Salesforce's 2026 Workforce AI Survey found that 67% of employees now use AI tools at work, yet ISACA's May 2026 Pulse Poll of over 3,400 digital trust professionals found only 38% of organisations have a comprehensive AI policy in place. That gap between adoption and governance is where the real risk sits, and it's growing faster than most businesses are tracking it.
This isn't a theoretical concern. IBM's 2025 Cost of a Data Breach Report found that shadow AI, employees using AI tools without organisational approval, was present in 1 in 5 of the breaches studied, adding an average of $670,000 to the cost of each one. This guide sets out a practical way to close that gap: how to write AI policies that hold up in practice, secure the data flowing through AI tools, assign real ownership, and balance innovation against risk without simply banning AI outright.
Employees aren't waiting for a policy before they start using AI, and prohibition alone doesn't work. Multiple 2026 surveys converge on the same story from different angles: PagerDuty found two-thirds of office professionals at large organisations have used AI tools they believed weren't permitted under company policy, and BlackFog found 69% of C-suite respondents said they prioritise speed over privacy when deciding whether to use an unapproved AI tool themselves.
The data exposure risk is concrete, not abstract. Analysis from Technology Radius found personally identifiable information appears in around 65% of shadow AI-related incidents, with intellectual property involved in roughly 40%. Once information is pasted into a public AI tool, an organisation typically has no control over how it's stored, used for training, or exposed downstream.
Regulatory pressure is building too, even though the UK hasn't passed a dedicated AI Act. Businesses are still expected to govern AI use under existing law: the Information Commissioner's Office holds a statutory duty, as of May 2026, to produce a Code of Practice on AI and automated decision-making, expected to carry binding legal weight once finalised. In the meantime, the five principles set out in the UK's 2023 AI White Paper, safety and robustness, transparency, fairness, accountability, and contestability, are already the yardstick regulators use when assessing how organisations govern their AI use. If you sell into or process data from the EU, the EU AI Act applies directly regardless of where your business is based.
You don't need to adopt all of these, but understanding what each one actually does will save months of rework.
NIST AI Risk Management Framework. A voluntary, US-originated framework built around four functions: Govern, Map, Measure, and Manage. It doesn't prescribe specific controls; instead it gives you a structured way to think about AI risk and document decisions. This makes it the fastest realistic starting point for most SMBs, since it requires no certification and adapts to your existing size and risk appetite.
ISO/IEC 42001. The world's first certifiable international standard for AI management systems, following the same Plan-Do-Check-Act cycle as ISO 27001. Unlike NIST, it involves formal documentation, internal audits, and third-party certification. It's worth pursuing once you need to demonstrate governance maturity to clients, procurement teams, or regulators, rather than as a first step.
EU AI Act. The world's first comprehensive AI-specific regulation, using a four-tier risk classification from unacceptable to minimal risk. It's legally binding, but only directly relevant if you have EU market exposure or deploy systems classed as high-risk there.
Governance that only says no tends to fail quietly. Awareways' 2025 Trend Report found a meaningful share of prospective employees say AI access influences their choice of employer, meaning heavy-handed blocking can cost you talent as well as drive AI use further underground where you have no visibility at all. Where organisations have provided approved, secure alternatives to popular consumer AI tools, unauthorised usage has dropped sharply as a result, evidence that giving people a sanctioned path is more effective than restriction alone.
| Framework | Type | Best starting point for |
|---|---|---|
| NIST AI RMF | Voluntary, risk-based | Most SMBs building their first governance structure |
| ISO/IEC 42001 | Certifiable management system | Businesses needing to prove governance maturity to clients or procurement |
| EU AI Act | Legally binding regulation | Any business with EU market exposure or high-risk AI use cases |
| UK principles (ICO / DSIT) | Sector-led, principles-based | All UK organisations, regardless of size, as the current baseline expectation |
Do we need ISO 42001 certification, or is NIST enough? For most SMBs starting out, NIST AI RMF is the more practical first step since it requires no certification and can be implemented internally. ISO 42001 becomes worth pursuing once clients or regulators specifically require documented, audited proof of your AI governance.
Does the EU AI Act apply to us if we're only based in the UK? It can. The EU AI Act applies based on market impact, not company location, so if you offer products or services into the EU, or process data belonging to EU residents through AI systems, elements of the Act may still apply to you.
Who should own AI governance internally? Not IT alone. Effective governance typically sits with a small cross-functional group covering IT, legal or data protection, and the business functions actually using AI, with one named individual accountable for keeping the register and policy up to date.
How long does this actually take to put in place? A basic register, ownership structure, and acceptable use policy can realistically be built within 6 to 8 weeks for most SMBs. Pursuing ISO 42001 certification is a longer undertaking, typically several months, given the documentation and audit requirements involved.
Can Protrona help us build this? Yes. Our compliance-as-a-service and risk management services cover AI policy development, risk classification, and ongoing review, alongside our guidance on using AI safely.