Responsible AI: what it means when you are not a big tech company
What responsible use of AI means for a small business: the handful of commitments that matter and how to keep them.
The short answer
Responsible AI, as discussed by large technology companies, means frameworks, review boards, model cards and research programmes, because they build the models and shape the technology. A small or mid-sized business does none of that. It uses models built by others, in a handful of places: customer contact, decisions that affect people, work on personal data, and tasks it relies on. Its responsibilities are correspondingly narrower and more concrete, and they fit on one page. No automated decision about a person without a human who decides and can explain why. Honesty whenever a customer is dealing with AI. Data used only under proper terms, minimised, and never sensitive data in consumer tools. Testing against real examples before anything is relied on. A route for people to complain and for mistakes to be corrected. And a named person who owns the list. Most of this is ordinary good practice applied to a new tool, and writing it down is what turns a vague intention into something the whole business can actually follow.
The commitments that matter
| Commitment | What it means in practice | Why |
|---|---|---|
| Human decision about people | AI may propose; a person decides on hiring, credit, pricing, eligibility, claims, tenancy, discipline, and can see why the proposal was made | Legal in the EU for significant decisions; ethical everywhere; where the reputational damage lives |
| Honesty in customer contact | Say when a customer is talking to or receiving AI-generated content; provide a route to a person | Required under the EU AI Act for interaction; trust |
| Proper data terms | Business terms with training excluded; processing agreement; minimisation; no sensitive data in consumer tools | Data protection law; confidentiality; your own assets |
| Testing before reliance | Evaluate on real examples; monitor after launch; know the error rate | You are accountable for what the tool does in your name |
| Complaint and correction | A way for customers and staff to flag AI mistakes, and a process that fixes them | Accountability; early warning; the law’s expectation |
| Equal treatment | Check that outcomes do not differ unfairly by group where AI touches people | Discrimination law; fairness; reputation |
| Ownership | A named person responsible for the list, the register of AI uses and the reviews | Nothing on this page happens without one |
Writing your one page
- List every AI use in the business, including the informal ones staff adopted themselves.
- Mark which touch people, customers or personal data.
- For each of those, apply the commitments: human decision, honesty, data terms, testing, complaint route.
- Name the owner of the page and of each use.
- Write the staff rules in plain language: what tools are approved, what data may go where, what must always have a human.
- Tell customers what you use AI for, plainly, where it affects them.
- Review quarterly, adding new uses and removing retired ones.
What you can leave to others
Model safety research. Benchmarks and audits of foundation models. Industry standards for training data. Those are the responsibilities of the companies that build the models, and of regulators. Your job is to use the models responsibly in your business, which is smaller, more concrete and entirely within your control.
What this means for you
Responsible AI for a small business is one page: a register of uses, human decision on anything about people, honesty in customer contact, proper data terms, testing before reliance, a complaint and correction route, equal treatment checks and a named owner. Write it, tell your staff and customers, review it quarterly, and leave the frameworks to the companies that build the models. This is general information rather than legal advice.
Frequently asked questions
Is responsible AI something a ten-person business needs to think about?
Yes, in proportion. A ten-person business is not training models or shaping the technology, so most of what the large frameworks cover does not apply. It is using AI in customer contact, in decisions about people, on personal data, and in work it relies on, and each of those carries a small set of concrete responsibilities: honesty, human decision, proper data terms, testing, and a route to correction. That fits on one page and takes an afternoon to write.
Where does this go wrong in a small business?
Letting AI decide something about a person without a human: which applicant proceeds, which customer gets a discount, which claim is flagged, which tenant is approved. It feels efficient and it is where the law, the ethics and the reputational risk all converge. The fix is simple: AI may propose, a person decides and is accountable, and the person can see why the proposal was made.
Do we have to tell customers when they are talking to AI?
In the European Union, yes, where a person interacts with an AI system in a way they might mistake for a human, and it is good practice everywhere. A plain sentence at the start of a chat or a clear label on a generated message costs nothing and preserves trust. Customers dislike discovering they were misled far more than they dislike knowing they are talking to an assistant with a route to a person.
Sources
- European Commission: AI Act (accessed 2026-09-12)