How do I write an AI policy for my company?
Keep it to one or two pages and cover four things: which AI tools are approved, what data can and can't go into them, who signs off new tools, and what happens when something goes wrong.
Read the answer →Home › Blog › AI Governance & Compliance
Pillar guide
Govern AI before you scale it. Good governance is what lets people adopt AI with confidence instead of fear, and it keeps you on the right side of ISO 42001, the EU AI Act and GDPR. These guides translate the frameworks into plain English for UK SMEs.
Keep it to one or two pages and cover four things: which AI tools are approved, what data can and can't go into them, who signs off new tools, and what happens when something goes wrong.
Read the answer →You're not legally required to have ISO 42001.
Read the answer →A handful of specialist AI and governance consultancies run AI data protection audits in the UK.
Read the answer →A DPIA, or Data Protection Impact Assessment, is a structured check you do before higher-risk processing of personal data.
Read the answer →Yes.
Read the answer →AI governance doesn't have to be complex or expensive. A plain-English guide to the policies, processes and oversight that enable safe adoption.
Read the guide →A three-layer structure (sandbox, guardrails, steering group) gives people a fast, safe route and cuts shadow AI.
Read the guide →The EU AI Act becomes enforceable August 2026. Despite Brexit, UK businesses trading with the EU face compliance requirements.
Read the guide →ISO 42001 is voluntary; the EU AI Act is law by August 2026. When you need each, and when you need both.
Read the guide →73% of UK businesses don't know where their AI vendor stores data. Cloud sovereignty and GDPR compliance aren't optional.
Read the guide →AI governance for a UK business covers what data may be used with AI tools, which decisions require human involvement, who is accountable when something goes wrong, and what evidence is retained to demonstrate all of that. For most organisations it is anchored on UK GDPR obligations, with ISO/IEC 42001 providing the management-system structure where formal certification is wanted.
It depends on exposure rather than location. A UK business that places AI systems on the EU market, or whose AI output is used in the EU, can fall within scope regardless of where it is based. A UK business operating only domestically is governed principally by UK GDPR and sector regulation. The determining question is where the system and its output are used, not where the company is registered.
Start with a SPARK Discovery, or talk it through with Chris first.