🧪 AI & Technology

AI Testing Before Regulation: What SMEs Need

Bank of England Governor Andrew Bailey argues that rigorous AI testing should come before formal regulation. For UK SMEs, the practical question is how to assess tools sensibly without treating emerging policy debates as new legal duties.

TG
Thind Global Services
30 September 2026 · 14 min read
AI Testing Before Regulation: What SMEs Need

What Andrew Bailey Actually Said About AI Regulation

Andrew Bailey, Governor of the Bank of England, argued on 30 September 2026 that regulation is not the right place to start when dealing with the risks of artificial intelligence. BBC News reported that Bailey made the case in his first ever article for Substack. His central argument was that rigorous testing should come first, so vulnerabilities can be found and safeguards developed to contain risk.

That distinction matters. Bailey did not argue that AI risks are minor. According to BBC News, he described those risks as real and increasingly significant. Nor did he argue that AI development should be halted or prohibited. He said the benefits are immense, while also calling for a system that allows intervention and establishes boundaries within which AI operates.

Bailey also pointed to work already taking place in the UK, including the AI Security Institute. He said that testing should form part of a set of standards, that progress needs to accelerate and that the process should be approached with a degree of humility. In his view, failures discovered through testing should not automatically be treated as proof that testing itself has failed. Models behaving unexpectedly is, in his argument, part of the reason testing is necessary.

It is important to keep the status of those remarks clear. A Substack article by a central bank governor is an argument, not a rule imposed on businesses. Bailey also said testing should not be treated as an alternative to regulation forever. BBC News reported that he believes a more formal regulatory framework may emerge over time, but that regulation is not, in his view, the right starting point.

Why Testing Before Rules Is Not a Soft Position

It would be easy to hear “testing before regulation” and interpret it as a call for fewer controls. That is not what Bailey’s reported argument says. His position puts the emphasis on understanding how systems fail before trying to write a formal framework around them.

The practical logic is straightforward. If an AI system can behave unexpectedly, then a rule written without enough evidence about those behaviours may fail to address the important risks. Bailey’s argument is that testing can expose vulnerabilities, create evidence and help establish safeguards. Regulation may follow later, but the testing phase is intended to make any eventual boundaries more informed.

His remarks also recognise that testing will sometimes produce uncomfortable results. BBC News reported Bailey’s view that failures and unexpected model behaviour are not evidence that testing has failed. They are evidence of why testing is required. That is a materially different approach from assuming a system is safe because no obvious problem has appeared yet.

For businesses, the useful distinction is between assurance and certainty. Testing can improve understanding of how a system behaves under particular conditions. It cannot turn an uncertain technology into something that never fails. Bailey’s repeated emphasis on humility is relevant here: the process is about finding limits and weaknesses, not claiming that every possible outcome can be predicted in advance.

What Frontier AI and the Closed-Loop Warning Mean

Bailey specifically highlighted frontier AI. BBC News described this as highly advanced self-learning systems. His concern is that, without an effective way to intervene, such systems could become a closed loop in which the model progressively governs itself.

In plain business terms, the concern is about control. The more a system can act, adjust or make further decisions without meaningful outside intervention, the more important it becomes to understand where the boundaries are and whether somebody can step in if behaviour moves outside them. Bailey’s warning is not that every AI tool used by a business operates this way. It is directed specifically at highly advanced systems and the risks that arise when intervention becomes difficult.

That is why the idea of safeguards appears alongside testing in his argument. Testing is intended to find weaknesses; safeguards are intended to help contain what happens when a system does something it should not. The combination matters because simply knowing that something can go wrong is not enough if there is no practical way to respond.

For SME owners and managers, the most useful takeaway is not to assume that every current business AI product should be treated as frontier AI. Bailey’s remarks are broader than day-to-day office software. However, the underlying management principle is understandable even at a smaller scale: businesses should know what a tool is allowed to do, where human oversight sits and how problems can be detected.

How Bailey’s Approach Differs From the US Accord

A different approach was reported from the United States on the same date. BBC News said that on Tuesday 29 September, President Donald Trump hosted leaders from OpenAI, Anthropic, Nvidia, SpaceX, Meta and Google at the White House. Trump said the executives had signed what he described as a morally binding document intended to provide protection from potential AI risks.

Under that agreement, according to BBC News, the companies are responsible for ensuring the safety of their own technology. They agreed to introduce safeguards to keep models operating as intended, quickly detect and fix issues, and work with independent auditors to assess whether their systems are working as intended and whether their platforms are hacking or accessing technical systems in unintended ways.

The accord was signed by Trump, Google boss Sundar Pichai, Anthropic chief Dario Amodei, Meta’s Mark Zuckerberg, OpenAI President Greg Brockman, SpaceX’s Elon Musk and Nvidia chief executive Jensen Huang. Trump described the document as almost like a constitution and said he would create a board to oversee AI tool safety, although BBC News reported that he did not say who would sit on it.

The US agreement also attracted direct criticism. AI governance researcher Jose Miguelito Enriquez told BBC News that the pact shows an emerging consensus but does not address whether developers should be held accountable for incidents. Kimberlee Weatherall, a law professor at the University of Sydney, called the agreement deeply unimpressive and argued that it appears to leave companies to define safety themselves without setting consequences for breaches. Jeannie Paterson of the Centre for Artificial Intelligence and Digital Ethics at the University of Melbourne said self-regulation could result in companies setting only minimal safeguards and that the agreement inspired very little confidence given recent incidents of AI going rogue.

ApproachWho is driving itWhat it asks of companiesWhat it does not do
Testing and assurance first, as argued by BaileyAndrew Bailey, Governor of the Bank of England, in a Substack articleTest systems rigorously, find vulnerabilities and develop safeguards before treating regulation as the starting pointIt is not a rule, does not replace possible future regulation and does not guarantee that testing will prevent failures
Company self-regulation, as in the US accordTrump and the named AI company leaders who signed the accordCompanies take responsibility for their own technology, use safeguards, detect and fix issues and work with independent auditorsBBC News reported criticism that it does not resolve accountability for incidents or clearly state consequences for breaches

Why Any of This Matters to a UK SME

None of these developments creates a new duty for a UK SME simply because it uses AI. Bailey’s Substack article is an argument about how AI risk should be approached, not a legal requirement. The US accord also places no obligation on a UK business. Separately from the debate, it is worth knowing what UK AI regulation already asks of a small business today, which is a much narrower list than the headlines suggest.

It still matters because many businesses rely on technology provided by larger companies. When major AI developers, policymakers and regulators debate testing, safeguards, independent auditing and responsibility, they are discussing questions that also affect how businesses think about suppliers. An SME may not be developing frontier AI, but it can still depend on an AI tool for part of its work. The one place a hard rulebook already bites is Europe, and the EU AI Act reaches UK firms that sell into the bloc.

The point is not to copy the governance structures of a major AI laboratory. A small or medium-sized company does not need to pretend it has the same resources or risk profile. What it can do is pay attention to the direction of the debate: understand what a tool does, understand where failures could matter and make sensible decisions about oversight.

There is also a useful distinction between using a product and transferring responsibility to it. A supplier may provide the technology, but a business still makes choices about where that technology is used in its own operations. That makes basic internal assurance worthwhile even where no specific new rule has been imposed.

What AI Testing and Assurance Can Look Like for an SME

The following is Thind Global Services’ practical view, not a description of a legal requirement. For most SMEs, “AI assurance” does not need to begin with a large formal programme. It can start with ordinary business controls: knowing what is being used, deciding what matters if it goes wrong and checking that important outputs are not accepted blindly. Writing that down is usually the cheapest step available, and a short AI use policy is enough for most firms.

At SME scale, useful testing can be proportionate to the task. A business might review how an AI tool performs on the kind of work it is actually used for, look for obvious failure patterns and decide when a person must review the result. The purpose is not to prove that the tool can never fail. It is to understand where reliance is reasonable and where additional checking is sensible. In practice the first obstacle is visibility, because staff are often already using tools nobody approved.

A short readiness review can help. These are agency-view questions a business can ask about an AI tool it already uses:

These questions are intentionally basic. They are not a substitute for specialist assurance where the consequences of failure are significant. Their value is that they turn an abstract discussion about AI risk into normal management questions about purpose, responsibility, review and response.

  1. What business task are we actually using this tool for?
  2. Who checks its output before we rely on it?
  3. What would matter most if the output were wrong?
  4. Can we spot when the tool behaves unexpectedly?
  5. Do staff know when they should not rely on the output alone?
  6. Who owns the decision to keep using or change the tool?
  7. Do we understand what the supplier says the tool is designed to do?
  8. What would we do if the tool produced a serious error?

Questions to Put to an AI Vendor or Supplier

This section is also Thind Global Services’ agency view. When an SME is considering an AI supplier, the goal should not be to extract a promise that nothing can go wrong. Bailey’s argument itself recognises that models can fail and behave unexpectedly. A more useful conversation is about how the supplier tests, detects and responds. It is also worth asking how the supplier handles prompt injection, since that is the failure mode most likely to reach a business tool.

Ask how the provider tests the system for the way customers actually use it. Ask what kinds of failures or unintended behaviour it looks for and how those issues are handled when discovered. If a supplier makes broad claims about safety or reliability, ask what process sits behind those claims rather than treating the wording alone as assurance.

It is also reasonable to ask where human intervention is possible. Bailey’s frontier-AI warning is specifically about the danger of systems becoming difficult to intervene in. An SME is unlikely to be operating at that frontier itself, but the basic question still travels well: if something goes wrong, who can stop, correct or override the process?

Finally, ask who is responsible for monitoring the product after deployment and how customers are told about material changes or problems. The aim is not to demand a perfect answer to every uncertainty. It is to understand whether the supplier has a credible process for identifying problems and responding to them, rather than relying only on general statements about what the technology is supposed to do.

What Is Still Unsettled and Should Not Be Over-Read

The most important point is that these reports describe a live policy and governance debate, not a settled framework for UK SMEs. Bailey explicitly said that a more formal regulatory structure might emerge over time. He did not present his testing-first approach as the final shape of regulation.

The US accord is also not evidence of an international standard. It is an agreement involving Trump and the named technology leaders, with companies taking responsibility for the safety of their own technology. The criticism reported by BBC News shows that there is disagreement about whether that structure is strong enough, particularly around accountability, the definition of safety and consequences when things go wrong.

There are other signs of how unsettled the wider debate remains. BBC News reported that bosses of leading AI companies including Anthropic and OpenAI have called for AI development to slow down and for an internationally co-ordinated approach to risk assessment and safeguards. OpenAI recently said it would not release its latest AI model because of safety concerns. Trump has rejected the idea of slowing development, saying the US is leading the AI race ahead of China and adding that whoever wins AI, wins.

BBC News also reported that Trump signed an executive order on 29 September instructing US government departments and agencies to use the terms SI and Super Intelligence and stop acknowledging the term artificial intelligence in official correspondence, websites and reports. That is another reminder that terminology and policy positions can shift quickly. UK businesses should be careful not to treat one announcement, one article or one agreement as the final shape of AI governance.

Sensible Next Steps for UK SMEs

Thind Global Services’ view is that SMEs do not need to wait for every policy question to be settled before improving how they use AI. Equally, there is no reason to treat emerging debates as a signal to stop using tools that are already useful. The practical middle ground is to apply normal business discipline. The industry is moving in parallel on this, as the consortium push on agent security showed earlier the same week.

Start by identifying which AI tools are already in use and what they are being used for. Then focus attention on the areas where a wrong output, unexpected action or lack of oversight would matter most to the business. That gives management a clearer basis for deciding where human checks and supplier questions are most valuable.

It is also sensible to document basic responsibility. Somebody should know who owns each significant AI use case, who reviews outputs where review is needed and what happens when a tool produces something unreliable. That is not the same as building a formal regulatory programme. It is ordinary operational control applied to a technology that can behave unpredictably.

Bailey’s argument is useful because it puts evidence before assumption. Test first, learn where systems fail, build safeguards and stay open to stronger frameworks as knowledge improves. For UK SMEs, the same principle can be applied modestly: understand the tools you rely on, challenge supplier claims where necessary, keep people involved where errors matter and avoid treating either optimism or fear as a substitute for evidence.

Frequently asked questions

Has Andrew Bailey introduced new AI rules for UK businesses?

No. BBC News reported that Bailey set out his views in his first Substack article, arguing that rigorous testing should come before regulation. His comments are an argument about how AI risk should be approached, not a new rule for UK SMEs. He also said that a more formal regulatory framework might emerge over time.

Does the US AI accord apply to UK SMEs?

No. The accord reported by BBC News involved Trump and leaders from OpenAI, Anthropic, Nvidia, SpaceX, Meta and Google. It places responsibility on those companies for the safety of their own technology and includes commitments around safeguards, issue detection and independent auditing. It places no obligation on a UK business.

What does Bailey mean by testing AI before regulating it?

Bailey’s argument is that rigorous testing should be used to find vulnerabilities and help create safeguards before regulation becomes the starting point. He also said unexpected model behaviour and failures are reasons for testing rather than proof that testing has failed. He did not say testing should permanently replace regulation.

What should an SME do about AI testing now?

Thind Global Services’ view is to keep the response proportionate. Know which AI tools the business uses, understand where errors would matter, decide where people should review outputs and ask suppliers how they test and respond to problems. This is practical business assurance, not a claim that any particular compliance outcome is guaranteed.

Need help putting this into practice?

Talk to our Birmingham team — free consultation, no obligation, fixed quotes.

Get a free quote