ModelCharter
ModelCharter Team

What Is AI Governance? A Practical Guide for Small Teams

AI robot representing artificial intelligence governance for business teams

Photo: Kindel Media / Pexels

Key takeaways

  • AI governance is three artefacts: a usage policy, an approved-tools register, and a record that staff acknowledged it.
  • Team size doesn't set your risk level - the sensitivity of the data flowing through AI tools does.
  • The EU AI Act's AI-literacy duty has applied since 2 February 2025 and can reach non-EU businesses.
  • Shadow AI - unapproved tools used quietly - is the most common first failure mode.
  • Frameworks like NIST AI RMF and ISO 42001 are structured versions of the same basics, not a different starting point.

AI governance is how an organisation decides who can use AI, what they're allowed to put into it, and how it proves that later if someone asks. It sounds like a job for a compliance department, but the moment anyone on your team pastes a client brief into ChatGPT, you already have AI risk sitting on the books, governed or not. The good news is that for a small or mid-sized team, AI governance isn't a department, a budget line or a six-month project. It's three short documents and the discipline to keep them current. This guide covers what those three things are, why 2025 and 2026 made them harder to skip, and where a team of five or fifty actually starts.

The three artefacts that cover most of it

You don't need a governance committee to have AI governance. For most small and mid-sized teams it comes down to three things: an AI usage policy that spells out what's allowed and what isn't; a register of which AI tools are approved, and for what kind of data; and a record showing that staff have actually read and acknowledged the policy. Put those three in place and you've covered the large majority of what an auditor, an enterprise customer's security team, or a regulator will realistically ask to see. Everything else - deeper risk assessments, a named governance owner, staff training sessions - builds on top of that base rather than replacing it.

Why it became urgent in 2025 and 2026

Three things happened at roughly the same time. AI tools went from novelty to daily habit across marketing, support, HR and engineering teams, often faster than anyone formally decided to adopt them. Regulators started acting rather than just talking: the EU AI Act's AI-literacy duty has applied since 2 February 2025, and it reaches any business whose staff, customers or output touch the EU, not only EU-headquartered ones. And enterprise buyers began asking about AI directly inside SOC 2 and vendor security reviews, so a missing AI policy now shows up as a gap in a sales process, not just a compliance one. None of that requires you to be a big company; it just requires you to use AI, which by now is almost everyone.

Does a ten-person company really need this?

Yes, and the reasoning has nothing to do with headcount. Governance exists to manage risk, and risk tracks how much sensitive data flows through AI tools, not how many people you employ. A five-person team handling client financial records carries more AI risk than a two-hundred-person team that only ever uses AI for internal brainstorming. The honest answer is this: if anyone on your team uses AI with real customer, patient, financial or proprietary data, you need governance now, and putting the basics in place takes an afternoon, not a quarter. The cost of getting started is genuinely small compared with the cost of explaining, after the fact, why no one had thought about it.

Shadow AI is the risk hiding in plain sight

The biggest day-one risk for most teams isn't a rogue AI model doing something dramatic. It's shadow AI: employees quietly using unapproved tools on personal accounts, often ones that train on or retain whatever gets typed into them. Shadow AI doesn't announce itself when it starts. It surfaces months later, when a vendor quietly changes its data policy, or a customer asks a pointed question about where their information went. A written policy plus an approved-tools list is the cheapest way to pull that activity into the light before it turns into a bigger problem.

What actually happens if you skip it?

Nothing happens on day one, which is exactly why it's easy to postpone. The cost shows up later: an employee pastes a customer contract into a free AI tool and there's no policy that says they shouldn't have; a SOC 2 auditor or an enterprise prospect asks for your AI policy and you don't have one to hand over; a regulator or a curious customer asks how you evidence AI literacy under the EU AI Act, and the honest answer is that you don't. None of these are catastrophic in isolation, but they compound, and every one of them is avoidable with a few hours of upfront work. The pattern we see most often isn't a dramatic incident; it's a slow accumulation of small, unrecorded decisions that nobody can reconstruct six months later when someone finally asks.

How governance relates to the bigger frameworks

If you've seen references to NIST AI RMF or ISO 42001 and wondered whether you need either, the short version is that they're structured, formalised versions of the same three artefacts, built for organisations that need to prove maturity to auditors or certification bodies. The NIST AI Risk Management Framework organises governance into four functions - govern, map, measure, manage - while ISO/IEC 42001 is a certifiable AI management-system standard, similar in spirit to ISO 27001 for information security. Most small teams don't need to certify against either one. They're useful as a checklist for what 'good' looks like as you grow, and our frameworks hub maps each one to what it actually requires in practice.

What this looks like in practice

Picture a twenty-five-person accountancy firm. Nobody there has 'AI governance' in their job title, and nobody wants it. But three of the partners had started using a free AI chatbot to draft client emails, and a bookkeeper was summarising financial statements through a browser extension nobody had vetted, and the firm had no idea until a client asked, reasonably, whether their financial data had gone anywhere it shouldn't. The fix took an afternoon: a short policy naming which tools were approved and which data could never leave the firm, a five-minute walkthrough in a team meeting, and a signed acknowledgement from everyone involved. That's the whole shape of AI governance for a team that size - no committee, no consultant, just three documents that now actually exist.

Where to start this week

Don't overthink the sequence. Generate an AI usage policy - it takes a few minutes, not a few weeks. Check your most-used AI tools against a risk directory so you know which ones are safe to approve outright and which need a paid, non-training tier to be safe. Then circulate the policy and get everyone to acknowledge it. That's not a partial fix; for most teams, it's most of what 'AI governance' actually means in practice. Put a date in the calendar to revisit both documents in six to twelve months, and you've built something that will still hold up when someone finally asks to see it.

FrameworkTypeBest fitCore structure
In-house basicsLightweight practiceTeams under ~100 people with no certification needUsage policy + tool register + attestation
NIST AI RMFVoluntary frameworkUS-facing teams, or responding to enterprise vendor questionnairesGovern, Map, Measure, Manage
ISO/IEC 42001Certifiable standardTeams needing to prove maturity to auditors or enterprise customersManagement-system clauses, published December 2023
EU AI ActBinding law (EU-reaching)Any business with EU staff, customers or outputRisk tiers plus Article 4's AI-literacy duty
How AI governance frameworks compare
Responsible AI risk-management practices can lead to more trustworthy AI systems, but on their own they don't eliminate risk.
NIST AI RMF 1.0

Frequently asked questions

Is AI governance only for companies that build their own AI models?
No. Most AI governance is about how you use AI tools someone else built, such as ChatGPT, Copilot or Claude, not about training models yourself. If your team is a 'deployer' rather than a 'provider,' the obligations are lighter but still real: a policy, an approved-tools list and basic AI literacy for staff.
Who should own AI governance at a small company?
Usually whoever already owns IT, security or HR policy. It doesn't need a dedicated hire. What matters is that one named person is responsible for keeping the policy and tool register current, not that the role is senior or full-time.
How is AI governance different from a general IT policy?
An IT policy covers devices, accounts and software broadly. AI governance is narrower and sharper: it deals specifically with what data can go into a third-party AI model, because that's a different and newer risk than simply installing approved software.
Does AI governance slow teams down?
Done well, it speeds them up, because it gives people a clear, approved way to use AI instead of a grey area they have to guess about. Most of the slowdown people fear comes from vague or absent rules, not from having any at all.
How often should the policy and tool register be reviewed?
At least once a year, plus any time you adopt a new AI tool, a vendor changes its data-handling terms, or a relevant regulation like the EU AI Act updates its guidance.

Put this into practice

Generate a free AI usage policy for your team, then see which of your tools are safe to use.

Open the generator