Do You Need an AI Policy? Questions and Answers for UK SMEs

No UK law requires an AI policy. Procurement, insurance and incidents do. What a two-page policy contains, who needs one and when writing it can wait.

No UK law currently requires a standalone AI policy. The pressure comes from elsewhere: client contracts, insurance renewals and incidents that happen without ground rules. A short, specific policy is worth writing for those reasons rather than regulatory ones, and for most smaller organisations it runs to two pages.

Is an AI policy legally required in the UK?

No. No UK statute or regulation obliges an organisation to publish or maintain a document called an AI policy. The UK has taken a principles-based, regulator-led approach rather than passing a single AI act.

Existing law still applies to how you use AI. UK GDPR governs personal data fed into AI tools, and Article 22 limits solely automated decisions with legal or similar significant effects on individuals. Regulators including the FCA and the ICO expect firms to explain and control their systems whatever the technology. Which rules bite depends on who supervises you, which our answer on UK AI regulation by sector sets out. Selling into the EU changes the position, because the EU AI Act imposes documented governance obligations on providers and deployers of higher-risk systems, and UK suppliers are caught when their product reaches EU users.

What actually happens if we do not have an AI policy?

No regulator will fine you for the missing document. The consequences are commercial and operational. They arrive in a fairly predictable order.

Procurement comes first. Enterprise buyers commonly include AI questions in their supplier due diligence packs, and “we do not have a policy” delays or loses deals; our guidance on answering the AI section of a security questionnaire sets out the usual shape of those questions. The incident comes second, and it is the expensive one. Without ground rules, staff make individual judgement calls about what they paste into which tool and whether output is checked before it leaves the building. You discover the decision after client data has already gone, at which point you are reconstructing events from memory rather than from a policy and a log. Insurance comes third: professional indemnity and cyber renewals commonly include AI usage questions, and unanswered ones invite exclusions or loaded premiums.

The underlying problem is that absence of policy is not absence of AI use. It is unmanaged AI use, Shadow AI in the ordinary sense, and every unlogged tool is a supplier you have not assessed. Finding out which tools staff already use is the cheapest first step.

Do small businesses really need one, or is this an enterprise concern?

Smaller organisations often need one more urgently, because they have fewer compensating controls. A large firm has procurement checkpoints, a security team and legal review that catch bad AI decisions before they compound. A twenty-person consultancy has none of that, so one employee’s choice of tool becomes company policy by default.

Size changes the depth of the policy rather than the need for one. Our AI Security Programmes scale the same handful of questions up and down. The proportionate answer here is not an enterprise governance programme.

What does a minimum viable AI policy contain?

Five components cover most smaller organisations.

  • Scope. Which systems and which people, contractors included.
  • Approved tools. A named list plus the process for requesting additions. A short allowlist beats a long banned list, because bans age faster than approvals.
  • Data rules. What categories of information must never be entered into a third-party AI system, stated plainly enough that a non-technical employee can apply them without asking.
  • Human review. Where output needs sign-off before it reaches a client, a regulator or a decision about a person.
  • Escalation. Who to contact when a rule is broken or an output looks wrong, and the explicit expectation that reporting will not be punished.

What you leave out matters as much as what goes in. Long definitions of machine learning, aspirational ethics statements and tool-specific configuration detail all age badly and crowd out the parts staff need to read. The working test is whether a new joiner can read the document in five minutes and then act correctly on a Tuesday afternoon with a deadline. If your draft fails that test, it is documentation rather than policy. Where a client has asked for the document directly, our answer on what a client’s AI policy request is really testing covers what they check.

How is an AI policy different from our existing IT or security policy?

Existing policies govern access, devices and data handling and they assume the system does what it is instructed to do. AI systems break that assumption: output varies, reasoning is not directly inspectable and the model can be persuaded by input it processes. That is why we add explainability, fairness and traceability to confidentiality, integrity and availability under CIA+EFT, since a system can be perfectly confidential and still produce an unexplainable decision.

Two options work: an AI annex to the existing policy set, or a standalone policy that references the others. What fails is assuming the old documents already cover it.

Where does ISO 42001 fit into this?

ISO 42001 is the international management system standard for AI, and its structure of roles, risk assessment, impact assessment on affected individuals, supplier controls and monitoring is a useful blueprint even if you never certify. Certification is a much larger commitment, requiring evidence that the system operates, internal audit and external assessment, which is why many smaller firms first map their two-page policy against the clauses and close gaps in order of commercial pressure. Whether that step is worth taking is covered in is ISO 42001 worth it for a company our size, and we use the standard the same way during an AI Security Gap Analysis: as a reference model rather than a checklist.

How do we know whether our policy is working?

A policy is working when behaviour matches it, which is measurable. Compare the approved tool list against what is actually in use through expense records, browser telemetry or a candid staff survey. Sample recent AI-assisted client output and ask whether the required human review happened. Count escalations, because zero reports usually means people are not reporting rather than nothing going wrong. Where the stakes are higher, AI Behaviour Verification tests whether a deployed system stays inside its stated boundaries when pushed, which no document review can establish.

When should we write one, if not now?

Two situations justify waiting and two mean acting now. Wait if you have no AI use and no roadmap for it, because governance for something you do not do wastes effort. Wait if a larger governance review is already scheduled within a quarter, and fold the AI work into it.

Act now if staff are already using AI tools, sanctioned or not. Act now if you have a live tender that will ask the question. In both cases the exposure exists today and the document is the cheapest control available.

Related reading: AI Governance explains the wider structure a policy sits inside.

A policy that matches how you actually work

We help UK organisations write a short, specific AI policy and put the small number of controls behind it that make the document true.