top of page

AI Governance Sounds Like a Big-Company Problem. It Is Five Steps.

Writer: cAIberOps (SY-ber-ops) | MSSP
cAIberOps (SY-ber-ops) | MSSP
3 days ago
5 min read

AI governance, for a small or medium business, is not a committee, a 40-page binder, or a big-company budget. It is five steps: know what AI is in use, decide what is allowed, write it down on one page, put a name and a rhythm on it, and back the paper with actual controls. Here is the whole program, in order.

The reason to run it is measured. IBM's 2026 Cost of a Data Breach study, a cross-industry survey, found 68 percent of breached organizations had no AI governance policy in place, and the study's sharpest finding was about the gap between paper and practice: only 40 percent of organizations applied access controls to AI models and data, and among AI-related breaches, more than nine in ten victims lacked proper AI access controls. Policy without control is the pattern that fails. The five steps below exist to close that gap at a size a 10-to-500-person business can actually run.

Step 1: Inventory the AI already in use

Governance starts with a list, not a policy. Before any rule can mean anything, you need to know every AI tool, browser extension, notetaker, and agent running on machines that touch client, patient, financial, or employee data, and which login each one runs under. The login matters as much as the tool: Verizon's 2026 Data Breach Investigations Report found 67 percent of people using AI on corporate devices were on non-corporate accounts, where personal terms, not business terms, decide what happens to the data.

Do this by looking, not by asking. Surveys catch what people remember and admit; discovery catches what is actually installed and signed in. In our experience, expect the list to be two to three times longer than anyone guesses.

Step 2: Sort the list and set the one rule

With the inventory in hand, sort every tool into three buckets: approved, pending review, and not for sensitive work. Then set the single rule that does most of the work of a policy: sensitive client, patient, financial, or employee information goes only into approved tools on business accounts, and summarizing or rewriting counts as going in.

Approval is mostly a terms question, and the vendors' own pages answer it: business tiers with training off by default and a data agreement available can be approved for sensitive work; personal tiers cannot. Everything else your staff want to try stays fair game with non-sensitive data, which keeps the approved list short and the rule livable.

Step 3: Write the one-page policy that matches reality

Now, and only now, write the policy. One page. It names the rule from step 2, points to the approved list (kept separately so the policy does not change every month), covers the two special cases that generate the most trouble, meeting recording and client-facing work, and names the owner from step 4.

The order matters. Most small-business AI policies fail because they were written first, copied from a template, and never matched what staff actually use. IBM's numbers show where that leads: a third of organizations had policies still in development while the tools were already at work. A one-page policy that matches a real inventory beats a binder that matches nothing.

Step 4: Put a name and a rhythm on it

Governance decays without an owner, so give it one: a person, not a committee. In most small and medium businesses that is the owner, the office manager, or the IT lead. The job is a rhythm, not a project: re-check the terms of approved tools quarterly, because vendor terms move with weeks of notice; refresh the inventory monthly, because new tools show up on staff machines constantly; and decide on pending tools as they appear. One recurring hour a month covers it at first.

The survey data says this step is where most organizations are behind: Vanta's 2025 State of Trust research, a survey of 3,500 business and IT leaders, found fewer than half of respondents with a framework for granting or limiting AI autonomy, and IBM found only 19 percent of organizations coordinate between whoever owns governance and whoever owns security. In a small business those can be the same person, which is an advantage. Use it.

Step 5: Back the paper with controls, then measure

This is the step most programs skip, and the one IBM's 2026 data singles out. A policy nobody enforces is what "policy without control" means: the rule exists, the blocking and monitoring do not. Backing the paper means the approved list is enforced on the machines, new AI tools and sign-ins get flagged when they appear rather than discovered in an incident, and the two numbers that matter get tracked: what share of AI use runs on business logins, and how many new tools showed up this month.

The stakes of skipping it are priced: breaches involving shadow AI averaged 5.39 million dollars in IBM's 2026 study, up from 4.63 million a year earlier, against a global average of 4.99 million. Cross-industry figures, and nobody bills a small business at enterprise rates, but the direction is the point: unmanaged AI is getting more expensive, not less.

Where this fits with the formal frameworks

If a client, carrier, or auditor asks what standard this maps to, the answer starts with NIST's AI Risk Management Framework, released in January 2023, voluntary, and built around four functions: govern, map, measure, and manage. The five steps above are a small-business on-ramp in that spirit: steps 1 and 2 are mapping, step 3 and 4 are governing, step 5 is measuring and managing. Start with the five steps; grow into the framework language when someone with a questionnaire asks for it. And if you want the decision-level view of the same territory, the five decisions every small and medium business should make is the companion piece to this program.

The honest part

Running these five steps does not make you compliant with anything by itself, and a one-page policy will not impress an enterprise procurement team. That is fine. The program's job is smaller and more useful: it means you know what AI is in your business, your staff know the one rule, someone owns the drift, and there is a control behind the paper. That already puts a small business ahead of the 68 percent of breached organizations that had no policy in place, and of the many whose policy was only paper.

Where we fit

Steps 1 and 5 are the two that need tooling, and that is the layer we run. Our Managed AI Security service starts with a free AI Discovery: a light install, about a week of observation, then a report of the AI tools, extensions, and agents found in use across your machines, including which are on personal logins, risk ranked in plain English. That is step 1, delivered instead of assembled. From there we enforce the approved list you set and flag new tools as they appear, which is step 5 running continuously and most of the owner's monthly hour handled. Steps 2, 3, and 4 stay yours, because deciding what is allowed in your business is not something to outsource.

The question worth asking this week

Not "do we need AI governance." Ask the step-zero question: could you produce, today, a list of every AI tool your staff used this week and which login each one ran under?

We work with small and medium businesses nationwide from our home base in McLean, Virginia. If you are in Washington DC, Northern Virginia, Maryland, or anywhere in the country and the answer is no, book a free 15-minute call. The discovery that produces that list is free, and the five steps start from it.

Comments


bottom of page