I've reviewed a lot of AI policies recently. Some are two pages of vague guidance. Some are beautifully designed PDFs with sections on ethics, data security, and departmental use cases. A few are genuinely impressive documents.
Almost none of them would satisfy an auditor asking whether the business is compliant with the EU AI Act or ISO 42001.
That's not a criticism of the people who wrote them. The problem is that most AI policies are written to manage employee behaviour, not to demonstrate regulatory compliance. Those are two different jobs, and conflating them is the most common mistake I see.
This article is for the business owner who wants a straight answer to a question that's harder than it looks: what do I actually need?
Jake Whitford
Founder, Magnetic AI
Jake has run a manufacturing business and now helps UK SMEs adopt AI practically — process first, tools second. He works directly with every client from his Plymouth base.
Does any of this apply to me?
Yes, and this is where most conversations start on the wrong foot.
The EU AI Act became law in August 2024. It applies to any organisation that places AI systems on the EU market or puts them into service within the EU — which, for most UK businesses, means if you have any EU customers, partners, or staff, you're in scope. Brexit didn't remove that obligation.
For businesses operating purely within the UK, the picture is less clear for now. The UK government has chosen a principles-based approach rather than legislation, but UK regulators — the ICO, FCA, CMA — are all developing AI guidance within their own domains. Getting compliant with the EU framework now is a sensible hedge regardless of where your customers are.
ISO 42001 is a voluntary international standard for AI management systems, published in 2023. You're not legally required to achieve certification, but increasingly, enterprise clients and public sector procurement are asking for evidence of structured AI governance.
The difference between a use policy and a management system
An employee use policy tells your staff how to use AI tools safely and responsibly — data security, authorisation, approved tools, incident reporting. That's genuinely valuable, and every business using AI should have one.
A management system is something different. It's the documented framework that demonstrates your organisation understands what AI systems it uses, has assessed the risks, has appointed accountable people, measures outcomes, and improves over time.
Think of it this way. A use policy is the highway code. A management system is the evidence that you have a roadworthy vehicle, a licensed driver, and a process for servicing the car. Both matter. But if someone asks whether you're compliant, showing them the highway code doesn't answer the question.
What ISO 42001 actually requires
Seven core things you need to demonstrate.
Define scope
Which AI tools, systems, and processes fall within your management system, and which don't.
Document organisational context
What your business does, who your stakeholders are, and what external factors affect how you use AI.
Leadership commitment
Senior leadership takes active, documented responsibility for the AI management system and allocates resource to it.
Formal planning
Identify risks and opportunities from your AI use, set measurable AI objectives, and plan how to achieve them.
Documented competence
A record of who needs what capability, how it will be developed, and how you'll verify it.
Operational lifecycle management
Manage AI systems from selection and procurement through deployment, monitoring, and decommissioning — including impact assessments before deploying new systems.
Performance evaluation & improvement
Internal audits, management reviews, and a documented process for acting on what you find.
None of this needs to be complicated. For an SME, the entire framework can live in a handful of documents. But it does need to exist as a system, not just a policy.
What the EU AI Act actually requires
The Act takes a risk-based approach. The first thing it requires is classifying every AI system your business uses according to its risk level.
Prohibited
Systems the Act bans outright — social scoring, real-time biometric surveillance, AI designed to manipulate people subliminally. Most SMEs won't be near this category.
High-risk
AI used in recruitment and HR decisions, credit scoring, education, healthcare, critical infrastructure. If you're using AI to screen CVs or make consequential decisions about people, you may be here. Triggers conformity assessments, technical documentation, human oversight, logging, and EU registration.
Limited-risk
Chatbots and similar. Transparency obligations apply — if a customer interacts with an AI, they need to know.
Minimal-risk
Most general business productivity use of tools like ChatGPT or Claude. No specific obligations beyond basic good practice.
The Act also distinguishes between providers (organisations that develop or place AI systems on the market) and deployers (organisations that use AI systems built by others). If you're using Microsoft Copilot or ChatGPT, you're a deployer. If you're building AI-powered products for clients, you may be a provider. The obligations differ.
What your AI policy framework actually needs to cover
A compliant AI framework for an SME needs to operate at two levels.
Management system layer
Scope, governance, objectives, risk assessment processes, impact assessment procedures, and review cycles. For most SMEs, a concise framework document — ten to fifteen pages — rather than a sprawling manual.
Operational layer
The employee-facing use policy. Tool authorisation, data security requirements, acceptable use, do's and don'ts, departmental guidance, and incident reporting. What most businesses already have.
What most SMEs are missing
AI system register
A live inventory of every AI tool or system in use, with its risk classification, data handling status, and approval record.
Impact assessment process
A structured way to evaluate new AI tools before deployment — required under the EU AI Act for high-risk systems.
Board-level governance structure
Clear accountability at director level — not just at the operational level — showing who is responsible for AI governance.
The questions I get asked most often
Do I need ISO 42001 certification?
Probably not right now, unless your clients are specifically asking for it or you're building AI products for regulated sectors. But building towards the standard is good practice regardless, because the discipline it imposes — defining scope, assessing risk, reviewing performance — makes your AI use better managed even if you never sit an audit.
Can I use a template AI policy?
As a starting point, yes. But a template only gets you to the use policy layer. It won't give you a management system, and it won't classify your AI systems under the EU AI Act. You need to do that work specific to your business.
Who should own this?
Someone at director or senior management level needs to own AI governance, not just an operational AI lead. ISO 42001 is explicit about leadership responsibility, and the EU AI Act places accountability on organisations, not individuals. That means if something goes wrong, it comes back to the business. Board-level visibility matters.
How often do I need to update it?
The EU AI Act is still being implemented in phases, with full compliance for most systems required by August 2026. The UK regulatory picture will continue to develop. Your framework should be reviewed at least annually, and any significant new AI deployment should trigger a review of your impact assessment before go-live.
The honest summary
A well-written employee use policy is necessary but not sufficient. It manages day-to-day behaviour, and that's valuable. But it doesn't tell an auditor, a client, or a regulator that your organisation has thought seriously about AI risk, governance, and accountability.
The businesses that will be in the strongest position over the next two to three years are the ones building the management system layer now, before it's demanded of them.
A clear register of AI systems, a documented impact assessment process, an honest risk classification, and a governance structure with named accountability at director level — that's the framework most SMEs are missing, and it doesn't require a compliance department to build it.
Get those foundations in place, and the use policy becomes what it should be: the operational rulebook that sits on top of a structure that actually holds.
Go deeper
Want help building an AI governance framework that actually holds up?

