issues becoming real problems.
Accountability
Who owns AI governance at a senior level. ISO 42001 and the EU AI Act both place accountability on the organisation, so a named director-level owner matters.
Beyond the policy itself, the governance layer most SMEs are missing is an AI system register — a live inventory of every AI tool in use, with its risk classification and approval record — and a simple impact assessment process for evaluating new tools before deployment. These are required under the EU AI Act for high-risk systems and are good practice regardless.
Check where your business stands
Free AI Governance Healthcheck
Not sure whether your current AI policy would survive a serious compliance question? Take the free AI Governance Healthcheck — a short assessment that scores your governance across the areas that matter and gives you practical, prioritised advice.
Want help building a governance framework that holds up?
Magnetic AI helps UK SMEs build proportionate AI governance — from a first policy to a full management system. Book a free, no-pressure discovery call.

