LATEST FROM THE SEPIDRA AI BLOG · 8 SEPTEMBER 2026
Your Small Business Needs an AI Traffic-Light Policy
A one-page Green–Amber–Red policy can help a small team use AI confidently without turning every experiment into a data, customer or decision risk.
AI use is spreading faster than most small-business controls. The Office for National Statistics reported in July that 35% of UK businesses with 10 or more employees used at least one AI technology in June 2026, up from about 12% in late 2023. Yet only 10% of AI-using businesses described their use as extensive.
That gap matters. Informal experimentation is useful, but it becomes a business risk when staff cannot tell which tasks are safe to delegate. A practical answer is a one-page traffic-light policy.
Green — AI can assist
Green tasks are internal, reversible and low sensitivity: drafting an agenda, restructuring notes you already own, or generating ideas from public information. Staff can use an approved tool, but they remain responsible for checking the result.
Amber — a named person must review
Amber tasks involve customers, personal data, confidential information or commercial commitments. Examples include drafting a customer reply, summarising a complaint or preparing a quote. These require an approved tool, the minimum necessary data, a named human reviewer and a record of the final decision. The Information Commissioner's Office makes clear that data-protection duties still apply when AI processes personal information.
Red — stop without a designed control
Red tasks should never be handed to AI without a designed control and accountable human decision. That includes authorising payments or refunds, making final hiring or eligibility decisions, issuing legal or medical advice, and uploading passwords, financial details or trade secrets to an unapproved service.
The policy should name the approved tools, prohibited data, task owner and escalation route. Then test whether it works. Once a month, sample ten AI-assisted outputs and record four measures: minutes saved, correction rate, customer-impact errors and any data incident. If staff repeatedly correct the same failure, improve the workflow or stop using AI for that task.
The UK government's 2026 AI adoption research found that 84% of AI-using businesses applied at least some human input or checking, but its qualitative interviews found specific checking procedures were uncommon. Human oversight is stronger when it is an operating step, not an assumption.
A small business does not need enterprise-sized bureaucracy. It needs a boundary people can remember.
Sources
- Office for National Statistics — Artificial intelligence in UK businesses: 2023 to 2026
- UK Government — AI Adoption Research
- Information Commissioner's Office — Artificial intelligence and data protection
- UK Government — AI Adoption Plan: Creative Industries
The Green–Amber–Red model, ten-output sample and four measures are SEPIDRA editorial recommendations, not a universal standard or legal advice.
PREVIOUS ARTICLES