AI governance UK — start with rules, roles and risk checks
If you run a GP practice, a dental surgery, a care home or a solicitor’s in Yorkshire, one of your staff has probably pasted a client or patient document into ChatGPT this month and asked it to “make it sound better.” Their intent was fine — quicker turnaround, cleaner writing. The problem is that whatever was in that document is now training data for a US-based AI company, and under DSPT (if you’re in health) or the ICO’s guidance (if you’re not) that’s reportable.
That’s the version of AI governance that actually matters this year. Not the boardroom slide deck. The version where a receptionist meant well and now the practice manager is on the phone to a DPO on a Friday afternoon.
The good news is you don’t need a compliance programme. You need three decisions — who’s allowed to use what, on which data, and what happens if it goes wrong — and you need them written down.
Where AI is actually breaking in Yorkshire businesses right now
Three patterns we see repeatedly across our client base — Leeds professional services, Bradford healthcare providers, M62-corridor manufacturers:
A practice manager summarising a patient complaint into ChatGPT to draft a response to the ICB. The complaint text has names, dates of birth and clinical detail in it. Every paste trains a model owned by a company outside the UK — and the practice is now processing personal data via a supplier they haven’t documented, haven’t risk-assessed, and haven’t included on their DSPT.
A solicitor using a free AI legal-research tool that pulls case data from the browser tab it’s installed in — including matters still under injunction. Nobody at the firm has read the tool’s data-retention terms.
A recruitment coordinator running CVs through an AI shortlister. It ranks candidates but nobody can explain which factors it weights. When a rejected candidate asks why, there is no defensible answer under the Equality Act.
None of the people involved are doing anything malicious. They’re solving today’s problem with the fastest tool available. Governance is what stops that from becoming an ICO letter.
The three decisions that actually matter
Who owns AI decisions. One named person, senior enough to say no. In a small business this is usually the MD or a director by default — that’s fine. What matters is a name and a decision path, not a committee.
What’s in scope. Draw a line between AI use that touches identifiable data (patient records, client detail, financial data, HR information) and AI use that doesn’t (marketing copy, generic research, drafting a boilerplate email). Different rules apply either side of the line. Mapping that scope takes about an hour for most small businesses — do it once, keep it as a single page, update it when a new tool arrives.
What the rules are. Three sentences is enough for most:
No identifiable data goes into public AI tools. Ever.
Anything AI writes that affects a person — an employment decision, a credit decision, a clinical or safeguarding decision — gets human review before it goes anywhere.
If you’re unsure whether a use case is fine, ask before you use it, not after.
Pin those three rules to the wall. That’s already more governance than 90% of UK SMEs currently have.
Where DSPT and Cyber Essentials fit in
If you’re in health or social care, DSPT already requires you to record which systems process personal data, who has access, and how the data flows. That framework extends cleanly to AI — treat each public AI service as another data processor, list it, and be honest about what’s being sent to it. If the answer to “what data are we sending?” is one you’d rather not write down, the tool needs to stop being used until you can.
Cyber Essentials doesn’t yet address AI directly, but the same access-control principles apply. If a staff member shouldn’t be able to email a spreadsheet of customer data externally, they also shouldn’t be able to paste it into a browser-based AI tool. Practically that means content-filtering rules that treat ChatGPT the same way you’d treat any external cloud upload.
The monthly fifteen-minute review
Once a month, spend fifteen minutes on four questions:
Has any new AI tool been introduced this month? (Ask, don’t assume you’d know.)
Any near-misses reported — anyone realising they nearly pasted the wrong thing?
Any external guidance changed? The NCSC and ICO both update their AI pages regularly and the DSPT toolkit refreshes annually.
Do our three rules still cover us, or is there a gap?
Log the review in whatever way suits — a shared note, a Teams post, a dated line in a spreadsheet. The record matters more than the format.
The two references worth having open
The NCSC’s AI security guidance is the best free UK-specific technical resource and is regularly refreshed with plain-English language: NCSC advice and guidance. For DSPT-specific questions the NHS Digital DSPT Support Team is genuinely useful — they’d rather help you close a gap than have you file it wrong.
The businesses we work with across Yorkshire — from Leeds healthcare providers through professional services in the LS1 core to manufacturers along the M62 — are all wrestling with this. The common mistake is assuming AI governance is an enterprise problem to worry about at 500+ staff. It isn’t. The near-miss that turns into an ICO incident doesn’t wait for you to be enterprise-sized. Start with the three decisions above, put them on a wall, and revisit them next month.







