You Do Not Need an AI Ethics Board. You Need Four Answers.

Every AI governance framework published this year was written for a company ten times your size. They prescribe an AI Ethics Board, a Risk Officer, and a Model Owner. At sixty people that is not governance, it is theater. Here is the version that fits, and the honest answer on which regulations reach you.

Shielded dome of AI workers
Listen to this article
0:00
0:00
Listen on: Spotify Apple Podcasts YouTube
?Question

What is an AI governance framework, and what does one need to cover?

Quick answer

An AI governance framework is the set of written answers your organization gives to four questions: which AI tools may be used, what data may go into them, who releases AI-assisted work, and what gets checked afterward.

bosio.digital
The Founders’ AItrained on 25 years of our work

Want this made concrete for your company? Ask me, or pick one:

Formal standards exist for this. ISO/IEC 42001:2023 defines a certifiable AI management system, the NIST AI Risk Management Framework offers a voluntary structure built on four functions (Govern, Map, Measure, Manage), and the EU AI Act became generally applicable on 2 August 2026. Most published frameworks assume a compliance department. A company of fifty to five hundred people needs the same four answers written down, owned by a named person, and small enough that people actually follow them.

Every framework you can find was written for someone else

Search for an AI governance framework and you will find good material from Databricks, IBM, Snowflake, Microsoft and a dozen security vendors. Read four of them and you will notice they agree on the shape of the answer.

You need an AI Ethics Board. You need Risk Officers. You need Model Owners, a central AI system register, a risk taxonomy, and a cross-functional governance committee that meets on a cadence.

Now picture that in your company.

If you have sixty people, you do not have a board to spare. You have one person who already owns three other things and would now own this. The framework is not wrong. It was written for an organization with a compliance department, a legal team, and the headcount to absorb a committee. When you apply it at sixty people, you do not get governance. You get a document nobody reads and a process nobody runs.

So this piece does something different. It gives you the four answers underneath every one of those frameworks, sized for a company that does not have a Chief AI Ethics Officer and is not going to hire one.

4questions a governance framework actually answers, underneath the committee structure
2 August 2026the date the EU AI Act became generally applicable, five weeks ago (Regulation (EU) 2024/1689, Article 113)
225Swiss francs to read ISO/IEC 42001, the standard everyone cites (ISO)

The three problems governance actually solves

Before the framework, it is worth being precise about what is broken without one. Not the compliance story. The operational one.

Risk you cannot see

Your employees are already using AI. The only question is whether you know how, where, and with what data.

This is not recklessness. People are trying to hit deadlines with tools that are free, instant, and genuinely good. Without a stated boundary, every person makes a private judgment call about what is acceptable. Most of those calls are fine. Some are not. You have no way to tell which is which, because nothing was ever written down to compare them against.

The exposure compounds quietly. Nobody reports pasting a client contract into a chat window. It does not generate a ticket. It surfaces later, in a place you were not looking.

If you want the full version of that argument, I wrote a separate examination of the hidden liability of personal AI accounts in business. The short version: a conversation with a personal AI account is a data transfer you cannot monitor, audit, or retract.

Quality you cannot trust

AI produces confident output at speed. It also fabricates, and it fabricates in exactly the same tone it uses for things that are true. Model confidence tells you nothing about model accuracy.

So when someone uses AI to draft a client proposal or summarize a contract, the question is simple and usually unanswered: who checked it before it left the building?

Without governance the honest answer is “it depends who was working that day.” That inconsistency is the liability, more than any single error.

There is now case law on this. In Moffatt v. Air Canada (2024 BCCRT 149), British Columbia’s Civil Resolution Tribunal heard a claim from a passenger who had been told by Air Canada’s website chatbot that he could apply for a bereavement fare retroactively. He could not. He claimed the difference, $880. The tribunal held Air Canada responsible for the information its chatbot provided and found the airline had not taken reasonable care to ensure the chatbot was accurate.

The sum is small. The principle is not. A company is accountable for what its AI tells a customer, whether or not a human approved the specific sentence.

Opportunity you cannot capture

This is the one that gets left out, and it is the reason governance is worth your time rather than merely worth your compliance budget.

Missing governance does not only create risk. It creates hesitation.

When people do not know what is allowed, they slow down. They avoid the tool entirely, or they use it and quietly hope nobody asks. Teams duplicate effort second-guessing each other’s AI-assisted work because there is no shared standard to check against. Leadership cannot greenlight anything quickly because nobody can articulate the risk parameters.

The point

Good governance does not slow AI adoption down. It is the thing that lets people move without checking over their shoulder.

Clear boundaries are permission. That is the part the compliance framing misses entirely.

The AI Briefing

Tuesdays. 500+ leaders. No hype, just what works.

The four answers

Here is the framework. Four layers, in order. Each one is a written answer to a question you are already being asked informally, by someone, every week.

The four-layer AI governance framework
1
What may be usedWhich AI tools are sanctioned, which are prohibited, and what a person does when they want something that is on neither list. The answer to a new tool cannot be silence.
2
What may go inWhich categories of data may enter an AI tool, and which may never. Written as categories your team recognizes, not as abstractions.
3
Who releases whatWho may send AI-assisted work outward without review, and what requires a second person. Drawn by consequence and reversibility, never by seniority.
4
What gets checkedThe small number of things actually reviewed, by whom, and how often. If it is not on this list, you are not checking it, and you should stop claiming that you are.
↻  Every incident and every near miss revises the layer that failed

That is the whole framework. Not because governance is simple, but because these are the four decisions everything else derives from. A risk taxonomy, an approval workflow, a tool register: each is an implementation detail of one of these four.

If you can answer all four in writing, and your team can find the answers and follows them, you have AI governance. If you cannot, you have some combination of hidden risk, uneven quality, and unrealized capability, and you will not know which until something surfaces.

Layer one: what may be used

The instinct is to write a list of approved tools and ban everything else. That fails, reliably, and the reason it fails is worth understanding.

Prohibition-only approaches collapse when the prohibited thing is free, instant, and genuinely useful. Your employees face real pressure to produce. If the sanctioned path is slow, unclear, or does not exist, they will use whatever helps them succeed and simply not mention it. Telling people not to use tools without giving them an alternative is not governance. It is a wish.

So layer one has two halves, and most policies only write the first:

  1. The sanctioned list. What is approved, for whom, with what account. Company accounts, not personal ones, so that the data boundary is enforceable rather than aspirational.
  2. The route for everything else. What a person does when they find something new. Who they ask. How long the answer takes. If that route does not exist, or takes three weeks, your sanctioned list is decorative.

The second half is what makes the first half real.

Layer two: what may go in

This is the layer with the sharpest edges, and the one to write in your team’s own vocabulary.

Not “confidential information,” which everyone interprets differently. Name the actual categories. Client contracts. Candidate records. Anything under NDA. Pre-announcement financials. Personnel matters. Source code, if that applies to you. Layers one and two are what an AI acceptable use policy puts in front of your team, and there is a complete one-page version of that document there to copy.

Then state the boundary in a form somebody can apply at speed, because the moment of decision is a person with a document open and a deadline in four hours. A rule that requires interpretation will be interpreted generously.

One structural point that saves arguments later: the boundary depends on where the tool sends the data, not on how the tool feels. A company account inside your own tenant and a personal account on the same underlying model are different decisions, even though the interface looks identical.

Layer three: who releases what

Every framework written for enterprises answers this with roles. Model Owner, Risk Officer, Ethics Board.

At your size, answer it with consequences instead.

Sort AI-assisted work by what happens if it is wrong:

Tier What it means Who releases it
Low Wrong is cheap and reversible. An internal draft, a summary for yourself, a first pass nobody acts on directly. The person doing the work
Medium Wrong is visible internally and costs time to unwind. Analysis that informs a decision, internal reporting, a document colleagues rely on. The person, with a named reviewer
High Wrong reaches a client, a regulator, or a candidate, or it cannot be taken back. Client deliverables, external communications, hiring and compensation decisions, anything with a legal consequence. A named second person, always

Tiering by consequence rather than by technology is what keeps this usable. It does not matter which model produced the draft. It matters what breaks if the draft is wrong.

Notice what this replaces. You do not need an Ethics Board to run this. You need one person who owns the answer and a second pair of eyes on the high tier.

Layer four: what gets checked

Most governance documents fail here, silently. They describe monitoring that nobody performs.

Write down the small number of things you will actually review, and accept that the list is short. A quarterly look at which tools are in use and whether the sanctioned list still matches reality. A periodic sample of high-tier output against your own standard. A named place where people report a near miss without it becoming an incident report.

That last one does more work than the other two combined. Most of what you need to learn about how AI is used in your company will come from someone volunteering it, and people only volunteer when volunteering is safe.

If a check is on the list and has not happened in two quarters, take it off the list. A framework that describes activity you are not doing is worse than a shorter one that is true, because it tells you that you are covered when you are not.

Where this goes next

Not sure where you stand?

Take the 90-second AI readiness read: five dimensions, a scored result, and a clear next step.

Take the readiness read →

Who owns this when there is no committee

The enterprise answer is a cross-functional governance board. Here is the version that works at fifty to five hundred people.

One named owner. A person, not a function. Their name is on the document. They do not have to be technical, and in most companies they should not be the most technical person available, because this job is mostly judgment about the business. What they need is the standing to say no and the access to say yes quickly.

One reviewer per high-tier domain. Whoever already reviews client work reviews AI-assisted client work. You are extending an existing habit, not inventing a role.

One escalation path. Where a question goes when the owner is not sure. Usually a founder or an executive. Named, so nobody has to guess.

That is three answers, and only the first is a genuine assignment of new responsibility. It is also the reason so much governance stalls: the question of who owns AI adoption inside a company is almost never settled explicitly, so it lands on nobody.

Which of these standards actually binds you

Every framework on the internet cites the same three sources. Almost none of them tell you plainly which ones apply to you. Here is the honest version.

ISO/IEC 42001:2023

The first international standard for AI management systems, published in December 2023. It “specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within organizations,” and ISO states it is for “organizations of any size involved in developing, providing, or using AI-based products or services.”

It is voluntary. It is also certifiable, which is the reason it matters commercially: if you sell into enterprises or regulated industries, a customer may eventually ask whether you are certified, the way they now ask about SOC 2.

Two honest notes. Certification is a real project with a real auditor, not a document exercise. And the standard itself costs 225 Swiss francs to read, which is worth knowing before you cite it in a policy you have not opened.

NIST AI Risk Management Framework

Released 26 January 2023 by the US National Institute of Standards and Technology, and explicitly “intended for voluntary use.”

Its structure is four functions: Govern, Map, Measure, Manage. If you want a vocabulary for the four answers above that will be recognized by any US enterprise customer, this is the one to borrow. It binds nobody by itself, but it is frequently referenced in contracts and procurement questionnaires, which is where a voluntary framework quietly becomes a requirement.

The mapping to the four layers is close enough to be worth using out loud in a procurement conversation:

NIST function The layer it corresponds to
Govern The whole framework, and the named person who owns it. NIST puts this first deliberately: without an owner, the other three are activities rather than a system.
Map Layers one and two. Knowing which AI is actually in use and which data can reach it. You cannot manage a risk you have not located.
Measure Layer four. The short list of things you genuinely review, and the honesty about what is not on it.
Manage Layer three. Acting on what you found, which in practice means the release decision and who makes it.

The value of borrowing this vocabulary is not intellectual. When an enterprise buyer sends you a security questionnaire asking how you govern AI, answering in the terms their own framework uses shortens the conversation considerably. You are describing the same four decisions either way. One phrasing takes three emails and the other takes one.

The EU AI Act

This is the one with actual force, and the one most commonly described incorrectly.

Regulation (EU) 2024/1689 entered into force in 2024, but entering into force and applying are different things. Article 113 sets the schedule: “It shall apply from 2 August 2026.” Chapters I and II applied earlier, from 2 February 2025, and a further set of obligations from 2 August 2025. Article 6(1) and its corresponding obligations apply from 2 August 2027.

The general application date was five weeks ago. If your last read on the AI Act was a 2024 summary saying it phases in over the coming years, that read is now out of date.

The penalties are frequently misquoted as a blanket figure. The top tier is specific: non-compliance with the prohibited practices in Article 5 is subject to “administrative fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.” That ceiling attaches to the prohibitions, not to every obligation in the Act.

Now the question a US company actually has. Does it reach you?

Article 2 casts a wide net. It covers providers who put AI systems on the Union market, and it says this applies “irrespective of whether those providers are established or located within the Union or in a third country.” It covers deployers located in the Union. And then it reaches further, to providers and deployers sitting in a third country “where the output produced by the AI system is used in the Union.”

Read that last clause carefully, because it is the one that catches people. It is not about where your company is. It is about where the output lands.

The point

If you have EU clients, EU staff, or EU users of anything your AI helps produce, the Act is a question you have to answer. If you genuinely do not, it is a watch item and not a project.

That is the whole honest summary. Two voluntary frameworks worth borrowing vocabulary from, one regulation that binds you only if your output reaches Europe. Anyone telling a US mid-market company that all three are urgent compliance obligations is selling something.

Why policies without culture fail

Everything above is the written half. Here is the part that determines whether any of it matters, and it is the part most governance work skips.

Policies do not change behavior. Conditions do.

A policy that is harder to follow than to circumvent will be circumvented, and not by bad people. By competent people under deadline pressure who found a faster path. If your sanctioned tool requires a request form and a two-week wait while the unsanctioned one is a browser tab, you have not written a rule. You have written a preference, and you have told your team that the rule matters less than the deadline.

So the work is to make compliance the path of least resistance:

This is not a soft addendum to the framework. It is the mechanism by which the framework becomes real. Humans First is not a slogan here; it is the observation that governance is a human system, and human systems run on whether the correct action is also the easy one.

What this looks like at your size

The four answers do not change. The apparatus around them does.

Ten to fifty people. One page. Genuinely one page, covering all four layers. One named owner, usually a founder or an operations lead. The tiering conversation happens in a meeting, not a document. Review quarterly, which at this size means twenty minutes and a look at what people are actually using.

Fifty to five hundred. The four answers still fit on a few pages, but now they need a home that people can find, and the layers need per-department specifics. Marketing, finance and HR have genuinely different data boundaries. Named reviewers per domain. This is the size where the steps of AI adoption start requiring deliberate sequencing rather than momentum, and where the governance layer either supports that or quietly blocks it.

Five hundred and up. Now the enterprise frameworks start earning their complexity. A register, a formal risk taxonomy, and eventually a committee, because coordination cost has genuinely exceeded the cost of the structure. Borrow ISO/IEC 42001’s structure at this point rather than earlier.

The mistake is adopting the five-hundred-plus apparatus at sixty people because that is what the published frameworks describe. You get the overhead without the benefit, the document ages, and everyone learns that governance is paperwork.

Start Building

Draft Your Four Answers This Week

Paste this into your AI assistant. It interviews you about how your company actually works and returns a first-draft governance document covering all four layers, in your language rather than a template’s.

Prompt · paste into your AI

Context: I am drafting an AI governance framework for a [INDUSTRY] company with [NUMBER] people. We do not have a compliance department or a legal team. I want something a new hire could read in ten minutes and follow. Interview me one question at a time and push back when my answers are vague or when I describe a process we do not actually run.

Step 1. What may be used: Ask which AI tools are already in use here, including the ones people use without asking. Then ask what happens today when somebody wants a new tool, and how long that takes. If the answer is that there is no route, say so plainly rather than inventing one.

Step 2. What may go in: Interview me until you can list the specific categories of data in my business that must never enter an AI tool. Push me past “confidential” to actual named categories. Ask for one example of a borderline case and how I would decide it.

Step 3. Who releases what: Help me sort our AI-assisted work into three tiers by consequence: reversible, internally visible, and reaching a client or regulator. For each tier, ask who releases it. Do not accept a job title if no specific person holds it.

Step 4. What gets checked: Ask what I will genuinely review and how often. Challenge anything I am unlikely to sustain for two quarters. A short true list beats a long aspirational one.

Step 5. The honest gaps: List everything I could not answer, marked UNDECIDED. Do not fill these in for me.

Output: A one-page framework covering the four layers in plain language, a tiering table with named people, the short review list, and the UNDECIDED list kept separate at the end.

The UNDECIDED list is usually the most useful thing that comes out of this. Those are the questions your company has never actually settled, which means no policy could have covered them and no vendor could have supplied the answer. See where you stand →

Where to start on Monday

If you do nothing else, do this in order.

Write layer two first. What may go into an AI tool, in your own categories, on one page. It is the layer with the sharpest consequences and the one your team is guessing at right now.

Then layer three, because it costs nothing but a decision and it removes the ambiguity that makes people hesitate.

Then layer one, because building a real sanctioned route takes longer and is easier once you know what the data boundary is.

Layer four last, and keep it short enough that you will still be doing it in six months.

Nobody will thank you for this. It will not trend anywhere. But the version of your company that has these four answers written down moves faster than the version that does not, and it is not close. Clarity is what lets people stop hedging and start using the thing.

Sources

Frequently Asked Questions

What is an AI governance framework?

An AI governance framework is the written set of decisions an organization makes about AI use: which tools are sanctioned, what data may enter them, who is permitted to release AI-assisted work, and what gets reviewed afterward. Formal versions exist, including ISO/IEC 42001:2023 and the NIST AI Risk Management Framework. Most published frameworks assume a compliance department and a governance committee, which is why they translate poorly to companies under a few hundred people.

Do small and mid-sized companies really need AI governance?

Yes, and arguably more urgently than large enterprises, because the buffer is thinner. A large organization has legal and compliance teams to absorb a mistake. A company of sixty does not, so a single data exposure or a fabricated client deliverable lands proportionally harder. The four answers stay the same at any size. What scales is the apparatus around them, not the questions.

Does the EU AI Act apply to a US company?

It can, and the test is not where your company sits. Article 2 of Regulation (EU) 2024/1689 reaches providers who place AI systems on the Union market, deployers located in the Union, and, critically for US firms, providers and deployers in a third country “where the output produced by the AI system is used in the Union.”

That last clause is the one people miss. A California company with no EU office, no EU entity and no intention of opening one can still fall in scope if what its AI helps produce is used in Europe. So the practical question is not about your incorporation. It is about your clients, your staff, and where the work ends up. If none of that touches the EU today, treat the Act as a watch item rather than a project, and revisit it the moment your customer base changes.

When did the EU AI Act take effect?

Article 113 states the Regulation “shall apply from 2 August 2026.” Chapters I and II applied from 2 February 2025, and a further set of provisions from 2 August 2025. Article 6(1) and its corresponding obligations apply from 2 August 2027. Entry into force in 2024 is a separate and earlier event from application, which is the source of most confusion about the timeline.

Is ISO 42001 certification worth it for a mid-sized company?

It depends entirely on who buys from you. ISO/IEC 42001:2023 is voluntary but certifiable, so its commercial value is in procurement: enterprise and regulated customers may ask about it the way they now ask about SOC 2. If you do not sell into those buyers, the structure is still worth borrowing without pursuing certification. Certification is a genuine audit project, and the standard costs 225 Swiss francs simply to read.

Who should own AI governance if we do not have a compliance team?

One named person, not a function or a committee. They need the standing to say no and the access to say yes quickly, which matters more than technical depth. Add one reviewer for each high-consequence domain, usually whoever already reviews that kind of work, and one named escalation path for questions the owner cannot settle. That is three decisions, and only the first creates genuinely new responsibility.

Where this goes next

Turn scattered AI into a system your company runs on.

CompanyOS is the AI operating system your whole company runs on: governed accounts, real adoption, and visibility you own.

See CompanyOS → Not sure where to start? Take the 90-second readiness read →
Sascha Laura

Say hello.

A 30-minute conversation. If we're not the right fit for where you are, we'll tell you, and point you somewhere better.

Join 500+ leaders The AI Briefing · Tuesdays · no hype
bosio.digital · AI Transformation That Elevates Human Talent · © 2026 Bosio Inc. · SF · Lake Arrowhead