Global styles
All content
Opinions
10 Aug 2026

Outsourced AI, in-house risk

Many SME leaders assume AI risk sits with the vendor, but UK evidence shows accountability stays in-house. Read to understand what that means for your governance and who needs to own it.

A silver-blue stone storehouse stands with its door left open, warm amber light spilling out as a lone figure walks away.
Written by
The gecco team

The assumption is understandable: you licensed a third-party AI tool, the vendor built it, the vendor maintains it, so if something goes wrong, the vendor carries the liability. Plenty of well-run SMEs are operating on exactly that logic right now. The problem is that UK evidence suggests the logic is wrong. Accountability for what an AI system does inside your business does not transfer to the tool provider when you sign up. For SME leaders and compliance officers trying to use AI responsibly, that gap between assumption and reality is where the risk lives.

Why this myth has such a strong hold

The vendor-liability assumption did not emerge from carelessness. It follows a reasonable analogy. When a business uses accountancy software and the software miscalculates, the software maker is at fault. When a courier delivers the wrong parcel, the courier is responsible. AI tools arrived on the market dressed in the same SaaS clothing, so the same mental model followed.

Vendors reinforce this by foregrounding their own safety investments. Terms of service describe content filters, moderation layers, and responsible-use policies. For an SME leader reading those documents, the natural takeaway is that the vendor has handled the risk side. The assumption that your business is simply a consumer, not a risk owner, feels rational.

The grain of truth here is real. Vendors do carry certain obligations, particularly around product defects and data processing agreements. But that coverage is narrower than most leaders believe. The moment an AI output reaches a customer, informs a business decision, or affects an employee, the question of who chose to deploy that output, and whether they reviewed it, falls on your organisation.

What the evidence shows about the accountability gap

The numbers in this area are striking. Research published in 2026 found that 46% of business leaders said they had no idea they could be legally accountable for AI output. Nearly half of the people making decisions about AI adoption were unaware of a risk that could expose them to reputational, legal, or customer-service consequences.

The structural picture is no more reassuring. UK Tech News reported in August 2026 that three-quarters of UK businesses had no formal written AI governance policy. That means most organisations deploying AI tools have no documented process for who reviews outputs, who owns each use case, or what happens when something goes wrong.

The regulatory context matters here too. UK businesses are expected to maintain accountability, privacy controls, and risk oversight when using third-party AI, particularly where outputs affect customers, employees, or regulated decisions. The ICO has been clear that data controllers cannot outsource their obligations simply by using a third-party processor. The same principle extends to the decisions made on the back of AI-generated content: the decision-maker retains accountability, not the model provider.

The real cost of getting this wrong

For SME leaders and compliance officers, the practical risks divide into three categories.

The first is reputational. If a customer receives AI-generated communication that is factually wrong, discriminatory, or inappropriate, the damage lands on your brand. The vendor does not appear in that conversation. You do.

The second is legal. Depending on your sector, AI outputs that inform credit decisions, HR processes, or customer contracts may fall under existing legislation. If no one inside the business has reviewed and approved those outputs, you have a governance gap that a regulator or a claimant could exploit.

The third is cultural. When teams assume that risk belongs to the vendor, they stop asking the important questions. They do not document what the AI was asked to do. They do not flag outputs that look wrong. They do not escalate. A team operating without internal governance is a team that has quietly handed its quality controls to a third-party system that knows nothing about your customers, your obligations, or your values.

This is not a technology problem. It is a people and process problem. AI adoption is roughly 80% about how humans work alongside the tools and 20% about the tools themselves. The accountability gap exists because the governance conversations have not happened, not because the AI is inherently ungovernable.

A realistic approach to closing the gap

The intervention here is not complex, but it does require deliberate action from leadership. Three steps form the foundation.

1. Assign an internal owner for each AI use case. Someone in your organisation needs to be named as accountable for the outputs of every AI-assisted process. That person does not have to be technical. They need to understand the business context and have the authority to pause use if something looks wrong.

2. Document review steps for outputs. Before AI-generated content reaches a customer or informs a significant decision, there should be a defined human review point. What gets checked, by whom, and how the review is recorded. This does not need to be elaborate. It needs to exist.

3. Align contracts and policies with actual accountability. Review your supplier agreements to understand what the vendor is and is not responsible for. Then make sure your own AI policy reflects what your business actually does, not a generic template downloaded from the internet.

Compliance officers are often already aware of these gaps but lack the internal mandate to act on them. SME leaders who understand that vendor accountability is narrower than assumed are far more likely to give compliance functions the authority and budget they need.

It is worth being honest about one limitation: governance documentation alone does not make AI use safe. Documents that are written and filed but never read, reviewed, or enforced create a false sense of security. The goal is living governance, which means the people using AI tools know what the policies say and have a clear escalation route when they are unsure. That requires ongoing conversation, not a one-time policy exercise.

gecco's Training and consultancy offering supports SME leaders in building that internal understanding, helping teams recognise that ownership of AI outputs sits inside the business and giving them practical frameworks to act on it.

Your next step if this resonates

If your organisation is using third-party AI tools and has not yet mapped out who owns each use case, this is the right moment to start. The AI Readiness survey is designed to surface exactly these kinds of governance gaps, including accountability structures, review processes, and policy coverage.

Take the AI Readiness survey. You will get access to 65+ free resources and a custom AI Readiness report. We then offer a free 45-minute AI Readiness call to walk through your results.

If you want support in structuring the accountability conversations your leadership team needs to have, gecco's Training and consultancy work is built around that challenge: helping SME leaders understand where AI risk actually sits and what practical governance looks like in a business of your size.


Website · LinkedIn · Case Studies · Newsletter

Get your free AI Readiness report
Silhouetted figures with scattered lanterns cross a dusk hillside settlement, one shared beacon glowing brighter in silver-blue and amber light.
Insights
10 Aug 2026

Most SMEs have no AI governance policy

Three-quarters of UK SMEs have no formal AI governance policy, leaving teams exposed to data risk and inconsistent use. This article explains what good AI governance looks like in practice and how to build it.

Three stone aqueducts converge into one basin, its spilling water lit copper-gold beneath a slate-blue sky brightening at the horizon.
Automation
10 Aug 2026

How automated reporting pipelines save SME teams hours each week

Manual reporting is one of the most common time drains in UK SMEs. An automated AI reporting pipeline can replace repetitive data work with a working system in four to six weeks.