SEPIDRAAIContact ↗

LATEST FROM THE SEPIDRA AI BLOG · 8 SEPTEMBER 2026

Your Small Business Needs an AI Traffic-Light Policy

A one-page Green–Amber–Red policy can help a small team use AI confidently without turning every experiment into a data, customer or decision risk.

SEPIDRA AIPRACTICAL AI FOR SMALL BUSINESSES8 SEPTEMBER 20264 MINUTE READ

AI use is spreading faster than most small-business controls. The Office for National Statistics reported in July that 35% of UK businesses with 10 or more employees used at least one AI technology in June 2026, up from about 12% in late 2023. Yet only 10% of AI-using businesses described their use as extensive.

That gap matters. Informal experimentation is useful, but it becomes a business risk when staff cannot tell which tasks are safe to delegate. A practical answer is a one-page traffic-light policy.

Green — AI can assist

Green tasks are internal, reversible and low sensitivity: drafting an agenda, restructuring notes you already own, or generating ideas from public information. Staff can use an approved tool, but they remain responsible for checking the result.

Amber — a named person must review

Amber tasks involve customers, personal data, confidential information or commercial commitments. Examples include drafting a customer reply, summarising a complaint or preparing a quote. These require an approved tool, the minimum necessary data, a named human reviewer and a record of the final decision. The Information Commissioner's Office makes clear that data-protection duties still apply when AI processes personal information.

Red — stop without a designed control

Red tasks should never be handed to AI without a designed control and accountable human decision. That includes authorising payments or refunds, making final hiring or eligibility decisions, issuing legal or medical advice, and uploading passwords, financial details or trade secrets to an unapproved service.

The policy should name the approved tools, prohibited data, task owner and escalation route. Then test whether it works. Once a month, sample ten AI-assisted outputs and record four measures: minutes saved, correction rate, customer-impact errors and any data incident. If staff repeatedly correct the same failure, improve the workflow or stop using AI for that task.

The UK government's 2026 AI adoption research found that 84% of AI-using businesses applied at least some human input or checking, but its qualitative interviews found specific checking procedures were uncommon. Human oversight is stronger when it is an operating step, not an assumption.

Green to assist. Amber to review. Red to stop.

A small business does not need enterprise-sized bureaucracy. It needs a boundary people can remember.

Sources

The Green–Amber–Red model, ten-output sample and four measures are SEPIDRA editorial recommendations, not a universal standard or legal advice.

PREVIOUS ARTICLES