Skip to main content
Download free report
Softblues
Softblues
Back to Blog
AI Strategy & Consulting
July 23, 20268 min readLast updated: July 29, 2026

AI Governance for UK Mid-Market Companies: Policies, Guardrails and Sign-Off

78% of employees use AI tools their employer hasn't approved. Shadow AI is already in your building. Here's what an AI governance policy should contain, who signs it off, and how the EU AI Act reaches UK firms.

By Ivan Pylypchuk, CEO of SoftBlues

In July 2025, 78% of employees said they use AI tools their employer has not approved (WalkMe/SAP, Aug 2025). Shadow AI is already in your building. Your staff are running the AI experiment. Governance is how you find out what they are doing, and make it safe, before it becomes a problem.

For a UK mid-market company, governance is not a 40-page policy nobody reads. It is a short set of rules: what data can go into which tools, who is accountable, and where a human has to check the output. This guide covers what an AI governance policy should contain, who signs it off, and how the EU AI Act reaches UK companies.

Key facts

  • 78% of employees use unapproved AI tools at work (WalkMe/SAP, July 2025 survey of 1,000 workers).
  • 69% of organisations suspect or have evidence that staff are using prohibited public generative AI tools (Gartner, 2025).
  • 38% of employees have shared confidential data with an AI platform without approval (CybSafe & National Cybersecurity Alliance, late 2024).
  • The EU AI Act's obligations for general-purpose AI took effect on 2 August 2025 and can apply to UK companies that put AI systems or outputs into the EU market (Baker McKenzie, Aug 2025).
  • Gartner expects at least 30% of generative AI projects to be abandoned after proof of concept by the end of 2025, with weak risk controls among the causes (Gartner, Jul 2024).

  • What is AI governance for a mid-market company?

    AI governance is the set of rules and accountabilities that decide how your company uses AI. Which tools are allowed. What data can go into them. Who owns the risk. How outputs get checked before they reach a customer or a regulator. It is the difference between "our team uses ChatGPT for some things" and "we know exactly what runs where, and who signs it off."

    For a 50-to-500-person company, governance should fit on a few pages. You are not trying to match a bank's model-risk framework. You are trying to stop confidential data leaking into public tools, stop unchecked AI output going out under your name, and give one named person the authority to say yes or no.

    Important
    Governance is not the enemy of adoption. The companies that write down clear rules move faster, because staff stop guessing what is allowed and start building on approved ground.

    Why does AI governance matter now?

    Because the experiment is already running without you. When 78% of employees use tools you have not sanctioned, and 38% have pasted confidential data into one, the risk is live whether or not you have a policy. Shadow AI is the default state of an ungoverned company.

    Three pressures make this urgent for UK mid-market firms in 2026. Data exposure: a supplier contract or client record pasted into a consumer AI tool may be retained and used for training. Accountability: if an AI-drafted email, quote or report is wrong, the liability is yours, not the tool vendor's. Regulation: the EU AI Act now bites on some UK companies, and UK sector regulators such as the FCA and the ICO already expect you to control automated decisions.

    None of this requires you to ban AI. It requires you to know where it runs. If you want the upside without the exposure, governance is the price of entry.

    What should an AI governance policy actually contain?

    A workable mid-market policy answers five questions in plain language. Which tools are approved. What data is allowed in each. When a human must review the output. Who is accountable. How staff report a problem. Everything else is detail.

    The right weight depends on your sector and how automated the decision is. A marketing team drafting copy needs lighter rules than a finance team touching client money. Match the control to the risk:

    ApproachBest forWhat it looks likeAvoid if
    Light-touch guardrailsLow-risk internal work: drafting, summarising, researchApproved-tools list, a "no confidential data in public tools" rule, human review before anything goes externalYou handle regulated data or automate decisions about people or money
    Structured policyMid-market firms in finance, legal, healthcare, HRThe above plus data-classification tiers, a named owner, an approval step for new use cases, and an audit trailYou are pre-revenue or have no sensitive data at all
    Full model-risk frameworkLarge regulated enterprises, automated credit or clinical decisionsModel validation, bias testing, documented sign-off per model, continuous monitoringYou are a 50-to-500-person company. This is usually overkill and stalls adoption

    Most mid-market companies belong in the middle row. A structured policy is enough to be safe and still ship.

    Who signs off on AI use, and how?

    Governance fails when nobody owns it. The fix is to name people, not committees. Here is a RACI that works for a company of 50 to 500.

    1. An accountable owner. One executive, often the COO, CTO or Head of Operations, owns the AI policy and has the authority to approve or block a new use case. Not a working group. One name.

    2. Use-case sign-off, not tool-by-tool. Approve what you are doing with AI, for example "summarise inbound client emails", not just "we bought a licence." The owner checks the data involved and the review step before it goes live.

    3. A human-in-the-loop rule for anything that leaves the building. AI can draft. A person approves. Nothing goes to a customer, a regulator or a payroll run without a named human checking it.

    4. A simple register. One page or spreadsheet listing each approved use case, the tool, the data class, and who reviews the output. This is what a regulator or an auditor will ask to see.

    5. A reporting route. Staff need one channel to flag a bad output or a near-miss, with no blame attached. Near-misses are how you find the gaps before a customer does.

    💡Tip
    Start the register with what people already do. You will find shadow AI use you did not know about, and turning it from hidden to logged is most of the governance win.

    What does the EU AI Act mean for a UK company?

    Leaving the EU did not put UK companies out of reach of the AI Act. The Act applies by market, not by headquarters. If your AI system, or its output, is placed on or made available in the EU market, you can be in scope regardless of where you are based (Baker McKenzie, Aug 2025).

    The general-purpose AI obligations that took effect on 2 August 2025 land mainly on model providers, not on a mid-market company using an off-the-shelf tool. Two things still matter for you. If you substantially modify a general-purpose model, retraining or fine-tuning it so its behaviour changes materially, you may become a provider yourself, with the provider's obligations. And if you build a higher-risk AI system for the EU market, the Act's risk tiers apply on their own timeline.

    For most UK mid-market firms in 2026, the practical answer is short. Know whether you touch the EU market. Keep documentation of what your AI does. Do not fine-tune a model into a new product without legal advice. This sits alongside UK expectations from the FCA and ICO, not instead of them. The AI vendor security questionnaire covers the supplier side of the same problem.

    Red flags that mean your AI use is out of control

  • No approved-tools list. If nobody can tell you which AI tools are sanctioned, all of them are, including the free consumer ones that train on your data.
  • Confidential data with no boundary. Client records, contracts or health data going into tools with no data-processing agreement.
  • AI output shipping with no human check. Quotes, advice or customer replies going out unreviewed.
  • No owner. "Everyone" owns the policy, so no one does.
  • A policy nobody has read. A 40-page document filed and forgotten is not governance. A one-page rule people follow is.
  • A practical way to start in 90 days

    1. Weeks 1 to 2: find the shadow AI. Ask teams what they already use and for what. No blame. You are mapping reality, not auditing it.

    2. Weeks 3 to 4: write the one-pager. Approved tools, data-classification tiers, the human-review rule, the owner, the reporting route. Keep it to two pages.

    3. Weeks 5 to 8: stand up the register and pick two safe use cases. Move two high-value, low-risk tasks onto approved tools with a review step. Prove the model works.

    4. Weeks 9 to 12: review and widen. Check the register, close any gaps, and approve the next set of use cases. Governance is a habit, not a launch.

    This is the same sequence we use with clients. Know where AI runs, control the data, name the owner, then scale. You can see the disciplined version of it in our work on monthly compliance file review for a financial-advice firm, where the review step and audit trail were the point, not an afterthought.


    Frequently asked questions

    Do we need an AI governance policy if we only use AI internally?

    Yes. Most of the risk, confidential data leaking into public tools, happens on internal work. A light-touch policy with an approved-tools list and a "no sensitive data in public tools" rule covers the common case.

    How long should an AI governance policy be for a mid-market company?

    Two pages of rules people actually follow beats a 40-page framework nobody reads. Keep the policy short and put the detail in a register of approved use cases.

    Who should own AI governance?

    One accountable executive, usually the COO, CTO or Head of Operations, with the authority to approve or block use cases. Committees diffuse accountability. A named owner keeps it.

    Does the EU AI Act apply to UK companies?

    It can. The Act applies by market: if your AI system or its output is made available in the EU, you may be in scope regardless of being UK-based. Most mid-market firms using off-the-shelf tools face limited obligations, but fine-tuning a model into a new product changes that.

    What is shadow AI and why does it matter?

    Shadow AI is staff using AI tools without approval, which 78% of employees admit to. It matters because it moves confidential data and business decisions into tools you do not control or audit.

    How do we let staff use AI without losing control of data?

    Publish an approved-tools list with proper data-processing agreements, classify what data can go into which tool, and require a human review before AI output leaves the company. Log each use case in a register.

    Is governance going to slow down our AI adoption?

    Done well, it speeds adoption. Clear rules stop staff guessing what is allowed, so they build on approved ground instead of hiding what they do.


    SoftBlues is an Anthropic Partner Network member and a Google Cloud Partner. We are practitioners, not slide-deck consultants. We help UK and Ireland mid-market teams put AI to work with the guardrails and sign-off that keep it safe. If you want a governance model that fits your risk without stalling adoption, and a plan to move real work onto approved tools, see how we approach business automation or read our Claude Enterprise implementation checklist.

    Book a discovery call.

    See it in production

    Systems we have built and run for clients, with the numbers that came out of them.

    Browse all case studies

    Related Articles