
AI use without rules is a legal risk
Three-quarters of UK SMEs have no AI governance policy, yet leaders remain legally accountable for AI outputs regardless of which vendor supplied the tool. This article replaces the 'no policy, no liability' myth with a practical, lightweight governance approach any business can act on.


The assumption is understandable. You are using Microsoft Copilot, or OpenAI's ChatGPT, or some other tool built and maintained by a large technology company. Surely if something goes wrong, the legal exposure sits with them? It is a reasonable read of the situation, and it is wrong. New UK research shows three-quarters of British businesses are operating without a formal AI governance policy. Nearly half of business leaders are unaware they can be held legally accountable for the outputs their teams generate using third-party AI tools. The gap between assumption and legal reality is wide, and for compliance officers and business leaders at UK SMEs, it is worth closing quickly.
Why the 'no policy, no problem' myth took hold
The myth has genuine logic behind it. AI tools are products. You buy or subscribe to them. The terms of service are written by the vendor. Most business leaders, already stretched across a dozen priorities, reasonably conclude that accountability follows the contract. If the tool hallucinates a fact, misrepresents a figure, or generates something that causes a complaint, the vendor is exposed, not the organisation that used it.
This logic works well for a photocopier. It does not work for AI.
With AI tools, your organisation is not just a passive consumer. You are directing the tool, framing the prompts, selecting which outputs to use, and sending those outputs to clients, regulators, or internal decision-makers. You are the deployer. That role carries accountability under existing UK law regardless of which company built the underlying model.
What the evidence actually shows
The data here is not ambiguous. Research published by UKTN in August 2026, drawing on Startups.co.uk survey data, found that 75% of UK businesses operate without a formal written AI governance policy. The same research found that 46% of UK business leaders did not know they could be held legally accountable for the integrity and ethical output of third-party AI models used in their organisation.
That figure is striking. Nearly half of the people making decisions about AI use in their businesses have a materially incorrect understanding of their legal position.
On the regulatory side, the picture is becoming clearer. The UK does not yet have a single comprehensive AI statute. However, data protection law, employment law, and consumer protection law all apply to AI-assisted decisions right now. For businesses that serve EU customers, the EU AI Act adds a further layer. Analysis by IT Brief notes that deployers of AI systems under that framework will face transparency and governance requirements that go well beyond what most UK SMEs currently have in place. Meanwhile, fewer than a quarter of UK firms name regulatory compliance as a top AI concern, compared with 44% of their EU counterparts. The gap in awareness is not trivial.
The Shoosmiths and FT Longitude research cited in the same UKTN coverage makes the positive case plainly. Firms with clearer AI strategies are measurably better placed for regulatory compliance and reputational protection. Policy is not bureaucracy. It is a commercial asset.
What believing this myth costs in practice
For compliance officers and business leaders, the cost of the 'no policy' position is not theoretical. It shows up in specific, addressable ways.
First, there is the output integrity risk. Without a review requirement for AI-assisted work, your team may be shipping client-facing documents, financial summaries, or operational reports that contain AI-generated errors no one has been asked to check. The legal and reputational exposure from a material error in a client document sits with your organisation, not with the tool provider.
Second, there is the data handling risk. Most AI tools process whatever text you put into them. Without a clear policy on what data may be used in AI prompts, staff will make their own judgements. Some will be appropriately cautious. Others will paste in contract terms, personal data, or commercially sensitive information because no one told them not to. That is a data protection exposure.
Third, there is the accountability gap. When something does go wrong and something will, eventually, the question regulators and clients will ask is: what governance did you have in place? 'We had no policy' is not a defence. It is the evidence that governance was absent.
The good news is that fixing this does not require a large programme. The intervention is lightweight and practical.
What a workable AI governance policy actually looks like
A practical AI governance policy for a UK SME does not need to be a lengthy document. It needs to answer four questions clearly.
1. What data may be used in AI prompts? Define which data categories are permitted, which are restricted, and which are off-limits entirely.
2. Which tools are sanctioned? Provide a short list of approved tools and a clear instruction that unapproved tools require sign-off before use.
3. What review is required before AI-assisted work is used or sent externally? Set a minimum standard. A human must check AI outputs before they reach a client, a regulator, or a public channel.
4. Who is accountable for AI-related decisions? Name a role. It does not need to be a dedicated AI officer. It needs to be someone whose job includes reviewing and updating the policy as the landscape changes.
That structure, documented and communicated to staff, closes the most significant gaps. It does not slow adoption. It gives adoption a foundation.
Considerations and honest limitations
Governance policy alone is not a complete answer. A written document that no one reads, or that is not connected to actual working practices, provides limited protection. The real test is whether the policy changes how people behave at the point they use AI tools. That requires training, not just documentation.
It is also worth being clear that UK AI regulation is still evolving. The four-question framework above addresses current exposure under existing law. As AI-specific legislation develops, organisations will need to revisit and update their governance approach. Building that review into your annual compliance cycle now is more efficient than retrofitting it later.
For businesses already using AI Agents, the governance question becomes more acute. Agents can act autonomously across workflows, touching data, generating outputs, and triggering downstream processes. The case for structured handoffs and quality gates is strongest here. gecco's AI Agents service is built around exactly that model, with structured handoffs and quality gates embedded in the workflow design so that compliance checks run without slowing adoption.
Your next step on AI governance
If you are a compliance officer or business leader who has recognised your organisation in the 75% without a formal AI governance policy, the AI Readiness survey is a practical starting point. It surfaces the specific governance gaps in your current setup, not a generic checklist.
Take the AI Readiness survey. You will get access to 65+ free resources and a custom AI Readiness report. We then offer a free 45-minute AI Readiness call to walk through your results.
If you want structured support building AI governance into your working practices, gecco's training and consultancy work helps compliance officers and business leaders establish the frameworks, review processes, and accountability structures that make AI adoption both fast and defensible.

Most SMEs have no AI governance policy
Three-quarters of UK SMEs have no formal AI governance policy, leaving teams exposed to data risk and inconsistent use. This article explains what good AI governance looks like in practice and how to build it.

How automated reporting pipelines save SME teams hours each week
Manual reporting is one of the most common time drains in UK SMEs. An automated AI reporting pipeline can replace repetitive data work with a working system in four to six weeks.

