AI Governance for UK Businesses
Most UK businesses are already using AI. Very few are actually governing it. We help owners and leaders put the frameworks, oversight and privacy design in place before the regulator, the board, or a customer asks the question you can't answer.
Advising business owners and leaders across the UK, Australia, New Zealand, Canada, Sweden and the Philippines. Members of the IAPP.
Your Business is Already Using AI. The Question is Who's Governing It
Your team started using ChatGPT six months ago. Nobody signed anything off. Your CRM added AI features in the last update. Your accounting software is quietly summarising client data with a model you've never reviewed. Someone in marketing built a workflow that emails customers based on what an AI decided.
This is common in UK businesses in 2026. What is less common is a business that can say, in writing, what AI it is using, what data goes into it, who signed it off, and what happens if it gets something wrong.
That is the difference between using AI and governing it. It is where regulatory, privacy and accountability risks start to emerge, and where obligations under UK GDPR and the EU AI Act would apply if something went wrong. It is what boards are starting to ask about, and what customers will ask about next.
AI should be the tool, not the objective. We help UK businesses keep it that way.
Where you are with AI
Already using AI
No governance. No privacy design. No audit trail. The exposure is already there. You just haven't been asked about it yet.
About to deploy AI
The decisions you make now on vendor, contract, data flows and oversight determine how hard it is to undo later. Get it wrong at the start and you're paying for it for years.
Something has already gone wrong
A near breach. A regulatory question. A board or a customer asking hard questions. We help you work out what happened, what to say, and what to do next.
So What Actually is AI Governance?
Most people hear "AI governance" and think it means writing a policy. It is more than that.
AI governance is the system of decisions, roles, controls and oversight that determines how your business uses AI safely and deliberately. A policy is one piece of it. On its own, a policy is a document nobody reads.
Here is what a real AI governance framework covers.
What an AI governance framework covers:
Every AI tool in your business represents a decision. What data can go into it. What it's allowed to do. Who signed off on the vendor. What happens when it gets something wrong. Whether customers know they're interacting with it.
Most businesses are making those decisions by accident. Someone in a team clicked "enable AI features" and nobody has looked at it since. A governance framework means making those decisions on purpose, writing them down, monitoring them, and reviewing them when things change.
AI governance roles and accountability
Who is responsible for AI in your business? It should not automatically sit with IT.
AI decisions cut across privacy, legal, operations, customer experience and risk. Governance means naming the roles, including a senior sponsor, a governance owner, a privacy lead and someone accountable at board level. It also means giving those roles the authority to make decisions.
If something goes wrong and a regulator asks who was responsible, the business needs to know the answer before they ask.
AI governance and UK regulation: ICO, EU AI Act and ISO 42001
The UK's approach to AI regulation is principles-based, with existing regulators such as the ICO, the FCA,and the CMA. That does not mean less obligation. It means the obligations are already live, under existing law, and each regulator is applying them to AI in their sector. The ICO's guidance on AI and data protection sets out that using AI on personal data without a proper assessment is a UK GDPR issue on its own, regardless of whether the AI ever misbehaves.
The EU AI Act can apply to UK companies too. Being based outside the EU does not automatically put a business outside its scope. Depending on your role, and how the AI system is provided or used, the Act can apply in a range of situations. Two of the most common are where a UK business places an AI system or model on the EU market, and where the output produced by an AI system is used in the EU. The important question is not simply where your business is based, but what AI you provide, how it is used, and where that use takes place.
ISO 42001 is the new international standard for AI management systems. It is becoming useful for businesses selling to enterprise customers who are starting to ask for it in procurement.
Why an AI policy is not AI governance
Businesses often tell us they have handled AI governance because they wrote an acceptable use policy last year. We usually ask three questions in return. Who signs off on new AI tools? Who reviews the risk before deployment? Who is checking the tools already in use?
Most businesses cannot answer those questions. That is the gap governance closes.
The AI Risks Most Businesses Miss
Shadow AI: staff using personal ChatGPT, Claude or Copilot accounts for work. Uploading client data, contracts and financials with no oversight and no record.
AI agents acting autonomously: making decisions, sending emails, booking appointments and processing data with no human in the loop. Most leaders do not know how many they have running.
Third-party AI risk: you may have reviewed the AI tool before buying it, but what about the companies behind it? Where does your data go, who else has access to it, and what happens when their technology or terms change?
Data retention: what happens to the data fed into AI tools. Where it goes. Whether it trains someone else's model. Who owns the output.
Privacy policy silence: not being transparent with customers about AI use. This is a live UK GDPR issue, not a future one.
AI you didn't choose: existing software providers are adding AI features all the time. A system you approved a year ago may now be processing or using your data in ways your contract never covered.
Accountability gaps: "AI did it" is not a defence. If AI makes a decision that costs money or harms a customer, the business is responsible. You deploy or use AI at your own risk.
These are the most common. Yours may go further.
Not sure which of these apply to your business?
A 20 minute call will tell you.
See where your
AI exposure sits
How We Help
Three ways in, depending on where you are
AI Governance & Privacy Review
A focused engagement where we work out exactly where your business stands with AI. What you have. What you're missing. What to do next. You leave with a strategic plan you can actually execute, not a 200-page report that sits on a shelf.
Document & Policy Review
Contracts, DPAs, privacy policies, acceptable use policies and internal procedures reviewed through an AI governance, risk and privacy lens. We find what's actually happening inside your business from an operational perspective, and what the paperwork is quietly missing.
AI Governance & Privacy Advisory
Ongoing oversight of AI in your business, built in from the start. Governance framework, privacy design, risk decisions, board-level reporting, and the operational calls most businesses overlook. This is the fractional advisor most UK businesses need but don't have the headcount to hire.
AI Governance in Practice: Recent Client Work
A UK-based chatbot widget startup needed contracts that reflected how its AI service actually operated. We drafted their Data Processing Agreement and reviewed their Terms of Service, closing gaps that most standard templates miss entirely, including how customer data can and cannot be used to train AI models. The results were clearer contractual boundaries around customer data and a stronger privacy foundation as the business grows.
A global travel company came to us already using AI chatbots across their customer service operation. We provided governance and privacy guidance, completed privacy impact assessments on their AI tools, aligned their privacy policy with upcoming regulatory deadlines, and rolled out AI-specific staff training. A full governance framework is rolling out next. This gave the business a clearer view of where AI was being used, the privacy and governance risks that needed attention, and the controls required.
We're Marnie McLeod and Roger McCluskey, governance and privacy advisors specialising in AI.
We've lived what we advise on. Between us, we’ve run businesses, sat on boards, supported organisations through regulatory investigations, and helped businesses strengthen governance, privacy and information security programmes across global organisations. We've worked with clients across the UK, Australia, New Zealand, the Philippines, Sweden and Canada. We know what goes wrong because we've seen it firsthand.
Why Us
What Good AI Governance Looks Like
CERTAINTY
Reduced exposure to regulatory action, outages, data breaches and AI failures.
CONTROL
Clear oversight of every AI tool and agent in your operation.
CONFIDENCE
AI deployed with privacy built in from the start.
CLARITY
Knowing exactly what your AI investment costs, and where the risks of blowout are.
Questions We get Asked
-
AI governance is the framework of decisions, roles, controls and oversight that determines how a business uses AI safely and deliberately. It covers policies, risk assessments, privacy design, accountability and ongoing monitoring. A policy on its own is not governance. It is one part of it.
-
Often, yes. Being outside the EU does not automatically put a UK business outside the EU AI Act. It can apply if you provide AI systems or models in the EU, or if the outputs from your AI are used there. We work through the specifics with you so you know which of your AI activities fall in scope, and what that means for your business.
-
Not necessarily. You do not need to be ISO 42001 certified to benefit from it. The standard can provide a useful structure for managing AI risks, responsibilities and oversight. Certification may become more relevant if customers start asking for it during procurement or due diligence. We can help you use the parts that make sense for your business without turning it into an unnecessary compliance exercise.
-
If you are using AI with customers, employees, job applicants or other people's information, UK data protection rules including UK GDPR and the ICO's guidance may apply, even if you are a small business. Beyond the compliance question, governance is what stops small problems becoming bigger ones. Governance for a 20 person business looks nothing like governance for a 2,000 person business. Proportionality is built into the way we work.
-
IT manages the infrastructure. A DPO handles data protection. AI governance looks across the business at how AI is selected, used, managed, and who is accountable when something goes wrong. We work across risk, legal, operations and technology so your use of AI is consistent, documented and defensible. If you have a DPO, we work alongside them. If you do not, we can act as your fractional DPO too.
-
Start with a Review. Before writing policies or buying tools, you need to know what is actually in use, what purpose is it really solving, what data is going into it and where the immediate risks are.
-
Every engagement starts with a free 20 minute call. You will leave with a clear read on where your business sits with AI governance: what is working, what is exposed and what to prioritise. No pitch, no obligation. If it is a fit, we will usually recommend starting with a Review.
-
You can start seeing results within the first few weeks. The Review identifies where your immediate AI, privacy and governance risks sit and gives you a clear plan for what to address first. How long implementation takes depends on the size of the business, the number of AI tools in use, what needs to change, and the budget and resources available. Some actions can be addressed quickly, while broader governance is built and improved over time.
Let’s Talk
Send us a message or book a free 20 minute call. You'll leave with a clear read on where your business is exposed, what's working, and where to start. No pitch and no obligation.

