Managing AI Across
Your Team
Before your next staff member opens an AI tool — you are responsible for what they do with it.
A practical governance guide for small business owners with employees, associates, and contractors using AI tools. Covers your liability, the documents you need, and the five steps that establish a defensible position before something goes wrong.
If a staff member uses a free AI account with client data, the Article 28 breach is yours. Not theirs..
You are the data controller. They acted on your behalf. The absence of a written policy does not reduce your liability — it removes your only meaningful defence when the ICO asks what steps you took to prevent it.
This guide gives you the three documents that create that defence: a signed Acceptable Use Policy, a contractor AI clause, and a completed team audit. None of them take long to implement. All of them are significantly harder to produce after something has gone wrong.
Your Liability, if a staff member does this
-
Article 28 breach. No DPA exists on a free account. You are the data controller who failed to ensure lawful processing — regardless of whether you knew it was happening.
-
Potential RIPA 2000 criminal offence. Separate GDPR transparency breach. The fact that it was the employee who pressed record is not a defence.
-
Article 28 breach plus potential Article 9 breach if health data is involved. Your business is liable. The employee's personal account does not create a separate liability.
-
You can reach us anytime via our contact page or email. We aim to respond quickly—usually within one business day.
-
Potential RIPA 2000 criminal offence. Separate GDPR transparency breach.
AI In HR & People Management
Article 22 applies
AI-assisted recruitment screening
CV screening tools, scored application forms, automated video interview analysis
ICO Guidance
AI performance monitoring
Productivity tracking, AI-generated performance scores, communication sentiment analysis
Article 22 threshold
AI scheduling & workforce tools
AI shift allocation, absence prediction, employee efficiency scoring
Transparency & DPA
AI meeting transcription tools
Otter.ai, Fireflies, Microsoft Copilot notes, Google Meet transcription
Everything Included in this Guide
AI Acceptable Use Policy — with signed acknowledgement page. Issue to every employee and contractor before they use any AI tool for business purposes
Contractor AI Use Clause — ready to add to new agreements or send as an amendment to existing contractors
Staff AI & Data Notice — your transparency obligation to employees about how AI tools affect their own data
AI Tool Audit form — run this first. Captures every tool in use across your team, the account type, and whether a DPA is in place
Approved AI Tool Register — only tools on this register may be used for work involving personal data
Policy Sign-Off Log — a dated record of every team member who has been briefed and signed the Acceptable Use Policy
AI in HR guidance — recruitment screening, performance monitoring, scheduling tools, and transcription: obligations and safe practice for each
Completed worked example — Natalie Chen (Spark Studio, 6 staff) shows a compliant AI governance framework including a completed contractor clause and team AI Tool Register
Owner's Reference Card — a quarterly review checklist: green for in place, red for immediate action needed. Print it and keep it with your policy file
AI Safe Starter Pack — the foundational seven documents, included free with this guide
Recommended pathways
Managing AI Across Your Team — £67
The profession-specific guide with staff policy template, contractor clause, team audit form, and a week-one action plan built around the highest-risk gaps for SMEs with employees or contractors using AI tools.
Both SME Guides — £109
Managing AI Across Your Team plus Using AI in Customer Relationships — recommended for SMEs whose AI exposure covers both internal staff use and customer-facing tools, which applies to most small businesses.
Compliance Bundle — £149
Both SME guides plus the Legal Pack and Companion Guide — the complete compliance infrastructure for a small business that wants documented legal agreements, a breach response plan, and internal accountability from day one
Full Suite Bundle — £229
All three tiers — the complete compliance infrastructure including the Risk & Data Pack, which covers AI marketing liability, deepfake risk, and wearable device data for businesses using AI in customer-facing roles. Website Compliance Pack, DPA volumes 1&2