Back to Blog

AI Governance for Mid-Market: Guardrails Without the Bureaucracy

AIInformation TechnologyLeadership

Last updated: September 3, 2026

AI governance for a mid-market company is a short written standard that says which tools people may use, on which data, and who checks the output before it reaches anyone outside the room. It fits on one page. Companies get this wrong by building a committee first and writing the rules never.

A financial analyst at a distributor pasted the customer list into a chatbot in February. Eleven hundred accounts. Names, billing addresses, twelve months of order history, all of it. She wanted the accounts segmented by margin and ranked by reorder gap, and she had it back in about forty seconds, correctly, on a job that had eaten two days of her life the previous quarter.

Nobody had told her not to.

That is the whole story. No villain in it. She did good work, fast. The company had never written down a rule, so she followed the only one available to her, which was the one about hitting the deadline. I have watched some version of that at four companies this year, and the reaction is always the same two bad options. Ban the tools. That lasts about six weeks and then pushes everything onto personal phones. Or form a committee, which produces a framework in the third quarter that nobody reads and nothing enforces.

Both of those are what happens when you skip the boring middle option. Write the rules down. Make them short enough that people remember them without looking. Then most of the work needs no approval at all, which is the entire point.

Who is talking and what I sell, so you can weigh it properly. I run an ERP and business systems consulting group, and a company that decides its stack needs rules is a company that sometimes ends up on my calendar. This also runs on a staffing firm’s site, and KORE1’s AI and ML engineer staffing practice places the people who end up holding whatever you write. Neither of those changes the page I am about to hand you. It is free, it is short, and I will tell you which parts you can skip. If you have not decided where to point any of this yet, the piece on practical AI for business operations comes before this one.

Team classifying AI use cases on a whiteboard by who sees the output, the core AI governance test

It Is Rules, Not a Committee

AI governance is the standing set of rules that decides who may use which AI tools, on which categories of data, with what review, and who is accountable when the output turns out to be wrong. At mid-market scale it fits on a single page, and it names actual people rather than roles.

The reason this gets overbuilt is that the word governance arrived here from banking and pharma, where it means a function with a budget and a head count. Search the term and you get definition pages from companies selling governance platforms. They are not lying. They are describing what governance looks like at an insurer with nine thousand employees and a model risk committee that has existed since 2011.

You are not that. Nowhere close. If you sit between fifty million and a billion in revenue you have somewhere between two and maybe fifteen people who touch anything technical. Adding a review board to that is not caution. It is a new place for work to stop.

The NIST AI Risk Management Framework is the closest thing to a neutral spine here, and it is worth reading precisely because it does not tell you to build a department. It splits the work into four functions, govern, map, measure and manage, and it treats govern as the thing woven through the other three rather than a gate that sits in front of them. That is the correct instinct. Governance is not a checkpoint. It is the default setting everything else runs against.

Here is the part that should change how you think about timing. The Census Bureau tracks actual AI use by real firms every two weeks, and as of early May 2026 the national rate was 19.8 percent, with 32 percent among firms of one hundred to two hundred forty-nine employees and 37 percent above two hundred fifty. So roughly a third of companies your size are already running this inside a business function. The governance conversation is not ahead of adoption. It is behind. It has been behind the whole time.

Which means you are not writing rules to prepare for something. You are describing something. It is already going on in your building, probably in finance, probably on a customer list.

Three Classes, and Most of Your Work Is Class A

We run regulated work at Foretopia, where some deliverables sit inside validated systems and an auditor is allowed to ask how any given thing got made. So we have a real change control document. A controlled one. Not a slide. The part of it I keep translating for companies nowhere near regulated is not the AI section. It is the classification.

Every change gets a class before anyone starts. One question decides the class. Not how clever it is. Not which tool made it. The question is who ends up seeing the result.

ClassThe testWhat it costs you
AThe output stops with the person who asked for it. Summarizing a call, drafting a first pass at an email, explaining an error message, cleaning up your own notes.Nothing. Approved standing, on the page, forever. No ticket, no review, no meeting.
BThe output reaches a colleague, or it changes a number somebody will act on. A margin analysis. A forecast input. A candidate summary a hiring manager will read.A named person checks it before it moves. One line recorded, not a form.
CThe output reaches a customer or a regulator, or it writes into a system of record with no person in between. Anything automated, anything that touches money leaving the building.A named owner, a written spec, a test somebody wrote by hand, and approval before it runs the first time.

Run your actual list through that and something useful happens. Almost everything lands in A. Meeting notes, first drafts, research, code explanations, the tedious reformatting nobody wanted to do anyway. Class A is where the productivity is, and it is also where nine out of ten governance conversations waste their time, because a committee cannot resist reviewing the thing it can most easily understand.

Class B is small. It is where judgment lives. Class C is smaller still, and it is the only place the word risk is doing real work. If you are about to build your first one of those, the mechanics of building an agentic workflow and deciding where it stops for a human are a separate piece.

One detail from the controlled document is worth stealing outright, and almost nobody does it. You record the reasoning for the classification, not just the letter. A change classified A is auditable on the basis of why it was classified A. That is one sentence per decision, and it is the difference between a policy you can defend nine months later and a spreadsheet full of letters that means nothing to the person who inherits it.

The other thing that falls out of the class test is that it survives the tool changing. You are not writing a rule about a chatbot. You are writing a rule about blast radius, and blast radius does not care which vendor won the bake-off.

Hands sorting folders into three stacks representing class A, B and C AI work under a written AI governance standard

Two Rules Keep the Page Honest

A classification scheme with no teeth becomes paperwork within a quarter. Two rules stop that. Both are one line long.

Changes are not bundled to avoid assessment. Somebody works out that six small things shipped together get looked at once, and they are not being sneaky about it, they are being efficient in the way your incentives asked them to be. Assess each one on its own, then assess the combination as well. The combination is its own change. Two class A items that individually stop with the person who asked can absolutely add up to something that lands in front of a customer, and that is exactly the case nobody catches.

The person who assesses is not the person who implements. This is the rule people take personally and they should not. It is not about trust. If you built the thing, you cannot see the assumption you made while building it, and no amount of integrity fixes that. In a small shop it means the finance analyst’s class B output gets a second set of eyes from anybody other than the finance analyst. That is it. It is not a review board. It is a person.

Those two cover most of what actually goes wrong, which is never a rogue model doing something exotic. It is ordinary work quietly crossing a line nobody drew.

Notice what is not on this page. No approval queue for daily use, no request form, no tooling review board, no quarterly attestation. If you find yourself designing one of those, you have drifted from governance into procurement, and procurement is a different problem with a different owner. The engineering-side version of this same argument, about who actually holds review authority once machines are in the loop, is worked through in the piece on who owns the merge button.

Your Vendor Ships Changes You Never Approved

This is the section I get the most argument about. It is also the one I would defend hardest.

You classified something in March. Class A, output stops with the requester, approved standing, done. In August the vendor pushes a release. The feature now writes back to a record, or the model behind it got swapped for a different one, or the thing that used to summarize now also sends. Your classification is stale, and nobody filed a ticket, because from the vendor’s point of view nothing broke. Sucks.

Platform releases are changes to your environment. They just happen to be changes you did not request and cannot decline. NetSuite ships twice a year on a published calendar, and Salesforce, Workday and Microsoft 365 land somewhere between quarterly and continuous. Treat those releases the way you treat an internal change. Assess them in advance, against the release preview rather than against production, and write down which of the functions you actually use are affected and what regression testing that implies. Telling a shipped capability from a roadmap slide is a skill in itself, and I worked through the ERP version of it in what is real and what is hype.

Call it half a day a quarter. That half day is the only thing standing between a live standard and a snapshot of what was true in the spring.

The failure mode here is specific. I have watched it twice. A team does the governance work properly, files it, feels good, and eighteen months later the page describes a system that no longer exists. Nothing was ignored. The ground just moved underneath it, on a schedule, in public, announced in release notes that nobody in the building has a job description that includes reading.

Somebody has to read them. That is a hiring question pretending to be a policy question, and I will come back to it.

What the Regulation Actually Asks You For

Most of what you have read about AI regulation was written for the companies building the models. You are not one. In European terms you are a deployer rather than a provider, and the obligations on deployers are considerably lighter than the headlines suggest.

Lighter is not zero. And the one that catches people is not the one they are watching.

WhatApplies fromDoes it touch you
EU AI Act Article 4, AI literacy measures for staffAlready in force, 2 February 2025Yes, if you have any EU operations or EU staff using AI on your behalf. This one binds deployers, not just builders.
Remainder of the AI Act2 August 2026Mostly transparency duties. Marking synthetic content is the practical one for marketing teams.
High-risk obligations, Annex III uses such as employment and credit2 December 2027, pushed back by the Omnibus amendmentOnly if you deploy AI into hiring, lending, education or similar. Check whether your ATS vendor did it for you.
High-risk obligations, Annex I embedded products2 August 2028Manufacturers of regulated products. If that is you, you already knew.

Two things about that table. The dates in the bottom half moved, and they moved recently, so anything you read last year about August 2026 being the high-risk deadline is out of date. The current sequence is published on the AI Act implementation timeline, and it is worth checking yourself rather than taking mine.

The row at the top is the interesting one. Article 4 has been in force since February 2025, and it asks providers and deployers to take measures supporting AI literacy among staff and anyone operating these systems on their behalf. No risk tier. No threshold. No carve-out for small companies. It has been live for over a year and I have met exactly two mid-market executives who knew it existed.

Good news is that it is satisfied by the thing you were going to do anyway. A written page, a session where somebody walks the team through it, an attendance record. That is a literacy measure. No curriculum required.

If a customer eventually asks you for a certificate rather than a policy, that is ISO/IEC 42001, the AI management system standard, and it is a real project with an auditor at the end of it. Do not start there. Almost nobody in the mid-market needs it, and the ones who do get told by a customer, in writing, with a deadline attached.

Two colleagues deciding who owns the company AI governance standard after it is written

The Page Needs an Owner, and It Is Probably Not You

Here is where the honest part gets uncomfortable.

Every company I have handed a version of this to nods along, agrees the page is short, agrees it is obviously worth doing, and then nothing happens for five months. Not because they disagreed. Because the page has no owner, and a document with no owner is a wish.

The seat is narrower than the job titles suggest. This person does not need to be a data scientist. Nobody is asking them to build a model. What they need is the ability to read a vendor release note and tell you which class it just broke, sit with the finance team without condescending to them, and say no to a bad class C in a room where saying no is unpopular. Part technical, part operational. Mostly judgment.

At a hundred people that is somebody’s Friday afternoon, layered onto a job they already have. At six hundred it is a real seat, and somewhere in between it stops being a favor and starts being a role with a name on it. Getting that wrong in the generous direction is expensive. Getting it wrong in the cheap direction is how you end up with a page nobody has opened since the day it was written.

A fair number of companies want that coverage for the twelve months it takes to get the standard written, socialized and running, and not permanently after that. That is a contract engagement rather than a hire, and it is worth being honest with yourself about which one you need before you post the job. KORE1 works both sides of it. Contract staffing for the interim version, direct hire once the seat has clearly earned its own line in the budget, and their placements run about seventeen days to fill with 92 percent still in the role a year later. If the answer turns out to be an executive rather than a practitioner, that is chief AI officer staffing, a different search entirely and priced like one.

You may also just want to know how far along you already are. There is a readiness scorecard for mid-market operations that walks a single decision through the chain and shows you where it stops. Run it before you write the page. The page gets easier.

Questions From the People Who Have to Sign It

We are four hundred people with no compliance department. Who owns this?

Whoever already owns systems. Usually the IT director or the controller, and at your size it is a slice of an existing job rather than a new one. The wrong answer is a cross-functional committee, because the page needs a person who can be wrong in public and fix it on a Tuesday.

Our lawyers want to ban the tools outright. Is that defensible?

Defensible for about six weeks. Then it stops being a ban and becomes an unmonitored ban, because the work still has a deadline and the phone in somebody’s pocket has no policy engine on it. I would rather have three approved tools with a written data rule than a prohibition that quietly relocates the same activity somewhere I cannot see it. Say that to your lawyers in those words. Most of them already know it.

How long does the one page actually take to write?

An afternoon for the draft, then two weeks of arguing. The drafting is not the work. The work is the conversation where operations says a task is class A and finance says it is class B, and you find out the two departments have different ideas about who reads the output. That argument is most of the value. I sat in one of those last year that ran ninety minutes over because nobody could agree whether a drafted collections email counted as reaching a customer, and by the end of it the AR team had rewritten how they escalate, which had nothing to do with AI and was worth more than the policy. Do not shortcut it to get the document signed.

Does any of the European stuff apply to us if we only sell in the US?

Probably not directly, but check two things before you conclude that. Whether you have EU-based staff or contractors operating these systems on your behalf, which is what pulls Article 4 in. And whether a European customer has flowed obligations down to you through a contract, which happens more than people expect and does not care where you are incorporated. US state law is moving separately and faster than the federal picture, so this stays a live question rather than a settled one.

What do we do about the tools people are already paying for on personal cards?

Amnesty, then a list. Ask what everyone is using, promise in advance that nobody gets in trouble for answering honestly, and mean it. You will get a longer list than you expect and two or three genuinely useful things you had never heard of. Punish the disclosure and you never get an accurate list again.

Six months in, how do I know the rules are working rather than just filed?

One number tells you, and it is how many things got reclassified. A standard that has produced zero reclassifications in six months is not being used, it is being stored. The healthy signal is boring and small. A handful of class B decisions logged with a name against each, one or two things that moved class after a vendor release, and no argument about whether the page applies.

An Afternoon, Not a Quarter

The thing I keep running into is that people treat governance as the tax they pay for going faster. It reads backwards to me. Standardization is what makes speed safe enough to keep doing, and a company that never wrote the rules is not moving fast, it is just moving without knowing where the edges are.

You already know most of your answers. Somebody in your building is doing something clever with a chatbot right now and has not mentioned it, because there is no obvious person to mention it to. Fixing that is a page and a name.

So do the short version this week. List the ten things people are actually using AI for, sort them into A, B and C by who sees the output, write one sentence per decision explaining why, and put a name at the top. That is the standard. It is not impressive. It is not supposed to be.

Then, the next time a vendor turns up with a governance framework and a proposal stapled to the back of it, you can hand them the page and ask which line they would change. Most of the time they will not have an answer, and that tells you something too.

If you want a second read on the classification before you take it to your leadership team, or you have worked out that the person who should own this does not work for you yet, talk to a KORE1 recruiter about the seat, or hit me up on LinkedIn. Send me your ten. I will tell you which ones I think you have classified wrong.