· AI governance
An AI governance checklist for regulated small and mid-sized organizations
Generative AI is already inside many small and mid-sized organizations, even when leadership has not formally approved it. The goal is not to stop every experiment. It is to make AI use visible, protect sensitive data, and keep human judgment in the workflow.
If you lead a regulated organization, the practical governance problem right now is not whether to adopt AI. It is that adoption has already happened in pieces you cannot see. Employees are using consumer AI tools on work problems. Vendors are enabling AI features inside platforms you approved years ago. Someone in finance is pasting a spreadsheet into a chatbot to get a summary.
That produces four questions most organizations cannot currently answer:
- Which AI tools are employees actually using?
- What data is being entered into them?
- Are vendor AI features enabled by default?
- Are outputs being reviewed before they affect customers, compliance, security, or business decisions?
And one that determines whether the others get answered: who is allowed to approve high-risk AI use?
For regulated organizations, AI governance is now part of cybersecurity governance. It touches data protection, vendor risk, access control, incident response, training, records, and audit readiness — all functions you already have. The work is mostly extension, not invention.
The checklist
-
Inventory current AI use
Start with what is actually happening, not what policy says should happen. Ask teams directly, review expense and SaaS spend for AI subscriptions, and check which approved platforms have shipped AI features. Expect the inventory to be larger than you assumed. An inventory you trust is the precondition for every other item here.
-
Define the data that cannot go into AI tools
Be specific and concrete rather than abstract. “Do not enter confidential information” is unenforceable because everyone classifies differently under time pressure. Name the categories: regulated customer data, protected health information, cardholder data, credentials, unreleased financials, personnel records, privileged legal material. People follow rules they can apply without judgment calls.
-
Classify AI tools by risk
Not every use warrants the same scrutiny. Drafting internal meeting notes is not the same as generating customer communications, screening candidates, or informing a credit or clinical decision. Tier by what the output touches and what data it consumes, then apply proportionate review. Uniform controls across all AI use are either too heavy to follow or too light to matter.
-
Assign ownership and approval authority
Name the person who approves new AI tools and high-risk use cases. This is the single highest-leverage item on the list. Without a named approver, requests either stall or route around governance entirely — and the second outcome is the common one. Make the path to a decision fast enough that using it is easier than avoiding it.
-
Review vendor AI terms and data handling
Read what the contract actually permits. Is your data used to train models? Are prompts, outputs, and metadata retained, and for how long? Which subprocessors and model providers are involved? Does the AI feature respect existing user permissions? Vendor AI terms are frequently different from the base agreement you negotiated, and they change.
-
Require human review for consequential outputs
Define where a person must review before an AI output has effect — anything reaching a customer, feeding a regulatory filing, informing an employment or credit decision, or changing a system configuration. Name the reviewer role rather than leaving it to whoever is closest. The control is not that a human glanced at it; it is that an accountable person owns the output.
-
Update access control and monitoring
AI tools are systems with accounts, permissions, and logs, and they should be governed like any other. Bring them into joiner-mover-leaver processes. Where AI agents act on systems, they need identities, scoped permissions, and credential lifecycle management like any other account — machine and agent identities belong inside your access management program, not beside it.
-
Train employees on approved use
Most inappropriate AI use is not defiance; it is people solving a work problem with the tool in front of them. Training should be concrete: here are the approved tools, here is what must never be entered, here is how to request something new, here is who to ask. Short and specific beats comprehensive and ignored.
-
Add AI scenarios to incident response
Work through the plausible cases before they happen. Sensitive data entered into a public model. An AI-generated output that was wrong and acted upon. A vendor disclosing an AI-related breach. A compromised agent identity. Each has different containment, notification, and evidence requirements, and your existing playbooks probably do not cover any of them.
-
Document decisions and revisit them
Record what was approved, by whom, on what basis, with what conditions. This is your audit evidence, and it is also how you avoid re-litigating the same decision quarterly. Set a review cadence — the tools, the terms, and the risks all change faster than annual policy cycles accommodate.
The point
The goal is not to stop every AI experiment. The goal is to make AI use visible, protect sensitive data, and keep human judgment in the workflow. A governance process that blocks everything gets bypassed, and bypassed governance is worse than none — because you now believe you have controls you do not have.
Related
- Your vendor just shipped an AI feature. Is it still the same approved tool? — the third-party half of this problem.
- Operating philosophy — why governance has to be usable to be real.