How often should a small business review the AI tools its staff are using?

10 September 2026

How often should a small business review the AI tools its staff are using?

A UK small business should do a light monthly AI tool check, a proper quarterly review, and an immediate review whenever risk changes. For most SMEs, that means checking who is using each tool, what data it touches, what it costs, whether settings have changed, and whether staff are still following the rules.

What is the honest review schedule?

The honest answer is monthly, quarterly and event-driven. Once a month, spend 20 to 30 minutes checking your AI register: which tools are in use, who owns them, what they cost, whether anyone has added a new tool, and whether any tool is now touching more sensitive data than before. Once a quarter, do a deeper review that looks at risk, value, permissions, data use, supplier changes, user behaviour and whether each tool still deserves to be approved.

That sounds more formal than it needs to be. For a 10-person business, the monthly review might be a spreadsheet check by the owner or operations lead. For a 40-person business, it might be a short meeting with operations, finance, data protection and the managers who actually see how the tools are being used. The point is not to create paperwork. The point is to avoid finding out six months later that staff have been pasting client contracts into a free account, paying for three overlapping tools, or relying on an automation nobody owns.

The review also needs trigger points. If a tool changes its privacy terms, adds new AI features, connects to your CRM, joins meetings, starts summarising customer conversations, uses browser access, stores prompts, or allows agents to take actions, review it immediately. The National Cyber Security Centre has warned that agentic AI increases risk because these systems can access data sources, remember context, use tools and take actions. That is a different risk level from a chatbot used for low-risk drafting.

A simple rule works well: monthly check, quarterly review, immediate review when risk changes. If you cannot explain what a tool is used for, what data it sees and who can turn it off, it should not be treated as approved.

Why quarterly is usually the minimum safe cadence

Quarterly is the minimum sensible cadence because AI use changes faster than most small business policies. Tools add features quietly. Staff discover new use cases. Vendors adjust data controls. Browser extensions gain extra permissions. Microsoft 365, Google Workspace, CRM platforms and project management tools keep embedding AI into places where business data already sits. If your review cycle is annual, your policy will almost certainly be out of date for most of the year.

The UK adoption data supports that point. The Office for National Statistics reported in July 2026 that self-reported AI use among UK businesses with 10 or more employees rose from around 12% in late 2023 to around 35% by June 2026. It also found adoption is still relatively shallow, with adopting businesses using an average of around 1.6 AI technologies. That is exactly the stage where small businesses can still get control without needing a heavy governance department.

DSIT's AI Adoption Research, updated in February 2026, found that around 1 in 6 UK businesses were already using at least one AI technology, and that 85% of AI adopters used natural language processing and text generation. It also found that, among adopters, 30% of staff used AI on average. For an SME, that means AI is rarely confined to one technical user. It spreads through normal work: emails, notes, reports, customer replies, meeting summaries, analysis and admin.

A quarterly review gives you enough rhythm to catch this spread while it is still manageable. You can ask: has usage expanded, has risk changed, are costs creeping up, are staff using the right accounts, and are managers checking outputs properly? If the answer is unclear, the tool needs attention before it becomes normal business practice.

What should you check each month?

The monthly check should be deliberately light. If it takes half a day, it will not happen. The owner, operations lead or named AI register owner should open the register and check five things: new tools, new users, new data, new costs and new incidents. That is enough to spot most early problems.

New tools means staff have started using something that is not on the approved list. This includes obvious tools such as ChatGPT, Claude, Copilot and Gemini, but also AI meeting assistants, transcription bots, browser extensions, design tools, spreadsheet add-ons and CRM features. New users means the tool has moved from one person experimenting to a team relying on it. That change matters because informal habits quickly become process.

New data means the tool is now seeing client names, emails, contracts, financial records, HR information, support tickets, supplier records or commercially sensitive plans. The AI.gov.uk security guidance makes a practical distinction between public AI applications, embedded AI applications and public AI APIs. It warns that with public AI applications you cannot easily control what users enter, and that embedded AI tools and extensions bring their own architecture, licence and security concerns. That is exactly why a monthly data check matters.

New costs means subscription creep. A small team can easily end up paying £20 to £30 per user per month for several overlapping tools, plus automation, meeting transcription and CRM AI add-ons. New incidents means anything that felt off: wrong advice sent to a customer, confidential data pasted into the wrong place, an automation making extra work, or a manager unable to explain where an AI output came from. The monthly check is not a full audit. It is an early warning system.

What should the quarterly review cover?

The quarterly review is where you decide whether each tool remains approved. For each AI tool, ask: what business problem does it solve, who owns it, who uses it, what data does it process, where is that data stored, what permissions does it have, what does it cost, what could go wrong, and how would we stop using it if needed?

This is also the time to compare value against reality. A tool that costs £300 a month and saves a team two hours a week may be worth keeping. A tool that costs £900 a month, produces work nobody trusts and needs constant correction should probably go. Track value in practical terms: hours saved, rework reduced, response speed improved, fewer handovers, fewer missed actions, better reporting or lower external spend. Avoid vague claims such as improved productivity unless someone can point to the work that changed.

Data protection should be part of the same review, not a separate mystery exercise. The ICO's AI and data protection guidance says organisations are responsible for complying with data protection law and demonstrating that compliance in AI systems that process personal data. Its accountability guidance says governance and risk management should be proportionate to the AI use case, and that organisations must demonstrate on an ongoing basis how they address data protection by design and default. For an SME, proportionate may mean a simple DPIA-style checklist for higher-risk tools rather than a formal enterprise programme.

The quarterly review should end with one of four decisions for each tool: keep approved, keep with conditions, pause until reviewed, or remove. Conditions might include staff training, switching to business accounts, turning off model-training settings where available, reducing permissions, limiting the data allowed, or assigning a named owner. The decision should be written down in the AI register.

Which changes should trigger an immediate review?

Some changes should not wait for the next month or quarter. Review immediately if a tool starts touching personal data, client files, finance records, HR information, confidential commercial plans, customer communications or operational systems. Also review immediately if it gains the ability to take actions, send messages, update records, call APIs, join meetings, browse websites, read files, create tasks or make decisions that affect customers or staff.

Agentic tools deserve special attention. The NCSC's 2026 guidance on agentic AI says organisations should start small, use agents only for low-risk tasks, apply established cyber security controls from the outset, and maintain visibility of the system's operation. It also states that if you cannot understand, monitor or contain an agent's actions, it is not ready for deployment. That is a clear review trigger for small businesses: any AI tool moving from advice to action needs a fresh approval.

Vendor and contract changes matter too. If a tool changes its terms, pricing, privacy notice, data retention, integration model, training settings or ownership clauses, review it before staff keep using it as normal. The same applies when a free tool becomes paid, when a personal account becomes a shared workflow, or when a tool is bought by another company. Most AI risk does not arrive with a dramatic warning. It arrives as a small setting, plugin, integration or shortcut that nobody formally approved.

There should also be a human trigger. If staff are confused about what is allowed, if managers cannot answer questions, if customers complain about AI-generated responses, or if people start hiding their tool use because the rules feel unrealistic, review the policy. Uncontrolled AI use is often a management signal, not just a staff behaviour problem.

When this is not right for you

This level of review is not right for every tiny use case. If one director is using a paid, approved AI assistant to rewrite internal notes with no personal data, no customer impact and no system access, a monthly check may be unnecessary. Record the tool, set the rule, review it quarterly and move on. Governance should match risk.

It is also not right to turn AI review into a blame exercise. If you discover staff are using unapproved tools, the first question should be why. Are approved tools too slow? Are staff trying to solve real bottlenecks? Has the business failed to provide a usable route for approval? The NCSC has noted that understanding why staff use unapproved AI tools is key to managing the security challenges they create. A ban without alternatives often pushes the behaviour underground.

On the other hand, do not under-react where risk is real. If AI is connected to customer service, HR, finance, legal documents, medical or care information, regulated work, safeguarding, lending, recruitment, disciplinary processes or critical operations, a casual quarterly glance is not enough. Those tools need proper ownership, access control, testing, monitoring, incident planning and documented approval.

The practical dividing line is simple: the more data, permissions, customer impact and automation a tool has, the more often it needs review. A low-risk writing assistant can sit on a quarterly cycle. A tool that can email customers, update a CRM or analyse client files needs monthly monitoring and immediate review when anything changes. If that sounds too much, the tool may be too powerful for the business's current maturity.

Is This Right For You?

This review rhythm is a good fit if your team already uses ChatGPT, Copilot, Gemini, meeting note tools, AI browser extensions, CRM AI features or workflow automation tools. It is especially useful if you have client data, staff using their own accounts, shared inboxes, customer records, finance files or operational workflows involved.

It is not right for you if you are trying to create enterprise-style governance for one harmless experiment. If one person is using an approved AI assistant for low-risk drafting with no client data, a simple entry in your AI register and a quarterly check may be enough. The aim is control without bureaucracy.

Frequently Asked Questions

Do we need a formal AI committee?

Usually not. A small business needs a named owner, a simple AI register and a clear approval route. A committee only makes sense if several teams are using AI across sensitive data, customer workflows or regulated decisions.

Who should own the AI tool review?

Give ownership to someone with operational authority, not just technical curiosity. In many SMEs that is the owner, operations manager, finance lead or data protection lead, with input from managers who see the tools being used.

What should be in the monthly AI check?

Check for new tools, new users, new data, new costs and any incidents. If nothing has changed, record that and move on. The monthly check should be quick enough that it actually happens.

What should be in the quarterly AI review?

Review purpose, ownership, users, data, permissions, supplier terms, costs, risks, value, incidents, staff training and whether the tool should stay approved. End with a written decision in the AI register.

Should free AI tools be reviewed too?

Yes. Free tools can still process sensitive information, store prompts, change terms, encourage personal-account use or create outputs staff rely on. Price is not the same as risk.

How often should we review Microsoft Copilot or Google Gemini?

Review embedded office-suite AI tools quarterly as a baseline, and sooner if you change permissions, roll them out to more staff, connect more data sources or allow customer-facing use.

What is the biggest warning sign that review is overdue?

If nobody can say which AI tools staff use, what data they touch, who approved them and who owns them, review is overdue. That is usually when shadow AI has moved from experimentation into business process.

Do we need to review AI tools after every product update?

Not every minor update. Review after changes that affect data use, privacy terms, permissions, integrations, automation, pricing, account ownership or the type of work the tool can do.