visitor-tracker

Who’s Accountable When AI Gets It Wrong? A Guide for Norwich Business Owners

AI accountability for Norwich businesses

At VMIT’s compliance and AI panel in Thetford this June, one question came up repeatedly. If an AI tool gets something wrong, who carries the responsibility? Most Norfolk business owners assume the answer sits with whichever IT companies in Norwich they’ve hired to keep their systems running. It doesn’t work that way, and understanding why matters more now than it did twelve months ago.

The assumption everyone makes

The idea that IT belongs to someone else in the business, whether an in-house team member or an outsourced provider, has been around for years. AI hasn’t changed that assumption. If anything, it’s made it worse, because AI tools get adopted and switched on faster than most businesses update their thinking about who’s in charge of them.

At the June panel, one insurance specialist described this as a mismatch between operating a system and being accountable for it. An IT manager, or the IT support Norwich businesses rely on day to day, runs the tools. Ownership of the decision to use them sits higher up, with the people who run the business.

The same logic already applies to hiring decisions and financial reporting. Delegating the task isn’t the same as delegating the accountability.

Why this sits with you

Company directors already carry legal responsibility for decisions made under their watch, whether or not they made the call personally. Section 172 of the Companies Act requires directors to act in ways that promote the success of the company, and that duty doesn’t pause when a decision involves technology. The same accountability applies as it would to a hiring choice or a supplier contract. The NCSC’s guidance for boards is explicit that this responsibility holds even when the technical work is outsourced to a provider.

Government figures back this up. The most recent Cyber Security Breaches Survey found that only 31% of UK businesses have board-level responsibility for cyber security formally assigned to anyone, and fewer than a quarter of businesses already using AI have any process in place to manage the risks that come with it. Some Norfolk businesses are already ahead of this curve, reflected in the mix of professional services firms and regulated SMEs VMIT works with. If your business falls into that wider gap, you have plenty of company.

What owning the risk looks like

Owning AI risk doesn’t take technical expertise. It starts with knowing which AI tools are already running inside your business, from a chatbot plugged into your website to the AI features quietly switched on inside Microsoft 365. Many directors are surprised by how much is already live before anyone made a formal decision to adopt it.

From there, it helps to put a short written policy in place, covering what staff can put into an AI tool and what should never go near one. A single page is often enough for a small business to start with, and it becomes the AI policy Norwich businesses can point to when a client or an insurer asks how AI is being managed. Just as important is treating your IT provider as someone you brief and question, rather than someone you wait to hear from. VMIT’s approach to security services follows the same principle. Technical controls matter, but deciding what level of risk is acceptable stays a business decision, made by the people running the company.

Three questions for your board

A few questions can move this from theory into practice at your next leadership meeting, echoing what NCSC guidance on AI and cyber security suggests boards should already be asking themselves.

  1. Which AI tools does the business currently use, including any built into software you already pay for?
  2. What happens to client or staff data once it’s entered into one of those tools?
  3. If an AI-generated decision or output caused harm to a client, who in this room would be answerable for it?

Where IT companies in Norwich fit in

Your IT provider doesn’t disappear from this picture. If anything, a good one becomes more useful once the business has taken ownership of the risk, because the conversation shifts from vague worry to specific questions your provider can answer.

IT companies in Norwich vary widely in how they handle this. Some will wait to be asked. Others, including VMIT, prefer directors know what’s running in their business before recommending a single technical control. That reflects the sector VMIT works in day to day, supporting professional services firms and other regulated Norfolk businesses that already answer to clients and regulators about how they handle data.

Whichever provider you use, raise these questions this month. Waiting until something goes wrong is a costlier route to the same conversation. If you’d like a second opinion on where your business currently stands, get in touch.

Frequently Asked Questions

Size doesn’t exempt you from the risk. A one-page policy covering what staff can and can’t put into an AI tool is achievable for a business of any size, and it gives you something concrete to point to if a client or insurer asks.

Your provider may hold technical responsibility for the systems they manage, but legal and regulatory accountability for how the business uses AI sits with its directors.

Not automatically. Many policies were written before AI tools became common, so it’s worth asking your insurer directly whether AI-related incidents are covered or excluded.

At minimum, a list of approved AI tools, rules on what data can and can’t be entered into them, and a named person responsible for reviewing it periodically.