Practical AI guardrails for small and medium businesses in the UK

How to safely adopt AI while protecting sensitive data and maintaining quality standards.

What goes in:

Confidential, client or commercially sensitive information should only ever go into AI tools your firm has approved, never a free tool found online.

What comes out:

Always keep a human in the loop – a person should check every output before it’s used or sent, and stay responsible for it. Mistakes and near misses should be reported, so everyone learns from them.

People and tools:

Keep a short, up-to-date list of approved tools. Review their performance, just as you’d review a member of staff. Have one set of rules everyone works to.

The pressure to use AI for streamlining processes and maximising productivity is irresistible. But professional firms such as lawyers, accountants, consultants and recruitment services need to act with caution, to ensure they’re not using AI with sensitive client information – or indeed their own information – without appropriate protection in place.

It’s essential to have a set of guardrails in place to enable the responsible use of AI in your organisation. If you don’t, you’re liable to run one of two major risks: a security or data breach, or employees feeling afraid to use AI and therefore missing out on the considerable benefits.

Any professional services firm can use the following AI guardrails for small businesses in the UK. Doing so will help you to confidently reap the rewards, knowing you have the right protections in place.

AI guardrails for small businesses

These fall into the following three categories:

1. What goes in:

  • Confidential information, personal data and commercially sensitive material must only ever be entered into an AI tool where the company has approved both the tool and its specific use. Before approval, the company should understand what data the provider collects, where it’s processed and stored, who can access it, whether it may be retained or used to improve the service, how it can be deleted, and what contractual and technical safeguards apply.
  • You must never use other versions of AI tools that are readily available online, especially if you’re entering data or information that you wouldn’t want to see repeated in public.

 

2. What comes out

  • A human employee must carefully check every output before it’s used or sent to a client. This needs to be the person who would have been responsible for the work, had it been done without the use of AI. They – and not the AI – will always remain responsible for the output.
  • It’s likely that mistakes will happen, especially when the AI system is new. This is to be expected. All AI-related mistakes and suspected incidents must be reported promptly through the company’s agreed process. You should report concerns and near misses without fear of unfair blame, while deliberate misuse, concealment or repeated disregard of the rules will be subject to the company’s normal disciplinary process.
  • Reporting of incidents and near misses enables us to monitor and improve outputs. Always think: was there anything worrying or surprising? Or anything useful we can learn from?

 

3. People and tools

  • We’ll keep a short list of the tools we’ve approved for AI usage and ensure it’s regularly updated.
  • We’ll monitor and review the performance of our AI tools, in a similar way to how we would for a human employee, in order to ensure compliance and enable improvement over time.
  • We’ll also carry out regular verification that the employees responsible for AI outputs are carefully checking the work produced by the tools.
  • Everyone in the firm must work to these rules. The alternative is that we will not be able to use AI.

 

For a useful guide on how to select the right AI vendor to fit your business, read our 12 questions to ask any AI vendor article 

Here’s how these AI rules work in practice for law firms, accountants, recruitment firms and consultancies:

  • As a law firm, you’ll hold large amounts of privileged information about clients that must remain confidential. It must therefore never be entered into an AI tool that doesn’t have appropriate data protection rules set up. There is also the risk of AI ‘hallucinating’ case law¹. The qualified fee earner or a partner must therefore independently verify and sign off all AI-generated outputs before they are sent to a client or court. Don’t let speed be an excuse for a breach of professional ethics.

  • As an accountancy firm, you’ll hold highly sensitive financial information about clients, payroll records, tax returns and other regulatory filings. Using unvetted AI tools, for example for tax planning or data analysis, risks exposing this information. A senior accountant or partner should check that only approved AI tools are being used, and that all outputs are correct according to original source documents. Never forget your duty of confidentiality or accuracy.

  • As a recruitment consultancy, you hold personal information about candidates as well as confidential business information regarding the clients you recruit for. This must never be entered into an AI tool that isn’t approved by the company. AI also risks suffering from unintentional biases or misrepresenting clients when screening, scoring or ranking them, doing interview analysis and handling rejections². The primary recruitment consultant must always review candidate profiles and rationales before responding to candidates or clients. You always have a duty of confidentiality and accuracy towards both.

  • Your consultancy firm holds client commercial confidences, market intelligence and trade secrets. Pasting proprietary client documents into consumer AI tools to generate analysis, slides or summaries risks leaking this information. The lead consultant or project director must ensure only approved AI tools are used for such purposes. They must also audit all AI-generated deliverables for accuracy before delivery. Never forget your duty of confidentiality towards your clients’ commercial operations, even when speed is of the essence.