Back to blog
AI Compliance for Businesses: 7 Practical Steps

AI Compliance for Businesses: 7 Practical Steps

17 September 2026

What is AI compliance?

AI compliance means meeting the legal, regulatory and contractual requirements that apply to how your business develops or uses artificial intelligence. The requirements depend on your activities, the information involved, the people affected and the countries where you operate.

For a small business, this might mean checking AI-written advertising before publishing it, protecting customer information when using an AI assistant, or assessing a recruitment tool before using it to evaluate applicants.

You can write an AI use policy to support compliance. You also need to put that policy into practice, assign responsibility and keep evidence of relevant checks. A document alone cannot establish that your business is compliant.

This guide focuses on small UK businesses using existing AI tools. It explains how to organise that work without assuming you have a legal department or a team building machine learning systems. The examples are practical starting points, not a complete legal assessment of every business or use case.

Why does AI compliance matter for small businesses?

AI can become part of everyday work before anyone formally approves it. An employee might use it to rewrite a supplier email, summarise customer complaints or create a product description. Each task introduces different questions about accuracy, confidentiality and responsibility.

In its July 2026 analysis, the Office for National Statistics reported that AI use among UK businesses with 10 or more employees rose from around 12% in late 2023 to around 35% in June 2026. These are self-reported adoption figures, not a measure of compliance. They show why businesses need to understand how AI is entering their operations.

Source: ONS, Artificial intelligence in UK businesses: 2023 to 2026

Consider a tanning cream seller using AI to improve product descriptions. The tool adds a sentence claiming that a cream provides sun protection. The sentence sounds convincing, but the supplier documentation does not support it. Without a check, a routine writing task could produce misleading information that affects a customer's purchasing decision and behaviour.

A practical AI compliance process helps the business catch that claim, identify who must review it and prevent the same problem from recurring. It also gives employees clear boundaries, so they can use approved tools with greater confidence.

AI compliance, AI governance and AI policy: what is the difference?

These terms describe different parts of managing AI responsibly.

Term Meaning Example for a tanning cream seller
AI compliance Meeting the requirements that apply to your AI use. Checking whether AI-assisted advertising and use of customer information meet applicable requirements.
AI governance The responsibilities and processes used to oversee AI and manage its risks. The owner approves tools, a designated employee checks marketing content, and staff know who handles incidents.
AI policy Written rules explaining how people may use AI. Staff may draft product descriptions with approved tools, but must verify ingredients and product claims before publication.

The policy records expectations. Governance makes those expectations part of everyday work. Compliance concerns whether the applicable requirements are met.

Voluntary standards and frameworks can support this work, but they are not automatically legal requirements. Similarly, following your own policy does not prove that the policy covers every relevant obligation.

Does this apply if you only use existing AI tools?

Using a tool supplied by another company still requires decisions about what your business enters into it and how you use its outputs. However, your responsibilities and the controls you need depend on the activity.

How your business uses AI Main questions to investigate
Drafting captions, emails or internal notes Is the information suitable to share? Who checks the output?
Connecting AI to email, customer records or a website chatbot What can it access or change? Can it send messages automatically? How can a person intervene?
Developing, substantially modifying or supplying an AI system What additional development, testing, documentation and legal responsibilities apply to your role?

A familiar brand or paid subscription does not answer these questions. Assess the particular task, account settings and connected systems.

Which AI compliance requirements should a UK business check?

Start with the rules relevant to what your business actually does. For example, AI use involving personal information raises data protection questions, while AI-assisted advertisements need to meet applicable advertising requirements.

The ICO's AI guidance covers issues including lawfulness, fairness, transparency, security and individual rights. The ICO currently notes that this guidance is under review following the Data (Use and Access) Act, so check its latest guidance when assessing a specific use.

Source: ICO, Guidance on AI and data protection

For marketing, objective claims need appropriate evidence and advertisements must not materially mislead. For our tanning cream seller, this means checking product benefits against reliable evidence before publication, regardless of who or what drafted the wording.

Source: ASA, Misleading advertising

Other areas to investigate include equality and employment obligations, intellectual property, confidentiality, sector-specific requirements and commitments made to customers or suppliers. Which ones matter depends on the use case.

When could the EU AI Act matter?

The EU AI Act's scope depends on factors including whether an organisation provides or deploys an AI system and the system's connection to the EU. Certain providers and deployers outside the EU can fall within scope where their AI outputs are used in the EU. Simply saying that a company “sells products in Europe” is not a sufficient assessment.

Source: European Commission, AI Act Article 2

The Act applies in stages. Its AI literacy provisions and prohibitions began applying in February 2025, while transparency rules began applying in August 2026. Other obligations have different dates and transitional arrangements. Check the official timetable for the category relevant to your business.

Source: European Commission, AI Act implementation timeline

If your business operates in other countries, including the US, assess the requirements relevant to those activities too. Keep a short record of each applicable requirement, its source, the action needed and the person responsible. Do not assume one country's rules cover every market.

 

Seven practical steps to improve AI compliance

1. List your AI tools and their uses

Ask staff which AI features they already use, including features inside existing software. Explain that the purpose is to understand the work and make it safer, so people feel comfortable disclosing informal use.

Create a simple tool register. Record the tool and account type, the task, the information entered, any connected accounts, the owner and approval status.

For the tanning cream seller, one entry might read:

Field Example entry
Tool Approved writing assistant, business account
Task Draft product descriptions
Inputs Approved product specifications and brand guidance
Connected systems None
Owner Marketing lead
Approval Drafting only; manual review before publication
Review trigger New features, changed terms, different data or an incident

Approve a defined use, rather than giving a tool unrestricted approval for every possible task.

2. Assess what could go wrong

For each use, ask who could be affected, what information could be exposed and what an incorrect output could cause. Consider whether a person can spot and correct the problem before it causes harm.

Use a short risk register to record the concern, control, owner and remaining risk. You can use internal priority ratings to decide what needs attention first. These are management judgements, not EU AI Act legal classifications.

Use Possible problem Practical control Owner
Product descriptions AI invents an SPF rating or ingredient Compare every claim with approved product evidence before publication Marketing lead
Customer replies Staff share a customer's skin condition unnecessarily Use generic questions without customer details; escalate product safety enquiries Customer service lead
Product images Generated results exaggerate what the cream achieves Review images for misleading impressions and reject fabricated results Marketing lead

Review the remaining risk after applying controls. If staff cannot verify important claims or prevent harmful outputs, restrict or pause that use while seeking help.

3. Check suppliers and protect information

Before approving an AI tool, check its documentation, contractual terms and the settings available on your specific account. Ask:

  • Are prompts, uploads or outputs used to train models?
  • How long is information retained, and what deletion options exist?
  • Who can access it, where is it processed, and which other providers are involved?
  • What security and access controls are available?
  • What permissions does the tool request for connected accounts?
  • How can you report an incident, remove access or leave the service?

Seek evidence relevant to your use. A supplier's assurance statement is a starting point, rather than a substitute for checking the terms and safeguards.

For initial writing tasks, a practical rule is to use approved product information and fictional examples. Keep customer records and confidential material out unless a specific process has been assessed and approved. Removing a name does not necessarily make a detailed customer story anonymous.

Where personal data is involved, assess the lawful basis, transparency information, safeguards and whether a data protection impact assessment is required.

Source: ICO, Guidance on AI and data protection

4. Write an AI use policy people can follow

Use the findings from your tool register and risk assessment to write specific rules. Identify who the policy covers, including contractors where relevant, and give it an owner, version number and review date.

The following is an illustrative extract for the tanning cream seller, to be adapted to its actual tools and processes:

Policy area Example wording
Permitted use Staff may use tools on our approved list to draft product descriptions, social posts and general customer replies.
Information Use approved product documents. Do not enter customer records, payment details, health information or confidential supplier material unless the business owner has approved a specific process.
Accuracy Check ingredients, instructions, prices and product benefits against current approved sources before publishing or sending content.
Restricted content Do not invent testimonials, certifications, SPF ratings or results. Do not use generated images that misleadingly represent product performance.
Human review A named member of staff must approve customer-facing content. Escalate questions about skin reactions or product safety to the responsible person.
New tools and connections Obtain approval before using a new AI tool for work or connecting one to email, files or customer systems.
Reporting Report incorrect published claims, inappropriate replies or accidental information sharing promptly to the business owner.
Review Review this policy every six months and after significant changes or incidents.

The six-month interval is an example management choice, not a universal legal deadline. Choose a schedule suited to your risks, and respond to significant changes immediately.

5. Assign responsibility and make human review meaningful

A small business may have one owner approving tools and one employee reviewing content. The important point is that responsibility is explicit and there is cover when someone is absent.

A reviewer needs reliable source material, time to check the output and authority to reject it. A quick glance or an approval tick is not enough when the wording makes a product safety claim.

For customer-facing content, use a short checklist: are the facts correct, are claims supported, is confidential information absent, and could the wording or image mislead someone? Decide whether any disclosure about AI use is required for the particular activity and jurisdiction.

For consequential uses such as recruitment decisions, seek appropriate advice before deployment. Also consider how affected people can ask questions, challenge an outcome or reach a person.

6. Train staff and prepare for mistakes

Use scenarios from actual work. Ask staff what they would do if AI invented a certification, requested access to the whole inbox or drafted a confident response to a customer's skin complaint.

Training should cover approved uses, information restrictions, verification, permission requests and reporting. Include it when staff join or receive access to a new tool, then refresh it when risks, tools or observed mistakes change.

Write a short incident procedure:

  1. Pause the affected activity and limit further exposure.
  2. Tell the responsible person promptly.
  3. Preserve relevant evidence securely, including what was entered, produced or published.
  4. Assess who and what was affected, involving the supplier or specialist support where needed.
  5. Correct the issue and assess any reporting or notification obligations promptly.
  6. Update the process and test it before restarting.

Make prompt reporting a supported behaviour. Staff should know that raising a concern quickly helps the business respond.

7. Monitor the process and keep useful evidence

Keep the approved-tool register, policy versions, supplier checks, risk decisions and incident records together with appropriate access restrictions. Record important approvals without retaining unnecessary personal information.

Use a few measures that help you spot unfinished work:

Measure What it helps you check
Known tools assessed and approved Whether informal use has been reviewed
Staff briefed on the current policy Whether employees know the current rules
Sampled outputs meeting review requirements Whether checks happen in practice
Open incidents and overdue actions Whether problems are being resolved
Supplier reviews past their due date Whether approval is based on outdated information

These measures support oversight; they do not prove complete legal compliance. A rise in reported concerns may indicate better reporting rather than deteriorating behaviour.

Reassess after a supplier update, a new integration, a change in the information being processed or an incident. Begin automation with useful reminders, approval steps and access controls. More advanced scanning or monitoring should address an identified risk and be tested for limitations.

Do small businesses need NIST or ISO/IEC 42001?

The NIST AI Risk Management Framework is voluntary guidance for managing AI risks. Its four functions, Govern, Map, Measure and Manage, can help organise responsibilities, understand use cases, assess risks and take action.

Source: NIST, AI Risk Management Framework

ISO/IEC 42001 specifies requirements for an AI management system. It can support a more formal organisational approach and certification where that is useful or expected. It is not a universal prerequisite for a small business to begin setting sensible AI rules.

Source: ISO, ISO/IEC 42001

Neither adopting a framework nor obtaining certification automatically establishes compliance with every applicable law. Choose an approach that fits your activities, risks and customer commitments.

When are technical AI controls relevant?

Businesses developing or operating their own AI systems may need additional engineering controls. These include records of model and data versions, automated testing before software releases, and monitoring for changes in model performance over time.

Such work is often described as MLOps, or machine learning operations. It belongs with appropriately skilled teams. A retailer using an existing writing assistant can start with supplier checks, approved uses, output review and incident handling, while investigating additional controls as its use becomes more complex.

A practical 90-day action plan

Treat this as an organising schedule, not permission to delay urgent corrections or miss legal deadlines.

Period Action Evidence produced
Days 1 to 14 Identify tools, owners, information flows and immediate concerns Initial tool register and interim restrictions
Days 15 to 30 Assess priority uses, applicable requirements and suppliers Risk register and approval decisions
Days 31 to 60 Agree the policy, establish checks and brief staff Approved policy, review checklist and training record
Days 61 to 90 Test incident handling, sample outputs and close gaps Review notes, action owners and next review dates

Bring in specialist support when the consequences exceed your team's ability to assess them, particularly for sensitive information, consequential decisions, safety-related uses or uncertain cross-border obligations.

Turn AI compliance into everyday practice

Start by listing the AI tools your business already uses, the information entered into them and the person responsible for checking the results. That gives you a concrete basis for approving uses and writing rules staff can follow.

For our tanning cream seller, the first useful improvement might be requiring every AI-written product claim to be checked against approved evidence. The next might be keeping customer details out of drafting tools. Each action should address a real risk and have a clear owner.

If your team needs help recognising everyday AI risks, explore cyber security training for businesses from Optimise Cyber Solutions . Practical training can help employees apply your rules, check uncertain outputs and report concerns promptly.