Your company already uses AI. The only open question is whether anyone can say where, for what, and with which data. In Microsoft and LinkedIn's 2024 Work Trend Index (survey data from 2024, 31,000 people in 31 countries), 75% of knowledge workers said they use AI at work, and 78% of those AI users said they bring their own tools (Microsoft). Mid-sized companies are not the exception.
Large enterprises answer this with committees and dedicated risk teams. A company with a few hundred people needs something lighter that still holds up in front of an auditor, a regulator, or a buyer's due diligence team. This is the framework we use.
What AI governance is
AI governance is the set of owners, rules, and records that decides which AI a company uses, for what, with which data, and how it proves that afterwards. It is not a document. A policy nobody follows is not governance, and neither is a ban that everyone works around.
It rests on eight building blocks.
1. Ownership
Name one accountable executive. In mid-sized companies this is often the COO, CFO, or CIO; the title matters less than having budget and the authority to say no. Around that person, a small working group meets monthly: IT and security, data protection, legal (in-house or external), and two or three people from the business who actually use AI.
The group decides tool approvals, maintains the inventory and risk tiers, and prepares the board report. Keep it small. A governance group that needs a quorum of twelve will not meet often enough to keep up with the tools.
2. A policy people can read
One or two pages, written for employees, not for lawyers. It should answer:
- Which tools are approved, and where to find the list.
- Which data may go into which tool. A simple traffic light works: public data anywhere approved; internal data only in tools with enterprise terms; personal data, customer data, and confidential financials only in tools approved for that class.
- What always needs a human check before it leaves the company (anything sent to customers, anything published, anything that becomes a decision about a person).
- How to request a new tool, and how long an answer takes.
- Who to tell when something goes wrong.
Write the detailed rules in a separate standard for IT. The employee policy should fit on a screen.
3. Approved tools
Much shadow AI exists because the approved route is slower than a credit card. Fix that first. Approve at least one general-purpose assistant under enterprise terms (data not used for training, retention you control, single sign-on), and publish the list.
For each approved tool, record the vendor, the contract and data processing terms, where data is processed, which data classes are allowed, and who owns the relationship. Give requests for new tools a turnaround measured in days. A two-month approval process guarantees that people will use the tool anyway, just without telling you.
4. Shadow AI
Bans rarely work; people route around them on personal devices. Discovery plus a sanctioned alternative does. Practical sources for discovery:
- single sign-on and identity logs (which AI apps people sign in to);
- network or browser telemetry, where you already have it;
- expense reports and card statements (AI subscriptions are easy to spot);
- AI features switched on inside software you already license;
- simply asking, with an amnesty: "tell us what you use, and we will help you use it safely".
The goal is an inventory, not a disciplinary process. Everything you find goes into the register and through the same risk tiers as everything else. An AI audit can do this discovery for you as a one-off, but the process has to keep running afterwards.
5. Risk tiers
Not every use deserves the same scrutiny. Four internal tiers, aligned with the EU AI Act, keep the effort proportionate:
| Tier | Examples | What it takes |
|---|---|---|
| Prohibited | Inferring employees' emotions at work, social scoring, manipulative techniques (AI Act Article 5) | Not allowed. Check the inventory for anything close to this. |
| High-risk | Screening job applications, evaluating or monitoring employee performance, scoring the creditworthiness of individuals (Annex III) | Named owner, legal review, deployer obligations from 2 December 2027; for systems used at work, inform workers' representatives and affected workers before use |
| External or sensitive | Customer-facing chatbots, AI-generated content you publish, personal data processed | Owner, data protection review, disclosure where Article 50 requires it, human check before release |
| Internal productivity | Drafting, summarising, internal search, coding help | Approved tool, policy applies, no further review |
In our experience, most of a mid-sized company's usage lands in the bottom tier. The point of the tiers is to prove that, and to catch the few cases that do not.
6. Logging and evidence
Governance you cannot evidence does not exist when someone asks for it. Keep:
- the inventory: every AI system, its owner, its tier, and the reasoning behind the tier;
- approvals: who approved which tool or use case, when, and on what basis;
- training records: who received which AI training;
- usage logs for anything above the bottom tier. Where AI connects to company systems, log every action: which user, which agent, which tool call, what changed, who approved it.
That last point is where governance meets engineering. When AI tools reach your ERP, CRM, or document stores through one integration layer, the layer can enforce permissions and write the log in one place. We describe that architecture in MCP explained for the enterprise.
7. EU AI Act obligations for deployers
Most mid-sized companies are deployers under the AI Act: they use AI systems built by others. (If you put your own name on a high-risk system or substantially modify one, you can become a provider, with much heavier duties.) As amended by the Digital Omnibus, Regulation (EU) 2026/1744, the main deployer duties are:
- AI literacy (Article 4), since 2 February 2025. Take measures to support the development of AI literacy among staff and others using AI on your behalf, taking into account their knowledge and the context of use. The Omnibus made this an obligation of effort; it did not remove it.
- Prohibited practices (Article 5), since 2 February 2025. Two further prohibitions, on generating non-consensual intimate imagery and child sexual abuse material, apply from 2 December 2026.
- Transparency (Article 50), since 2 August 2026. Deployers must disclose deepfakes they publish, disclose AI-generated text published to inform the public on matters of public interest (unless it has undergone human review and editorial responsibility), and inform people exposed to emotion recognition or biometric categorisation systems.
- High-risk systems (Article 26), from 2 December 2027 for the Annex III use cases. Use the system according to its instructions; assign human oversight to people with the competence, training, and authority to exercise it; make sure input data you control is relevant; monitor operation and report serious incidents; keep the logs the system generates, where they are under your control, for at least six months; inform workers' representatives and affected workers before using a high-risk system at work; and inform people when a high-risk system is used to make decisions about them. Some deployers, including those scoring the creditworthiness of individuals, must also carry out a fundamental rights impact assessment (Article 27).
Fines for breaching the deployer and transparency obligations reach €15 million or 3% of worldwide turnover, whichever is higher; for SMEs and small mid-caps the lower of the two applies (Article 99). None of this is legal advice. For the board-level view of the same timeline, see the EU AI Act: what boards must do now.
8. Board reporting
A board does not need a dashboard. It needs one page, every quarter:
- the inventory by tier, and what changed since last quarter;
- new approvals and rejected requests;
- incidents and near misses, and what was done;
- training coverage against the plan;
- open actions and upcoming legal dates (the next one that matters for most companies is 2 December 2027).
If the page is hard to fill in, that is useful information in itself: it shows where the governance has gaps.
Frameworks worth borrowing from
You do not need to adopt a formal standard to govern AI well, but two are worth knowing. The NIST AI Risk Management Framework, released in January 2023, organises the work into four functions: Govern, Map, Measure, and Manage. ISO/IEC 42001:2023 specifies an AI management system that can be certified, which matters if customers ask you for evidence of how you manage AI. The eight blocks above map onto both, so you can grow into either later.
Where to start
- First month: name the owner, set up the working group, approve one general-purpose assistant under enterprise terms, and publish a short policy.
- Second month: run shadow AI discovery, build the inventory, and assign tiers. Flag anything in the top two tiers for review.
- Third month: train people on the approved tools and the policy, start the logs, and send the board its first one-page report.
Training is the part companies skip, and it is what makes the rest stick. People who know how to use the approved tools well stop looking for unapproved ones. Our AI Champions Program and AI workshops and training are built for that.
Talk to us
If you want to know where your company stands, or need a framework that fits your size rather than a bank's, talk to us.