Support Login 0800 046 9957

AI arrived before the rules. What now?

Kirsty Harrison
  • 28 Jul 2026
  • 4 min read

Introduction

Lots of organisations are now using AI; we’re past the point of it being a tool for those ahead of the curve and it’s now something that most organisations have at least dabbled with.

For most of these businesses though, AI adoption hasn’t been through a formal project or adoption plan. There hasn’t been a board meeting to decide which tools to use, how they should be used, and what the rules of usage should be. The use of AI has probably happened really organically where a couple of people started using a tool to help them do something faster, and somebody else in a different team did the same, and so on until AI is part of the way people work whether the business has officially adopted it or not.

That’s why we’re seeing changes in the conversations around AI. For SMEs, the challenge is now understanding how AI is already being used, and how they can make sure it’s being used in a safe and secure way.

The Short Answer Is

Many SMEs are already using AI whether they’ve formally adopted it or not. The challenge isn’t introducing AI, it’s understanding how it’s being used and putting sensible guardrails around it. Good AI governance isn’t about restricting innovation; it’s about helping people use AI confidently and responsibly.

AI arrived before the rules

Unlike previous technology rollouts, AI hasn’t always entered organisations through IT.

Marketing teams might be using ChatGPT to help write content. Sales teams might be using AI to prepare proposals or meeting notes. Managers might be using Copilot to summarise conversations or analyse information.

None of these uses are inherently problematic. In many cases they’re genuinely useful and can save significant amounts of time. The difficulty is that different people often adopt different tools in different ways, with very little visibility across the wider organisation.

As a result, AI usage can grow quickly without anyone having a clear understanding of what information is being shared, which tools are being used, or how outputs are being verified. And if something were to backfire or go wrong, it would likely be categorised as an ‘IT issue’.

The risks aren’t what people expect

When AI is discussed, as with a lot of things, the conversation tends jump straight to dramatic scenarios of how things might go wrong. More likely though, is issues that you might not even know are issues:

  • A team member passes confidential information into a public AI tool without understanding how that information is handled.
  • Someone uses AI-generated content without checking the output.
  • A process becomes reliant on a tool that nobody has formally approved or reviewed.

None of these examples involve people doing things deliberately wrong; they’re just trying to work more efficiently. The challenge is that efficiency and risk don’t always move in the same direction.

How AI Governance can help AI use

We know that the term ‘AI Governance’ sounds like something for large enterprises with dedicated compliance teams and hugely complex policy documents. But that’s not the case for SMEs; it’s so much simpler than that.

At its core, AI governance is simply deciding how AI should be used within your business. It’s finalising decisions like:

  • Which tools are approved?
  • Who in the business can access them?
  • What information can be entered into them?
  • Where should AI-generated outputs be reviewed by a person?
  • Who is responsible for making decisions about new tools?
  • How do we make sure company data stays protected?

Without answers to the above, your teams are left to make decisions individually, which creates inconsistency across your organisation.

Good governance doesn’t slow you down

One of the biggest misconceptions we see about governance is that it’s about restriction; locking everything down so nobody can do anything innovative. In reality, good governance should help your people use AI more confidently.

If your employees understand which tools they can use and what the boundaries are, they’re more likely to adopt AI effectively rather than cautiously experimenting in isolation. When AI governance is done well, it invites people to be innovative and use the toolset rather than creating barriers.

First steps for SMEs

The best first step is to start understanding what’s already happening. Speak to your teams. Ask them whether they’re using AI tools and what they’re using them for. You may discover adoption is far more widespread than expected.

Once you have that visibility, you can begin defining some simple guardrails. Start by identifying approved tools. Decide what types of information should never be entered into AI platforms. Establish where human review is required and where it isn’t.

Most importantly, once decisions are made, communicate those expectations clearly. Your people generally want to use these tools responsibly; they just need guidance on what responsible use looks like within your organisation.

Who owns AI in your business?

One of the biggest challenges SMEs face is deciding who is responsible for AI. Every time you bring something new into an SME you’re usually adding responsibility to someone who is already busy but it’s key that someone owns it.

In many organisations, AI adoption starts within individual departments. Marketing may introduce one tool, sales another and operations a third, so over time, AI becomes embedded across the business without anyone formally owning it. This doesn’t necessarily mean one person needs to control every AI decision, but there should be clear accountability for areas such as approved tools, governance, data protection and policy development.

Without ownership, organisations often find themselves reacting to AI usage rather than shaping it. By then, company or customer information could have already been shared with a tool that leaves this open for anyone to access.

Conclusion

The businesses getting the most value from AI are the ones who understand how it’s being used in their organisation, and are taking steps to ensure that usage is consistent, sensible and aligned with how the business operates. Once you understand how AI is being used, it’s much easier to decide how it should be used moving forwards, and that’s where things can really get exciting.


Want to keep in the loop?

Sign up for our Newsletter and get helpful articles like this one delivered straight to your inbox.


FAQs

What is AI governance?

AI governance is the process of deciding how AI tools should be used within an organisation, including which tools are approved, what data can be entered, and how outputs should be checked.

Why do SMEs need AI governance?

Without clear guidance, employees often make decisions individually about which AI tools to use and how to use them. This can create inconsistency, security risks, and challenges around accountability.

Is AI governance only relevant for large organisations?

No. In fact, SMEs often benefit from simple governance because AI adoption frequently happens informally across multiple teams without central oversight.

What are the biggest AI risks for SMEs?

Common risks include sharing confidential information, relying on inaccurate outputs, using unapproved tools, and creating business processes that depend on AI without proper oversight.

Will AI governance slow innovation?

Good governance should do the opposite. It creates confidence by helping employees understand what they can use, how they can use it, and where the boundaries are.

What’s the best place to start?

Start by understanding how AI is already being used in the business. Once you have visibility, you can establish approved tools, define guardrails, and communicate expectations clearly.

Who should be responsible for AI governance?

Responsibility varies by organisation, but AI governance is often shared between leadership, IT, operations and compliance stakeholders. The important thing is that accountability is clearly defined.

Is Microsoft Copilot safer than public AI tools?

Microsoft Copilot benefits from existing Microsoft 365 security controls and permissions, but organisations still need governance around how it is used and what information users can access. There are certain versions of Copilot that ensure your data remains yours and that your input isn’t being used to train their tool.

We use third-party cookies to personalise content and analyse site traffic.

Learn more