Skip to main content
    Insightful AI

    AI Ethics & Governance

    AI governance for SMEs and UK organisations

    Seven in ten employees using AI at work have not told their employer (DSIT). That applies to organisations of every size and sector. Your teams are likely using ChatGPT, Copilot, and tools you have not approved to get through their work. Most have not asked permission. Leadership often has no record of which tools are in use, what organisational data has been entered into them, or where the exposure sits if something goes wrong.

    The control model

    Audit and review

    People oversight

    Policy and process

    Technical controls

    Your AI use case

    No tool goes live until every layer around it exists. People keep authority over consequential decisions.

    Market context

    allow genAI
    61%allow genAI
    have policy
    31%have policy
    top concern
    80%top concern

    61% of UK organisations allow generative AI but only 31% have formal policies governing that use (DSIT). Of the organisations that do cite ethical concerns as a barrier to AI adoption, 80% rate those concerns as their most significant barrier (DSIT). Governance does not dissolve those concerns. It addresses them with documentation, process, and accountability.

    An AI policy does not stop any of this. It gives it structure.

    What does an AI governance engagement actually deliver?

    A governance engagement produces a tailored AI usage policy, risk registers covering your specific AI tools, Data Protection Impact Assessment (DPIA) documentation for high-risk use cases, and board or trustee briefing materials. All documentation is proportionate to your organisation's size and risk profile. You receive the evidence the Information Commissioner's Office (ICO) expects to see during an audit.

    The scope depends on how many AI tools your organisation is using and how much personal data those tools process. A 30-person charity using Copilot for internal communications needs a different level of documentation than a 200-person business using AI in recruitment or customer-facing services.

    What every engagement produces is a set of documents that each serves a specific purpose. The AI usage policy tells teams what is and is not allowed. The risk register records what could go wrong and what you have done to reduce that risk. The DPIA shows the ICO that you identified data protection risks before deploying AI tools, not after. The board or trustee briefing gives leadership a clear picture of your AI position without requiring them to understand the underlying technology.

    Engagement models range from project-based work addressing a specific compliance gap to ongoing monthly arrangements, including our Fractional Chief AI Officer (CAIO) service for organisations that need board-level AI leadership without a permanent executive appointment.

    The starting point for all Stage 2 work is the AI readiness scoping workshop: a structured day that assesses your current AI position, regulatory exposure, and identifies the use cases worth prioritising. You receive a written findings and recommendations report, priced at £1,500 ex VAT, and the governance engagement is scoped from what we find together. Not sure whether you need any of this yet? The free AI Governance Check maps your AI use and scores your gaps in about ten minutes.

    Do we need AI governance if we only use ChatGPT and Copilot?

    Yes. UK GDPR (the General Data Protection Regulation, as retained in UK law) applies to any AI tool that processes personal data. Your organisation needs a DPIA if the tool involves high-risk processing, and an acceptable use policy so teams know what data they can and cannot enter. 70% of employees using AI have not told their employer (DSIT), so the gap is likely larger than leadership realises.

    The tools themselves are not the problem. ChatGPT and Copilot are used productively across millions of UK organisations. The risk comes from how your specific teams use them with your specific data. A staff member pasting beneficiary records into a public AI tool is a UK GDPR breach regardless of intent. A manager using AI to assist with recruitment decisions triggers additional obligations under the Data (Use and Access) Act 2025 (which reformed automated decision-making rules in UK law from February 2026), requiring mandatory safeguards, individual notification, and the right to request human intervention.

    41% of local government staff use AI outside approved channels (DSIT research summary). The pattern is consistent across sectors. Staff are using tools because those tools help them work. Governance gives them a legitimate route to keep using them, within defined limits, with the documentation in place to show oversight.

    This service connects naturally with AI at Work, where we work through your team's actual tasks and build solutions during the engagement. Every AI at Work engagement produces a governance pack per use case. An overarching policy framework should be in place first.

    One objection that comes up regularly: "Our GDPR policies already cover this." They do not. UK GDPR policies and privacy notices address personal data processing. They do not cover AI-specific risks: tool approval processes, algorithmic bias, shadow AI, opaque automated decisions, or the EU AI Act's Article 26 deployer obligations. AI introduces categories of risk that have no equivalent in a standard data protection policy, and the ICO treats them separately.

    What does AI governance cost for an SME or charity?

    Advisory engagements are priced at £1,200 per day ex VAT. Independent UK AI governance specialists charge between £500 and £1,200 per day, compared with £2,000 to £5,000 at Big Four firms. The average ICO fine increased from £150,000 to over £2.8 million in 2025 (Measured Collective, 2025), which reframes the cost question considerably.

    Fixed-scope governance packages covering policy development, risk register, and a staff training session start from £5,000 ex VAT. The exact scope and price depend on the number of AI tools in use and the complexity of your data processing.

    A downloaded AI policy template costs under £30 (IT Governance) or under £10 (Modern HR). That comparison can look reasonable until you consider what a template does not do. It does not assess your specific AI tools. It does not map your data flows or identify your regulatory exposure. It does not produce the DPIA documentation the ICO expects during an investigation. It does not meet the Fundraising Regulator's December 2025 requirement for a policy addressing your organisation's specific AI use in fundraising. It does not brief your trustees or board.

    A downloaded AI policy template versus a full governance engagement, compared across what each covers
    What you needDownloaded templateGovernance engagement
    Risk assessment of your specific AI toolsNoYes
    DPIA documentationNoYes
    Board or trustee briefingNoYes
    EU AI Act deployer obligations reviewNoYes
    Regulatory updates as the law changesNoYes (with ongoing arrangement)
    Staff training on approved tools and data handlingNoYes

    For organisations with SME budgets or charity finances, the investment sits between two extremes. Big Four governance work is not designed for 30 to 200-person organisations. A downloaded template is not governance. A proportionate engagement, scoped to your actual AI use, sits within reach for most UK SMEs and charities.

    Does the EU AI Act apply to UK organisations?

    The EU AI Act can apply to UK organisations. If your AI system's output is used within the EU (by EU-based customers, employees, or beneficiaries), you are in scope regardless of where you operate. Article 26 of the Act places twelve specific obligations on deployers (organisations that use AI systems, not only those that build them). Fines for high-risk system breaches reach €15 million or 3% of global annual turnover.

    Parts of the Act are already in force. Since February 2025, certain AI practices are prohibited outright, including systems designed to manipulate user behaviour or enable mass biometric surveillance. AI literacy obligations now apply to all organisations deploying AI systems. Since August 2025, providers of general-purpose AI models face binding transparency and documentation requirements.

    The Act's first company-wide date has passed. Transparency obligations under Article 50 have applied since 2 August 2026. High-risk system requirements for Annex III uses (recruitment, credit scoring, access to essential services, and biometrics processing) now apply from 2 December 2027 under the EU's Digital Omnibus reforms. An organisation that has not classified its AI tools against the EU AI Act's Annex III categories does not yet know whether the December 2027 deadline applies to it.

    Those changes became law. The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026. It moved the Annex III high-risk compliance date to 2 December 2027, and to 2 August 2028 for AI embedded in regulated products. Transparency obligations were not deferred. The deferral gives preparation time. It does not remove any obligation.

    UK GDPR compliance carries no equivalence value under the EU AI Act. Organisations with fully compliant UK data protection arrangements still need to separately assess their EU AI Act obligations if they have any EU exposure. There is no mutual recognition arrangement between the UK and EU. Our AI Consulting & Advisory service covers vendor due diligence and AI Act readiness assessments for organisations that need an independent review before committing to a governance programme.

    What AI regulations apply to UK charities?

    UK GDPR and the Data Protection Act 2018 apply to all AI involving personal data. The Fundraising Regulator published AI guidance in December 2025 requiring charities to have a policy before using AI in fundraising. The Charity Governance Code, revised November 2025, now explicitly requires policies covering AI use. Trustees remain personally accountable for oversight of AI activity in their organisation.

    Only 10% of UK charities have an AI policy in place. 41% have none at all, with a further 41% in the early stages of developing one (Phoenix/NCVO, 2025). 95% of charities report they are not confident they have the right policies and assurance in place (Phoenix/NCVO). 76% of charities are using AI tools in some form (Charity Digital Skills Report 2025). The gap between usage and governance is not closing on its own.

    The accountability gap at board level is significant. 40% of charity boards rate their AI skills as poor (Charity Digital Skills Report 2025). 50.7% of directors across all sectors cite limited board-level AI expertise as a barrier to adoption (IoD Policy Voice, March 2025). The governance service includes a trustee or board briefing session designed to give leadership the information they need to exercise oversight without requiring them to become AI experts. Charity trustees can discharge their duty of care on AI by approving a documented policy, reviewing the risk register, and receiving periodic briefings on regulatory changes. SME boards and leadership teams are served by the same session, adapted to their regulatory context. None of those steps requires technical expertise.

    Public sector organisations face additional requirements under the Algorithmic Transparency Recording Standard (ATRS), which requires disclosure of significant AI tools used in decision-making. 125 ATRS records have been published across 38 UK organisations as of April 2026 (GOV.UK ATRS register). The AI Playbook for the Public Sector sets out government expectations for AI governance in central and local government. Departments and local authorities procuring AI governance support can access this service via G-Cloud.

    The AI for Leaders & Senior Decision-Makers training course (half day, £995 ex VAT) addresses board accountability, risk appetite, and the governance questions senior decision-makers are being asked to answer. It sits alongside, not instead of, the governance service.

    How long does it take to get an AI policy in place?

    A governance engagement covering policy development, risk assessment, and a board or trustee briefing can be completed within four to six weeks for most SMEs and charities. The timeline depends on how many AI tools are in use and how many high-risk use cases require individual DPIAs. The scoping workshop at £1,500 ex VAT identifies both before work begins.

    For organisations with a specific trigger (a board question about AI, a trustee concern, a data incident, or a contract requiring evidence of governance), the policy, risk register, and leadership briefing can be delivered faster. The DPIA documentation for individual high-risk use cases is scoped case by case, with timelines dependent on the complexity of the processing involved.

    What happens if we don't have an AI policy and something goes wrong?

    Without documented governance, your organisation cannot demonstrate accountability to the ICO, the Fundraising Regulator, or a court. UK GDPR fines reach £17.5 million or 4% of global annual turnover. The ICO issued seven times more fine money in the first half of 2025 than in all of 2024 (Measured Collective, 2025). A policy and risk register are the minimum the ICO expects to see during an audit.

    The pattern from the 2018 GDPR deadline is instructive. When the deadline arrived, only 8% of small firms had completed their preparations. 33% had not started. 18% were entirely unaware of GDPR (Computer Weekly/FSB, 2018). AI governance readiness in 2026 follows the same curve, with the same consequences for organisations caught without documentation: enforcement action with no mitigation argument available.

    The ICO does not exempt small organisations from its enforcement expectations. The average ICO fine increased from £150,000 to over £2.8 million between 2024 and early 2025 (Measured Collective, 2025). PECR fines (the Privacy and Electronic Communications Regulations, which covers marketing and tracking) are now aligned with UK GDPR ceilings under the Data (Use and Access) Act 2025.

    EU AI Act fines reach €35 million or 7% of global annual turnover for the most serious breaches. For SMEs, fines are capped proportionally: an organisation with €2 million annual turnover faces a maximum Tier 1 fine of €140,000, not €35 million (EU AI Act Article 99). The proportional cap does not eliminate the obligation. It scales the penalty to the organisation's size.

    You can read more about how we handle client data during engagements on our Security & Data Protection page.

    Can you help us comply with the EU AI Act now the August 2026 date has passed?

    Yes. The service includes EU AI Act readiness assessment, high-risk system classification, Article 26 deployer obligations review, and gap analysis against your current governance arrangements. Transparency obligations have applied since 2 August 2026. For organisations deploying AI in areas covered by Annex III (recruitment, credit scoring, essential services, and biometrics), preparation should continue against the 2 December 2027 high-risk deadline set by the Digital Omnibus in July 2026.

    The Act's high-risk provisions require organisations to implement risk management systems, data governance procedures, human oversight mechanisms, and post-market monitoring for AI used in regulated domains. Organisations that have not yet classified their AI tools against the Annex III categories do not know whether the December 2027 deadline applies to them. That classification is where an EU AI Act readiness review starts.

    The AI Governance for Organisations training course (full day, £1,695 ex VAT) covers EU AI Act risk classification, accountability mapping, AI policy development, and supplier due diligence. It builds the internal capability to maintain governance arrangements after the initial engagement.

    Why governance comes first in everything we deliver

    Our co-founder Ben Sefton spent 18 years as a Senior Forensic Investigator with Greater Manchester Police, working in environments where data handling had direct legal and operational consequences. Evidence was managed to strict chain of custody standards. Documentation was not optional. The ICO's expectations of accountability during an AI audit are not conceptually different from those environments: the question is always whether you can demonstrate, after the event, that you acted responsibly.

    Ben now serves as Chief AI Officer at Cheshire Community Foundation and has presented on AI governance and AI-enabled threats to the National Crime Agency, the National Police Chiefs' Council, the North West Regional Organised Crime Unit, and a number of individual police forces. That access reflects recognised expertise in high-accountability AI governance, not in marketing.

    Insightful AI builds governance into every engagement from the outset, not as a retrospective compliance layer. You can read more about Ben's background at /about/ben-sefton/.

    For a full view of how governance runs through our delivery process, see How We Work.

    Organisations with documented governance adopt AI faster, not slower. Their teams have permission to act within clear rules. The organisations without policies are the ones where AI stalls.

    Not ready for a conversation yet? The assessment helps you understand where your organisation stands.

    Frequently asked questions

    Do we need AI governance if we only use ChatGPT and Copilot?
    Yes. UK GDPR applies to any AI tool that processes personal data. Your organisation needs a DPIA if the tool involves high-risk processing, and an acceptable use policy so teams know what data they can and cannot enter. 70% of employees using AI have not told their employer (DSIT), so the gap is likely larger than leadership realises.
    What does AI governance cost for an SME or charity?
    Advisory engagements are priced at £1,200 per day ex VAT. Fixed-scope governance packages covering policy development, risk register, and a staff training session start from £5,000 ex VAT. The exact scope and price depend on the number of AI tools in use and the complexity of your data processing.
    Does the EU AI Act apply to UK organisations?
    The EU AI Act can apply to UK organisations. If your AI system's output is used within the EU, you are in scope regardless of where you operate. Article 26 places twelve specific obligations on deployers. Fines for high-risk system breaches reach €15 million or 3% of global annual turnover. Transparency obligations have applied since 2 August 2026. High-risk obligations under Annex III apply from 2 December 2027.
    What AI regulations apply to UK charities?
    UK GDPR and the Data Protection Act 2018 apply to all AI involving personal data. The Fundraising Regulator published AI guidance in December 2025 requiring charities to have a policy before using AI in fundraising. The Charity Governance Code, revised November 2025, now explicitly requires policies covering AI use. Only 10% of UK charities have an AI policy in place.
    How long does it take to get an AI policy in place?
    A governance engagement covering policy development, risk assessment, and a board or trustee briefing can be completed within four to six weeks for most SMEs and charities. The timeline depends on how many AI tools are in use and how many high-risk use cases require individual DPIAs. The scoping workshop at £1,500 ex VAT identifies both before work begins.
    What happens if we don't have an AI policy and something goes wrong?
    Without documented governance, your organisation cannot demonstrate accountability to the ICO, the Fundraising Regulator, or a court. UK GDPR fines reach £17.5 million or 4% of global annual turnover. The ICO issued seven times more fine money in the first half of 2025 than in all of 2024. A policy and risk register are the minimum the ICO expects to see during an audit.
    Can you help us comply with the EU AI Act now the August 2026 date has passed?
    Yes. The service includes EU AI Act readiness assessment, high-risk system classification, Article 26 deployer obligations review, and gap analysis against your current governance arrangements. Transparency obligations have applied since 2 August 2026. For organisations deploying AI in areas covered by Annex III (recruitment, credit scoring, essential services, and biometrics), the high-risk deadline moved to 2 December 2027 under the Digital Omnibus. The deferral is preparation time, not an exemption.