Proportionate governance for a small team.
For companies without a governance function: the controls that apply at any size, what the law scales down for you, and a first week one person can run.
Who this is for.
You have a small team, little time and nobody whose job title says governance. You probably buy more AI than you build, and some of it was signed up for by staff with a company card. The floor still applies, but the law and the standards scale the rest to your size. This route starts with what one person can set up in a week and grows from there.
- Founders and managing directors
- CTOs and lead engineers
- Operations and IT leads
- Whoever holds compliance part-time
On the learning path, start at The minimum viable stack or Shadow AI discovery.
New to the field? Read AI governance explained: the definition, the frameworks and where engineering fits.
Three questions you bring.
Each one answered in brief here, and in full in the Body of Knowledge.
-
What is the least we must do?
Some controls do not scale down: every AI system in production registered with an owner and a tier, prohibited practices eliminated, every accepted risk with a named acceptor and an expiry, and every agent that acts with its own identity and a tested kill switch.
-
Does the EU AI Act ease anything for small companies?
In form, not in substance. SMEs and start-ups get priority access to regulatory sandboxes (Art. 62(1)(a)) and fines capped at the lower of the amount and the percentage (Art. 99(6)) 1. SMEs and small mid-caps may draw up the technical documentation in a simplified form, and the quality management system is proportionate to their size (Arts. 11(1), 17) 2.
-
We only use third-party AI. What is ours to do?
As a deployer you own the use: the decision to deploy, the monitoring, disclosing deep fakes you publish (Art. 50(4)) and, for a high-risk system, oversight by people with the competence, training and authority to act (Art. 26(2)) 1. The contract is where you get the evidence you need from the supplier.
Your route through the site.
In reading order: chapters at the section that matters, then the patterns, tools, templates, datasets and figures that turn them into work.
Week one
- The minimum viable stack Figure · The smallest set of controls one person can run.
- The minimum viable stack for a team of one Chapter 04 · A thin slice through all five layers, in the order that pays off first.
- A program without engineering capacity Chapter 12 · What to do when nobody can write the code yet.
- Acceptable use of AI by staff Chapter 12 · The first policy any company that uses AI needs.
- AI policy template Template · One source for the policy people approve and the rules a pipeline can run later.
- AI literacy curriculum Template · Role-based modules whose completions become training records.
- Shadow-AI Discovery Pattern · Find the AI already in use, including the free sign-ups.
Before you buy
- Build, buy or adapt Chapter 15 · Three routes, and the evidence burden each one carries.
- EU AI Act risk classification checker Tool · A first reading of role and risk class for one system, as a document you keep.
- Vendor / Model Due-Diligence Gate Pattern · Ask the supplier the right questions before the contract, not after.
- Vendor due-diligence request Tool · Build the due-diligence request for one supplier and export it.
- AI contract clause checklist Template · The terms to secure, each tied to the obligation it answers.
- Contract clauses Reference · Red flags and fallbacks in AI contracts and model licences.
Grow it
- Proportionate governance Chapter 13 · The tailoring matrix, by size, sector and appetite.
- Sandboxes and real-world testing Chapter 18 · Where a small provider can test with a regulator in the room.
- Maturity self-check Tool · Score the five layers and pick the one move that raises the floor.
- Obligations and deadlines planner Tool · Turn the dates that apply to you into a plan and a calendar file.
- The learning path Reference · Four stages from foundations to proof, if you are the one who will build it.
Start this week.
- List every AI tool the company uses, including the free ones staff signed up for. Shadow-AI Discovery
- Adopt a one-page acceptable-use policy and tell everyone where it is. Acceptable use of AI by staff
- Check each use against the Article 5 list and file the result. Art. 5 prohibited practices
- Find where Article 50 asks for a notice of AI interaction or a label on AI-generated content. Art. 50 transparency
- Run the maturity self-check and pick one move. Maturity self-check
The obligations that matter most.
The duties that reach a small company first, as a user and as a builder: literacy, prohibitions, transparency, the value chain, deployer duties, the documentation and QMS the Act scales to size, and real-world testing.
| Obligation | Applies | Evidence |
|---|---|---|
| EU AI Act Art. 4 AI literacy AIGE-OBL-EUAIA-ART4 | In force · | Literacy programme as code; role-based training records; onboarding gates |
| EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans) AIGE-OBL-EUAIA-ART5 | In force · | Policy-as-code blocklist; input/output guardrails; refusal and abuse detection |
| EU AI Act Art. 50 transparency for certain AI systems AIGE-OBL-EUAIA-ART50 | In force · | Content labelling and machine-readable marking (e.g. C2PA-style); chatbot disclosure banner |
| EU AI Act Art. 25 responsibilities along the AI value chain AIGE-OBL-EUAIA-ART25 | Deferred · | Value-chain due-diligence gate; provider/deployer responsibility allocation; AIBOM and model/data cards collected from upstream providers |
| EU AI Act Art. 26 deployer obligations for high-risk systems AIGE-OBL-EUAIA-ART26 | Deferred · | Deployment registry; monitoring hooks; assigned oversight and logging retention |
| EU AI Act Art. 11 technical documentation (Annex IV) AIGE-OBL-EUAIA-ART11 | Deferred · | AIBOM (CycloneDX ML-BOM, SPDX 3.0 AI); auto-generated technical documentation; model cards |
| EU AI Act Art. 17 quality management system AIGE-OBL-EUAIA-ART17 | Deferred · | QMS-as-code; versioned policies; pipeline controls and change management |
| EU AI Act Art. 60 testing in real-world conditions outside sandboxes AIGE-OBL-EUAIA-ART60 | In force · | Real-world testing plan; Art. 61 informed-consent records; test monitoring, logging and incident hooks |
Sources
- [1] Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026 (Arts. 26(2), 50(4), 62(1)(a) and 99(6)). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng (verified: primary)
- [2] Regulation (EU) 2026/1744 (Digital Omnibus on AI) (amended Arts. 11(1) and 17: simplified technical documentation and a proportionate QMS for SMEs and small mid-caps). Publications Office of the EU (EUR-Lex). 2026-07-24. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified: primary)
Other routes.
- For engineers ML, platform, MLOps, application and security engineers who build and run AI systems.
- For CISOs and risk leads CISOs, heads of risk, model risk managers, internal audit and third-party risk managers.
- For legal counsel and DPOs In-house counsel, data protection officers, privacy and compliance leads, and contract managers.
- For executives and boards Board members, executive committees, and chief AI, data and technology officers.
- For the public sector Public bodies and operators of public services: CIOs, service owners, procurement and oversight.
- AIGP candidates The public AIGP body of knowledge read against this site. Not affiliated with or endorsed by IAPP.
- Certifications Certifications and assessments in AI governance, and what each one evidences.
Start at the top of the route.
Step 01 is The minimum viable stack. Each step after it builds on the one before.