How Can a Small Business Check Whether an AI Tool Is Safe Enough Before Paying for It?
16 September 2026
How Can a Small Business Check Whether an AI Tool Is Safe Enough Before Paying for It?
Before paying for an AI tool, run a short supplier check covering data use, training settings, retention, permissions, integrations, security, support and exit. For a UK small business, the key question is not whether the tool sounds clever. It is whether you can use it without exposing client data, losing control of business information or creating a workflow nobody can monitor.
What should you check first?
Start with the data. Before you pay for any AI tool, ask what information staff will put into it, whether that information includes personal data or confidential client material, and whether the supplier uses prompts, files or outputs to train its models. If you cannot answer those three questions, you are not ready to buy.
The first check should be practical, not legalistic. List the likely inputs: customer emails, contracts, call notes, invoices, proposals, HR documents, sales records, project notes, images, passwords, system exports or internal plans. Then mark each one as low, medium or high sensitivity. A tool used for brainstorming social media posts is not the same risk as a tool connected to a CRM or client document folder.
The ICO's AI and data protection guidance reminds UK organisations that accountability, governance, transparency and lawfulness still apply when AI is involved. The guidance is being updated after the Data (Use and Access) Act, but the core point remains: using AI does not remove your data protection duties. Source: ICO, Guidance on AI and data protection.
If the supplier cannot clearly explain data use, retention, deletion, training settings and where admin controls live, pause. You do not need a 40-page procurement process for every tool, but you do need answers before payment details go in.
Which supplier questions matter most?
Ask eight questions before paying. First, will our prompts, files or outputs be used for model training? Second, where is our data stored and processed? Third, how long is data retained? Fourth, can an admin control user access, sharing and deletion? Fifth, what permissions does the tool need if connected to email, files, CRM or accounts software? Sixth, what audit logs are available? Seventh, what happens if the tool gives a wrong answer or stops working? Eighth, how do we export or delete our data if we leave?
The answers do not all need to be perfect. A low-risk writing tool may not need the same audit depth as an AI support platform connected to customer records. But vague answers are a warning sign. Watch for phrases like enterprise-grade security without specifics, private by default without a policy link, or we never access your data without explaining subprocessors and support access.
The National Cyber Security Centre's secure AI system development guidance breaks AI security into secure design, secure development, secure deployment, and secure operation and maintenance. That is a useful lens for buyers too. You are not just buying a clever model. You are buying a system that needs to function as intended, stay available when needed, and avoid revealing sensitive data to unauthorised parties. Source: NCSC, Guidelines for secure AI system development.
For small businesses, the strongest supplier answer is usually specific and boring: clear data processing terms, configurable training controls, proper admin access, sensible logs, documented support, and a clean exit route.
How much checking is enough for a small business?
Use risk bands. Low-risk tools need a light check. Medium-risk tools need a written review. High-risk tools need proper approval before anyone connects data or pays for the product.
A low-risk tool might help write generic marketing ideas, summarise public information or improve internal notes with no client data. For that, check training settings, retention, admin ownership and cost. A medium-risk tool might summarise customer emails, analyse internal documents, draft sales follow-ups or connect to a shared drive. For that, add a data protection check, access review, sample testing and a named internal owner. A high-risk tool touches HR, finance approvals, legal advice, regulated work, sensitive client files, customer decisions, medical information, safeguarding, account access or automated actions inside business systems. That needs a much more serious review.
This matters because AI adoption is now common enough that ad hoc buying is risky. The Office for National Statistics reported that AI use among UK businesses with 10 or more employees rose from around 12% in late 2023 to around 35% by June 2026, with 28% of businesses with 0 to 9 employees reporting use of at least one AI technology. Source: Office for National Statistics, Artificial intelligence in UK businesses: 2023 to 2026.
In plain terms, your competitors and staff are already experimenting. That does not mean every tool needs a board paper. It means every tool needs a basic approval path that matches the risk.
What red flags mean do not pay yet?
Do not pay yet if the supplier avoids basic data questions, has no clear business terms, relies only on personal accounts, cannot explain training settings, or asks for broad access to email, files or CRM without a narrow reason. Be especially careful with browser extensions that can read pages your staff visit, because they may see information from multiple business systems at once.
Another red flag is a tool that cannot separate users, clients or workspaces properly. If you cannot manage staff access centrally, remove a leaver, restrict who can see uploaded files, or delete a workspace cleanly, the business may lose control quickly. A paid account should give you more control than a free account, not just higher usage limits.
Watch the commercial terms too. Monthly pricing can hide usage costs, premium model charges, integration fees, storage fees and support costs. Lloyds reported in July 2026 that two thirds of UK businesses had invested in AI, with the largest group spending less than £25,000, while 87% of AI-using businesses reported productivity gains. Source: Lloyds Banking Group, UK businesses adopting AI see strong gains. That shows there is real value available, but it does not justify paying for poorly understood tools.
The final red flag is no fallback. If the tool becomes unavailable, changes pricing, gives a wrong answer or quietly stops syncing, who notices and what happens next? If nobody owns that answer, do not make the tool part of an important workflow yet.
What does a simple approval process look like?
Keep it short. A small business can approve AI tools with a one-page form and a 20-minute review if the use case is low or medium risk. The form should capture the tool name, owner, purpose, cost, data used, permissions needed, supplier answers, risk level, review date and fallback plan.
The owner matters. Every approved AI tool needs a named person responsible for checking whether it is still useful, secure and worth paying for. Without that, subscriptions drift, staff keep using old tools, and nobody spots when terms or settings change.
For staff, make the process easy enough that they use it. If approval feels impossible, they may carry on with personal accounts and free tools. A good rule is: low-risk use can be approved quickly, medium-risk use needs manager and data review, high-risk use needs senior approval and possibly external advice. That gives staff a path without pretending all AI use is harmless.
Once approved, add the tool to an AI register. Review low-risk tools every six months, medium-risk tools quarterly, and high-risk tools before launch and after any material change. Also review immediately if the supplier changes terms, the tool adds new integrations, staff start using new data, or there is an incident.
When this is not enough
This checklist is not enough when the tool makes or heavily influences decisions about people, money, eligibility, legal rights, employment, credit, health, safety or regulated advice. It is also not enough when the tool processes large volumes of personal data, confidential client files, special category data, children's data, or data covered by strict client contracts.
In those cases, the business may need a DPIA, a supplier security review, contractual terms, processor due diligence, human review rules, incident response planning and legal or data protection input. That may sound heavy, but it is cheaper than approving a tool that leaks client information or produces unreviewed decisions the business cannot defend.
For most small businesses, the first version should be pragmatic. Ban passwords, confidential client uploads to unapproved tools, final HR or legal decisions, financial approvals, impersonation and unsupervised automations that can act in core systems. Allow low-risk drafting, summarising, planning and research in approved tools with clear rules. Review everything else before payment.
The goal is not to slow the business down. The goal is to buy useful AI tools without handing away data, control or accountability. If a supplier helps you answer the checks clearly, that is a good sign. If they make basic questions feel difficult, wait before paying.
Is This Right For You?
This is right for you if staff are asking to buy an AI tool, connect one to email or CRM, upload client files, install a browser extension, or move from a free account to a paid workspace. It is also useful if you already have shadow AI use and need a calm way to review tools without simply banning everything.
It is not enough for high-risk or regulated use cases on its own. If the tool will support legal, HR, finance, medical, regulated advice, credit decisions, safeguarding, automated customer decisions or confidential client work, you need stricter review and may need legal, data protection or cyber security advice.
A sensible first step is to keep a one-page AI tool register. Record the tool, owner, purpose, data used, permissions, cost, renewal date, supplier answers and review date. If you cannot fill that in, you are not ready to approve the tool.
Frequently Asked Questions
Should staff be allowed to buy AI tools on company cards?
Only after a basic approval check. Even a cheap monthly tool can create risk if it stores client data, connects to email or gives staff permission to upload confidential files.
Is a free AI tool less safe than a paid one?
Not always, but free tools often give the business less control over users, data settings, support, retention and admin access. Paid business plans are usually easier to govern, but you still need to check the terms.
What is the most important question to ask an AI supplier?
Ask whether your prompts, files and outputs are used to train models, and where that setting is controlled. If the answer is unclear, do not upload sensitive business or client data.
Do small businesses need a DPIA for every AI tool?
No. Low-risk internal tools may not need a DPIA. But if the tool processes personal data in a way that creates high risk, supports decisions about people, or handles sensitive information, a DPIA may be needed.
Can we approve AI browser extensions?
Be very careful. Some extensions can read page content across business systems. Only approve them if the permissions are narrow, the supplier is trustworthy, and staff know where they may and may not use them.
Who should own AI tool approval in a small business?
The owner or operations lead should own the process, with input from whoever handles data protection, finance and systems. Every tool should also have a named day-to-day owner.
What should go in an AI tool register?
Include the tool name, owner, purpose, supplier, cost, users, data used, permissions, risk level, approval date, renewal date, review date and any important supplier answers.
What should we do if staff are already using an unapproved AI tool?
Do not start with blame. Ask what they are using it for, what data has gone in, why it helps, and whether the use can be moved into an approved tool with safer settings.