What should an AI register include for a small business?

9 September 2026

What should an AI register include for a small business?

A small business AI register should list every AI tool or automation in use, who owns it, what it is used for, what data it touches, what risks it creates, what it costs, and when it was last reviewed. Keep it simple enough to maintain monthly. For most UK SMEs, a useful first version is a spreadsheet with 12 to 15 columns, not a heavy compliance platform.

What is an AI register in plain English?

An AI register is a single list of the AI tools, assistants and automations your business uses. It answers a basic management question: what AI is touching the business, who is responsible for it, and what could go wrong if it is used badly?

For a small business, this does not need to be complicated. It can start as a spreadsheet. Each row is one AI use: Microsoft Copilot in Outlook, ChatGPT Team for drafting, a meeting transcription tool, a customer service chatbot, an AI feature inside your CRM, a Zapier workflow that summarises enquiries, or a custom assistant connected to company documents.

The point is visibility. The Office for National Statistics reported that self-reported AI use among UK businesses with 10 or more employees rose from around 12% in late 2023 to around 35% by June 2026. That is fast growth, but the same ONS analysis found adoption is still relatively shallow, with the average adopting business using around 1.6 AI technologies. In practice, many small businesses are in the awkward middle: AI is already being used, but nobody has a complete list.

That gap creates risk. If nobody knows which tools staff are using, you cannot manage data protection, access, costs, supplier risk, customer disclosure or quality control. You also cannot tell whether AI is actually saving time. A register gives you a light control system before informal use turns into hidden dependency.

Source: Office for National Statistics, Artificial intelligence in UK businesses: 2023 to 2026.

What columns should the register include?

A useful small business AI register should include enough detail to make decisions, but not so much that nobody keeps it updated. Start with these fields: tool name, supplier, owner, department, purpose, users, data used, connected systems, customer or staff impact, risk level, cost, approval status, review date, fallback process and notes.

The owner field matters more than most people think. Every AI use needs a named person responsible for checking whether it still works, whether costs have changed, whether staff are using it properly and whether it should be retired. The owner is not necessarily technical. For a sales automation, it might be the sales manager. For AI meeting notes, it might be operations. For an AI chatbot, it might be customer service with external technical support.

The data field should be plain English. Avoid vague labels like "business data". Write what actually goes in: client emails, uploaded PDFs, call recordings, invoice details, employee notes, CRM contacts, website enquiries, product data or anonymised examples. This is where the register becomes useful for UK GDPR. The ICO's AI guidance is built around accountability, transparency, lawfulness, fairness and accuracy. You cannot evidence those principles if you do not know which AI systems process personal data or influence people.

The risk field can be simple: low, medium or high. Low risk might be drafting public social posts. Medium risk might be summarising customer enquiries for human review. High risk might be recruitment screening, finance decisions, legal advice, employee performance scoring or an automation that updates customer records without review.

How detailed does a small business AI register need to be?

Most small businesses should avoid copying enterprise governance templates. A 60-column register looks impressive for one week, then becomes stale. A stale AI register is worse than a simple one because it creates false confidence.

For a UK SME, the practical level is this: could a manager look at the register and understand what AI is being used, what data is involved, who owns it, what the main risk is and what should happen if it fails? If the answer is yes, the register is useful. If the answer is no, add detail only where the decision needs it.

A first version can be built in 90 minutes. Ask each manager to list the AI tools their team uses. Include obvious tools and embedded features. Copilot in Microsoft 365, Gemini in Google Workspace, ChatGPT Team, Claude, Canva, Notion AI, HubSpot AI, GoHighLevel AI features, transcription tools, spreadsheet assistants and automation platforms all count if they are being used for work.

Then classify each use. Does it touch personal data? Does it affect customers? Does it make or recommend a decision? Does it connect to a live business system? Does it cost money every month? Does anyone rely on it to complete a critical task? Those five questions are enough to separate harmless experimentation from something that needs proper review.

The ICO's AI and data protection risk toolkit is designed to help organisations reduce risks to individuals' rights and freedoms caused by their own AI systems. A small business does not need to turn that into a legal thesis, but the register should make it possible to spot which tools need a deeper DPIA-style review.

Source: ICO AI and data protection risk toolkit.

What should the register say about cost and value?

Cost belongs in the register because AI spending spreads quietly. One user starts paying for ChatGPT. Another team adds a meeting tool. Marketing upgrades Canva. Operations pays for an automation platform. A CRM feature gets switched on. Individually, the amounts look small. Across a year, they can become a meaningful software cost with no clear owner.

Include monthly licence cost, implementation cost, renewal date and expected value. For simple tools, the monthly cost might be GBP 20 to GBP 50 per user. For a workflow automation, there may be a setup cost of GBP 2,000 to GBP 10,000 plus platform fees. For a custom assistant connected to internal systems, costs may be higher because discovery, permissions, testing, monitoring and support all matter.

The register should not only ask "what does this cost?" It should ask "why are we keeping it?" Add a simple value field: saves time, improves quality, reduces errors, speeds up response, improves reporting, supports training, or strategic capability. If nobody can explain the value, mark it for review.

This also helps stop duplicate tools. It is common to find three different AI note-takers, two writing assistants and several disconnected automation experiments inside a small business. The register makes that visible. You may decide to standardise on one approved tool, cancel unused licences, or move sensitive work into a safer paid workspace.

If you already have an AI usage policy, the register is where that policy becomes operational. The policy says what is allowed. The register shows what is actually happening.

Who should maintain it and how often should it be reviewed?

Give the register one overall owner and several practical owners. The overall owner might be the business owner, operations lead, data protection contact or office manager. Their job is to keep the register complete and make sure reviews happen. Tool owners are responsible for individual entries.

Review rhythm depends on risk. Low-risk drafting tools can usually be reviewed every six months. Medium-risk tools that touch customer or staff data should be reviewed quarterly. High-risk uses, such as AI involved in recruitment, customer decisions, regulated advice, finance approvals or live system updates, need review before launch and after any material change.

The review should be short but real. Check whether the tool is still used, whether the supplier terms have changed, whether access is limited to the right people, whether staff understand the rules, whether outputs are being checked, whether incidents have occurred and whether the cost is still justified.

One useful habit is to make the AI register part of normal management housekeeping. Review it alongside software subscriptions, risk registers, data protection checks and process reviews. Do not make it a separate AI ceremony that everyone avoids. Small businesses need controls that fit inside existing rhythms.

For businesses with EU customers or AI outputs used in the EU, the EU AI Act may also matter. A UK business can be in scope where its AI system or output reaches the EU market. That does not mean every SME needs a complex compliance programme, but it does mean the register should flag location, customer impact and whether a use could fall into higher-risk areas such as HR, credit, education, insurance or essential services.

When this is NOT right for you

An AI register is not right if it becomes a substitute for judgement. A spreadsheet does not make a risky tool safe. It only makes the risk visible. If a tool handles sensitive client files, employee data, financial records or customer-impacting decisions, you still need proper assessment, testing and approval.

It is also not right to start with an expensive governance platform if the real problem is lack of basic visibility. Many small businesses need a clear spreadsheet, a short AI policy and manager conversations before they need specialist software. Paying for a platform will not fix shadow AI if staff do not know what they are allowed to use.

Do not use the register as a way to punish staff for experimenting. If the first message is "tell us what you use so we can catch you out", people will hide things. The better message is: "We know AI is useful. We need to use it safely, consistently and without risking client data." That is a management conversation, not a witch hunt.

Finally, do not include private prompts, passwords, secret keys, confidential client detail or copied source data in the register itself. The register should describe the category of data, not expose the data. Write "client proposal PDFs" rather than pasting a client file name. Write "CRM contact records" rather than exporting a customer list into the register.

Is This Right For You?

An AI register is right for you if staff are already using ChatGPT, Copilot, Gemini, Canva AI, CRM assistants, meeting note tools, workflow automation or custom AI workflows in daily work. It is especially useful if client data, employee information, financial records, customer messages or business systems are involved.

It is probably too much if you are a one-person business using one paid AI assistant only for low-risk drafting, with no client data and no automations connected to business systems. Even then, a one-page note of what you use, what you never upload and what it costs is still sensible.

If you want help turning informal AI use into a controlled policy and register, book a free call. No pitch, no pressure, just a practical conversation about what needs controlling and what can stay simple.

Frequently Asked Questions

Do we need an AI register if we only use ChatGPT or Copilot?

Yes, but keep it simple. Record the tool, who can use it, what it may be used for, what data must not be uploaded, what it costs and when it will be reviewed.

Should free AI tools go in the register?

Yes. Free tools can create more risk than paid tools because they are often unmanaged, individually owned and less clearly controlled by the business.

Who should own the AI register in a small business?

The overall owner should be someone with operational authority, such as the business owner, operations lead, data protection contact or office manager. Each tool should also have a practical owner.

How often should we update the AI register?

Update it whenever a new AI tool or automation is approved, and review it at least quarterly for tools touching customer, staff or financial data. Low-risk drafting tools can often be reviewed every six months.

What is the difference between an AI policy and an AI register?

An AI policy sets the rules. An AI register records the actual tools and use cases in the business, who owns them, what data they touch and what risks need managing.

Should we include AI features built into existing software?

Yes. If an AI feature inside Microsoft 365, Google Workspace, a CRM, accounts package or project tool is used for business work, it belongs in the register.

Do we need legal advice before creating an AI register?

Not to create a basic register. You may need legal or data protection advice if AI touches sensitive data, automated decisions, HR, finance, regulated advice or customers in higher-risk contexts.