ModelCharter

Blog

Guides to governing AI at work

Plain-English guides on AI policies, shadow AI and AI compliance, written for teams without a compliance department.

Person writing and signing an AI usage policy document

How to Write an AI Usage Policy Staff Actually Follow

Most AI usage policies get written, circulated, and forgotten. Here's how to write one that staff actually read, remember, and follow day to day.

Read →
Compass on grass symbolising a roadmap for implementing the NIST AI RMF playbook

The NIST AI RMF Playbook: A Practical Implementation Guide

The NIST AI RMF Playbook turns Govern, Map, Measure and Manage into suggested actions. How to actually use it, without adopting all of it.

Read →
Marketing team comparing the best AI marketing tools on laptops

Best AI Marketing Tools for Small Business in 2026

The best AI marketing tools for small business, reviewed for what they're actually good at and how they handle your customer data.

Read →
Dashboard graphs comparing AI risk management software platforms

5 AI Risk Management Tools Compared for Small Teams

AI risk management software compared: Credo AI, OneTrust, Holistic AI, Vanta and a lightweight in-house alternative, for teams without a GRC budget.

Read →
Person holding a smartphone, representing AI and personal data under GDPR

Does AI Use Your Personal Data? What GDPR Says in 2026

New ICO guidance on AI and automated decisions is landing in 2026. What UK employers need to know about AI and personal data right now.

Read →
Person typing on a laptop while reviewing Claude for Business

Claude for Business Review: Is It Safe for Company Data?

An honest review of Claude for Business and Enterprise for company data safety: training defaults, retention, HIPAA and GDPR fit, and pricing tiers.

Read →
EU flag flying outside the European Parliament ahead of the EU AI policy deadline

The EU AI Act's August 2026 Deadline: What SMBs Should Know

High-risk EU AI Act obligations apply from 2 August 2026. What's changing, what the Omnibus proposal delayed, and what SMBs actually need to check.

Read →
Stack of newspapers representing news coverage of AI ethics and governance

AI Ethics and Governance: Why the Two Are Converging

AI ethics and AI governance used to be separate conversations. Why regulation is now merging them, and what that means for how teams document AI use.

Read →
Security and privacy dashboard illustrating AI trust risk and security management

AI TRiSM Explained: Gartner's Framework for Small Teams

AI TRiSM is Gartner's trust, risk and security framework for AI. What its four layers mean and what's realistic for a team without a security function.

Read →
European Union flags outside the European Commission, representing EU AI Act risk categories

EU AI Act Risk Categories Explained

The EU AI Act sorts AI systems into four risk tiers. What unacceptable, high, limited and minimal risk actually mean for a small business.

Read →
Padlock on a keyboard symbolising AI and data protection

AI and Data Protection: A GDPR-Compliant Rollout, Case Study

How a 40-person UK firm rolled out AI tools while staying GDPR-compliant. What they got right, what they nearly missed, and what to copy.

Read →
Hand ticking off a checklist of responsible AI practices

10 Responsible AI Practices Every Small Business Should Adopt

Ten responsible AI practices small businesses can adopt without a compliance team, from data rules to human review and vendor checks.

Read →
Team reviewing an AI policy document together in an office meeting

What Is an AI Policy? A Plain-English Guide

An AI policy sets out what staff can and can't do with AI tools. What it covers, who owns it, and how to write one without overthinking it.

Read →
Certified risk management documents stamped for ISO/IEC 23894 compliance

ISO/IEC 23894 Explained: AI Risk Guidance Compared to ISO 42001

ISO/IEC 23894 is the standard for AI risk guidance, distinct from ISO 42001's management system. What it covers and whether your team needs it.

Read →
Magnifying glass over blocks spelling risk, representing AI risk mitigation

How to Mitigate AI Risk: A Step-by-Step Framework

Practical steps to mitigate AI risk at a small or mid-sized business: what to fix first, what to monitor, and how to avoid over-engineering it.

Read →
Checklist and form on a desk representing an AI governance checklist

AI Governance Checklist: 10 Steps for Small Teams

A 10-step AI governance checklist any ops, IT or HR lead can finish in a day, mapped to EU AI Act, GDPR, ISO 42001 and SOC 2 obligations.

Read →
Employee using a phone discreetly at a desk representing shadow AI tools at work

Shadow AI Tools: What Your Team Really Uses

Shadow AI tools are already inside your business. Why bans fail, where the real risk sits, and how to make the approved path easier to use.

Read →
Corporate office building representing enterprise AI governance programmes

Enterprise AI Governance: Policy, Registry, Controls

Enterprise AI governance scales the same three artefacts, policy, register, attestation, with roles, evidence and audit-ready controls.

Read →
Small business owner using a laptop to evaluate the best AI tools for small business

Best AI Tools for Small Business: Safe Picks by Use Case

The best AI tools for small business, picked by use case, with the tier and data rules that keep each one safe.

Read →
Team reviewing a laptop screen while vetting an AI tool before rollout

How to Vet an AI Tool Before Rollout

How to vet an AI tool before rollout: a fast, repeatable check on training data, DPAs, BAAs and the tier that makes each fact actually true.

Read →
Checklist and document on a desk representing an AI policy template for teams

AI Policy Template: A Free, Editable Structure for 2026

A free AI policy template covering scope, approved tools, data rules and attestation, plus a generator that tailors it for you.

Read →
Fork in the road representing the choice between consumer vs business AI tiers

Consumer vs Business AI Tiers: Why It Matters

Consumer vs business AI tiers explain why the same tool can be safe or risky. See how ChatGPT, Copilot and Gemini plans differ, and what to check.

Read →
Smartphone chat screen representing ChatGPT data privacy for business users

ChatGPT Data Privacy: What Happens to What You Type

ChatGPT data privacy explained: whether OpenAI trains on your chats, how long data is kept, and the tier that keeps it out of training.

Read →
Digital padlock icon representing AI privacy concerns and data protection

AI Privacy Concerns: What They Are and How to Fix Them

The real privacy concerns with AI tools, from training on your data to retention and third-party sharing, and practical steps to address each.

Read →
Documents and charts comparing NIST risk management frameworks side by side

NIST Risk Management Frameworks Compared

NIST publishes several risk management frameworks. How the Cybersecurity Framework, the AI RMF and RMF 800-37 differ, and which applies to AI.

Read →
Warning triangle sign representing AI risk for business teams

What Is AI Risk? The Categories Every Business Should Know

AI risk is the exposure a business takes on when it uses AI tools. The main categories, which apply to a small team, and how to manage them.

Read →
Employee handbook and workplace rules for an AI policy for employees

AI Policy for Employees: Rules That People Actually Follow

A good AI policy for employees is short, plain English, and answers three daily decisions. How to write one people actually read.

Read →
Business data charts comparing AI governance frameworks including NIST and ISO 42001

AI Governance Frameworks Compared: NIST vs ISO 42001

NIST AI RMF, ISO 42001, the EU AI Act and Singapore's Model AI Governance Framework compared, and where to start building your own.

Read →
Team planning strategy at a whiteboard for AI risk management

AI Risk Management: A Practical Framework for Teams

AI risk management doesn't need a risk team. A four-risk framework any ops, HR or IT lead can put in place this quarter.

Read →
AI apps on mobile and computer representing the best AI tools for business

Best AI Tools for Business in 2026: What to Approve and Why

The best AI tools for business depend on tier, not brand. How to evaluate ChatGPT, Claude, Copilot and Gemini before approving them.

Read →
Pen signing a form representing AI attestation and policy acknowledgement

What Is AI Attestation and Why Your Team Needs It?

AI attestation proves staff have read and accepted your AI policy. Why it matters for the EU AI Act and SOC 2, and how to automate it.

Read →
Compass representing values and ethics in a code of conduct for AI use

How to Write a Code of Conduct for AI Use at Work

A code of conduct for AI states the values behind your rules, not just the rules. How it differs from a usage policy, and what to include.

Read →
Security audit and business report representing SOC 2 AI compliance requirements

SOC 2 and AI Tools: What Auditors Are Now Asking

SOC 2 auditors now raise soc 2 ai questions about tool use, vendor risk and policy evidence. What to have ready before the engagement starts.

Read →
Business contract signing for AI vendor risk assessment checklist

AI Vendor Risk Assessment: A Practical Checklist

An ai vendor risk assessment checks whether a tool is safe for your data. Seven questions to ask before approving any AI vendor, with a scoring table.

Read →
Person typing on a laptop representing ChatGPT at work and productivity

ChatGPT at Work: Safe Use and Team Rules

ChatGPT in the workplace is already happening. Which tier your team uses and what rules you set decide whether it's an asset or a liability.

Read →
Professional using a laptop computer representing Microsoft Copilot data privacy

Microsoft Copilot and Data Privacy: What to Know

Microsoft Copilot's data handling differs by tier. What M365 Copilot does with your data, and what to put in your AI policy.

Read →
Technology platform and software tools for AI governance management

AI Governance Tools: What to Look For and How to Choose

AI governance tools handle policy, tool risk rating and staff attestation. What actually matters when you compare options in 2026.

Read →
Scales of justice representing AI compliance and legal obligations for business

AI Compliance: What It Is and What Your Business Must Do

AI compliance means meeting your legal duties around AI use - EU AI Act, GDPR, HIPAA and SOC 2 - explained for small businesses in 2026.

Read →
Risk management strategy planning documents for the NIST AI Risk Management Framework

NIST AI Risk Management Framework: A Plain-English Guide

The NIST AI Risk Management Framework explained simply: the four functions, GOVERN, MAP, MEASURE, MANAGE, and what they mean for a small team.

Read →
ISO certification standards representing the ISO 42001 AI management system

ISO 42001 Explained: The AI Management Standard

ISO 42001 explained in plain English: the clause structure, deployer vs provider duties, and how to use it as a governance blueprint.

Read →
Handshake representing trust and cooperation in responsible AI practices

Responsible AI: What It Means for Your Business

Responsible AI for SMBs, explained: the five principles, human review, transparency rules, and how to document it without an ethics board.

Read →
Business analytics dashboard on a laptop for AI governance software

Best AI Governance Software for Small Teams

AI governance software compared: policy builder, tool registry and staff attestation in one place, built for teams without a compliance department.

Read →
Professional working on a laptop reviewing AI compliance software

AI Compliance Software: What to Look For in 2026

AI compliance software should handle policy creation, tool vetting and audit trails. What actually matters when evaluating options for 2026.

Read →
Padlock on keyboard representing AI data privacy and cybersecurity

AI Data Privacy: What Every Business Needs to Know

AI data privacy explained: how ChatGPT, Copilot, Gemini and Claude handle your data by tier, and what GDPR and HIPAA actually require.

Read →
Business team conducting an AI risk assessment and evaluation

How to Run an AI Risk Assessment for Your Business

An AI risk assessment shows which AI tools put your business at risk. A practical framework you can run in an afternoon.

Read →
Person signing a business agreement representing an AI acceptable use policy

AI Acceptable Use Policy: What to Include

An AI acceptable use policy tells staff what they can and can't do with AI tools at work. The structure most teams need.

Read →
Team using communication tools representing a ChatGPT business policy

ChatGPT for Business: Creating a Clear AI Policy

A ChatGPT for business policy needs three things: the right tier, clear data rules, and a disclosure rule. Here's how to write it.

Read →
Robot technology representing generative AI policy for creative work

Generative AI Policy: A Starter Guide for Teams

A generative AI policy covers ChatGPT, Claude, Midjourney and Copilot. What to include, how strict to be, and a free generator.

Read →
Digital security shield protecting technology for the AI tool security checklist

AI Tool Security: What to Check Before Approval

A practical AI tool security checklist: what to check on training, retention, certifications and contracts before you approve any new AI tool.

Read →
Small startup team collaborating in an office for AI policy

AI Policy for Startups: A No-Jargon Starter Guide

A lightweight AI policy for startups: what a seed or Series A team actually needs, without slowing anyone down.

Read →
Healthcare professional using technology representing HIPAA AI compliance

HIPAA AI Compliance: What Healthcare Teams Must Do

HIPAA AI compliance means a signed BAA before any PHI touches an AI tool. What to check, which vendors offer one, and how to document it.

Read →
GDPR data protection concept representing EU privacy requirements for AI tools

GDPR and AI Tools: What EU Teams Must Know

GDPR and AI tools: when you need a DPA, your lawful basis for processing, and what data subject rights mean for AI vendors.

Read →
Employee AI training workshop for EU AI Act literacy requirements

Employee AI Training Requirements Under EU AI Act

What EU AI Act employee AI training requirements mean in practice: who counts as staff, what 'sufficient literacy' looks like, and how to document it.

Read →
Government building pillars representing the structure of an AI governance framework

AI Governance Framework: A Practical Build Guide

How to build an AI governance framework that lasts: the four components, NIST AI RMF vs ISO 42001, and how to avoid over-engineering it.

Read →
AI robot representing artificial intelligence governance for business teams

What Is AI Governance? A Practical Guide for Small Teams

AI governance explained without the jargon: what it is, why even small companies need it, and the three artefacts that cover most of it.

Read →
Shadow silhouette representing shadow AI and hidden technology risks at work

What Is Shadow AI, and How Do You Get It Under Control?

Shadow AI is employees using unapproved AI tools at work. Why it happens, the real risk it creates, and how to fix it without banning AI outright.

Read →
Notebook and pen on a desk for writing an AI usage policy

How to Write an AI Usage Policy (with a Free Template)

A step-by-step guide to writing an AI usage policy: what to include, how strict to be, and a free generator that builds one in minutes.

Read →
Person reviewing EU AI Act compliance documents and legal regulations

EU AI Act for Small Business: What You Must Do

Does the EU AI Act apply to your small business? The realistic eu ai act compliance duties for teams that just use AI tools, and what you can ignore.

Read →
Person using an AI chatbot on a laptop computer for work

Is ChatGPT Safe for Work? A Tier-by-Tier Guide

Is ChatGPT safe for work? It depends on the tier. The real difference between Free, Plus, Team and Enterprise, and the data rules to set.

Read →