<!-- Source: https://lab.cybersentriq.com/for-clients — generated from the prerendered page; canonical content. -->

# For Businesses — CyberSentriq AI Governance

## AI is already in your business.  
_Is it governed?_

Staff are using AI tools, approved or not. Some of those tools are handling customer data, financial records, or health information without the controls the law requires. Here is what to do about it.

Right now

### What is happening in most businesses

#### Shadow AI is widespread

Between 40% and 60% of AI tool usage in business environments is shadow usage: tools staff chose without IT approval and without data-handling guidance. Your business almost certainly has some.

#### Regulation has arrived

The EU AI Act is in force. UK GDPR requirements apply to AI-processed personal data. HIPAA requires Business Associate Agreements for AI tools handling health data. These are not future risks. They apply now.

#### Copilot creates new exposure

Microsoft Copilot can surface documents from across your Microsoft 365 environment. In most tenants, SharePoint permissions are broader than intended, which means Copilot can show confidential documents to the wrong people.

What the law requires

### Four rules that apply to most SMBs

You do not need a legal team to understand the basics.

#### UK GDPR

applies to everyone

When a staff member submits personal data (customer names, employee records, health information) to an AI tool, that is data processing. It must have a lawful basis, appropriate safeguards, and comply with the rights of the individuals whose data is used. Submitting personal data to a public AI tool without these controls in place is a breach of UK GDPR.

#### HIPAA

health data

If your business handles any health information for US clients or operations, any AI tool that might process that data requires a Business Associate Agreement (BAA) from the vendor. There are no exceptions based on the tool being widely used. No BAA means no lawful use. Your IT provider should maintain a BAA registry for all AI tools in your environment.

#### EU AI Act

EU operations

The EU AI Act (Regulation 2024/1689) is in force. It requires organizations using AI systems in EU markets to classify AI uses by risk, document high-risk applications, and implement human oversight for decisions that significantly affect individuals. If your clients or customers are in the EU, this applies.

#### FCA guidance

financial services

The FCA has issued guidance on AI in financial services emphasising explainability, non-discrimination, human oversight, and governance documentation. Regulated firms are expected to manage AI use within their existing regulatory obligations.

The baseline

### Four things that should be in place

Good AI governance does not require a compliance department.

-   1
    
    #### A clear AI usage policy
    
    A written document that tells your staff which tools are approved, what information they may and may not submit, and what to do when they want to use a tool that is not on the approved list. Short, readable, reviewed annually.
    
-   2
    
    #### Visibility of what is being used
    
    Your IT provider should be able to tell you which AI tools are being used across your business, including tools staff chose independently.
    
-   3
    
    #### A sensible exception process
    
    A structured way for staff to request a tool that is not yet approved. Exceptions should be tracked, time-limited, and reviewed. Without this, your policy is unenforceable.
    
-   4
    
    #### Regular reporting
    
    A quarterly summary showing what AI tools are in use, what exceptions are active, and what the current governance posture looks like.
    

Due diligence

### Questions worth asking your IT provider

If your IT provider cannot answer these questions confidently, that is useful information.

1.  1
    
    #### Do you have a written AI governance policy for your own business?
    
    An IT provider that cannot demonstrate its own AI governance posture is not in a position to deliver it to you.
    
2.  2
    
    #### Can you tell me which AI tools our staff are currently using?
    
    If the answer is "no" or "not easily", your IT provider does not have the visibility layer in place.
    
3.  3
    
    #### What is our process when a staff member wants to use an unapproved AI tool?
    
    "They ask their manager" is not a governed process.
    
4.  4
    
    #### Have you audited our Microsoft 365 environment for Copilot readiness?
    
    If you have Copilot licenses or are considering them, a permission audit is a prerequisite.
    
5.  5
    
    #### Can you produce an AI governance report for our auditors?
    
    If you are subject to ISO 27001, SOC 2, Cyber Essentials Plus, or sector regulation, your auditors will eventually ask.
    
6.  6
    
    #### For our healthcare operations: which AI tools have a signed BAA?
    
    If your business handles any health data, this is not optional.
    

The standard

### What a good AI governance service looks like

-   A written assessment of your current AI governance posture, with a score and a prioritized remediation list
-   Ongoing monitoring of AI tool usage across your estate, including shadow tools not on the approved list
-   A clear, documented process for approving, tracking, and reviewing AI tool exceptions
-   Regular reports showing governance activity and current posture, formatted for your QBRs and your auditors
-   A HIPAA BAA registry covering all AI tools if your business has healthcare operations or health data in scope
-   A Copilot readiness assessment before enabling Copilot, with a before/after score and remediation list
-   ISO 27001 / ISO 42001 / SOC 2 control mapping if you are working toward certification or have enterprise clients requiring compliance evidence

### Ask your IT provider where you stand

Or have them run the CyberSentriq client assessment: a scored posture report and a prioritized remediation list.

[Take the assessment](/assessment)
