Who should approve AI tools in a small business with no IT department?

16 August 2026

Who should approve AI tools in a small business with no IT department?

In a small business with no IT department, AI tools should be approved by a named business owner, the person responsible for the workflow, and a data protection or operations lead. Low-risk tools can use a light approval process, but anything involving client data, personal data, integrations, staff monitoring, finance, HR or customer decisions needs senior sign-off and, often, external advice.

Who should own the approval decision?

The owner or managing director should own the final approval for AI tools, but they should not make the decision alone. In a small business with no IT department, the right approval group is usually three people: the business owner or senior decision-maker, the person who owns the process being changed, and whoever is responsible for data protection, finance or operations. If you have an external IT provider, accountant, solicitor, compliance adviser or AI consultant, use them as technical input rather than handing them the business decision.

This matters because AI approval is not just a software purchase. It can affect client data, staff behaviour, supplier contracts, brand risk, legal obligations, and the quality of work sent to customers. The Office for National Statistics reported in 2026 that AI use among UK businesses with 10 or more employees had risen from around 12% in late 2023 to around 35% by June 2026. That growth means staff are often experimenting before leadership has put rules in place.

A simple approval rule works best: one person is accountable, two or three people review risk, and every approved tool has a named owner. Do not let approval drift into whoever has the company credit card or whoever is most enthusiastic about AI.

What should each person check before saying yes?

The business owner should check commercial fit. Is this tool solving a real problem, or is it another subscription people will try for two weeks and forget? What outcome will prove it is worth keeping? For a small business, that might be five hours a week saved on admin, faster response times, fewer missed enquiries, or better reporting. If the value cannot be described in one sentence, the approval should pause.

The process owner should check practical fit. They know how the work actually happens: which spreadsheet is out of date, which inbox gets messy, which customer cases are sensitive, and where mistakes would hurt. Their job is to say whether the AI tool will genuinely fit the workflow, what training staff need, and where human review must stay in place.

The data protection or operations lead should check risk. That means asking what data goes into the tool, where it is stored, whether the supplier can use it for model training, who has access, how outputs are checked, and what happens if the tool gives a wrong answer. If personal data, client files, contracts, health information, financial records or HR information are involved, the bar should be much higher. For many SMEs, the data protection lead may be the owner, office manager or external adviser rather than a formal DPO.

When do you need outside help?

You do not need a consultant for every AI subscription. A low-risk writing assistant used on public information can often be approved internally if staff follow clear rules. You should bring in outside help when the tool connects to business systems, processes personal data at scale, affects customer decisions, changes staff monitoring, touches regulated work, or creates a workflow the business will depend on every day.

The ICO's AI governance and accountability toolkit says organisations should appoint a DPO or nominated data protection lead with responsibility for overseeing AI systems, assign technical and operational roles, and evidence that senior management has seen and signed off AI risks. That is written for a broad range of organisations, but the small business version is straightforward: get named responsibility on paper before the tool goes live.

Outside support is especially useful for supplier questions. Many business owners can judge whether a tool feels useful, but not whether the contract protects their data, whether the integration is secure, or whether the supplier's claims about training data are meaningful. Paying £500 to £2,000 for a focused review can be cheaper than approving a tool that creates a privacy breach, locks you into the wrong system, or quietly pushes staff into unsafe habits.

What should the approval process look like in practice?

Keep the process short enough that staff will use it. A one-page approval form is usually better than a 20-page policy. Ask for the tool name, supplier, intended use, business owner, data being entered, systems connected, users who need access, expected benefit, monthly or annual cost, risk level, human review step, and review date. If nobody can fill that in, the business is not ready to approve the tool.

Use three approval levels. Low-risk tools can be approved by the process owner and business owner. Medium-risk tools, such as AI connected to CRM notes or internal documents, should also be reviewed by the data protection or operations lead. High-risk tools, such as AI that handles sensitive personal data, customer eligibility, HR, finance, legal work or automated decisions, should require external advice before approval.

Set spending thresholds too. For example, a team lead might request tools up to £50 per month, the owner approves anything up to £500 per month, and anything above that needs a business case. The point is not bureaucracy. It is preventing five separate teams from buying overlapping tools, uploading data to unknown suppliers, and discovering six months later that nobody owns the account.

When this is NOT right for you

A formal approval panel is not right for every single AI use. If a sole trader is using ChatGPT to rewrite public marketing copy, a meeting with three advisers would be overkill. The principle still applies, though: know what data is going in, know what the output will be used for, and keep human judgement in control.

This approach also does not work if the owner wants to avoid responsibility. Asking an office manager, freelancer or junior employee to approve AI tools without authority is unfair and risky. They may understand the workflow, but they cannot carry legal, financial or reputational accountability for the whole business. Equally, outsourcing all approval to an IT supplier can create blind spots, because the supplier may understand security but not your commercial priorities, customer promises or staff culture.

If your business is very small, simplify the model. The owner makes the decision, the person doing the work tests the workflow, and an external adviser checks privacy or security when data risk is meaningful. That is enough for many SMEs. What is not enough is letting AI tools enter the business through personal accounts, browser extensions, free trials and staff improvisation with no record of what is being used.

The practical answer for UK SMEs

The practical answer is to create a small AI approval triangle: business accountability, process knowledge and data risk. In a five-person company, that might be the founder, the operations manager and an external IT or data protection adviser. In a 40-person company, it might be the managing director, department head, finance lead and outsourced IT provider. The names matter less than the responsibilities.

Start with the tools people already use. Ask staff which AI tools are currently in personal accounts, browser plugins, CRMs, marketing platforms, meeting recorders and document systems. DSIT's 2026 AI Adoption Research found that 16% of UK businesses were already using at least one AI technology, and among AI adopters, 84% reported at least some human input or checking of AI outputs. That is encouraging, but it also shows why approval cannot stop at buying the tool. You also need rules for review, accountability and escalation.

A good first policy is simple: no new AI tool without a named owner, no client or personal data in unapproved tools, no automated customer or staff decision without human review, and every approved tool reviewed after 30 to 90 days. That gives staff permission to use AI without making the business casual about risk.

Is This Right For You?

This is right for you if staff are already experimenting with ChatGPT, Copilot, Gemini, meeting recorders, AI browser extensions, CRM assistants or automation tools, and nobody is quite sure who has authority to approve them. It is also right if you handle client data, personal data, financial records, operational schedules or customer enquiries and want AI use to grow without losing control.

It is probably too much if you are a sole trader using AI only for public marketing drafts or personal productivity. Even then, use a basic rule: do not put confidential, personal or client information into tools unless you understand the terms and settings. For most SMEs, the sensible middle ground is light governance with clear ownership.

Frequently Asked Questions

Does a small business need an AI committee?

Usually no. Most small businesses need a named owner and a short approval group, not a formal committee. Use the owner or managing director, the process owner, and the person responsible for data protection, operations or finance.

Should the owner approve every AI tool?

The owner should approve anything that affects customer data, staff, finance, legal risk, business systems or meaningful spend. Low-risk tools can be delegated, but the rules for delegation should be written down.

Can our outsourced IT provider approve AI tools for us?

They can advise on security, access, integrations and supplier risk, but they should not be the only approver. The business still needs to decide whether the use case is commercially sensible and operationally safe.

Who checks GDPR risk if we do not have a DPO?

Nominate a data protection lead, even if that person is the owner, operations manager or external adviser. For higher-risk uses involving personal data, complete a DPIA or get specialist advice before launch.

What AI tools should require senior approval?

Anything connected to your CRM, accounts system, HR records, customer service channels, contracts, sensitive personal data, automated decisions or external communications should need senior approval before use.

How often should approved AI tools be reviewed?

Review low-risk tools after 90 days and higher-risk tools after 30 days. Check usage, value, errors, staff feedback, costs, data access and whether the supplier has changed terms or features.

What should we do about tools staff already use?

Do a quick audit before banning everything. Ask what tools are being used, what data goes into them, what outputs affect customers, and which accounts are personal rather than business controlled. Then approve, restrict or replace them.