A plain-English approach to AI governance and responsible use
Most businesses did not decide to start using AI, it simply arrived through free tools that staff picked up on their own. This service helps you set clear, practical rules so your team can use AI with confidence, without a blanket ban and without guesswork. You come away with a plain-English policy and a small set of guardrails that actually fit how your business works.
In most businesses, AI is already in daily use before anyone has agreed how it should be used. Staff paste text into free tools to save time on a report, summarise a document or draft an email, often without thinking about what that text contains or where it goes afterwards.
Leadership teams are left choosing between two uncomfortable options: ban AI outright, which people tend to quietly ignore, or say nothing, which leaves the business exposed with no rules at all. Underneath both options sits a genuine, reasonable question that rarely gets a straight answer: what actually happens to information once it is typed into an AI tool, and does that create a data protection problem under GDPR. Most businesses do not need a lecture on AI risk. They need help working out what is actually safe, and what is not.
What this service covers
This service is about AI governance: the rules, permissions and habits that let your business use AI tools safely. It is not about persuading you to adopt more AI, and it is not about steering you away from it. It suits any small or medium-sized business where staff already use tools such as ChatGPT or Copilot, whether or not that use has been formally agreed.
An engagement typically includes a review of how AI is currently used across the business, an assessment of where the real risks sit, and a written, plain-English policy that your team can actually read and follow. This is not a service designed to frighten you away from AI, and it is not a generic legal compliance package; it focuses specifically on AI. For anything that needs formal legal sign-off, this work is designed to sit alongside proper legal advice, not replace it.
You receive a written AI policy in plain English, a short set of practical guardrails covering the areas that matter most, and clear next steps your team can put into practice straight away.
Why this matters more than people think
The AI incidents that cause real damage are rarely dramatic. They are usually small and avoidable: an employee pasting a client’s contract into a free AI tool to get a quick summary, a spreadsheet of customer details uploaded to see what an AI tool makes of it, a draft email containing commercially sensitive figures typed into a chatbot for a rewrite. None of this happens out of carelessness; it happens because nobody has ever told that employee where the line is. A short, well-written policy closes that gap far more effectively than a ban nobody follows.
What a workable AI policy covers
- Approved tools. Which AI tools staff are permitted to use for work, and which are off-limits or need sign-off first.
- Data handling rules. What kinds of information can and cannot be entered into an AI tool.
- Confidential information. Specific guidance on client data, financial information, personal data and anything covered by a contract or NDA.
- Escalation. Who to ask when someone is not sure whether something is safe to share.
- Review. A simple point in the calendar to check the policy still matches how AI is actually being used.
Data protection and GDPR in plain English
AI tools raise genuine data protection questions. If personal data is typed into a public AI tool, that information may be processed and stored somewhere outside your control, which matters under GDPR. This work looks at where personal data is likely to come into contact with AI tools in your day-to-day operations and helps you set sensible rules to reduce that risk. It is not a substitute for formal legal advice, and it does not replace a data protection impact assessment where one is needed.
Agent-specific governance
AI agents and automated processes need a different level of governance to a person typing into a chatbot, because an agent can take actions on its own, sometimes across several systems, without a person checking each step. Governance here focuses on permissions, human oversight, testing and ongoing monitoring. If you are exploring agents for your business, it is worth reading the AI Agents page alongside this one.
Benefits
A clearer picture of how AI is actually being used across your business today; a written policy your team can understand and follow; a reduced risk of sensitive or personal data ending up somewhere it should not, though no policy can remove risk entirely; staff who feel able to ask before they act; a defensible position if a client, auditor or board member asks how your business manages AI risk; and a foundation to build on if you later introduce AI agents or automation.
How it works
- Understand current AI use. A short conversation and review to find out which tools your team is already using, and how.
- Assess the risk. Identify where the genuine risks sit, focusing on data protection, confidentiality and anything specific to your sector.
- Draft a plain-English policy. Covering approved tools, data handling, confidential information, escalation and review.
- Roll it out with the team. Introducing the policy in a way that explains the reasoning, not just the rules.
- Review and update it periodically. A short check-in to keep the policy matched to how AI use changes over time.
Examples of this work in practice
Drafting a first AI policy for a business that has never had one; reviewing which AI tools are safe to use with sensitive client or patient data; setting up permissions and oversight for a new AI agent before it goes live; helping a leadership team prepare a clear answer to a board or client question about AI risk; reviewing an existing AI policy that has not been updated since new tools came into use; and running a short session with staff to explain a new AI policy, which often pairs naturally with AI training.
Why this work is handled carefully
This work is led directly by Mark Grice, who spent 13 years as CTO of a security software company used by police forces and government organisations, protecting data sensitive enough for law enforcement. That period included holding a certified penetration testing qualification, on top of more than 20 years of hands-on technology leadership. Mark founded that business and later exited it. Advice is independent throughout, with no software to sell, no commission and no vendor tie-in influencing what gets recommended.
Common questions before you start
“We’re worried about staff misusing AI or leaking data.” That worry is exactly what this work is for; most leaks happen because nobody set out clear rules.
“We’re small, do we really need governance?” Business size does not determine whether AI risk exists.
“Our staff are already using ChatGPT, is that a problem?” Not necessarily; the question is whether anyone has thought about which uses are fine.
“How does this relate to GDPR?” AI tools can create data protection questions when personal data is involved.
“Can you write the policy for us?” Yes, producing a written, plain-English AI policy is a core part of this service.
If you want a clear, honest read on where your AI risk actually sits, that is a straightforward conversation, not a sales pitch. Talk through your AI governance and risk using the form on this page.
Frequently asked questions
Do we actually need an AI policy?
If staff are using AI tools, even informally, then yes. A policy does not need to be long or complicated, but having clear, written guidance reduces the chance of sensitive information ending up somewhere it should not.
Is our data safe with AI tools?
It depends on the tool and what is entered into it. Free, consumer versions of AI tools generally offer fewer guarantees than paid business or enterprise versions.
How does this relate to GDPR?
When personal data is entered into an AI tool, that can raise questions under GDPR about where the data goes and how it is processed.
We're small, do we really need governance?
Yes, though it does not need to be heavyweight. A short, clear policy is often enough for a small business.
Can you write the policy for us?
Yes, a written AI policy in plain English is one of the main things you receive from this service.
How do we stop sensitive data leaking into AI tools?
Mostly through clarity: telling staff plainly what should never be typed into a free AI tool, which tools are approved for which purposes, and who to ask when they are unsure.