Responsible AI: what it means when you are not a big tech company

What responsible use of AI means for a small business: the handful of commitments that matter and how to keep them.

4 minread 842words last updated

The short answer

Responsible AI, as discussed by large technology companies, means frameworks, review boards, model cards and research programmes, because they build the models and shape the technology. A small or mid-sized business does none of that. It uses models built by others, in a handful of places: customer contact, decisions that affect people, work on personal data, and tasks it relies on. Its responsibilities are correspondingly narrower and more concrete, and they fit on one page. No automated decision about a person without a human who decides and can explain why. Honesty whenever a customer is dealing with AI. Data used only under proper terms, minimised, and never sensitive data in consumer tools. Testing against real examples before anything is relied on. A route for people to complain and for mistakes to be corrected. And a named person who owns the list. Most of this is ordinary good practice applied to a new tool, and writing it down is what turns a vague intention into something the whole business can actually follow.

The commitments that matter

CommitmentWhat it means in practiceWhy
Human decision about peopleAI may propose; a person decides on hiring, credit, pricing, eligibility, claims, tenancy, discipline, and can see why the proposal was madeLegal in the EU for significant decisions; ethical everywhere; where the reputational damage lives
Honesty in customer contactSay when a customer is talking to or receiving AI-generated content; provide a route to a personRequired under the EU AI Act for interaction; trust
Proper data termsBusiness terms with training excluded; processing agreement; minimisation; no sensitive data in consumer toolsData protection law; confidentiality; your own assets
Testing before relianceEvaluate on real examples; monitor after launch; know the error rateYou are accountable for what the tool does in your name
Complaint and correctionA way for customers and staff to flag AI mistakes, and a process that fixes themAccountability; early warning; the law’s expectation
Equal treatmentCheck that outcomes do not differ unfairly by group where AI touches peopleDiscrimination law; fairness; reputation
OwnershipA named person responsible for the list, the register of AI uses and the reviewsNothing on this page happens without one

Writing your one page

  1. List every AI use in the business, including the informal ones staff adopted themselves.
  2. Mark which touch people, customers or personal data.
  3. For each of those, apply the commitments: human decision, honesty, data terms, testing, complaint route.
  4. Name the owner of the page and of each use.
  5. Write the staff rules in plain language: what tools are approved, what data may go where, what must always have a human.
  6. Tell customers what you use AI for, plainly, where it affects them.
  7. Review quarterly, adding new uses and removing retired ones.

What you can leave to others

Model safety research. Benchmarks and audits of foundation models. Industry standards for training data. Those are the responsibilities of the companies that build the models, and of regulators. Your job is to use the models responsibly in your business, which is smaller, more concrete and entirely within your control.

What this means for you

Responsible AI for a small business is one page: a register of uses, human decision on anything about people, honesty in customer contact, proper data terms, testing before reliance, a complaint and correction route, equal treatment checks and a named owner. Write it, tell your staff and customers, review it quarterly, and leave the frameworks to the companies that build the models. This is general information rather than legal advice.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Is responsible AI something a ten-person business needs to think about?

Yes, in proportion. A ten-person business is not training models or shaping the technology, so most of what the large frameworks cover does not apply. It is using AI in customer contact, in decisions about people, on personal data, and in work it relies on, and each of those carries a small set of concrete responsibilities: honesty, human decision, proper data terms, testing, and a route to correction. That fits on one page and takes an afternoon to write.

Where does this go wrong in a small business?

Letting AI decide something about a person without a human: which applicant proceeds, which customer gets a discount, which claim is flagged, which tenant is approved. It feels efficient and it is where the law, the ethics and the reputational risk all converge. The fix is simple: AI may propose, a person decides and is accountable, and the person can see why the proposal was made.

Do we have to tell customers when they are talking to AI?

In the European Union, yes, where a person interacts with an AI system in a way they might mistake for a human, and it is good practice everywhere. A plain sentence at the start of a chat or a clear label on a generated message costs nothing and preserves trust. Customers dislike discovering they were misled far more than they dislike knowing they are talking to an assistant with a route to a person.

Sources

  1. European Commission: AI Act (accessed 2026-09-12)