AI governance for mid-market businesses (without an in-house lawyer)
75% of executives admit their AI strategy is theatre. Most of the gap is governance. Here's the lightweight four-pillar framework that fits a 200-person business without pretending to be enterprise.
75% of executives admit their AI strategy is "more for show" than actual guidance. Most of the gap is governance, the unsexy work of deciding who can use what AI for which decisions, and what happens when it goes wrong. Get governance right and your AI program is 2.2 times more likely to show ROI. Skip it and you're either over-restricting (nothing ships) or under-restricting (incidents ship instead).
Mid-market businesses face a specific version of the problem. Enterprise AI governance frameworks (NIST AI RMF, ISO 42001, the EU AI Act) are written assuming a Chief Risk Officer, a privacy team, an internal legal function, and a quarterly board risk committee. A 200-person Australian business has none of those things. Trying to operate enterprise governance at mid-market scale produces paper that nobody reads. Trying to operate without governance produces incidents that nobody saw coming.
The right answer for mid-market is a lightweight model that scales the formality up only where it has to.
What governance is actually for
Three jobs. None of them is "writing a 40-page policy."
Job 1: prevent obviously bad things. Personally identifying client data going into a public LLM. Models making decisions that should require a human in the loop. Vendor agreements that grant rights to your data you didn't intend to grant.
Job 2: catch surprises early. Models drifting in production. Vendors changing their terms. New regulations affecting what was previously fine.
Job 3: be defensible when something goes wrong. Because something will. The question is whether the response looks competent or chaotic.
Anything in your AI governance approach that doesn't directly serve one of these three jobs is theatre. Cut it.
The four-pillar lightweight framework
For mid-market businesses without dedicated risk, privacy, and compliance staff, governance reduces to four pillars. Each one needs an owner, a process, and a review cadence. Nothing more.
Pillar 1: data. What data can be used to train, fine-tune, or prompt AI systems. What data is off-limits (customer PII, contractual restrictions, regulated categories). Where data lives, who has access, how long it's retained. The deliverable is a one-page data-use policy that staff can actually read, plus an enforcement mechanism (technical controls in the LLM gateway, plus a quarterly audit).
Pillar 2: model and vendor. Which AI tools and vendors are sanctioned. Which are explicitly banned. What review a new vendor goes through before approval. What review an existing vendor goes through when its terms change. The deliverable is an approved-vendor list, kept current, with a simple intake form for new requests.
Pillar 3: deployment and decision rights. What kinds of decisions can be made by AI alone, what kinds require human review, and what kinds are off-limits to AI entirely. This is where the abstract becomes concrete. "AI can summarise meeting transcripts" is fine. "AI can decide who gets a promotion" is not. "AI can recommend which leads to call" is yes. "AI can decide which insurance claims to deny" is regulated and needs more scaffolding. The deliverable is a deployment-decision matrix specific to your business.
Pillar 4: incident response. What happens when a model produces a bad output, a vendor has a breach, a regulator asks a question. Who's notified, who decides, what gets logged. The deliverable is a one-page runbook plus an annual tabletop exercise.
Together those four documents are about ten pages of policy. They take a working group of three or four people about six weeks to draft and another four weeks to circulate. That's the entire mid-market governance build.
Enterprise governance is a 40-page policy nobody reads. Mid-market governance is a 10-page policy everybody actually consults when they have a question. The shorter version is significantly more effective because it gets used.
Who owns it
The answer is not "a committee." Committees produce policies. They don't enforce them.
In a mid-market business, AI governance ownership lives best with one of three roles, depending on the company's shape:
- A fractional or full-time Head of AI if one exists. Best fit because they already own the portfolio and have skin in the game on outcomes.
- The COO or CTO if no Head of AI. Acceptable, with the risk that AI governance gets squeezed by everything else on their plate.
- The CFO, surprisingly, if the company is heavily compliance-driven. Works because the CFO already cares about audit posture and has a working relationship with external auditors.
What doesn't work: handing it to "IT" by default, or to "Legal" if Legal is one part-time external counsel. The owner needs to understand both the technology and the business.
The Australian regulatory context
In 2026, Australia has the Privacy Act amendments (taking effect in tranches through 2025-2026), the AI Voluntary Standard from the Department of Industry, and emerging guidance from APRA for regulated financial entities. None of these is as prescriptive as the EU AI Act, but the direction of travel is the same.
The practical implication for mid-market: the Privacy Act amendments expand controller obligations around automated decision-making and require explicit consent for inferences drawn from personal information. Most existing AI deployments in Australian mid-market businesses haven't been audited against these obligations. They will be, over the next 18 months, in the same way that the Notifiable Data Breaches scheme reshaped how Australian businesses handled security incidents from 2018 onwards.
Building lightweight governance now is materially cheaper than retrofitting it after a regulator asks a question.
The minimum viable governance program
For a mid-market business that wants to start moving on this in the next quarter:
- Week 1-2: Name the owner. Inventory current AI use across the business (you'll find more than you expected; see the article on shadow AI for why).
- Week 3-6: Draft the four lightweight policies. Start from the NIST AI RMF as a checklist, simplify ruthlessly.
- Week 7-8: Circulate, gather feedback, ratify.
- Week 9-12: Implement enforcement. LLM gateway with data-loss prevention. Approved-vendor list in the procurement system. Deployment matrix in the engineering wiki. Incident runbook in the on-call playbook.
- Quarterly: 90-minute review. What changed in the regulatory landscape? What new vendors got approved? What incidents happened, and what did we learn?
That's a real governance program. It costs about a quarter of one senior person's time per year to keep current after the initial build, and it materially reduces the probability that an AI program produces an avoidable incident or fails its first regulator audit.
Frequently asked
Got one of these problems in front of you?
Beyond Data runs engagements that put the ideas in this insight into practice.
More insights
Shadow AI: 45% of your AI adoption is invisible to IT
Half your business is using AI for real work, on personal accounts, outside policy. Banning it makes the shadow harder to see. Here's the operating model that channels demand and blocks the genuinely dangerous fraction at the technology layer.
Fractional Head of AI: what does it actually mean, and when do you need one?
A fractional Head of AI is a part-time, senior AI leader who owns the strategy, the roadmap, and the vendor choices, without a $300k-plus salary. Here's when it fits, and when a full-time hire is the right answer instead.