DSIT's AIME: What It Was, What the Government Said, and What It Means for UK SMEs
In February 2026 the UK government confirmed it will not be publishing AI Management Essentials (AIME) as a final tool, and will not make it a government procurement requirement. This post explains what AIME was, what the government's response actually said, and what the right next step looks like for UK SMEs who still need to govern AI responsibly.
What AIME was
DSIT published AI Management Essentials as a consultation draft in November 2024. It was designed specifically for small and medium-sized enterprises: a self-assessment framework that would help organisations using AI understand where they stood across ten governance dimensions, without the cost and complexity of a full certification programme.
Crucially, DSIT built the draft on three reference frameworks: ISO/IEC 42001:2023 (the international AI management system standard), the EU AI Act, and the NIST AI Risk Management Framework. The draft questionnaire covered ten areas of practice, from keeping a record of your AI systems and having a working AI policy through fairness, risk assessment, data management and protection, to issue reporting and third-party communication.
It was a draft, and two things never arrived. The section ratings and generated action points promised for the final version were never published. And the draft contained no questions on human oversight of AI decisions at all, despite that being one of the most consequential areas in UK law (Article 22 UK GDPR, as reformed by the Data (Use and Access) Act 2025).
What the February 2026 government response said
On 6 February 2026 the government published its consultation response on the AIME consultation hub. The key points:
- The government will not be publishing AIME as a final tool.
- It will not make AIME a government procurement requirement.
- The government intends to publish simpler, SME-focused successor guidance. As of this writing, none has been published.
The framing in the response is a refinement, not a retreat: the government says it plans to develop future guidance focused on the foundational governance measures needed for responsible AI deployment, specifically targeted at SMEs and in a simpler, more accessible format. The plan is to build something lighter rather than to abandon the governance agenda.
"The government stepped back from AIME as a finalised tool. The governance need it mapped has not gone anywhere. ISO 42001, the NIST AI RMF and the EU AI Act remain the frameworks that define what responsible AI looks like."
What this means for UK SMEs
The honest answer is: less than the headline suggests.
The governance need is unchanged. If you use AI that touches personal data, makes decisions about people, or operates in a regulated sector, your UK GDPR, Article 22 (DUAA 2025) and Equality Act obligations apply today regardless of what happens with any government self-assessment tool. Those are hard legal duties.
The frameworks AIME was built on are still the right benchmarks. ISO/IEC 42001 is the only certifiable international AI-management-system standard. The NIST AI Risk Management Framework is globally influential. The EU AI Act is a hard legal duty for firms that touch the EU market and the most mature AI risk framework in existence. DSIT built the AIME draft on all three because those were the right frameworks. They still are.
The ten dimensions are still the right territory. Accountability, fairness, transparency, human oversight, data governance, privacy, security, safety and robustness, third-party communication, and continual improvement: this is the landscape any serious AI governance effort needs to cover. Whether or not a government tool exists to walk you through it, the gaps in those dimensions are the gaps that expose you to regulators, insurers and procurement teams.
What we recommend instead
We built our AI Governance Health Check on Nimble AI's own ten-dimension methodology, grounded in ISO/IEC 42001, the NIST AI RMF and the EU AI Act. It covers the same governance ground the AIME consultation mapped, and it goes further: a 0 to 3 scoring rubric, evidence checks, and explicit human oversight assessment.
The methodology is not AIME. It is what we have built over the work we do with UK SMEs, informed by DSIT's thinking and anchored to the real benchmarks that procurement teams, insurers and regulators actually check against.
Our free 10-minute AI Readiness Scorecard scores your business across our ten governance dimensions and gives you a RAG-rated readiness report with a plain-English recommended next step. If you want the full picture, the AI Governance Health Check takes one to two weeks, delivers a maturity heatmap and a prioritised action plan, and produces a board-ready summary you can point at anyone who asks.
How ISO 42001, NIST and the EU AI Act relate (without AIME as the bridge)
AIME was useful partly as an on-ramp: it translated the substance of ISO 42001 and the EU AI Act into plain-English questions a non-specialist team could work through. With AIME gone, that translation job doesn't disappear; it just needs to be done by someone who knows the frameworks. That is what a governance consultancy is for.
The relationships between the frameworks are worth knowing:
- ISO/IEC 42001 is the certifiable end-state: a full AI management system, independently audited, with a certificate you can show customers. The right goal for SaaS firms, regulated sectors and anyone selling to enterprise.
- NIST AI RMF is a comprehensive risk management framework, US-origin but globally used. Useful for firms with US partners or investors, and increasingly referenced by UK regulators as a benchmark.
- EU AI Act is a hard legal duty for firms with EU exposure. For purely domestic UK firms it is a voluntary best-practice benchmark, but the most mature and detailed one in existence.
You don't need AIME to use any of these. What you need is someone who can map where you sit against them and tell you proportionately what to do next.
"A government self-assessment tool being shelved does not make the governance need go away. ISO 42001, NIST and the EU AI Act are still there. The question is just who helps you navigate them."
The right way to start
Take the free 10-minute AI Readiness Scorecard. It scores you across our ten governance dimensions (informed by the same territory DSIT's AIME draft covered) and gives you a RAG-rated report and a recommended next step. If the full Health Check is the right next move, it'll say so. If a lighter-touch starter is proportionate, it'll say that instead.
The governance work is the same work it was before February 2026. It just doesn't have a government tool attached to it any more.