AI is already in use somewhere in your company. Staff have signed up for chat and writing tools. AI features have appeared inside software you already pay for. Your developers may be calling AI models directly. The work is useful, but if someone asked which data goes into which tool, who approved it, and who would answer for it, the honest reply might be "we're not sure".
Then you look at the frameworks, and they look built for companies with a governance department. You don't have one. You need a start that is real and small enough to finish.
Start with the data, not the AI
AI governance is data governance with a new urgency. Governance means knowing exactly who and what can reach your data, and being able to show what happened to it. The "what" matters as much as the "who": integrations, automated workflows and AI agents read and move data all day, often with more access than any one person.
That's where the gaps tend to be. IBM's 2026 research found that 92% of organisations that had an AI-related breach lacked proper AI access controls, and that fewer than half actively secure non-human identities, the system accounts and connections that act on someone's behalf 1. Many companies check who their staff are. Far fewer check what their systems can reach.
So the first question isn't "which AI tools do we use?" It's "which data could an AI tool reach, through a person or through a system?"
Use a framework as a checklist, not a binder
A framework gives finance, IT, security and the business a shared order of work. The most practical one for a mid-sized company is the NIST AI Risk Management Framework, published by the US National Institute of Standards and Technology. It's voluntary, and it has four functions 2:
- Govern: decide who may approve AI use, and who owns each use.
- Map: find where AI is used, what it's for, and what data it touches.
- Measure: judge which uses carry real risk, for example those touching personal data or feeding important decisions.
- Manage: decide what to allow, change, watch or stop, and keep checking.
NIST released the framework in January 2023 and added a profile for generative AI, the kind that writes text, images or code, in July 2024 2. You don't need to adopt it formally. Using those four words as the headings of your own one-page plan is enough to make sure nothing important is skipped.
Why EU rules come up even outside the EU
Companies in Singapore, the US or elsewhere still hear about the EU's rules, because customers, staff and data cross borders, and EU clients ask their suppliers about them. Two are worth knowing by name.
GDPR, the EU's data protection law, allows fines of up to EUR 20 million or 4% of worldwide turnover 3. The EU AI Act allows fines of up to EUR 15 million or 3% for breaches of operators' obligations, and up to EUR 35 million or 7% for banned practices; for smaller companies, the lower of the two amounts applies 4.
This isn't legal advice, and whether either law applies to you is a question for a lawyer. The practical point is simpler: if you can't show who used AI, on what data, under which rule, and who approved it, any serious review, legal, customer or audit, will be hard work. A basic record of AI uses makes it much easier.
Steps that fit your size
Small teams need two things: an approved list of AI tools, and a one-page rule saying what data may go into them. Name one person who owns both. Our article on shadow AI shows how to find what's already in use and write that rule.
Mid-sized companies add structure:
- A register of AI uses: a simple list of each tool or use, what it's for, its owner, the data it touches and the controls on it.
- An owner for every use: the person who decides whether it's still worth it and answers for it.
- Access controls that cover system accounts and integrations, not just people.
Larger organisations add evidence: records showing who and what reached which data, when, and through which tool, kept long enough to look back. This is where logs and approval records become part of normal work rather than something assembled after a problem.
Whatever your size, start with one part of the business, get it working, then extend it. A register that covers one department properly is worth more than a company-wide policy nobody follows.
When to get help
Most of this can be done in-house. Help is worth it when the work stalls: nobody owns the register, the AI bills don't match the tools people say they use, a supplier switches on AI features and nobody knows what data they reach, or answering a simple data question means asking around for a week.
Cost and governance often point at the same gap. A tool with no owner is hard to budget for and hard to control. That's why we treat governance as the foundation of AI spend management, not a separate project.
Sources
- IBM, "AI-powered adversaries and the enterprise risk challenge", 29/07/2026. Read 04/10/2026.
- NIST, AI Risk Management Framework, nist.gov/itl/ai-risk-management-framework. Read 04/10/2026.
- GDPR Article 83(5), gdpr-info.eu. Read 04/10/2026.
- EU AI Act Article 99, artificialintelligenceact.eu. Read 04/10/2026.
