Every live AI system needs a named owner. Here is the practical model UK SMEs can use to manage real risk, suppliers, changes and day-to-day performance.

Twenty-seven years in technology has taught me to get one name before a system goes live. One person must own what happens after the launch.

The project phase is tidy. There is a team, a plan, a budget and a date. Three months later, the people have moved on. The supplier has released an update. The inputs have changed. A customer has found the awkward case that never appeared in testing.

That is when ownership starts earning its keep.

AI has made this old problem harder to see. Its output can look convincing even when it has drifted away from the job. Suppliers describe products as autonomous. A monthly subscription creates the impression that somebody else is running the service for you.

You still own the outcome.

AI use is spreading faster than operational ownership

The Office for National Statistics reported that 29% of UK businesses used at least one type of AI technology in June 2026. That was eight percentage points higher than in June 2025. Text generation was the most common type, used by 17% of businesses.

More AI tools now sit inside everyday work. They draft replies, sort enquiries, recommend products, summarise records and pass data between systems. Each extra connection creates another place where a quiet change can reach a customer.

The legal position is plain. In March 2026, the Competition and Markets Authority published guidance for businesses using AI agents. It says a business is responsible for what an AI agent does in the same way it is responsible for an employee. That remains true when a third party designed or supplies the agent.

The CMA can fine a business up to 10% of its worldwide turnover for breaking consumer protection law. A supplier contract does not carry that responsibility for you.

The National Cyber Security Centre’s guidance also treats AI as an operating concern. It recommends monitoring system behaviour and inputs, managing updates, and treating major changes to data, models or prompts as new versions. Those are recurring jobs. Somebody needs the time and authority to do them.

What an AI system owner owns

Putting a name in a spreadsheet is a start. The role needs a clear job.

The business outcome

The owner should be able to say what the system does in one sentence, who it affects and what success looks like. They should also know where its authority ends.

An agent that drafts a refund response has a different risk from one that issues the refund. The second system moves money and affects a customer’s rights. Its owner needs tighter checks, lower limits and a clear route to a person.

The evidence

Someone must look at performance after launch. Accuracy in a test set will not tell you whether customers are receiving poorer answers this month.

The owner decides what to watch. That might include corrections by staff, customer complaints, failed actions, response times or cases sent for human review. A small set of useful measures beats a dashboard nobody opens.

The changes

AI systems change even when your own code does not. A vendor can replace a model. A team member can edit a prompt. A new data source can alter the answers. A connector can gain another permission.

The owner keeps a short change record, decides what needs retesting and confirms that the live system still matches the approved use. Without that record, a failure investigation turns into guesswork.

The stop decision

Every live AI system needs a safe way to pause it. The owner must know where that control is, what triggers its use and how the work continues while the system is off.

A manual fallback may be slower. That is fine. The aim is to keep the business trading while people find and fix the fault.

The response when something goes wrong

Customers need a route to a person. Staff need to know where to report an odd result. The owner needs access to logs, supplier contacts and the authority to correct an outcome.

This matters most when the AI speaks or acts in the name of the business. A customer will not care which model produced a bad answer. They will expect your business to put it right.

The owner does not need an AI job title

Most SMEs do not need a new department for this.

The best operational owner is usually close to the process. A customer service lead can own a support agent. A finance lead can own an invoice checker. An operations manager can own a scheduling assistant. A technical colleague or supplier can support them, but should not replace them.

The distinction is useful. Technical ownership covers how the system works. Operational ownership covers whether it is doing the right job for the business and its customers. Keep both names where the risk calls for it.

The operational owner also needs a deputy. Holidays, illness and staff changes cannot leave a live system without supervision.

Keep the ownership record to one page

I would record ten things for each live AI system:

  1. The system name and the job it performs.
  2. The operational owner and deputy.
  3. The technical contact and supplier.
  4. The data it can read, write or send.
  5. The actions it can take without approval.
  6. The points where a person must approve or review.
  7. The measures the owner checks and how often.
  8. The threshold for pausing the system.
  9. The manual fallback and incident route.
  10. The latest review date and next review date.

Keep that page beside the system inventory where people can use it. Review it when the model, prompt, data, permissions or business process changes.

Run the seven-day ownership test

Take every AI tool that touches customers, money, staff decisions or sensitive data. Ask four plain questions about each one:

  • Can the named owner explain what the system is allowed to do?
  • Can they show the latest change and the test that followed it?
  • Can they find recent outputs, complaints and corrections?
  • Can they pause it and move the work to a manual route?

A blank answer gives you the next job. Fix that before adding more users, data or authority.

This test also makes buying decisions easier. Ask a supplier how they notify you about model changes, what logs you can export, how incidents are handled and how you leave. If the answers are vague, the operating burden has moved back to you whether the contract admits it or not.

Small businesses can do this well

An SME has fewer layers between the person using a system and the person making the decision. Use that advantage. One named owner, one page, a short monthly check and a tested stop route can cover a modest use case.

As the system gains access to customer records, payments or automated decisions, add stronger testing and oversight. Spend effort in proportion to the harm a bad action could cause.

Ownership also helps commercially. Customers and larger buyers are starting to ask how suppliers use AI. A named owner, current record and visible review history give a better answer than a policy written for a tender and forgotten afterwards.

This is the first control I look for in an AI governance review. If nobody owns the live behaviour, the rest of the paperwork will not save it.

Before the next AI tool gets customer data or permission to act, put one person’s name next to it. Give them measures, a stop control and a review date. If nobody will own it, it is not ready for production.

AI Operations

Recommended Reads