How do I stop staff using AI to make decisions they are not qualified to make?
18 August 2026
How do I stop staff using AI to make decisions they are not qualified to make?
The practical answer is to separate AI assistance from business authority. Staff should be allowed to use AI for low-risk preparation work, but not to make decisions they are not trained, authorised or insured to make. In a UK SME, the safest rule is simple: if the decision affects someone's job, money, legal rights, health, credit, eligibility, contract, complaint outcome or sensitive personal data, AI may support the work, but a competent human must decide and document why.
The rule is simple: AI can advise, but it cannot own the decision
The cleanest way to stop staff overstepping is to remove ambiguity. AI tools should be treated as assistants, not decision-makers. They can help a person prepare, compare, summarise, draft and spot inconsistencies. They should not decide whether a candidate is suitable, whether a customer gets a refund, whether a supplier is paid, whether an employee is disciplined, whether a contract clause is acceptable, or whether a vulnerable customer should receive a particular recommendation.
This matters because AI use at work is no longer rare or centrally controlled. YouGov reported in March 2026 that 32% of workers in Britain use AI for their current job, but only 25% of those users said their employer requires it. Seventy-one per cent said they use tools that their employer neither requires nor prohibits, and 11% said they use tools their company would frown upon or has banned. In plain English, a lot of AI use is happening from the bottom up.
The Office for National Statistics also found that AI use among UK businesses with 10 or more employees rose from around 12% in late 2023 to around 35% by June 2026. The adoption is real, but it is often shallow and uneven. That is exactly when people improvise. A staff member does not usually set out to make an unauthorised AI decision. They ask a tool for help, get a confident answer, and then act on it because nobody has told them where support ends and authority begins.
Your policy should therefore use operational language, not legal abstractions. Say: AI may recommend, but it may not approve. AI may draft, but it may not send without review where the outcome affects a person or money. AI may score, but it may not be the only reason for a decision. AI may summarise evidence, but it may not replace professional judgement.
Which decisions should staff never delegate to AI?
Start by naming the red zones. These are the areas where staff need explicit permission, competence and human review before using AI outputs. The first is HR. AI should not decide who gets hired, shortlisted, promoted, disciplined, performance-managed or made redundant. It can help draft interview questions, summarise notes or check whether a job advert is clear, but a trained person must own the decision and check for fairness.
The second is finance. AI should not approve payments, credit, refunds, discounts, write-offs, payroll changes, customer eligibility or supplier selection without a human control. It can reconcile invoices, flag unusual transactions, compare quotes and prepare a recommendation. It should not press the button or become the reason nobody checks the button before it is pressed.
The third is legal and contractual work. Staff can use AI to simplify a clause, produce a plain-English summary or create a first list of questions for a solicitor. They should not use it as legal advice, accept contract risk, threaten action, concede liability or decide whether the business is compliant. The same applies to tax, financial advice, medical advice, safeguarding and regulated sectors.
The fourth is high-impact customer work. If the decision changes a customer's price, access, cancellation rights, complaint outcome, claim, refund, eligibility or personal data handling, AI should support but not decide. This is where UK GDPR becomes relevant. The ICO's guidance on Article 22 says extra rules apply to solely automated decisions that have legal or similarly significant effects. The ICO also makes clear that merely having a person involved somewhere in the process is not enough. The human review has to be meaningful and connected to the actual outcome.
A useful phrase for managers is: if we would not let a junior employee decide this alone, we should not let a junior employee plus an AI tool decide it alone either.
What does meaningful human review actually mean?
Meaningful human review is not a tick box. It means the reviewer understands the decision, has enough information to challenge the AI output, has the authority to change the outcome, and is not under pressure to rubber-stamp whatever the system says. If your process says a manager reviews AI recommendations, but the manager sees only a score and clicks approve 200 times a day, that is weak control.
The ICO's Article 22 guidance is useful here because it explains that human involvement before or around an automated process does not automatically make the final decision human-led. If a person simply feeds data into an AI system and the system's output produces the significant effect, the decision may still be solely automated. For human review to matter, it must usually happen after the AI output and relate to the actual outcome.
For a small business, this means three practical checks. First, can the human see the evidence, not just the AI answer? For example, a refund recommendation should show the order record, the customer message, the policy section and the reason for the recommendation. Second, can the human disagree without friction? A reviewer should be able to override the AI and record a short reason. Third, is the reviewer qualified for the decision? A line manager can review rota suggestions. They should not review employment law risk unless they are trained or supported by HR advice.
There is a cost to doing this properly. For most SMEs, adding review steps to a narrow AI workflow might add £500-£2,000 of setup time and a few minutes per case. That is cheaper than a bad dismissal process, an unauthorised refund pattern, a data protection complaint or a customer losing trust because your business blames the software.
How to write a decision boundary your team will follow
Most AI policies fail because they are too long, too vague or too separate from daily work. A useful decision boundary should fit on one page and be repeated inside the workflows where people actually make decisions. Do not write: use AI responsibly. Write: you may use AI to draft a customer complaint reply, but a manager must approve the final response before it is sent if the reply offers compensation, refuses compensation, admits fault or changes a contract term.
A practical structure is green, amber and red. Green uses are allowed without approval: summarising public information, rewriting internal notes, brainstorming, formatting non-sensitive text, producing meeting action lists from approved transcripts. Amber uses need review: drafting customer emails, analysing non-sensitive business data, preparing quote comparisons, creating recruitment shortlists for human review, summarising policies. Red uses are banned unless a named senior person approves the process in advance: HR decisions, legal advice, financial approvals, customer eligibility, credit, medical or safety advice, regulated work, processing special category data, and anything involving passwords or secrets.
Then add an escalation line. Staff need to know what to do when they are unsure. The line can be simple: if the AI output would change what we do for a customer, employee, supplier or regulator, ask your manager before acting. If the data includes personal, confidential or commercially sensitive information, use only approved tools and follow the data handling rule.
This does not have to slow the business down. In fact, it usually speeds up adoption because staff no longer have to guess. They know where they can move quickly and where they need support. The worst outcome is not cautious staff. The worst outcome is confident staff making decisions they were never authorised to make because the tool made the answer sound certain.
What should managers check before approving AI-supported decisions?
Managers need a repeatable approval checklist. It does not need to be complex, but it does need to be written down. Before approving an AI-supported decision, ask: what decision is being made, who is affected, what data was used, what tool was used, what evidence supports the recommendation, what could go wrong, who has authority to approve it, and where will the record be kept?
For low-risk decisions, the record might be a note in your CRM or project management system. For higher-risk decisions, keep the AI output, the human reasoning, the source evidence and the final decision. This is not bureaucracy for its own sake. It protects the business when someone later asks why a customer was refused, why a candidate was rejected, why an employee was warned, or why a payment was approved.
Managers should also check whether the AI tool is being used inside its competence zone. A tool that is useful for summarising meeting notes is not automatically safe for policy interpretation. A chatbot that writes tidy emails is not a contracts adviser. A spreadsheet assistant that spots unusual numbers is not a finance director. The more the decision depends on professional judgement, the more careful the review needs to be.
Finally, managers should look for automation bias. This is the tendency to trust a system because it appears objective. AI outputs are often fluent, structured and confident. That does not make them correct. A good review process deliberately asks for contrary evidence: what would make this answer wrong, what source did it rely on, and what would a qualified person check before acting?
When this does NOT apply
You do not need a heavy approval process for every AI use. If a staff member uses AI to rewrite a non-sensitive internal note, turn bullet points into a tidy agenda, summarise a public article or brainstorm names for a low-risk internal project, a formal sign-off process is usually unnecessary. Over-controlling harmless use makes the policy feel unrealistic, and staff will route around it.
The boundary should focus on consequence, not the presence of AI. Ask what happens if the answer is wrong. If the consequence is mild embarrassment or a manager asking for a rewrite, keep the process light. If the consequence is unfair treatment, financial loss, breach of confidence, regulatory exposure, discrimination, customer harm or contractual risk, add a proper review step.
This is also not an argument for banning AI at work. Bans often fail because staff can access tools from personal devices and because many business platforms now include AI features by default. A better approach is to make the safe path the easy path: approved tools, clear examples, short boundaries, named reviewers and a simple escalation route.
For most SMEs, the right goal is not to stop staff using AI. It is to stop AI quietly becoming the person with the most authority in the room. Keep the human accountable, make the decision trail visible, and train managers to recognise where an AI suggestion has crossed into unauthorised advice.
Sources used: ONS, Artificial intelligence in UK businesses, 2023 to 2026; YouGov, How are Britons using AI at work?; ICO, Article 22 and fairness in AI.
Is This Right For You?
This applies if your team already uses ChatGPT, Copilot, Gemini or built-in AI inside business software and you are not completely sure where the boundary sits. It is especially relevant if staff handle HR issues, quotes, refunds, contracts, customer complaints, finance approvals, recruitment, regulated advice or sensitive personal data.
It does not apply if your only AI use is harmless internal brainstorming with no customer, staff, legal or financial consequence. Even then, you still need basic data rules. But you probably do not need a heavy approval process for low-risk uses such as rewriting a meeting note or summarising a public article.
Frequently Asked Questions
Can staff use AI to shortlist job applicants?
Only with strict human review and a checked process. AI can help organise applications or highlight missing information, but it should not be the sole reason someone is rejected or shortlisted. Recruitment decisions carry discrimination and fairness risk, so a trained person must review the evidence and own the decision.
Can AI approve customer refunds or discounts?
AI can recommend a refund or discount based on policy, order history and previous cases, but a human should approve anything above a low-risk threshold. Set clear limits, such as AI may draft refund recommendations under £50, while a manager approves larger values, complaints, contract changes or cases involving vulnerable customers.
Does UK GDPR ban automated decision-making?
No. UK GDPR does not ban all automated decision-making. Article 22 creates extra protections for solely automated decisions with legal or similarly significant effects. If AI is involved in decisions about jobs, credit, eligibility, services or similar outcomes, you need to assess whether Article 22 applies and make sure meaningful human review, transparency and challenge routes exist.
What should our AI policy say in one sentence?
AI may draft, summarise, check and suggest, but it must not make or be the sole basis for HR, finance, legal, regulated, safety-critical or high-impact customer decisions. That sentence is not the whole policy, but it is the boundary staff need to remember.
Who should approve exceptions to the AI decision rule?
Use the person who already owns the risk. HR decisions should go to HR or the business owner. Financial approvals should go to finance or a director. Legal and contract issues should go to whoever is authorised to take legal advice. Customer-impacting decisions should go to a manager who understands the policy and the customer risk.
How much does it cost to put this control in place?
For a small business, a basic AI decision boundary and staff briefing might cost £500-£2,000 in internal time or external support. A fuller policy, workflow mapping, manager checklist and tool review usually sits around £2,000-£7,500 depending on how many teams and systems are involved. Regulated or multi-site businesses should budget more.
Should we log every AI output staff use?
No. Logging every harmless output creates noise and staff frustration. Log the decisions that matter: HR, finance, legal, regulated, customer-impacting, sensitive-data and high-value operational decisions. For those cases, keep the AI output, evidence reviewed, human decision and approval record.