AI Governance for Teams Under 200 People
You don't need an AI ethics board. You need one page, three rules, and a quarterly review. A practical governance starter for organizations without a compliance department.

Garrett
Founder, Elementa
Most AI governance content is written for enterprises — model risk committees, audit trails, three lines of defense. If you're a 60-person company, that guidance isn't just impractical, it's counterproductive. You'll either ignore governance entirely or freeze adoption under process you can't staff.
Here's the version that fits organizations under 200 people.
One Page, Plain Language
Your AI policy should fit on a single page and be readable by everyone who works for you. It needs to answer three questions: What data must never go into external AI tools? Which decisions always require a human? Who do I ask when I'm not sure?
That last one matters most. Governance fails not when rules are imperfect but when people hide their usage. A named, non-judgmental point of contact turns shadow AI into visible AI.
Three Rules That Cover Most Risk
Rule one: customer and employee personal data stays out of tools that haven't been approved — and the approved list is published where everyone can see it.
Rule two: AI drafts, humans decide. Any output that affects a person — hiring, pricing, support resolutions, performance feedback — gets human review before it ships.
Rule three: disclose when it matters. If a customer would feel deceived learning that AI produced what they received, tell them up front or don't send it.
Review Quarterly, Not Annually
The tool landscape changes too fast for annual policy review. Put a recurring 45-minute meeting on the calendar each quarter: what tools have people started using, what's worked, what near-misses happened, what should change on the page.
That's it. No committee, no framework license, no consultant retainer. Governance at this scale is a habit, not a department — and the teams that build the habit early are the ones that never need the department.
Keep Reading
Why Most AI Pilots Fail Before They Start
The failure point of most AI initiatives isn't the technology — it's the framing. Here's how to scope a pilot that actually survives contact with your organization.
Read article →Responsible AIThe Case for Responsible AI Isn't Ethical. It's Operational.
Responsible AI is usually framed as a values conversation. But the strongest argument for it is much more practical: irresponsible AI breaks, embarrasses, and costs.
Read article →AutomationFive Workflows You Should Automate Before Building Anything Custom
Custom AI systems are powerful — and premature for most teams. These five workflow automations deliver value in weeks and teach you what to build next.
Read article →