Most published AI governance guidance is written for organisations with a compliance function, a data protection officer and a risk committee. Applied to a 120-person business, it produces a forty-page document that satisfies nobody and changes nothing.

What follows is what we think is proportionate for an organisation of twenty to five hundred staff: a small number of decisions, a named owner, and about two pages of writing.

Start with four decisions, not a framework

1. What may staff use?

A short list of approved tools, at a named tier. The tier matters — the consumer and business versions of the same product often differ substantially in retention, training use and administrative visibility.

Keep the list short enough that people remember it. Three tools that everyone knows about beats fifteen in a document nobody has opened.

Say what happens when someone wants something not on the list: who they ask, and roughly how long an answer takes. If that route is slow, staff will bypass it, and you will be back where you started.

2. What must never go into them?

Name the categories, in your own terms rather than generic ones. For most businesses that means something like:

  • Personal data about clients, staff or applicants
  • Anything covered by a confidentiality clause in a client contract
  • Unpublished financial information
  • Credentials, keys and access details

“Confidential information” is too vague to act on. “Client contracts and anything with a client’s name and personal details in it” is something a person can apply at their desk.

3. Who is accountable?

One named person at director level, with authority over both technology and process — commonly the operations or finance director. Not IT alone: the decisions are about what data may go where and who owns the output, which are business decisions with technical consequences.

Their job is not to approve every use. It is to own the list, decide the edge cases, and be the person who notices when the position needs revisiting.

4. What needs a human check?

Where AI output feeds something that goes to a customer, a regulator or into a financial record, who reviews it and what are they checking? This is the control that addresses output quality, and it is generally more important for a smaller business than any access control, because the reputational exposure from a confidently wrong client communication is immediate.

What to write down

Two pages. Genuinely.

Page one: the approved tools, the categories of information that must not be used, who to ask, and what to do if you think something has gone wrong. Written for a member of staff, in the second person.

Page two: the owner, the review date, how new tools get assessed, and what the human check requirements are for the situations that need one.

Anything longer will not be read, and a policy that is not read provides no protection while creating the impression of some — which is worse than having none, because it stops you looking further.

The technical controls that do the work

The policy explains; these enforce.

Identity integration. Approved tools reached through your identity provider, so they inherit conditional access, device requirements and — critically — offboarding. When someone leaves, their access goes with everything else.

Restricted application consent. By default, users may be able to grant a third-party application standing permission to read their mail or files. Restrict this so it requires administrative approval. This single change closes the most common route by which an unassessed AI tool gains access to your data.

Browser extension management. Frequently the largest exposure and the least examined. An extension with permission to read every page a user visits has your CRM, finance system and webmail simultaneously.

Logging. Whatever your approved tools provide, turned on and retained in line with your other records.

Permissions hygiene. If you deploy an assistant that reads company files, it will surface exactly what your permissions allow. Over-shared SharePoint becomes an over-sharing assistant. Fix this before deployment, not after.

Assessing a new tool

A proportionate review, not a procurement exercise. Six questions:

  1. Where is the data processed, and under what terms?
  2. How long is content retained, and can we control that?
  3. Is our content used to train models? Under which tier?
  4. Does it support sign-in through our identity provider?
  5. What administrative visibility and logging do we get?
  6. What happens to our data if we stop using it?

If the answers to one, three and four are acceptable, the tool is probably usable. If the vendor cannot answer them clearly, that is itself the answer.

On UK GDPR

Putting personal data into an AI tool is processing, and the ordinary questions apply: lawful basis, purpose limitation, minimisation, transparency, international transfer, and whether the vendor is acting as a processor under adequate terms.

AI does not create a separate regime. What it does create is a large number of easy routes to processing personal data through a vendor you have not assessed, using terms you have not read. That is the practical risk, and the controls above address it.

We are technical advisers rather than lawyers. Where a question turns on legal interpretation, we will say so and tell you it needs your solicitor or DPO.

The review cycle

Set a date, six months out, and put it in a calendar. At that review, ask four questions:

  • What is actually being used now, compared with the approved list?
  • Has anything gone wrong, or nearly gone wrong?
  • Which tools have changed their terms?
  • Is the sanctioned route still faster than the workarounds?

That last question is the one that predicts whether the position will hold. Governance that makes people slower gets circumvented, every time, regardless of how well it is written.

What this gets you

Not certification, and not a defence against every conceivable AI risk. What it gets you is the ability to answer the questions you will actually be asked — by a client, by an insurer, by a tender questionnaire, or by your own board — with something better than a guess.

For an organisation of this size, that is the right target. The alternative is an enterprise framework that consumes a quarter of somebody’s year and describes an organisation you are not.