AI regulation is written for large organizations and read by small ones that assume it does not apply to them. For most small businesses, the assumption is partly right and dangerously incomplete: the heaviest obligations land on high-risk uses and on providers, while the transparency and data-protection expectations reach much further.
This guide explains the frameworks that matter in plain terms, what they require in practice for a small business, and how to stay proportionate. It is part of the Governance, Risk & Data pillar.
This article is general information, not legal advice. Confirm your specific obligations with qualified counsel.
Why a small business should care
Three reasons, in ascending order of likelihood.
- You may be a deployer of a regulated AI system. Where you use AI in employment, credit, education, health or safety contexts, obligations attach to how you use it, not only to who built it.
- You may be subject to transparency and data-protection rules in how you use AI on personal data and in how you communicate with customers.
- Your clients and contracts will ask. Increasingly, a client’s own compliance position depends on their suppliers’ AI practices, and the question arrives in a procurement or due-diligence form.
None of this requires a compliance function. It requires knowing which category your use falls into, documenting your controls, and being able to answer the question.
The frameworks that matter
NIST AI Risk Management Framework
A US framework for identifying, assessing and managing AI risk. It is voluntary, and its practical value is structural: it organizes risk work into govern, map, measure and manage.
For a small business, the useful translation is:
- Govern — a named owner, a policy, and an accountability line.
- Map — an inventory of where AI is used and on what data.
- Measure — the checks and measures that show the controls are working.
- Manage — a defined response when something goes wrong.
That is a page of work, and it maps directly onto the controls described elsewhere in this program.
The EU AI Act
Relevant if you place AI systems on the EU market or your output is used there. It takes a risk-based approach, with the heaviest obligations on higher-risk uses and lighter transparency duties on others. Most small-business uses of general assistants fall outside the highest tiers, but the transparency expectations — including disclosure in certain human interactions — are real and worth designing for.
Data protection law
Where AI processes personal data, existing data-protection rules apply unchanged. The practical implications for a small business are the same as for any processing: a lawful basis, transparency, data minimization, and the ability to honour deletion requests. The question to ask of any tool is what happens to the personal data in its retention and training terms.
Professional-body guidance
Sector guidance shapes what a professional is expected to do. Two examples: the American Bar Association’s Formal Opinion 512, on lawyers’ use of generative AI, and the ICMCI Code of Ethical Conduct for management consultants. Where you belong to a professional body, its guidance is often more immediately relevant than the legislation.
What it means in practice
For a small business, five actions cover most of the ground.
- Inventory your AI use — a list of tools and uses, reviewed periodically. This is the single most useful artefact, and most businesses do not have one.
- Classify each use — general assistance, or a use in a sensitive domain such as employment, credit, health or safety.
- Document your controls — the policy, the data rule, the verification step and the named owner.
- Dress the disclosure question — what you tell customers, clients and staff, and where a rule requires more.
- Keep it current — review twice a year, because both the rules and your use of AI move.
Two uses deserve particular caution for a small business: using AI to screen or assess people, and using AI where a decision has a significant effect on an individual. Those categories attract the heaviest obligations and the greatest reputational exposure.
Staying proportionate
The failure mode at small scale is over-reading the rules and producing a framework nobody uses. Three principles keep it proportionate.
- Match the control to the risk. General drafting assistance needs a policy and a check. Employment screening needs considerably more.
- Write for your size. A one-page policy and a tool inventory outperform an enterprise framework applied to ten people.
- Answer the question you will be asked. A client will ask what data you put into which tools, who verified the output, and whether you have a policy. Be able to answer in writing.
The five-question test
Before adopting any use of AI, five questions establish the regulatory position well enough for a small business.
- What decision does the output inform, and who is affected by it? If the answer includes an individual, the obligations increase.
- Whose data is involved? Personal data brings existing data-protection duties into play regardless of AI.
- Who interacts with the system? Direct customer interaction brings transparency expectations with it.
- What does our contract say? Engagement terms may address confidentiality, subcontracting or processing.
- What would we say if asked? If the honest answer is uncomfortable, the position needs changing rather than rehearsing.
The test is deliberately short. Its purpose is to sort uses into “proceed with ordinary controls” and “take advice”, which is the decision a small business actually needs to make.
Common mistakes
- Assuming it does not apply. Deployers carry obligations, not only providers.
- No inventory. You cannot classify or govern uses you have not listed.
- Treating all uses alike. Screening people is not the same as drafting a summary.
- Over-reading the rules. A framework nobody uses provides no protection.
- No disclosure position. Transparency duties are among the most commonly missed.
- Never reviewing. Both the rules and your tooling change within a year.
Frequently asked questions
Does AI regulation apply to small businesses?
Some of it does, depending on where you operate and what you use AI for. Deployers carry obligations in higher-risk uses, and transparency and data-protection rules reach much more widely.
What is the NIST AI Risk Management Framework?
A voluntary US framework for managing AI risk, organized around governing, mapping, measuring and managing. Its value for a small business is the structure it gives a short policy.
Does the EU AI Act apply to us?
If you place AI systems on the EU market or your output is used there, it likely applies in some form. It takes a risk-based approach; most small-business uses of general assistants are outside the highest tiers, but transparency expectations still apply.
What are the highest-risk AI uses for a small business?
Using AI to assess or screen people, and any use where the output has a significant effect on an individual. These attract the heaviest obligations and the greatest reputational exposure.
Do we need a compliance officer?
No. A named owner, a short policy, a tool inventory and a disclosure position cover most small-business obligations. Where a use falls into a higher-risk category, take advice.
How often should our AI position be reviewed?
Twice a year at least, and whenever a new tool or use is added, or the regulatory position changes.
Do we need to disclose that we use AI?
Sometimes — where customers interact with an AI system directly, where use is material to the work, or where a contract or rule requires it. Even where it is not required, deciding the position in advance is better than improvising later. See AI Disclosure.
Next step
Build the inventory of your AI tools and uses, classify each one, and record your controls against it. See Writing an AI Acceptable-Use Policy and the AI Policy Template, or book an AI adoption call to review your position.
Sources
- NIST AI Risk Management Framework — voluntary US framework for AI risk management (govern, map, measure, manage).
- EU AI Act — risk-based regulation applying to providers and deployers where systems are placed on or used in the EU market.
- ABA Formal Opinion 512 (American Bar Association) — guidance on lawyers’ use of generative AI.
- ICMCI Code of Ethical Conduct (International Council of Management Consulting Institutes) — professional conduct expectations for consultants.
No statistic in this article is invented. This article is general information, not legal advice; confirm your specific obligations with qualified counsel.