AI use can spread through a small business faster than the rules around it.
Someone uses ChatGPT to tidy an email. Someone else uploads a document to summarise it. A manager asks an AI tool to analyse a spreadsheet.
Each use might look harmless on its own.
The problem starts when nobody has agreed what information staff are actually allowed to put into these tools.
And that gap is not hypothetical.
The UK Business Data Survey 2026 found that 41% of businesses handling digitised data said they used AI. Among businesses using AI, only 17% reported having either a formal or informal AI policy or guidance.
That does not mean every business without a policy is using AI badly. It does suggest that AI use is moving faster than formal governance in many businesses.
Source: UK Business Data Survey 2026, Department for Science, Innovation and Technology.
The rule I would put in place first
Before staff paste, upload or type business information into an AI tool, use this rule:
If the information is not public, dummy, properly anonymised, or explicitly approved for that tool and that task, stop and check first.
That is deliberately simple.
Your staff shouldn't need to understand AI regulation to know when to pause.
What can go wrong?
The risk is not AI itself.
The risk is using a tool without knowing what happens to the information being entered, whether that use has been approved, or whether the business has the right controls in place.
Personal information deserves particular care. The Information Commissioner's Office says organisations using AI to process personal data still need to meet their data protection responsibilities and assess and manage the risks involved.
But personal data is not the only concern.
Think about:
customer information;
employee information;
contracts;
commercially sensitive figures;
passwords or access details;
payroll, banking or tax information;
health or safeguarding information;
confidential documents belonging to somebody else.
The safe answer is not “never use AI”.
It is ‘know what you are using, what you are giving it, and what the business has approved.’
A safer quick win
You can still let staff learn what AI can do without starting with sensitive business information.
Try this with information already published on your own website.
Safe prompt:
“Using only the public information below, draft five frequently asked questions and answers for a customer. Do not add facts that are not in the source. Flag anything you are unsure about.”
Then review the result yourself.
You have now tested a useful AI task without needing customer records, employee information or confidential files.
Your 15-minute experiment
Choose one page from your public website.
Give one approved AI tool the public text and ask it to turn the information into:
a customer FAQ;
a checklist;
a short internal training outline; or
a first draft of a customer explanation.
Then spend a few minutes checking:
Was it accurate?
Did it actually save time?
What did the human reviewer have to correct?
Record the answer.
That gives you evidence about whether the task is useful, rather than adopting AI because everybody else seems to be doing it.
One staff rule you can use today
Before putting business information into AI, stop and check. Use public, dummy, anonymised or specifically approved information only. If you are unsure, do not upload it until somebody responsible has confirmed the tool and the task are approved.
Simple rules are more useful than telling staff to “use AI responsibly” and leaving them to work out what that means.
Take the next step
I have turned this into a one-page SME AI Staff Safety Rule Sheet that you can use as a starting point with your team.
Download the PDF below:
It is not a substitute for your own data protection, security or legal requirements. It is a practical first control for a business that wants staff to use AI without making up the rules as they go.
One question worth asking inside your business this week:
Do we know which AI tasks our staff are already doing?
Barbara @ AI Made Human
