Diagnostic instrument · September 2026
AI Governance Gate
Seven gates. Each answer narrows the advice — and, just as usefully, rules obligations out. Built for a UK small or mid-sized business; the worked example is a UK cyber-security vendor running about twenty personal Claude licences.
AI governance in a small company fails in one of two ways. It governs behaviour it cannot see — a policy written for accounts nobody controls. Or it complies with obligations it does not have, spending months on a regime that was never going to reach it. Both failures are expensive, and both are avoidable by asking questions in the right order.
Six principles
- Govern the account, not the behaviour.
A policy asks people to remember something at the moment they are busiest. The contract you hold with the vendor decides what is possible at all — whether the provider is your processor or its own controller, whether it may train on what you send, how long it keeps it, and whether you can ever get it back. Fix the tenancy and most of the behavioural problem disappears without anyone reading anything.
- Establish the perimeter before you build controls.
Roughly half the AI governance effort in UK companies is spent on obligations that do not apply to them. Working out which regimes actually reach you is not administrative throat-clearing; it is the single largest saving available, and it determines how much of everything else you can ignore.
- Classify the data, not the tool.
Risk lives in what goes in, not in whose logo is on the interface. The same assistant is entirely appropriate for a marketing draft and catastrophic for a customer's unremediated findings. Policies that list approved tools age badly; policies that name prohibited data classes survive.
- Separate what is law from what is good practice.
Only a narrow band of AI use is genuinely regulated — decisions made about individual people. Everything else is contract, prudence and reputation. Conflating the two makes an organisation slow where penalties are statutory and needlessly timid everywhere else.
- Track autonomy, not capability.
A more capable model that only drafts is not more dangerous. An adequate model that acts on systems without anyone approving each step is. Controls should scale with blast radius — what it can reach and what it can do unsupervised — rather than with how impressive it is.
- Make the compliant path the fast path.
Prohibition has already been tried and abandoned: outright bans on generative AI fell from 28% of organisations to 7% in a year, while roughly half of employees report using AI against company policy anyway. Governance that slows the sanctioned route simply funds the unsanctioned one.
Why these seven gates, in this order
The output that matters most is the negative one. Knowing precisely which obligations do not apply to you — and why — is a reusable asset: it answers questionnaires, it settles the same argument permanently, and it is the difference between governing your AI and performing compliance with someone else's.