Managing AI Across

Your Team

Before your next staff member opens an AI tool — you are responsible for what they do with it.

A practical governance guide for small business owners with employees, associates, and contractors using AI tools. Covers your liability, the documents you need, and the five steps that establish a defensible position before something goes wrong.

If a staff member uses a free AI account with client data, the Article 28 breach is yours. Not theirs..

You are the data controller. They acted on your behalf. The absence of a written policy does not reduce your liability — it removes your only meaningful defence when the ICO asks what steps you took to prevent it.

This guide gives you the three documents that create that defence: a signed Acceptable Use Policy, a contractor AI clause, and a completed team audit. None of them take long to implement. All of them are significantly harder to produce after something has gone wrong.

Your Liability, if a staff member does this

  • Article 28 breach. No DPA exists on a free account. You are the data controller who failed to ensure lawful processing — regardless of whether you knew it was happening.

  • Potential RIPA 2000 criminal offence. Separate GDPR transparency breach. The fact that it was the employee who pressed record is not a defence.

  • Article 28 breach plus potential Article 9 breach if health data is involved. Your business is liable. The employee's personal account does not create a separate liability.

  • You can reach us anytime via our contact page or email. We aim to respond quickly—usually within one business day.

  • Potential RIPA 2000 criminal offence. Separate GDPR transparency breach.

AI In HR & People Management

Article 22 applies

AI-assisted recruitment screening

CV screening tools, scored application forms, automated video interview analysis

ICO Guidance

AI performance monitoring

Productivity tracking, AI-generated performance scores, communication sentiment analysis

Article 22 threshold

AI scheduling & workforce tools

AI shift allocation, absence prediction, employee efficiency scoring

Transparency & DPA

AI meeting transcription tools

Otter.ai, Fireflies, Microsoft Copilot notes, Google Meet transcription

Everything Included in this Guide

AI Acceptable Use Policy — with signed acknowledgement page. Issue to every employee and contractor before they use any AI tool for business purposes

Contractor AI Use Clause — ready to add to new agreements or send as an amendment to existing contractors

Staff AI & Data Notice — your transparency obligation to employees about how AI tools affect their own data

AI Tool Audit form — run this first. Captures every tool in use across your team, the account type, and whether a DPA is in place

Approved AI Tool Register — only tools on this register may be used for work involving personal data

Policy Sign-Off Log — a dated record of every team member who has been briefed and signed the Acceptable Use Policy

AI in HR guidance — recruitment screening, performance monitoring, scheduling tools, and transcription: obligations and safe practice for each

Completed worked example — Natalie Chen (Spark Studio, 6 staff) shows a compliant AI governance framework including a completed contractor clause and team AI Tool Register

Owner's Reference Card — a quarterly review checklist: green for in place, red for immediate action needed. Print it and keep it with your policy file

AI Safe Starter Pack — the foundational seven documents, included free with this guide

Recommended pathways

Managing AI Across Your Team — £67

The profession-specific guide with staff policy template, contractor clause, team audit form, and a week-one action plan built around the highest-risk gaps for SMEs with employees or contractors using AI tools.

Both SME Guides — £109

Managing AI Across Your Team plus Using AI in Customer Relationships — recommended for SMEs whose AI exposure covers both internal staff use and customer-facing tools, which applies to most small businesses.

Compliance Bundle — £149

Both SME guides plus the Legal Pack and Companion Guide — the complete compliance infrastructure for a small business that wants documented legal agreements, a breach response plan, and internal accountability from day one

Full Suite Bundle — £229

All three tiers — the complete compliance infrastructure including the Risk & Data Pack, which covers AI marketing liability, deepfake risk, and wearable device data for businesses using AI in customer-facing roles. Website Compliance Pack, DPA volumes 1&2

Previous
Previous

Using AI in Customer Relationships

Next
Next

Therapists & Counsellors