AI Governance for UK Businesses

Most UK businesses are already using AI. Very few are actually governing it. We help owners and leaders put the frameworks, oversight and privacy design in place before the regulator, the board, or a customer asks the question you can't answer.

Advising business owners and leaders across the UK, Australia, New Zealand, Canada, Sweden and the Philippines. Members of the IAPP.

Your Business is Already Using AI. The Question is Who's Governing It

Your business is already using AI

Your team started using ChatGPT six months ago. Nobody signed anything off. Your CRM added AI features in the last update. Your accounting software is quietly summarising client data with a model you've never reviewed. Someone in marketing built a workflow that emails customers based on what an AI decided.

This is common in UK businesses in 2026. What is less common is a business that can say, in writing, what AI it is using, what data goes into it, who signed it off, and what happens if it gets something wrong.

That is the difference between using AI and governing it. It is where regulatory, privacy and accountability risks start to emerge, and where obligations under UK GDPR and the EU AI Act would apply if something went wrong. It is what boards are starting to ask about, and what customers will ask about next.

AI should be the tool, not the objective. We help UK businesses keep it that way.

Where you are with AI

Already using AI

 Already using AI

No governance. No privacy design. No audit trail. The exposure is already there. You just haven't been asked about it yet.

About to deploy AI

About to deploy AI

The decisions you make now on vendor, contract, data flows and oversight determine how hard it is to undo later. Get it wrong at the start and you're paying for it for years.

Something has already gone wrong

Something has already gone wrong

A near breach. A regulatory question. A board or a customer asking hard questions. We help you work out what happened, what to say, and what to do next.

So What Actually is AI Governance?

Most people hear "AI governance" and think it means writing a policy. It is more than that.

AI governance is the system of decisions, roles, controls and oversight that determines how your business uses AI safely and deliberately. A policy is one piece of it. On its own, a policy is a document nobody reads.

Here is what a real AI governance framework covers.

What an AI governance framework covers:

Every AI tool in your business represents a decision. What data can go into it. What it's allowed to do. Who signed off on the vendor. What happens when it gets something wrong. Whether customers know they're interacting with it.

Most businesses are making those decisions by accident. Someone in a team clicked "enable AI features" and nobody has looked at it since. A governance framework means making those decisions on purpose, writing them down, monitoring them, and reviewing them when things change.

AI governance roles and accountability

Who is responsible for AI in your business? It should not automatically sit with IT. 

AI decisions cut across privacy, legal, operations, customer experience and risk. Governance means naming the roles, including a senior sponsor, a governance owner, a privacy lead and someone accountable at board level. It also means giving those roles the authority to make decisions.

If something goes wrong and a regulator asks who was responsible, the business needs to know the answer before they ask.

AI governance and UK regulation: ICO, EU AI Act and ISO 42001

The UK's approach to AI regulation is principles-based, with existing regulators such as the ICO, the FCA,and  the CMA. That does not mean less obligation. It means the obligations are already live, under existing law, and each regulator is applying them to AI in their sector. The ICO's guidance on AI and data protection sets out that using AI on personal data without a proper assessment is a UK GDPR issue on its own, regardless of whether the AI ever misbehaves.

The EU AI Act can apply to UK companies too. Being based outside the EU does not automatically put a business outside its scope. Depending on your role, and how the AI system is provided or used, the Act can apply in a range of situations. Two of the most common are where a UK business places an AI system or model on the EU market, and where the output produced by an AI system is used in the EU. The important question is not simply where your business is based, but what AI you provide, how it is used, and where that use takes place.

ISO 42001 is the new international standard for AI management systems. It is becoming useful for businesses selling to enterprise customers who are starting to ask for it in procurement.

Why an AI policy is not AI governance

Businesses often tell us they have handled AI governance because they wrote an acceptable use policy last year. We usually ask three questions in return. Who signs off on new AI tools? Who reviews the risk before deployment? Who is checking the tools already in use?

Most businesses cannot answer those questions. That is the gap governance closes.

The AI Risks Most Businesses Miss

shadow ai
shadow ai

Shadow AI: staff using personal ChatGPT, Claude or Copilot accounts for work. Uploading client data, contracts and financials with no oversight and no record.

ai agents acting autonomosly
ai agents acting autonomosly

AI agents acting autonomously: making decisions, sending emails, booking appointments and processing data with no human in the loop. Most leaders do not know how many they have running.

third party ai risk
third party ai risk

Third-party AI risk: you may have reviewed the AI tool before buying it, but what about the companies behind it? Where does your data go, who else has access to it, and what happens when their technology or terms change?

data retention
data retention

Data retention: what happens to the data fed into AI tools. Where it goes. Whether it trains someone else's model. Who owns the output.

data protection
data protection

Privacy policy silence: not being transparent with customers about AI use. This is a live UK GDPR issue, not a future one.

ai you dint choose
ai you dint choose

AI you didn't choose: existing software providers are adding AI features all the time. A system you approved a year ago may now be processing or using your data in ways your contract never covered.

accountability gaps
accountability gaps

Accountability gaps: "AI did it" is not a defence. If AI makes a decision that costs money or harms a customer, the business is responsible. You deploy or use AI at your own risk.

These are the most common. Yours may go further.


Not sure which of these apply to your business?
A 20 minute call will tell you.

See where your
AI exposure sits

How We Help

Three ways in, depending on where you are

AI Governance & Privacy Review

A focused engagement where we work out exactly where your business stands with AI. What you have. What you're missing. What to do next. You leave with a strategic plan you can actually execute, not a 200-page report that sits on a shelf.

Document & Policy Review

Contracts, DPAs, privacy policies, acceptable use policies and internal procedures reviewed through an AI governance, risk and privacy lens. We find what's actually happening inside your business from an operational perspective, and what the paperwork is quietly missing.

AI Governance & Privacy Advisory

Ongoing oversight of AI in your business, built in from the start. Governance framework, privacy design, risk decisions, board-level reporting, and the operational calls most businesses overlook. This is the fractional advisor most UK businesses need but don't have the headcount to hire.

AI Governance in Practice: Recent Client Work

A UK-based chatbot widget startup needed contracts that reflected how its AI service actually operated. We drafted their Data Processing Agreement and reviewed their Terms of Service, closing gaps that most standard templates miss entirely, including how customer data can and cannot be used to train AI models. The results were clearer contractual boundaries around customer data and a stronger privacy foundation as the business grows.

A global travel company came to us already using AI chatbots across their customer service operation. We provided governance and privacy guidance, completed privacy impact assessments on their AI tools, aligned their privacy policy with upcoming regulatory deadlines, and rolled out AI-specific staff training. A full governance framework is rolling out next. This gave the business a clearer view of where AI was being used, the privacy and governance risks that needed attention, and the controls required.

We're Marnie McLeod and Roger McCluskey, governance and privacy advisors specialising in AI.

We've lived what we advise on. Between us, we’ve run businesses, sat on boards, supported organisations through regulatory investigations, and helped businesses strengthen governance, privacy and information security programmes across global organisations. We've worked with clients across the UK, Australia, New Zealand, the Philippines, Sweden and Canada. We know what goes wrong because we've seen it firsthand.

Why Us

What Good AI Governance Looks Like

CERTAINTY

Reduced exposure to regulatory action, outages, data breaches and AI failures.

Certainty

CONTROL

Clear oversight of every AI tool and agent in your operation.

Control

CONFIDENCE

AI deployed with privacy built in from the start.

Confidence

CLARITY

Knowing exactly what your AI investment costs, and where the risks of blowout are.

Clarity

Questions We get Asked

Let’s Talk

Send us a message or book a free 20 minute call. You'll leave with a clear read on where your business is exposed, what's working, and where to start. No pitch and no obligation.