6 practical documents — AI tools register, acceptable use policy, risk register, vendor checklist, staff training guide, and board reporting template. Written in plain English for business owners, not IT teams.
They open ChatGPT. They paste in a client email. They ask it to draft a reply. They copy the response and send it.
It took 30 seconds. It looked professional. And a customer's personal data just left your organisation and landed on an external AI server.
This is happening in businesses across the UK, every single day. Not because staff are careless — but because no one has told them what the rules are. There is no policy. There is no register of which tools are approved. There is no training. There is no governance.
The risk is not theoretical. It is operational. And for most UK SMEs, the fix is a set of clear, practical documents — not a six-figure compliance project.
UK GDPR applies to personal data processed through AI tools. Staff entering customer data into ChatGPT may be a compliance gap you are not aware of.
Now in force. If you supply goods or services to EU customers, or use AI affecting people's rights, this legislation creates obligations most UK SMEs haven't assessed.
An AI tool that produces incorrect information — a hallucinated citation, a made-up statistic — can cause real damage when it goes out under your name.
Criminals are using AI to write perfect phishing emails. The old "look for spelling mistakes" advice no longer works. Your staff need updated rules.
The Pyralink AI Governance Pack gives you everything you need to govern AI use in your organisation — without a consultant, without jargon, and without weeks of work. Each document is written to be used by a real business, not filed away and forgotten.
Record every AI tool your organisation uses or considers using. Includes fields for risk level, data categories processed, approval status, and vendor details. Know what is in use. Know who approved it.
A clear, readable policy that tells staff exactly what they can and cannot do with AI tools. Covers data rules, approved tools, personal use, and consequences. Ready to issue on day one.
A framework for identifying and recording risks associated with specific AI tools and use cases. Mapped to GDPR and EU AI Act risk categories. Helps you prioritise governance attention.
A structured checklist for evaluating any new AI tool before approval. Covers data handling, GDPR compliance, encryption, and sub-processor disclosure. Never approve a tool without checking these boxes.
Plain English guide for all staff. Explains what AI is, the data rules, how to spot AI-powered phishing, and five scenarios every employee should navigate. Immediate training value.
A quarterly reporting template for non-technical leadership. RAG status. Tools summary. Training completion. EU AI Act position. GDPR status. Everything the board needs, in a format they can read.
Three tiers. Instant download. No subscription required.
Documents 1 + 2 — the foundation of your AI governance
All 6 documents — complete AI governance framework
All 6 documents + 60-minute strategy call with Michael Adedeji
Michael Adedeji CISM | CISA | CEH | CC is a certified cybersecurity professional with expertise in governance, risk, compliance, and information security management. He holds four industry-recognised certifications and an MSc in Data Science from the University of Sunderland.
These documents were written with one objective: to give UK SMEs the governance tools that enterprise organisations have, without the enterprise price tag or the enterprise complexity.
Plain English. Practical. Legally conscious. Ready to use.
Most UK SMEs are one staff mistake away from a GDPR incident involving AI. This pack closes those gaps in a single afternoon.
Get the Full Pack — £297Or start with the essentials: Starter Pack — £97 | For a personalised review: Full Pack + Review Call — £797
Email: info@pyralink.co.uk | Phone: +44 (0) 191 300 2979
502 Aidan House, Sunderland Road, Gateshead, NE8 3HU
The documents included in this pack are templates designed to support organisations in developing their AI governance framework. They are provided for informational and operational purposes only and do not constitute legal advice. You should seek independent legal advice if you have specific questions about your regulatory obligations under GDPR, the EU AI Act, or any other applicable legislation. Pyralink Innovation Ltd accepts no liability for decisions made on the basis of these documents without appropriate professional review. These documents are licensed for use within the purchasing organisation only and may not be resold, redistributed, or sub-licensed without written permission.