What governance actually means at the operational level

AI governance is not a 40-page document approved by a steering committee. At least, it should not start as one. At the operational level it is the answers to four questions: who is allowed to deploy AI in their team; who is responsible when an AI tool produces something wrong; how do we evaluate a new AI tool before it touches real data; and what do we do when an employee uses an external AI tool with company information. If you cannot answer those four questions in plain sentences today, your governance is implicit, which means it is whatever the most adventurous person in your company decides it is.

Stage 1: minimum viable governance

For an organisation under 100 people just beginning to deploy AI, you do not need a CAIO and a multi-stakeholder committee. You need three documents totalling roughly six pages. (1) An acceptable-use policy for external AI tools, covering what data classes can and cannot leave the company. (2) A short approval process for new AI deployments — a one-page form covering data, users, vendor, and a named owner. (3) A monthly review meeting (45 minutes) where active AI deployments are looked at by the same small group. That is it. The point is not to be exhaustive; it is to make the implicit explicit so the conversations happen out loud.

Stage 2: scaling past the first three deployments

When you reach four or more active AI deployments, the minimum framework starts cracking. Symptoms: nobody can list all the active AI tools; two teams have built overlapping things; an external auditor or customer asks "what AI do you use" and you cannot answer in under a day. At this point you need (a) a register of AI systems (which model, which data, which owner, last reviewed), (b) a risk classification (low/medium/high based on data sensitivity and decision impact), and (c) different review cadences per class. High-risk gets quarterly; medium-risk gets semi-annual; low-risk gets a yearly check. The register is the artefact you cannot skip; everything else hangs off it.

Stage 3: regulated and high-impact use

If your AI touches customer-facing decisions (credit, insurance, hiring, healthcare, public-sector services), or you operate in a regulated industry, you graduate to a more structured framework. The EU AI Act, for instance, mandates specific documentation and human-oversight requirements for high-risk systems. At this stage governance includes a written impact assessment per system, a documented escalation path for AI-driven decisions a customer disputes, a model-validation process before each major change, and audit-ready logs. This is real work — typically 0.5–1 FTE for an organisation with 5–10 high-risk systems — but it is also where the EU is heading regardless.

The accountability question

The hardest single question in AI governance is: when an AI tool is wrong, who is accountable? The wrong answer is "the vendor" — that produces unaccountable systems and angry customers. The wrong answer is also "the AI" — accountability has to land on a human. The right answer, in our experience, is a named owner per deployment, a documented escalation path, and a clear statement that the owner is responsible for the outcomes the system produces, not for the model itself being correct. This sounds harsh, but it is what makes the rest of governance work. Without a named human, every issue becomes a committee meeting.

Common mistakes to avoid

Three patterns we see fail. First: writing a long policy in isolation by a legal or compliance function with no input from the people who actually deploy AI. The result is a document that ignores how the work is done and gets routed around. Second: trying to govern shadow AI by banning it. Employees pasting client data into ChatGPT will not stop because of a policy; they stop when they have a sanctioned tool that does the job. Govern by enabling. Third: treating governance as a one-time launch instead of a continuing operation. The register goes stale in six months without a review cadence; the policy gets ignored after a year without retraining. Governance is a function, not a project.

A 30-day starter plan

Week 1: name an executive sponsor and a working group of three to five people from across the business (engineering, ops, legal/compliance, a senior individual contributor from an affected team). Week 2: write the acceptable-use policy and the approval form. Week 3: inventory existing AI usage — including the ChatGPT and Copilot accounts people are quietly running. Most companies are surprised by what they find. Week 4: hold the first monthly review meeting. After that, iterate. Most of the value of governance comes from the conversations the framework forces, not from the documents it produces. We have a sample policy and review template and are happy to share them — get in touch.