Generative AI can help a small business draft documents, summarise information, analyse data and remove repetitive administration. The benefits are real, but so are the risks created when employees adopt public AI tools without agreed rules.
The UK government published its AI Cyber Security Code of Practice on 31 January 2025. Although much of the detailed guidance is aimed at organisations that develop or deploy AI systems, its secure-by-design principles are equally useful when an SME selects and governs an AI service.
Start with an approved-use policy
Your policy does not need to be long. It should tell people which services are approved, which accounts they must use and what information must never be entered. Customer records, passwords, private contracts, health information, payment data and unpublished intellectual property should be excluded unless the chosen service has been formally assessed and configured for that purpose.
Make one person accountable for the policy and review it regularly. AI services and their terms change quickly, so an approval made six months ago should not be treated as permanent.
Six controls to put in place
- Inventory AI use. Ask teams which tools they already use, what data they submit and which outputs influence business decisions.
- Use managed business accounts. Avoid personal accounts for company work. Apply single sign-on, multi-factor authentication and prompt removal of access when somebody leaves.
- Classify information. Give employees simple examples of public, internal, confidential and restricted information so they can make safe decisions.
- Check suppliers. Review how prompts and files are stored, whether they are used for model training, where data is processed and how it can be deleted or exported.
- Keep a human in the loop. AI output can be inaccurate or incomplete. Important technical, legal, financial and customer-facing work should always be checked by a competent person.
- Log and respond. Provide a route for reporting accidental disclosure, unsafe output or suspicious activity, and make AI services part of your incident-response plan.
Protect the surrounding technology
An AI policy cannot compensate for weak identity or device security. Keep endpoints supported and patched, restrict administrator privileges, secure cloud storage and maintain recoverable backups. Where an AI assistant connects to email, files or customer systems, grant only the minimum permissions needed for its task.
Begin with a low-risk pilot and measure whether the tool produces a genuine improvement. A controlled trial is easier to secure, support and evaluate than an organisation-wide launch.
How MSP247 can help
MSP247 can review your current AI usage, identity controls, devices and cloud configuration, then help you build a practical policy that supports productivity without losing control of business data. Our IT consultancy and managed IT support services cover the complete environment rather than one isolated application.
Contact MSP247 to plan a secure AI pilot or review tools already in use.

