AI Ethics for Small Businesses: A Practical Checklist

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for AI Ethics for Small Businesses: A Practical Checklist.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for AI Ethics for Small Businesses: A Practical Checklist.

It should cover six areas: honesty (would customers be surprised?), privacy and consent, fairness in any decision about people, a named person accountable for every output, the effect on staff, and the truthfulness of what you publish. Run each AI use through the questions before launch and again every six months; a "no" on some means stop.

Ethics here isn't philosophy. It's the set of questions that stops a well-meant AI idea from embarrassing you or harming someone. It overlaps with the law but goes further, because plenty of things are legal and still a bad idea; for the legal side specifically, see the AI compliance checklist for small businesses. Below is the checklist in six groups, each question with why it matters and how to check it, followed by a worked example, the red lines, and a way to keep the whole thing to about 20 minutes per use.

Follow me on Instagram@sagnikteaches

1. Honesty: would a customer be surprised?

  • Would a customer be surprised or upset to learn AI was involved here? Why: surprise is where trust breaks. Check: imagine explaining this use to your most loyal customer, face to face. If you'd feel awkward, disclose it or rethink it.
  • Could anyone think they're dealing with a person when they aren't? Why: people speak and decide differently when they think a person is listening. Check: read the first message your chat or phone assistant sends. Does it say it's an AI?
  • Are AI-generated images or voices presented as real? Why: realistic fakes, even innocent ones, undermine everything else you show. Check: every AI image in your marketing or product pages carries a label.
  • Are you claiming a personal touch you don't provide? Why: "a personal note from the owner" that AI wrote and nobody read is a small deception customers remember. Check: search your templates for "personal", "handwritten" and "from me".

That last check tends to turn something up. Imagine a small wine merchant whose monthly subscription box carries a card headed "A personal note from me", which is now drafted by AI from the month's tasting sheet and printed without the owner reading it. The honest fixes are both cheap. Change the heading to "This month's notes from the shop", or keep "from me" and have the owner add one line of his own to the draft each month. Either passes the loyal-customer test; the original doesn't.

Connect on LinkedInSagnik Bhattacharya

2. Privacy and consent: whose information is this?

  • Whose information goes into the tool, and would they expect it to be used this way? Why: data given for one purpose (booking an appointment) feels misused when it turns up in another (AI profiling). Check: compare the use with what your privacy notice and sign-up forms tell people.
  • Is it the minimum needed? Why: the less that goes in, the less can leak. Check: could it work with first names only, or with no names at all?
  • Is the tool on a plan that doesn't train on your content? Why: on business plans (ChatGPT Business, Claude Team, Microsoft 365 Copilot, Gemini in Workspace) your content stays out of model training as standard, while on consumer plans it depends on how each person has set the model-training switch in their privacy settings. Check: confirm the account type and privacy settings before anyone uses it.
  • Does it involve children's information, health information or anything else sensitive? Why: the harm from a mistake is far greater, and so is the legal protection. Check: if yes, the default answer is "not in a general AI tool" until you've taken advice.
  • Could you find and delete someone's information if they asked? Why: people have rights over their data, and you can't honour them if you don't know where it went. Check: know where the tool stores inputs and for how long.

The minimum-needed question usually has a short answer once someone asks it. In an illustrative mobile dog-grooming business, the owner had been pasting whole client records into an AI tool to write appointment reminders: full name, home address, mobile number, the dog's vet details and a note that the client was "recently bereaved, be gentle". The reminder needed three things: the client's first name, the dog's name and the appointment slot. Cut to those, the reminder read just as well, and the tool never saw an address or a note about someone's grief. The bereavement note mattered for tone, so the owner now adds a kind line by hand when she sends that one.

Subscribe on YouTube@codingliquids

3. Fairness: decisions about people

  • Does the AI influence who gets a job, a place, a price, credit or a service? Why: these are the decisions where bias does real damage. Check: list every point where AI output feeds a decision about a person.
  • Could it disadvantage a group of people? Why: AI learns from patterns in past data, including unfair ones, and can penalise names, ages, disabilities or ways of writing. Check: test it with inputs that differ only in one such detail and compare the results.
  • Can the person affected understand and challenge the outcome? Why: a decision nobody can explain can't be put right. Check: could you explain, in two sentences, why the AI suggested what it did?
  • Does a person make the final decision, with real authority to disagree? Why: "human review" that always rubber-stamps isn't review. Check: how often has the reviewer overruled the AI? If never, find out why.

The paired test is quicker than it sounds. In an illustrative four-person lettings agency that uses AI to summarise tenant applications for landlords, the owner made two copies of a real application with the details removed. They were identical except for one sentence in the "anything else" box: copy B added "I'm a single parent with two children at primary school." The prompt, used on both:

Summarise this tenant application for the landlord in 5 bullet
points: income, employment, rental history, references, and
anything the landlord should know.

Illustrative results: copy A's fifth bullet read "No concerns noted." Copy B's read "Childcare commitments may affect reliability; consider a guarantor." Nothing in either application justified that. The fix was two changes to the prompt: remove the "anything the landlord should know" bullet, which invited speculation, and add "Do not comment on family, health, age or personal circumstances." Re-run, both copies came back with the same five bullets. Keep the pair and re-run it whenever the tool or prompt changes.

The tutorials on AI bias in hiring, pricing and credit decisions and spotting bias and stereotypes in AI-written content go deeper on how to test for this.

4. Accountability: a named person for every output

  • Who is responsible for each AI output? Why: "the AI did it" is never an answer a customer accepts. Check: a named role against every use, written down. For an illustrative five-person bike shop, the whole list fits in four lines: website chat replies, the owner (weekly read of ten transcripts); product descriptions, the online-shop assistant (every one read before publishing); service-due reminders, the workshop manager (template checked once, then spot checks); social captions, whoever posts (read before posting).
  • Is the checking proportionate to the harm a mistake could do? Why: checking everything equally wastes time; checking nothing is reckless. Check: customer-facing and decision-making uses get a full human check. Setting up human review without slowing down shows how to tier it.
  • Is there a simple way to report a mistake? Why: errors you don't hear about repeat. Check: do staff and customers know who to tell?
  • Is someone keeping track of what goes wrong? Why: patterns only show up over time. Check: a short log, or a line in your risk register.

5. Staff: how AI changes people's work

  • Were the people whose work changes asked for their view? Why: they know where it will go wrong, and imposed change breeds resistance. Check: did anyone who does the task help design the new process?
  • Does it monitor or assess staff? Why: surveillance damages trust quickly. Tools that claim to read people's emotions are a particular concern, and for businesses with EU customers they're banned outright in workplaces and education, apart from narrow medical and safety uses. Check: read what the tool records about the people using it.
  • Does it shift work unfairly? Why: AI often moves effort from writing to checking, sometimes onto one person. Check: who's doing the checking, and has their workload been adjusted? A realistic way this shows up: in a small marketing agency, three junior staff start drafting client newsletters with AI, and every draft goes to the senior copywriter to check. Her checking time climbs from almost nothing to about six hours a week, nobody takes anything else off her list, and by week five she's skim-reading. The draft that finally slips through thanks a client for an industry award they never won.
  • Is the time saved shared fairly? Why: if every hour saved simply becomes more of the same work, people learn that efficiency is a trap. Check: can you name what the freed time is for?

6. Truthfulness: what you publish

  • Are facts, figures and claims checked before publishing? Why: AI invents statistics and details that sound right. Check: every number in AI-assisted content has a source someone has looked at.
  • Are reviews, testimonials and endorsements real? Why: AI-written reviews presented as genuine deceive customers and can break consumer law. Check: nothing in your reviews or testimonials was written by AI. Where the legal line is with AI testimonials explains the risk.
  • Does any AI content imitate a real person, brand or competitor? Why: imitation invites complaints and legal trouble. Check: no "in the style of" a named competitor, no likeness of a real person without permission.
  • Do you have consent for any person's image or voice used with AI? Why: using a staff member's or customer's photo in AI-edited marketing without asking is a breach of trust even when it's legal. Check: written consent on file for each.

Running the checklist on a nursery's report-writing idea

Here is an illustrative case: a children's nursery whose manager wants to use AI to draft the termly progress summaries sent to parents, working from practitioners' observation notes. Each practitioner writes about 12 summaries a term, taking around 40 minutes each. Here's how the idea fared:

  • Honesty. Parents would be surprised if they found out afterwards. Condition: parents are told how summaries are written and that each child's key person writes and signs the final version.
  • Privacy. This is children's developmental information, the most sensitive data the nursery holds. Pasting named observations into a general AI chat tool fails the check outright. Two acceptable routes: an AI feature inside the nursery's specialist records system, if its data terms have been checked and approved, or using a general tool only to produce a structure and neutral phrasing from anonymised notes ("Child A"), with the key person adding every specific detail afterwards.
  • Fairness. In a test run, AI drafts compared children to age norms in a way that read as deficit language for children with additional needs. Condition: the prompt forbids comparisons with other children or age norms; the key person decides what developmental points to include.
  • Accountability. The key person is responsible for each summary; the manager spot-checks five a term.
  • Staff. Two practitioners worried it would devalue their knowledge of each child. Condition: AI helps with wording only; observations and judgements stay entirely theirs.
  • Truthfulness. In testing, the AI added a milestone that wasn't in the notes. Condition: "Only include what's in the notes" in the prompt, and a line-by-line check against the observations.

Verdict: yes, with conditions, using the anonymised-structure route. Early timings suggested summaries would take about 25 minutes instead of 40, a smaller saving than hoped, but with the privacy and fairness problems designed out.

In the same month, the nursery was offered a camera system claiming to detect children's moods. That one failed at the first question. It's the kind of use the red lines below exist for.

Red lines: answers that should stop a project

Most "no" answers mean "change the design". These mean "don't do it":

  • It only works if people don't realise AI is involved.
  • It puts children's, health or similarly sensitive information into a tool without approved data terms.
  • It makes decisions about people with no one able to overrule it.
  • It tries to infer the emotions of staff, pupils or children.
  • It creates reviews, testimonials or endorsements that aren't real.
  • Nobody is willing to be named as responsible for it.

Using the checklist without it turning into paperwork

A checklist that takes a day per idea will be skipped. Keep it light:

  1. Match effort to risk. An AI tool drafting generic marketing copy needs a five-minute pass through groups 1 and 6. Anything involving people's data or decisions about people gets the full checklist.
  2. Do it in pairs. The owner or manager plus one person who does the work. Twenty minutes, before launch.
  3. Record three lines: the use, the conditions you set, and who's responsible. The natural home is your AI risk register. For the nursery above, the three lines read: "Termly progress summaries, anonymised-structure route only. Conditions: parents told; no names or observations in the general tool; no comparisons with age norms; line-by-line check against notes. Responsible: each child's key person; manager spot-checks five a term; review in six months."
  4. Re-run it when the use changes, when you switch tools, or every six months, whichever comes first.

Re-runs catch changes you didn't make yourself. At the bike shop above, the six-month pass found that the workshop booking software had added an AI "suggested quote" feature, switched on in an update. It priced the same service differently for different customers, and the software's help pages didn't say how. Comparing a dozen quotes side by side suggested that customers with higher past spending were getting higher suggestions. That's a group 3 question (does AI influence a price, and could anyone explain it?) that didn't exist when the tool was first checked. The shop switched the feature off, noted it in the register, and added "check release notes for new AI features" to the six-monthly review.

Larger or regulated organisations sometimes adopt a formal standard such as ISO/IEC 42001, the AI management system standard published in December 2023. A small team doesn't need certification to use AI responsibly. Twenty-five honest questions, asked before launch and revisited twice a year, cover most of what matters.

Further reads

Sources: EU AI Act Article 5(1)(f) on emotion recognition in workplaces and education; ISO/IEC 42001 publication date. Checklist and example are illustrative guidance, not legal advice.

Weighing up an AI idea that involves people's data?

On a 1:1 call we'll run your idea through these questions together, decide what conditions would make it acceptable, and set up the checks your team will keep.

Book a 1:1 call with me