Frequently Asked Questions
Answers to the questions UK organisations ask about AI Security, including ISO 42001, the EU AI Act and Shadow AI.
AI Act Preparedness
- Can We Use AI on Customer Data We Already Hold? Practitioner Q&ALawful basis, purpose compatibility, training versus inference and transparency duties when AI is applied to customer data your organisation already holds.
- EU AI Act Accountability: Who Owns Which Obligation? A Practitioner Q&AWho owns which EU AI Act duty: provider versus deployer, Article 4 AI literacy, Article 14 human oversight and the evidence a regulator will expect to see.
- EU AI Act Compliance for UK Organisations: The Definitive FAQPractitioner FAQ for UK GRC Managers on EU AI Act scope, risk classification, enforcement timeline, penalties and where to start.
- EU AI Act and UK Businesses: Frequently Asked QuestionsDoes the EU AI Act apply to your UK business? Extraterritorial scope, provider versus deployer, the four risk tiers and the deferred high-risk deadlines.
- Is ChatGPT GDPR Compliant? UK GDPR FAQ for SME Owners and DPOsUsing ChatGPT can comply with UK GDPR under conditions. Lawful basis, consumer versus business tiers, DPIAs, unapproved staff use and what the ICO expects.
- UK AI Regulation by Sector: Practitioner Q&AThe UK has no AI Act. Which rules bind you depends on your regulator. FCA, SRA, MHRA and ICO expectations, plus where the EU AI Act reaches into UK firms.
AI Amnesty
AI Behaviour Verification
AI Enablement
- Is Microsoft Copilot Safe for Our Company Data?Microsoft 365 Copilot is as safe as your permissions model. What to check before rollout, where the data goes and how oversharing becomes visible overnight.
- Our Software Just Added AI Features: Does That Change Our Risk?A supplier has switched on AI in a tool you already run. What actually changed, where to look for it, when to opt out and how to record the decision you take.
- What Should I Check Before Deploying an AI Tool Company-Wide?Six checks before a company-wide AI rollout: data flows, access and identity, supplier posture, usage policy, staff training and monitoring, in that order.
AI Security Gap Analysis
- CIA+EFT Framework: AI Security Questions UK Boards Are AskingWhat the CIA+EFT framework is, why traditional security controls leave gaps in AI systems, how it maps to ISO 42001 and the EU AI Act and how to apply it in practice. For UK boards, CISOs, DPOs and AI governance leads.
- How Do I Assess an AI Vendor's Security?Assess five things in order: data handling, model provenance, tenancy and isolation, subprocessors and independent assurance. A practitioner Q&A for buyers.
- What Should I Ask Suppliers About Their AI Features and Their Own Use of AI?A copy-usable supplier AI due diligence question set: what to ask about AI in the product, what to ask about the supplier's own AI use, and how to score it.
AI Security Programmes
- A Client Has Asked for Our AI Policy: What Should It Say?What a client actually checks when they ask for your AI policy: the six sections that matter, who should own it and how specific to be about approved tools.
- AI Governance in Practice: What It Actually Involves Day-to-DayWhat AI governance involves day-to-day: tool approvals, usage reviews, incident routing, supplier checks and training, and how the workload scales with headcount.
- Do You Need an AI Policy? Questions and Answers for UK SMEsNo UK law requires an AI policy. Procurement, insurance and incidents do. What a two-page policy contains, who needs one and when writing it can wait.
- Help Me Answer the AI Section of a Security QuestionnaireWhat reviewers test in the AI section of a security questionnaire, how to answer when you are early and what to produce when a deal is blocked this week.
- What Do Customers Expect Us to Have in Place for AI Security?What enterprise buyers check on AI security, what evidence satisfies them at each contract size and how to answer a questionnaire before your programme is ready.
- What Do Investors Expect Us to Have in Place for AI Security?What AI due diligence covers in a fundraise, how seed and growth expectations differ, what belongs in the data room and how AI findings move valuation and terms.
AI Security Projects
- AI Security Projects: MCP, Prompt Injection and Agentic AI - Practitioner Q&AHow MCP servers get secured, what prompt injection testing involves, where agentic AI risk sits and the audit-ready evidence an AI Security Project delivers.
- Adding an AI Feature to Your Product: What Are the Security Risks?The four risk classes an LLM feature introduces, how severity scales with what the feature can read and do, and what belongs on a pre-launch security checklist.
- Can Our Website Chatbot Be Attacked? A Practitioner Q&AYes. Any public chatbot can be manipulated in plain English. What that means for your liability, why penetration testing misses it and how behaviour is tested.
- Testing an LLM Application Before Launch: Practitioner Q&AWhat to test before an LLM application goes live, in what order, how long it takes and which parts to run in-house rather than commission. For UK engineering leads.
- What Is Prompt Injection, and Should My Business Care?Prompt injection explained for executives: which AI deployments are genuinely exposed, what happens when an attack succeeds and how to assess your own risk.
ISO 42001
- ISO 42001 Audit Evidence: What Certifiers Actually Ask UK Organisations to ShowFAQ on the seven evidence categories UK certifiers request in ISO 42001 audits, stage 1 vs stage 2 differences and realistic preparation timelines.
- ISO 42001 Certification in the UK: A Lead Auditor's Q&AThe ISO 42001 certification path, cost, timeline and how the standard compares with ISO 27001, plus what auditors expect to see and where efforts stumble. For UK GRC and AI governance teams.
- ISO 42001 vs ISO 27001: Which Standard Does Your AI Programme Actually Need?Practitioner FAQ for UK GRC teams comparing ISO 42001 and ISO 27001: scope, overlap, sequencing, costs and EU AI Act alignment.
- Is ISO 42001 Worth It for a Company Our Size?When ISO 42001 certification earns its cost, what it really involves in fees and internal time and which lighter options answer most buyer questions instead.
Shadow AI Discovery
- An Employee Put Confidential Data Into an AI Tool: What Do I Do Now?A calm first-hour response to confidential data entered into an AI tool: establish the facts, contain the exposure, assess notification duties, close the gap.
- Can I Find Out Which AI Tools My Employees Are Using?Yes. Network logs, identity records, extension inventories and finance data name most AI tools within days. Where the evidence sits, and what UK law allows.
- How Do I Stop Staff Pasting Client or Company Data Into AI Tools?Three layers stop client data reaching AI tools: an approved tool, controls at the point of egress and a reporting route staff will actually use. Bans do not.
- Shadow AI Discovery: A Practitioner Q&A for UK GRC TeamsWhat shadow AI is, how to find it without spying on people, how it differs from shadow IT and how to govern it once found. For UK GRC and security leads.
- Should I Be Worried About Employees Using ChatGPT at Work?Staff are already using ChatGPT at work. What to worry about, what is overstated and the first three steps that bring unsanctioned AI use under control.
vCAIO
- AI Leadership Roles Explained: A Practitioner Q&A for UK Boards and GRC TeamsWhat a CAIO, CAIRO, Director of AI Governance and CDAO each own, how the roles differ and who is ultimately accountable for AI risk. A Q&A for UK boards.
- Board Questions on AI Risk: A Practitioner Q&A for NEDs and ChairsWhat boards should ask about AI risk, what a credible answer sounds like and how to tell assurance apart from evidence. Written for UK NEDs, chairs and CEOs.
- Do You Need an AI Risk Officer at 50 People? A Practitioner Q&AWhether a 50-person company needs a dedicated AI risk officer, where accountability should sit instead, what regulation requires and how fractional support works.
- Who Should Be Responsible for AI in Our Company?Why AI accountability belongs to one named executive, why handing it to IT fails and what a workable ownership arrangement looks like at 50, 250 and 1,000 people.