Most of what has been written about AI ethics is completely irrelevant and utterly useless to a small or mid-sized business.
The discipline of AI ethics grew up around the people building the models. Bias in training data. Explainability. Transparency about what a system was built on. Whether a model can be manipulated, and what happens when it is.
These are serious questions. Which is why there are whole teams at Harvard, Oxford, UNESCO, MIT and IBM working on them.
But if you run a business that is not building an AI model, you are still facing ethical dilemmas created by AI. You are choosing tools, rolling them out, deciding which parts of your business they touch, and what decisions you are prepared to hand over. If you don’t navigate that properly, the damage can be immense.
That is not covered by the current body of work on AI ethics.
Or at least, it wasn’t.
What do we actually mean by ethics?
Ethics is thinking about stakeholders beyond your shareholders, and doing your best to treat them fairly. Your employees, your customers, your suppliers, the public, the environment.
Your business exists to make money. But not at any cost. If it is profitable because it pollutes, or because it underpays, or because it squeezes suppliers until they break, or because it misleads customers, that is a problem. Most leaders accept that without argument.
The difficulty is that there is no universal test. Ask ten leaders the same ethical question and you will get a genuine split, and every one of them will think their position is the obvious one.
So there is no ethics list to check yourself against. Staying legal is the floor, not the answer. What you are left with is a question you have to answer for yourself: could you defend this decision to the people it affected?
Why is it harder to spot an ethical problem when AI is involved?
AI has not changed what ethics is. The same question applies: could you defend this to the people it affected? What has changed is how hard that question is to see coming.
Ethical decisions used to arrive looking like ethical decisions. Making people redundant. Moving production abroad. Taking on a client whose business you have reservations about. You knew you were deciding something. You may have got it wrong, but you knew you were choosing.
AI decisions often do not arrive that way. They arrive as a tool your operations manager wants to trial. A subscription that costs £80 a month. A time saving nobody in the room would argue against. Nothing about that meeting feels like an ethical decision, so nobody treats it as one.
Then the tool is in the business. It is sifting applications, or scoring leads, or recording every internal conversation, or drafting things that go out under your name. The decision about how much you were prepared to hand over got made somewhere between the free trial and the third month, and nobody remembers making it.
That is before you get to speed and scale. A bad judgement used to affect one person at a time and take weeks to play out. Now it applies to every applicant, every customer, every employee, immediately and consistently, which means the same mistake happens a thousand times before anyone notices it.
If you’re not building AI, only using it, which ethical problems are you responsible for?
There are two sets of responsibilities here, and almost everything published is about the first one.
The ethics of building AI covers what goes into the model. Was the training data fair? Can the system explain how it reached a decision? Can it be manipulated by someone who knows what they are doing? Is the company honest about what it was trained on? Is it safe for the people it affects?
Those are questions for the model builders. OpenAI, Anthropic, Google, Meta, xAI (many of which are failing dramatically at answering them). And for whichever software company has taken one of those models, built a product on top of it and sold it to you.
The second set is the ethics of applying AI. That is what you use it for, what decisions you let it make or influence, who is affected, whether they know, and whether you are cutting a corner you would not have cut if a person were doing the work. It also includes what you ask of the companies you buy from, because choosing who to trust is one of the decisions you are accountable for.
That second set is entirely yours. Nobody else in your business is going to do it, and nobody outside it has written it down for a company your size.
How to be the SME that gets AI ethics right
None of this requires a department. It requires you to decide these are your decisions (you can’t decide they are not), and then set things up so they do not get made without you knowing.
1. Audit what is actually being used
Not what you approved. What is being used. Which tools, by whom, for what, and what data has gone into them. Most businesses discover things in this exercise that nobody ever signed off, because someone found a tool that solved their problem and started using it. That is the point of doing it.
2. Have somewhere for dilemmas to go
When someone hits a decision they cannot call, they need to know exactly where it goes. In an SME, that might be a person, not a committee. But it has to be someone senior enough to make the call and fluent enough in AI to understand what is being asked. Both. Senior and not fluent gets you a confident wrong answer. Fluent and not senior gets you someone who cannot make the decision stick.
3. Bring other people into the decision
One person cannot see all the consequences of a decision, because one person only has one set of experiences. Get someone from a different part of the business in the room. Whoever deals with the customers. Whoever deals with the staff. They will spot what you cannot.
4. Train your team, and keep training them
Every person using AI in your business can create the ethical incident. They cannot make good calls about a technology they do not understand, and a single workshop last year is not sufficient. This needs to be ongoing, because what they learned six months ago is already out of date.
5. Write it down
A document that says how AI will be used here. Who can use what. What data can go into which tools. What needs approval before it is deployed. How incidents get reported. What happens when someone ignores it. Then read it and update it every two months, because the tools change substantially in that time and a policy written in March describes a business that might be very different by May.
6. Keep your eyes on it
Governance on paper is not visibility. You need to know what is happening while it is happening, so you can step in before it becomes something you are explaining to a customer. And when it does go wrong, you take responsibility for it.
7. Bring in support
Talk to your lawyer about what is legal. Talk to your industry body, though expect them to be behind on this. Bring in consultants where you need expertise you do not have. Talk to your accountant, to peers who have made the same decision in their own business, to anyone who will tell you when you are wrong.
What none of them can do is decide what is right. A lawyer will tell you where the line is legally, and that is the floor, not the answer. A consultant can tell you what is possible, not what you should do. The judgement stays with you (as do the consequences), but you should reach it having heard from people who know things you do not.
8. Stay current
You cannot make good decisions about AI without knowing what it does, what it fails at, and what has just happened. This is not optional and it does not stop. It is the reason I run the Insider’s AI Briefing every month, thirty minutes covering the AI stories that matter for leaders (you can sign up for the next one here and access the recordings on this SubStack if you are a paid member.
That gets your business set up. It does not tell you what to do when a specific decision lands on your desk, which is a different problem and the one people find hardest.
I work through that below, along with the full recording of my AI Ethics for Leaders session.
What to ask when an AI decision lands on your desk
This section includes the eight questions a leader should ask when facing and AI moral dilemma and a recording of my workshop, AI Ethics for Leaders, which covers this topic in more detail.
A moral dilemma in AI is usually just a decision about whether to introduce a policy or adopt a tool. When one arrives, work through these:
Do we need AI to be able to do this?
Who will be directly affected by this decision?
Who might be indirectly affected by this decision?
How severe or significant will the impact be?
Am I making this decision independently, free from external influence?
If we were on the receiving end of this, would it be acceptable to us?
Who needs to be consulted in order to make this decision?
AI has not changed what ethics is. It has changed how quickly things go wrong, how many people it reaches, and how hard it is to see coming. The fundamentals have not moved. Tell the truth. Do not cause avoidable harm. Treat people fairly. Take responsibility for what you decide.
You do not need to have all the answers. You do need to be asking the questions, and to keep asking them, because this is moving and the ground under these decisions is moving with it.



