Global styles
All content
Insights
10 Aug 2026

Most SMEs have no AI governance policy

Three-quarters of UK SMEs have no formal AI governance policy, leaving teams exposed to data risk and inconsistent use. This article explains what good AI governance looks like in practice and how to build it.

Silhouetted figures with scattered lanterns cross a dusk hillside settlement, one shared beacon glowing brighter in silver-blue and amber light.
Written by
The gecco team

Three-quarters of UK SMEs have no formal AI governance policy. That statistic is striking, but the real story sits underneath it. Most of those businesses are already using AI. The gap is not between those who have adopted AI and those who have not. The gap is between businesses using AI in a structured way and those using it in a way nobody has formally agreed to. For management and compliance teams, this is a workflow problem dressed up as a policy problem.

The scale of ungoverned AI use in UK SMEs

AI tools are now accessible to any employee with a browser and a free account. The barrier to entry is essentially zero. That is, in many respects, a positive development. Individuals can draft documents, summarise data, and automate repetitive tasks without waiting for IT approval.

The practical consequence is that AI use spreads faster than policy can keep up. One team member uses a public AI tool to summarise a client brief. Another pastes supplier pricing into a chat window to generate a comparison table. A third uses AI to draft HR correspondence. None of these actions is inherently wrong. But without a formal policy in place, no one has agreed on what data can be entered, how outputs should be checked, or who is accountable when something goes wrong.

For management and compliance teams, this is where the real exposure sits.

Why this is a workflow problem, not a paperwork problem

The instinct for many organisations is to respond to a governance gap by writing a policy document. That document goes into a shared drive. It is read once at induction, if at all. Eighteen months later, nothing has changed.

AI governance does not work that way. The moment a team member needs to make a decision about what to put into an AI tool, the policy needs to be present at that moment. Not retrievable from a folder. Present.

This means governance has to be built into how AI is used, not bolted on afterwards. The most practical approach is to embed rules at the point of use: in the AI workspace itself, in the assistants employees interact with, and in the automations that move data between systems.

That is a fundamentally different mental model from compliance-as-documentation. It treats governance as a design constraint, not an audit function.

What the people and process dimension reveals

At gecco, our view is that AI adoption is 80% people and culture, 20% technology. The governance gap in UK SMEs reflects that ratio precisely.

The technology is not the barrier. Free and low-cost AI tools are already in use across most teams. The barrier is that no one has had a structured conversation about acceptable use. No one has set clear rules on what data can be entered into which tools. No one has defined how AI outputs should be reviewed before they reach a client, a regulator, or a colleague in HR.

For compliance teams, the ICO's guidance on UK GDPR is unambiguous: organisations are responsible for how personal data is processed, regardless of whether a human or an AI tool performs that processing. If an employee enters customer data into a public AI model, the organisation carries the data responsibility. A policy document that no one reads does not change that.

Management teams face a parallel accountability question. If AI is being used to draft contracts, produce financial summaries, or support hiring decisions, and no one has checked the outputs systematically, the risk is reputational as well as regulatory.

What structured AI governance looks like in practice

Businesses that have moved beyond ad hoc AI use share several practical characteristics.

First, they define the boundary clearly. They specify which data categories can and cannot be entered into AI tools. Customer personal data, commercially sensitive pricing, and unpublished financial information typically sit outside the boundary for public AI models.

Second, they build the rule into the workspace. Rather than relying on individual team members to remember the policy, they configure AI assistants with system-level instructions that prompt the right behaviour. An assistant built for contract review, for example, can be set up to flag when a user appears to be entering data that falls outside agreed parameters.

Third, they define an output-checking step. AI-generated content does not go to a client or into a formal document without a named review stage. That review does not need to be onerous. It needs to be consistent and recorded.

Fourth, they document risk in a format that can be shown to an auditor or regulator. This does not require a sophisticated system. A simple log of which AI tools are in use, for which purposes, and who has been trained on the policy is a meaningful starting point.

Fifth, they revisit the policy at a fixed interval. AI capabilities change quickly. A governance framework written in 2024 may not address tools that became widely available in 2025. A quarterly or bi-annual review cycle keeps the policy current.

Implementation safeguards

UK GDPR and ICO guidance apply directly to AI use in any business that handles customer, employee, or commercial data. This is not a future consideration. It applies to current practice.

The most common areas of practical exposure are public AI tools used to process personal data, AI-generated outputs used in regulated decisions such as credit, employment, or insurance, and AI-assisted communications that do not carry an appropriate review step before dispatch.

Organisations should carry out a data protection impact assessment if they are deploying AI in a way that involves systematic processing of personal data or automated decision-making. The ICO publishes guidance on when this is required. The assessment does not need to be complex, but it does need to exist.

Internal data governance policies also need to reflect AI use. A policy that defines how employees handle data on spreadsheets but says nothing about AI tools has a meaningful gap.

Making this work for your business

Building AI governance does not require a dedicated compliance team or an expensive external audit. It requires structured thinking and consistent implementation.

For most SMEs, the practical starting point is a short, structured workshop with the people who make decisions about AI use: management, compliance leads, and the team members who use AI most frequently. The output of that session should be a clear definition of acceptable use, a data boundary, and an agreed output-checking process.

From there, the governance rules can be built into the AI workspaces the business uses. Assistants configured with GRAFT, gecco's assistant design methodology, can carry governance instructions at the system level, so the policy is present every time a team member opens the tool, not filed away in a document no one reads.

The goal is not a perfect policy on day one. The goal is a documented, reviewable framework that the business can show to a client, a regulator, or a new team member, and that improves with each review cycle.

Taking the next step on AI governance

If your management or compliance team is trying to move from ad hoc AI use to something structured and defensible, the AI Readiness survey is a practical starting point for understanding where your business currently sits.

Take the AI Readiness survey. You will receive 65+ free resources and a custom AI Readiness report based on your answers. From there you can book a free 45-minute AI Readiness call to walk through the results with a gecco advisor.

Website · LinkedIn · Case Studies · Newsletter

Get your free AI Readiness report
Three stone aqueducts converge into one basin, its spilling water lit copper-gold beneath a slate-blue sky brightening at the horizon.
Automation
10 Aug 2026

How automated reporting pipelines save SME teams hours each week

Manual reporting is one of the most common time drains in UK SMEs. An automated AI reporting pipeline can replace repetitive data work with a working system in four to six weeks.

A crumbling stone weir releases a river into countless bright streams across a valley glowing in pale rose dawn light.
Assistants
10 Aug 2026

OpenAI upgrades ChatGPT with free reasoning for all users

OpenAI has upgraded ChatGPT with a more reliable GPT-5.6 Sol model for subscribers and a new Luna model giving free users access to higher-reasoning capabilities. UK business owners and IT managers can now build AI habits across their teams without worrying about subscription costs.