Proportionate governance for a small team.

For companies without a governance function: the controls that apply at any size, what the law scales down for you, and a first week one person can run.

Who this is for.

You have a small team, little time and nobody whose job title says governance. You probably buy more AI than you build, and some of it was signed up for by staff with a company card. The floor still applies, but the law and the standards scale the rest to your size. This route starts with what one person can set up in a week and grows from there.

  • Founders and managing directors
  • CTOs and lead engineers
  • Operations and IT leads
  • Whoever holds compliance part-time

On the learning path, start at The minimum viable stack or Shadow AI discovery.

New to the field? Read AI governance explained: the definition, the frameworks and where engineering fits.

Three questions you bring.

Each one answered in brief here, and in full in the Body of Knowledge.

  1. What is the least we must do?

    Some controls do not scale down: every AI system in production registered with an owner and a tier, prohibited practices eliminated, every accepted risk with a named acceptor and an expiry, and every agent that acts with its own identity and a tested kill switch.

  2. Does the EU AI Act ease anything for small companies?

    In form, not in substance. SMEs and start-ups get priority access to regulatory sandboxes (Art. 62(1)(a)) and fines capped at the lower of the amount and the percentage (Art. 99(6)) 1. SMEs and small mid-caps may draw up the technical documentation in a simplified form, and the quality management system is proportionate to their size (Arts. 11(1), 17) 2.

  3. We only use third-party AI. What is ours to do?

    As a deployer you own the use: the decision to deploy, the monitoring, disclosing deep fakes you publish (Art. 50(4)) and, for a high-risk system, oversight by people with the competence, training and authority to act (Art. 26(2)) 1. The contract is where you get the evidence you need from the supplier.

Your route through the site.

In reading order: chapters at the section that matters, then the patterns, tools, templates, datasets and figures that turn them into work.

Start this week.

  1. List every AI tool the company uses, including the free ones staff signed up for. Shadow-AI Discovery
  2. Adopt a one-page acceptable-use policy and tell everyone where it is. Acceptable use of AI by staff
  3. Check each use against the Article 5 list and file the result. Art. 5 prohibited practices
  4. Find where Article 50 asks for a notice of AI interaction or a label on AI-generated content. Art. 50 transparency
  5. Run the maturity self-check and pick one move. Maturity self-check

The obligations that matter most.

The duties that reach a small company first, as a user and as a builder: literacy, prohibitions, transparency, the value chain, deployer duties, the documentation and QMS the Act scales to size, and real-world testing.

Obligations for this route (SMEs and start-ups), with status, date and evidence
Obligation Applies Evidence
EU AI Act Art. 4 AI literacy AIGE-OBL-EUAIA-ART4 In force · Literacy programme as code; role-based training records; onboarding gates
EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans) AIGE-OBL-EUAIA-ART5 In force · Policy-as-code blocklist; input/output guardrails; refusal and abuse detection
EU AI Act Art. 50 transparency for certain AI systems AIGE-OBL-EUAIA-ART50 In force · Content labelling and machine-readable marking (e.g. C2PA-style); chatbot disclosure banner
EU AI Act Art. 25 responsibilities along the AI value chain AIGE-OBL-EUAIA-ART25 Deferred · Value-chain due-diligence gate; provider/deployer responsibility allocation; AIBOM and model/data cards collected from upstream providers
EU AI Act Art. 26 deployer obligations for high-risk systems AIGE-OBL-EUAIA-ART26 Deferred · Deployment registry; monitoring hooks; assigned oversight and logging retention
EU AI Act Art. 11 technical documentation (Annex IV) AIGE-OBL-EUAIA-ART11 Deferred · AIBOM (CycloneDX ML-BOM, SPDX 3.0 AI); auto-generated technical documentation; model cards
EU AI Act Art. 17 quality management system AIGE-OBL-EUAIA-ART17 Deferred · QMS-as-code; versioned policies; pipeline controls and change management
EU AI Act Art. 60 testing in real-world conditions outside sandboxes AIGE-OBL-EUAIA-ART60 In force · Real-world testing plan; Art. 61 informed-consent records; test monitoring, logging and incident hooks

Every obligation in the register

Sources

  1. [1] Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026 (Arts. 26(2), 50(4), 62(1)(a) and 99(6)). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng (verified: primary)
  2. [2] Regulation (EU) 2026/1744 (Digital Omnibus on AI) (amended Arts. 11(1) and 17: simplified technical documentation and a proportionate QMS for SMEs and small mid-caps). Publications Office of the EU (EUR-Lex). 2026-07-24. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified: primary)

Start at the top of the route.

Step 01 is The minimum viable stack. Each step after it builds on the one before.