SME directors are facing a growing dilemma: AI has become embedded in daily operations long before the rules are written. The risks of ‘shadow AI’—where staff experiment with unapproved tools or automate sensitive processes beyond IT’s reach—are now hiding in plain sight. With Microsoft’s AI Code of Conduct setting out public governance standards, it is clear: technical controls and certifications will not protect your business from risks you can’t see or own.
AI governance standards are the set of principles, controls, and accountabilities that guide the responsible use of artificial intelligence in business. Microsoft’s AI Code of Conduct has rapidly gained attention for moving beyond broad ethical statements to outline how AI should be controlled, reviewed, and owned at every stage—from design to deployment.
For SMEs, this shift has real implications. Microsoft’s code puts clear emphasis on measurable accountability, robust oversight, and transparent risk management. It sets an explicit expectation: boards and leadership teams can no longer delegate AI oversight to IT teams or rely on generic compliance statements.
The arrival of formal AI governance standards is not some distant policy concern. It signals a broad change in how responsibility for AI risk will be enforced—and ultimately, where liability will fall. For SME directors, the underlying risks of unsanctioned AI use—unmonitored data flows, unapproved automation, or unintended decisions—are strategic, not just technical.
In my experience, most SME leaders have invested in cyber security controls, staff awareness training, or data protection toolkits. Yet, shadow AI introduces a different type of risk. Unlike traditional IT, where service providers or certification schemes provide a sense of assurance, AI-driven risks often emerge quietly from day-to-day operations: a staff member experimenting with a ChatGPT plugin, sensitive data shared with a freemium AI assistant, or critical business decisions delegated to an unvetted algorithm.
Recent news has brought AI company leaders into the spotlight calling for a slowdown in AI development. The urgent message: the rate of innovation is now outpacing society’s ability to govern, regulate—and meaningfully control—the risks. I share this concern. If policy, leadership practice, and board oversight do not adapt, SMEs could find themselves exposed on multiple fronts:
Shadow AI is no longer theoretical. Tech Insider and others have documented real cases: marketing teams using unsanctioned AI to draft sensitive copy, HR uploading personal data to AI resume screeners, or finance staff trialling AI-powered analytics without legal review.
| Visibility | Without clear policy, you likely have unknown AI tools acting on company data right now. |
| Risk ownership | Who, on your leadership team, owns the consequences if a staff member’s AI tool leaks personal data? |
| Policy lag | Most board policies have not kept pace with the versatility—and unpredictability—of modern AI. |
| False assurance | Certification, security tools and even managed services have limited ability to prevent risks emerging from ungoverned AI use. |
From a security perspective, shadow AI shifts risk from IT-controlled environments into board-level blind spots. Certification frameworks and technical controls are useful, but they are not substitutes for real-world ownership of emerging risks. As Microsoft’s conduct code makes clear, governance is about more than technology—it is a leadership function.
Practical, accountable action is now needed at board level. Based on established best practice and Microsoft’s public standards, SME directors should take the following steps:
Calls from AI leaders to slow the rate of innovation are more than a plea for responsible R&D. They are a signal that boards, regulators, and governments are scrambling to catch up with the real-world pace of deployment. For SMEs, using this window to implement accountable governance—and align with emerging standards like Microsoft’s AI Code of Conduct—may determine future commercial resilience.
Managing AI risk will become a test of board leadership, not just IT professionalism. Policy, ownership, and oversight must evolve in lockstep with the technology itself. Those willing to pause, reassess, and set clear boundaries now will be better placed as regulation— and customer scrutiny—intensifies.
For UK SME directors, the era of ‘AI on autopilot’ is ending. Microsoft’s AI Code of Conduct sets the standard for a new, governance-led approach—one where AI risk is visible, owned, and addressed strategically. The practical challenge is to bring shadow AI into the light before regulators, customers, or incidents force the issue.
A board-level response to AI governance is now essential. Taking measured action today will put your business on the right side of trust, compliance, and resilience tomorrow.