AI Essentials: From AI experimentation to confident growth

What a Responsible AI Essentials programme could offer small businesses

The Federation of Small Businesses' Confidence Code makes a strong economic case for helping smaller firms use AI well.

AI use among small businesses has risen from 20% to 55%, yet 92% now have concerns about it. FSB estimates that £42 billion could be added to the UK economy each year if more firms adopted AI and existing users expanded their use.

The opportunity is not simply to increase the number of businesses using AI. It is to help them move from occasional experimentation to uses that improve products, customer experience and business models.

FSB found that firms using AI for basic tasks reported average productivity gains of 10% and revenue gains of 3%. Those using it for more advanced tasks, including developing products and services, reported gains of 13% and 5%. These are self-reported associations rather than proof that AI caused each improvement, but the pattern is useful: how a business adopts AI may matter as much as whether it adopts it at all.

Confidence is part of the growth infrastructure

The report describes a familiar starting point. Businesses adopt technology to save time or reduce costs, then use the capacity they create to expand, improve services or focus on customers.

Among firms that had adopted technology, 22% of AI users said it had enabled them to expand, compared with 8% of businesses that did not use AI. However, 68% of recent AI adopters had not yet seen a change in revenue. Investment, training and changes to working practices take time to produce results.

This suggests that AI policy should not be judged only by licence purchases or headline adoption rates. It should help businesses:

  • choose suitable uses
  • implement them effectively
  • develop their people
  • manage the associated risks
  • demonstrate their approach to customers

A common assurance scheme could support this. It could reduce the need for every customer or larger supplier to create a different AI questionnaire and give smaller businesses a recognised way to show that they have sensible controls.

There is a caution here. FSB reports that only 3% of small businesses held Cyber Essentials certification in 2025, with cost and time contributing to low take-up and lapsing certificates. As certification becomes more important in supply chains, poorly designed requirements can exclude the firms they were intended to help.

A Responsible AI Essentials programme would therefore need to make implementation easier, not merely introduce another badge.

Start with an AI Action Toolkit

Certification may not be the right first step for every business.

FSB found that lack of implementation know-how has become a more significant barrier, rising from 17% in 2023 to 29%. A fifth of small businesses do not know where to start, while only 4% of technology adopters had received support from a government-funded service.

A complementary AI Action Toolkit, based on the NCSC's Cyber Action Toolkit, could help close this gap.

The Cyber Action Toolkit gives small firms free, tailored and bite-sized actions. It organises them into progressive layers, explains why each action matters and allows businesses to track their progress. NCSC research with 2,500 users found that this interactive approach encouraged action more effectively than static guidance alone. It also provides a route towards Cyber Essentials rather than trying to replace certification. (cybertoolkit.service.ncsc.gov.uk)

An AI version could follow a similar structure:

  • Foundation: identify the AI tools in use, set simple rules for company data, use managed accounts, protect access and verify sensitive requests independently.
  • Improver: assess suppliers, train staff, check important outputs, manage integrations and decide which information each system may access.
  • Enhanced: control action-taking AI, limit permissions, introduce approval points, retain logs and prepare to stop, investigate and recover from failures.

The toolkit would not provide certification. It would turn broad advice into practical work and help organisations build the evidence needed for a later assessment.

It could also connect with FSB's proposed AI Skills Hub, adoption course, advisers and vouchers. A business would have somewhere to begin, a way to track progress and a route to further support where changes required time or specialist help.

One standard and proportionate assessment

For businesses that need to demonstrate assurance, a Responsible AI Essentials certificate could provide a common baseline.

Its claim should remain focused:

The organisation has put baseline controls in place to approve and use AI systems, protect its information and remain in control of what those systems can do.

That would not certify every legal, ethical and social question associated with AI. Copyright, discrimination, employment, environmental impact, privacy and security each involve different evidence and expertise. Relevant guidance should sit around the programme, while the certificate itself remains understandable and assessable.

There could be one standard and one certificate, with questions determined by what an organisation's AI can do.

A writing assistant using non-sensitive information would attract a relatively small set of requirements. Further controls would apply if the system could search internal records, retain memory, access sensitive data, call APIs, run code or change business systems.

Certification should also cover a continuing process rather than a fixed product list. AI tools and supplier features will change during the life of a certificate. The organisation should be able to introduce a new system, assess its capabilities and apply the relevant controls without seeking a new certification each time.

FSB proposes self-assessment with independent audit. In practice, a proportionate model may sit between a declaration and a full technical audit.

The applicant could complete a structured assessment and submit selected evidence. An independent assessor would review it, challenge unclear answers and decide whether the requirements had been met. Technical testing could be reserved for systems with sensitive access or the ability to take consequential actions.

This would provide more confidence than self-declaration without imposing a full audit on a sole trader using an ordinary supplier-managed service.

Design for frontier and agentic AI

Any baseline introduced now will need to account for systems becoming more capable.

NCSC describes agentic AI as systems that can plan tasks, make decisions and take actions on a user's behalf. They may access data, remember context, use tools and operate without continuous human involvement. NCSC advises organisations to begin with bounded, lower-risk uses, apply least privilege, monitor behaviour and retain the ability to contain the system. Where an organisation cannot understand, monitor or contain an agent's actions, it is not ready for deployment. (National Cyber Security Centre)

A Responsible AI Essentials standard would therefore be more durable if it assessed capabilities rather than labels such as assistant, copilot or agent.

The relevant questions are practical:

  • What information can the system reach?
  • What tools and business systems can it use?
  • What actions can it complete?
  • Which actions require independent approval?
  • Can the organisation see what it has done?
  • Can access be withdrawn and changes reversed?

This also reflects NCSC's broader frontier AI message. AI does not remove the need for established cyber-security controls, but it raises the consequences when those controls are absent. (National Cyber Security Centre)

Responsible AI Essentials should therefore complement Cyber Essentials. Existing evidence on identities, devices, access and security updates could be reused, while the AI assessment concentrated on the additional risks created by data use, unreliable outputs, manipulated instructions, system connections and autonomous action.

Adoption changes roles as well as tools

The report's workforce findings are important because successful adoption is not primarily a software installation exercise.

Businesses reporting revenue gains were more likely to have gathered employee feedback, trained staff, developed an implementation plan and introduced an AI policy. FSB's qualitative research also found that automation was often accompanied by upskilling. Roles shifted towards creativity, strategy and customer engagement, while staffing reductions were more commonly achieved by not replacing leavers than by immediate redundancies.

Human oversight should reflect this changing division of work.

It does not necessarily mean asking someone to check every routine output indefinitely. It may mean people setting boundaries, approving important exceptions, reviewing patterns and outcomes, and remaining accountable for significant decisions.

There is also a question of who benefits. Female entrepreneurs in the survey were slightly more likely to use AI than male entrepreneurs, but reported lower productivity and revenue gains. FSB suggests that greater concern about liability and responsible use may be limiting the systems, data and workflows they feel able to use. Disabled entrepreneurs also reported greater concern about security, liability and deepfakes.

Accessible guidance and credible guardrails could therefore support more inclusive growth. Confidence would not only help non-users begin. It could help existing users move into more valuable applications.

Gather supplier information once

Many of the questions facing small businesses cannot be answered through their own controls.

FSB found widespread concern about where data is processed, whether it is used for training, who owns AI-generated outputs and where liability sits. Its proposal for centrally published model cards could reduce the need for every small firm to investigate the same major suppliers.

These profiles could cover:

  • data location and retention
  • use of customer inputs for training
  • available security and administrative controls
  • supported integrations and actions
  • logging and incident notification
  • changes to models and capabilities
  • output ownership and contractual responsibility

The organisation would remain responsible for its configuration and use. Providers would supply information about the systems they are better placed to understand.

The wider market also matters. FSB's chapters on technology subscriptions describe unpredictable costs, difficulty moving data and supplier lock-in. Its research on small technology firms highlights the role of open-source models, access to usable data and proportionate access to compute.

An assurance programme should not become a list of favoured vendors. It should consider portability, exit arrangements and interoperability so that certification does not make it harder for small firms to change services or for smaller AI providers to compete.

Build a pathway from guidance to mature governance

The UK is not starting from nothing.

The AI Cyber Security Code of Practice provides lifecycle security principles for developers and organisations deploying AI, including risk assessment, human responsibility, supply chains, documentation, testing, monitoring and incident management. It is being taken forward through ETSI as the basis for international requirements. (GOV.UK)

AI Management Essentials attempted to turn broader governance frameworks into an accessible self-assessment. The consultation supported the objective but called for simpler language, more practical guidance and different journeys based on how organisations interact with AI. The government decided not to publish AIME in its proposed form and is instead focusing on foundational support for SMEs. (GOV.UK)

ISO/IEC 42001 sits further along the assurance journey. It provides requirements for establishing, maintaining and continually improving a full AI management system. It is valuable where an organisation needs comprehensive governance, but involves a broader organisational commitment than many small users of supplier-managed AI will initially require. (ISO)

Other countries offer useful components. Singapore's AI Verify combines a governance framework with technical and procedural testing, while its newer framework for agentic AI emphasises bounded authority, human approval points and lifecycle controls. Australia simplified its voluntary safety standard into six essential practices for AI adoption. The US NIST AI Risk Management Framework provides a flexible risk framework and a specific generative AI profile. The EU AI Pact supports voluntary action on governance, high-risk system mapping and staff literacy. (IMDA)

The opportunity for the UK may be to connect these ideas into a clear progression:

  1. An AI Action Toolkit helps a business take its first practical steps.
  2. Responsible AI Essentials provides independent assurance that a defined baseline has been met.
  3. ISO/IEC 42001 supports organisations that need a comprehensive AI management system.

The stages would complement one another rather than compete.

From caution to useful adoption

FSB's report is ultimately about growth.

Small businesses are already using AI, but uncertainty is shaping where they feel able to use it. That may keep adoption concentrated in low-risk drafting and administrative tasks, even where more valuable opportunities exist.

A certificate alone will not solve this. Smaller firms need a practical route from awareness to action, support when implementation becomes difficult and credible assurance when customers ask for evidence.

An AI Action Toolkit could provide the starting point. Responsible AI Essentials could establish a recognised baseline. Existing standards and regulation could address more complex organisations, providers and higher-risk uses.

Together, these measures could help small businesses use AI with greater ambition while retaining control of their information, decisions and operations.

The policy question is therefore not only how to reduce the risks of AI. It is how to give businesses enough confidence to use it where it can make the greatest difference.

References

  • Federation of Small Businesses, The Confidence Code: The challenges and opportunities of AI for small businesses, July 2026.
  • National Cyber Security Centre, Cyber Action Toolkit.
  • National Cyber Security Centre, Frontier AI: what you need to know.
  • National Cyber Security Centre, Thinking carefully before adopting agentic AI, May 2026.
  • Department for Science, Innovation and Technology, AI Cyber Security Code of Practice, January 2025.
  • Department for Science, Innovation and Technology, Guidance for using the AI Management Essentials tool: government response, February 2026.
  • ISO, ISO/IEC 42001:2023: Information technology — Artificial intelligence — Management system.
  • ETSI, EN 304 223: Baseline Cyber Security Requirements for AI Models and Systems, December 2025.
  • Singapore Infocomm Media Development Authority, AI Verify.
  • Singapore Infocomm Media Development Authority, Model AI Governance Framework for Agentic AI, updated May 2026.
  • Australian Government, Voluntary AI Safety Standard and subsequent Guidance for AI Adoption.
  • US National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework 1.0, January 2023.
  • US National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, July 2024.
  • European Commission, AI Pact.