AI governance
A workable approach to AI risk for UK regulated firms in three steps: identify where AI is actually used, control what you can genuinely control, and keep evidence that survives scrutiny.
29 July 2026 · 9 min read
AI risk management is the discipline of knowing where AI is used in your firm, controlling what it is allowed to do, and keeping evidence of both. For most UK firms the biggest AI risk is not a rogue model. It is ordinary staff and systems using AI on client data with nobody able to say where, on what, or with what safeguards.
Most of what is written about AI risk is aimed at organisations that build AI: model validation, bias testing, drift monitoring. That is a real discipline, and if your firm trains or fine-tunes its own models you need it. But it describes a small minority of firms. The far larger group, which almost certainly includes yours, faces a different problem: AI that other people built is now woven through daily work, and the risk sits in how it is used. That is the problem this guide addresses, and it is a management problem before it is a technology one, which is why it belongs with the MD, FD or Operations Director rather than with whoever looks after the laptops.
The approach is three steps in a fixed order: identify, control, evidence. Firms get into trouble by starting in the middle, writing rules for a landscape they have not mapped, or at the end, hoping records will exist retrospectively. They will not.
Before the process, the substance. The risks that matter in practice cluster into four groups.
Data risk. Client information, personal data, matter details, unreleased work or commercially sensitive material entered into an AI tool outside the firm's control. Under UK GDPR, personal data does not stop being personal data because it was typed into a chat window. For a law firm, the sharper edge is confidentiality and the SRA Code. For any firm, a client NDA can be breached by one pasted paragraph, and the client may consider that worse than a fine.
Accountability risk. Regulated firms are expected to keep adequate records and to demonstrate that oversight is real. Under the Senior Managers and Certification Regime, a senior manager is expected to be able to evidence reasonable steps, not merely describe intentions, and Consumer Duty and SYSC record-keeping expectations point the same way. If AI now assists client-facing work and no record exists of where and how, that is an accountability gap with a named owner. Where the EU AI Act applies to your activities, it adds obligations of its own; establishing whether and where it applies to you is worth doing deliberately rather than by assumption. To be clear, this page is general information about regulatory themes, not legal advice.
Quality risk. AI output that is wrong, invented or subtly out of date, passed into client work without review. The control here is human, a review step that is actually followed, but you cannot check that the review step is followed in places you do not know AI is being used. Quality risk is downstream of visibility.
Cost risk. The quietest of the four. AI spend spreads across personal subscriptions, per-seat licences and metered API usage, and arrives with no attribution. Unmanaged, it grows; unattributed, nobody owns it. This one rarely triggers the project, but it is often what the FD notices first.
Notice what all four have in common: you cannot manage any of them in the places you do not know AI is being used. Which is why the process starts where it starts.
Every AI risk assessment begins with an inventory, and most inventories fail the same way: they record the AI the firm approved, not the AI the firm uses. You need the second list. AI enters a firm through three routes, and each needs its own method.
Approved tools. The chat tools and assistants you pay for. Their vendors keep audit logs, and the business tiers generally expose them. This is the easy third, though four vendors means four log formats and four retention windows, none of which know about each other.
In-house agents and API tools. The scripts, integrations and agents your own people have built against AI APIs. These are invisible to per-seat licence reports, and they matter disproportionately because they run without a person in the loop and can touch systems directly. Ask your developers what calls a model. The first list you get will be incomplete; treat it as a start, not an answer.
Shadow AI. The free tools, personal accounts and browser extensions nobody declared. You find these from evidence rather than by asking: your firewall, proxy, secure web gateway or SIEM logs already record the destinations traffic goes to, and AI services are identifiable destinations. No new monitoring is needed to get a first, honest picture. We have written a full guide to shadow AI covering why it happens and what to do about the people involved, which is usually nothing punitive: shadow AI is mostly capable people trying to work faster with tools the firm has not caught up with.
The output of this step is a live register of actual AI use: which tools, which people and systems, what kinds of work, roughly what cost. Live matters. A register compiled once for a board paper is out of date before it is presented.
With a real map, you can set rules that fit reality. Two principles keep this step honest.
Match the control to the route. Different routes support different strengths of control, and pretending otherwise is how firms end up with paper controls. Traffic you can route, in practice your own agents and API tools pointed through a governed gateway, can be checked and stopped in real time before a request leaves the firm: approved vendors and models only, supported UK PII and customer-defined blocked terms such as matter codes stopped at the boundary, out-of-hours rules, a spend cap. Traffic you cannot route, which includes vendor tools used through their own apps and anything discovered as shadow AI, you detect and evidence instead: you see it, record it and act on it, but Evaident does not block it at the moment of use. Evaident works exactly this way, and we state the boundary plainly because a control that exists only in a diagram is a risk of its own. Anyone who tells you every route can be blocked is describing a firm with no internet connection.
Proportionate beats comprehensive. A blanket ban is a real option, but understand what it does: it converts visible use into shadow use and removes a productivity gain your competitors keep. For most firms the better shape is a short approved list with clear data rules, hard automatic controls on the routable traffic, and detection everywhere else, backed by a policy people can actually follow. What that policy should say, and why writing it is the third step rather than the first, is covered in our broader guide to AI governance.
Give each risk in your register an owner with a name. A risk owned by the firm as a whole is owned by nobody, and if a regulator asks who was accountable, the firm as a whole is not an answer.
Here is the uncomfortable question at the end of every AI risk framework: when someone external asks you to demonstrate that all of this happened, what do you hand them?
A policy document proves you had intentions. Minutes prove you discussed it. Neither proves what your firm and its systems actually did, and the gap between those two things is precisely what an auditor, a client's security team or a regulator is probing. We have made this argument in full in why an AI policy is not evidence, and it is the reason evidence is a step of its own rather than a by-product.
Useful evidence of AI risk management has three properties. It is continuous: collected automatically from the point controls went live, not reconstructed for the occasion, because records cannot be produced retrospectively. It is complete across routes: covering approved tools, in-house agents and shadow AI in one record, because evidence with a hole where the riskiest usage sits invites exactly the wrong questions. And it is tamper-evident: kept so that any alteration is detectable, for instance by cryptographically sealing each record to the one before. A record that could have been quietly edited is management information; a record that demonstrably has not been is evidence.
This is the layer Evaident exists to provide: one tamper-evident record across all three routes, real-time enforcement on gateway-routed traffic, and a stamped evidence pack with an integrity certificate on demand. It supports your compliance function; it does not make you compliant, and no product can. Nor is it data loss prevention: Evaident is an accountability and evidence layer for the AI channel, not a DLP replacement, and it does not cover every route data can leave the firm.
You do not need a transformation programme to start. A realistic first week looks like this.
AI risk does not reward heroic annual efforts. It rewards a boring, continuous record of a firm that knew what was running, controlled what it could, and can prove both. Start the record this week.
---
_Evaident supports your governance and compliance functions. It does not provide legal advice. Regulatory regimes are referred to in general terms; take advice on your own obligations before relying on anything here._
The free AI Exposure Check gives you an instant score across visibility, shadow AI, evidence, governance and data-leak risk — no data connection needed.