AI Governance for Small Businesses: Read This Before Rolling Out AI
Updated: Aug 25

Updated August 2026: I originally wrote this article after a client contacted me before expanding AI use across their business. Since then, both the technology and the conversation around AI governance have continued to develop quickly. I have also had more opportunities to work through AI adoption with small businesses and see the questions that come up once employees move beyond experimenting with AI and start incorporating it into actual business workflows. I decided this article needed a substantial update because AI governance for small businesses is no longer just about writing an acceptable use policy or deciding whether employees can use ChatGPT. It is becoming part of a much larger conversation about governance, business risk, data, cybersecurity, compliance, vendor management, employee access, and even cyber insurance.
The client who originally led me to write this article did something I wish more businesses would do. They had already started building AI workflows, testing use cases, and figuring out where AI could help their team, but before expanding that access across the company, they wanted to understand what needed to happen behind the scenes. They asked about data governance, whether employees should use personal or company managed AI accounts, what guardrails should exist, and how employees should be trained. Those questions changed the project from simply choosing an AI tool into a much broader discussion about how the business wanted AI to operate inside its environment.
I think that distinction has become even more important. I use AI extensively myself and have written about how I use AI to simplify parts of my business and everyday life. I see tremendous value in these tools, so my approach to AI governance is not about preventing businesses from using them. I want small businesses to get the benefits without allowing adoption to move so quickly that nobody knows which tools employees are using, what business information is going into them, which accounts own the work, what systems those tools can access, or who is responsible for deciding whether a new use case is appropriate.
Employees May Already Be Using AI
One of the first things I would tell a small business owner is not to assume that AI adoption begins when the company officially purchases an AI platform. Employees may already be using ChatGPT, Claude, Microsoft Copilot, Gemini, or another AI tool because it helps them write an email, summarize a document, research something, organize information, or work through a problem. In many cases, they are not trying to bypass company security or intentionally create risk. They found a useful tool and started using it before the business had established rules around it.
That is where Shadow AI starts to become important. Shadow AI generally refers to AI systems or applications being used without the organization's approval or oversight. From a business owner's perspective, the problem is not simply that an employee has an AI account. The bigger problem is that the company may not know which tools are being used, what information employees are putting into them, which account owns the conversations or work product, what data handling terms apply, whether AI applications have been connected to other business systems, or whether the business can remove access when an employee leaves.
I have seen this same underlying problem across different types of businesses, which is why I do not think AI governance belongs only to large corporations or heavily regulated industries. I recently wrote about AI governance for small law firms and what happens when employees are already using AI. Law firms have their own confidentiality and professional responsibility concerns, but the broader problem is not unique to attorneys. Construction companies, professional services firms, healthcare related businesses, nonprofits, and other small organizations can all reach the same point where AI use has grown faster than the structure around it.
“AI adoption is moving faster than AI governance.”
SNL Tech Services
That is why I do not think the answer to Shadow AI is simply telling employees to stop using AI. I would rather understand what they are already using, what they are using it for, what information is involved, and whether those tools and use cases are appropriate for the business. Once I know that, we can start making informed decisions about approved tools, company managed accounts, data handling, human review, integrations, access controls, employee training, documentation, and the other pieces of governance that need to surround the technology.
AI Governance Is Really a Business Risk Conversation
When small business owners hear the word governance, it can sound like something designed for a large corporation with a compliance department, attorneys, risk officers, and a stack of policies nobody outside those departments ever reads. That is not what I think practical AI governance needs to look like for a small business. A ten person company does not need to pretend it is a Fortune 500 organization, but it still needs to make decisions about who can use AI, what they can use it for, what information they can provide to it, and who is responsible for those decisions.
This is where I think GRC, which stands for Governance, Risk, and Compliance, provides a useful way to think about AI. Governance establishes who is responsible, what the business allows, which tools and use cases are approved, and how those decisions are communicated. Risk asks what could go wrong, what the impact would be, and what the business can reasonably do to reduce or manage that risk. Compliance asks what legal, regulatory, contractual, insurance, client, or industry obligations need to be considered. Not every small business will have the same answers because not every business handles the same information, operates under the same requirements, or intends to use AI for the same purposes.
The compliance part is also where I want to be careful about my role. I can identify technical risks, document the technology environment, evaluate how an AI platform is configured, implement access and security controls, and provide the technical information a business needs to make decisions. I am not replacing the client's attorney, compliance consultant, insurance broker, or another specialist responsible for determining the legal, regulatory, contractual, or insurance requirements that apply to that business. Good GRC actually makes those roles clearer because everyone can work from the same understanding of how the technology is being used.
How the NIST AI Risk Management Framework Fits
There is a formal framework behind a lot of this thinking. The National Institute of Standards and Technology, or NIST, created the Artificial Intelligence Risk Management Framework, commonly called the AI RMF, to help organizations manage risks associated with AI. As of August 2026, AI RMF 1.0 remains the current published framework, although NIST is actively revising it. NIST also maintains an AI RMF Playbook and a Generative Artificial Intelligence Profile that addresses risks specifically associated with generative AI.
It is important to understand what the NIST AI RMF is and what it is not. It is voluntary guidance, not a law or a compliance requirement that every small business must implement. NIST intentionally designed it so organizations of different sizes and industries can adapt the framework to their own circumstances. I like that approach for small businesses because I can use the concepts without handing a business owner an enormous enterprise checklist and pretending every item applies equally to their organization.
NIST organizes AI risk management around four functions: Govern, Map, Measure, and Manage. Govern establishes the culture, policies, accountability, responsibilities, and processes surrounding AI risk. Map establishes context by understanding what the AI is being used for, who is involved, what information and systems are affected, and what risks may exist. Measure involves assessing and tracking those risks. Manage is where the organization prioritizes the risks it has identified and decides what to do about them.
For a small business, I translate that into much more practical questions. What AI are we using? Why are we using it? Who is using it? What business information is involved? What can the AI connect to? What could go wrong? How serious would that be? What controls do we already have? What else should we implement? Is the remaining risk something the business is willing to accept?
That is GRC in a form a small business can actually use.
NIST also makes an important point that I think applies directly to small businesses: these functions are not meant to be treated as a one time checklist. AI risk management needs to continue as systems, use cases, risks, and business expectations change. That matters with AI because the platforms themselves can change quickly. New capabilities appear, integrations are added, business plans change, employees find new use cases, and a tool that originally had access to very little information may eventually become connected to email, files, CRM data, or other parts of the business.
Start With an AI Inventory, Not Just an AI Policy
One of the biggest changes I would make to the way I originally presented AI governance is that I would not start by blindly downloading an AI policy template. Before I can write useful rules for a business, I need to understand what I am trying to govern. That means establishing some form of AI inventory.
An AI inventory for a small business does not have to be complicated. I want to know which AI platforms are being used, who is using them, whether the accounts are personal or company managed, what plan or subscription the business is using, what the tool is being used for, what categories of information may be involved, and whether the AI platform has access to other business systems. That gives me a much better picture than a policy that simply says employees should “use AI responsibly.”
The specific product and plan matter. I do not make blanket statements about how all AI platforms handle business data because they do not all operate under the same terms, settings, security controls, retention practices, or training policies. Those details can even differ between consumer and business versions of the same platform. For example, OpenAI currently states that data from ChatGPT Business, Enterprise, Edu, its healthcare and teacher offerings, and the API platform is not used to train its models by default. That is different from making a general statement about every ChatGPT account or every AI provider.
This is why I wrote Can You Trust AI With Your Business Data? It's the Wrong Question. Asking whether an AI company is “safe” is not enough. I need to know which product, which plan, which account, what information is involved, how the product is configured, what it connects to, what the provider's current terms say, and what the business intends to do with it.
Evaluate the AI Use Case, Not Just the AI Product
Approving an AI platform does not mean every possible use of that platform should automatically be approved. This is one of the most important distinctions I want small business owners to understand. A marketing employee using an approved AI tool to brainstorm ideas for a generic social media post presents a very different business risk from an employee uploading confidential client documents, using AI to analyze financial information, connecting an AI application to the company's entire SharePoint environment, or relying on an AI generated answer to make a consequential business decision.
That is why I prefer to evaluate use cases, not simply maintain a list of “good AI” and “bad AI.” The same platform may be appropriate for one workflow and inappropriate for another. The business also needs to decide what level of human review is required. Generative AI can produce inaccurate or fabricated information, often referred to as hallucinations or, in NIST terminology, confabulation. Data security can be perfectly configured and an AI generated answer can still be wrong.
For a small business, an AI risk review might look something like this:
AI use case | What I would consider | Possible business decision |
Drafting general marketing content | Accuracy, brand voice, human review | Allow with employee review |
Summarizing confidential client documents | Data sensitivity, provider, plan, terms, access and retention | Require an approved business platform and additional review |
Connecting AI to SharePoint | Existing permissions, scope of access and oversharing | Review Microsoft 365 permissions before enabling |
Using a personal AI account for company work | Ownership, organizational control, offboarding and business data | I generally recommend a company managed account |
Using AI for a consequential business decision | Accuracy, bias, accountability, legal or contractual concerns | Require higher level review before approval |
Those are examples, not universal risk classifications. The appropriate decision depends on the business and the specific use case. What matters is that somebody has actually thought through the decision instead of assuming that purchasing an AI subscription settles the question.
Your Existing Permissions Matter More Once AI Can Reach Your Business Data
AI governance also cannot be separated from the rest of the technology environment. If I connect an AI tool to SharePoint, OneDrive, email, a CRM, file storage, or another business system, I need to understand what the user and the integration can already access. AI does not fix poor permissions. In some situations, it can make existing permission problems much easier to discover because employees can ask questions across information they technically had access to but might never have known how to find manually.
This is one reason AI projects can lead me back into the Microsoft environment. If a business is preparing to connect AI capabilities to Microsoft 365, I may need to understand its identities, SharePoint permissions, OneDrive sharing, third party applications, device management, Conditional Access, and other parts of the tenant before I am comfortable treating the AI rollout as an isolated project. That is the same reason my Microsoft 365 Tenant Security Review looks beyond licensing and asks how the tenant is actually configured.
The same principle applies outside Microsoft. Every integration deserves its own questions. What information can it read? Can it create or modify information? Does access follow the employee's existing permissions? What happens when that employee leaves? Who approved the integration? Can the business revoke it? Those questions become increasingly important as AI moves from a separate browser window into applications that can interact directly with business systems.
Build the AI Policy From What You Learned
Once the business understands its AI inventory, use cases, data, risks, and existing technology environment, the AI policy becomes much more useful because it can reflect how the company actually operates. For most small businesses, I do not think the goal should be a massive policy employees will never read. I want employees to be able to answer the questions they are actually going to encounter while working.
A practical AI policy should help employees understand things such as:
Which AI tools are approved for business use?
Which account should I use?
What types of business information can I provide to an approved AI tool?
What information is prohibited or requires additional approval?
Can I use AI for client work?
Which AI generated work requires human review?
Can I connect an AI application to Microsoft 365, Google Workspace, a CRM, or another company system?
What should I do if I want to use a new AI tool or feature?
What should I do if I accidentally provide information to an unapproved AI platform?
What happens to my AI access if I change roles or leave the company?
That is also why I generally recommend company managed AI accounts for business use rather than employees conducting company work through personal accounts. This is my professional recommendation, not a universal legal requirement. A managed business workspace can give the company a better foundation for account ownership, access management, administrative settings, offboarding, and business data governance, but the exact capabilities depend on the AI provider and plan.
I have worked through that distinction in real implementations as well. In How I Set Up Claude Teams for a Small Business Safely, I explain why giving employees access to an AI platform was only one part of the project. The business also needed to think about ownership, accounts, employee use, data, and the controls surrounding the platform.
Human Review Has to Be Part of AI Governance
Data leakage gets a lot of attention in conversations about AI, but it is not the only risk. A business can choose an appropriate enterprise AI platform, configure the accounts correctly, restrict access, and still create problems if employees blindly trust the output.
Generative AI systems can produce information that sounds confident and plausible while being incomplete, misleading, or simply wrong. NIST's Generative AI Profile specifically identifies confabulation as one of the risks associated with generative AI. This is why the level of human review should reflect what the AI output is going to be used for. A brainstorming suggestion for an internal meeting does not carry the same potential impact as an AI generated contract provision, financial analysis, client recommendation, hiring decision, technical configuration, or communication that will be sent externally under the company's name.
I want employees to understand that using AI does not transfer accountability to the AI provider. If the business sends the email, submits the proposal, publishes the article, changes the configuration, or makes the decision, somebody still needs to be responsible for reviewing the work at the level appropriate for that use case. Good AI governance should help employees understand when AI is assisting them and when a human needs to slow down and verify the result.
Where Cyber Insurance Fits Into AI Risk Management
Cyber insurance belongs in this conversation, but I want to be more precise about it than I was when I originally wrote this article. The insurance market is still developing its approach to AI. Some insurers and policy forms are beginning to address AI through definitions, exclusions, endorsements, sublimits, or affirmative coverage, while a significant amount of AI exposure remains under policies that do not explicitly address AI.
That means I would not tell a small business owner that failing to have an AI policy automatically means a cyber insurance claim will be denied. I also would not assume an AI related incident is covered simply because the business has cyber insurance. Coverage depends on the actual policy, carrier, endorsements, exclusions, circumstances of the loss, and potentially other types of insurance the business carries.
From a GRC perspective, insurance is one way a business may transfer part of a financial risk, but transferring risk does not eliminate the need to understand it. If AI is becoming part of the company's workflows, I recommend having a specific conversation with the insurance broker rather than waiting until renewal paperwork or a claim forces the issue.
Questions I would ask the broker include:
Does our current cyber policy specifically address AI related incidents?
Are there AI specific exclusions, endorsements, sublimits, or definitions?
How would the policy respond if confidential information were exposed through an AI platform?
Does coverage change if employees use unapproved or personal AI accounts?
Are AI generated content or professional errors handled under our cyber policy, professional liability coverage, another policy, or not at all?
Does the carrier currently ask about AI governance, approved tools, employee training, or AI security controls during underwriting?
Is there documentation the carrier recommends we maintain regarding our AI use?
The answer may be different from one carrier or policy to another, which is exactly why I want the business owner asking the broker rather than relying on a generic statement online.
Governance Does Not End When the AI Accounts Are Created
AI governance is not something I consider complete after the policy is signed and employees receive their accounts. The environment needs to be revisited because the technology and the business will change. Employees leave. New employees join. Vendors release new features. AI platforms add integrations. A department finds a new use case. The company begins handling a different category of information. A client adds contractual requirements. An insurance carrier changes its questions. The provider changes a setting, plan, or term that affects how the business wants to use the platform.
This is where the Measure and Manage portions of the NIST AI RMF become particularly useful. The business needs some way to determine whether the controls it established still make sense and what to do when the risk changes. That does not necessarily mean a small business needs an expensive GRC platform. It may mean maintaining an AI inventory, periodically reviewing accounts and approved tools, documenting important decisions, revisiting higher risk use cases, updating employee guidance, and making sure access is removed when employees leave.
Documentation matters here too. If I approve a platform for a particular use case because of the business plan, security controls, data handling terms, and configuration available today, I want enough documentation to understand why that decision was made when we review it later. If the product changes, I can compare the new environment with the assumptions behind the original decision instead of starting from memory.
What AI Governance Looks Like for a Small Business
When I work through AI governance with a small business, I am not trying to build an enterprise bureaucracy around every prompt an employee types. I am trying to give the business enough structure to use AI intentionally. That usually means understanding the current AI environment, identifying the business use cases, evaluating the data and systems involved, determining which platforms and account types are appropriate, establishing access and employee guidance, documenting important decisions, and creating a process for reviewing new tools and uses as they appear.
That process also helps me identify when somebody else needs to be involved. A regulated use case may need input from a compliance professional. Contractual questions may need an attorney. Insurance coverage belongs with the broker or carrier. Employment related AI may create questions outside my role. My responsibility is to understand and manage the technical side, document what I find and implement, and make sure the business has accurate technical information when those other professionals need to make decisions.
For the client who originally led me to write this article, I provided an AI Governance Guide, a Cyber Insurance AI Checklist, and guidance around prompts and employee use, and we worked through their workflows together before they expanded AI across the team. Looking back at that project through a GRC lens makes the process even clearer. The important part was not simply selecting an AI tool. It was establishing ownership, understanding the use cases and risks, deciding what controls made sense, documenting those decisions, and giving the business a structure it could continue to manage as its AI use grew.
AI Governance Questions Small Business Owners Are Asking
Does a small business really need an AI policy?
I recommend establishing one once employees are using AI for business activity, but the policy should reflect how the business actually uses AI rather than being a generic document downloaded from the internet. Employees should understand which tools are approved, which accounts to use, what information can be used, what requires additional approval or human review, and how a new AI tool or use case gets approved.
Should employees use personal ChatGPT, Claude, Gemini, or other AI accounts for company work?
I generally recommend company managed accounts for business use because they give the organization a better foundation for account ownership, administrative control, access management, and offboarding. The specific security, privacy, retention, training, and administrative capabilities vary by provider, product, and plan, so those details should be verified before the business selects a platform.
Can employees put confidential information into an AI tool?
There is no responsible universal yes or no answer for every AI platform and every type of confidential information. The decision depends on the specific provider, product, plan, configuration, contractual terms, data involved, use case, integrations, and any legal or regulatory requirements that apply to the business. The company should define those rules rather than leaving each employee to decide for themselves.
What is Shadow AI?
Shadow AI is the use of AI tools or applications without appropriate organizational approval or oversight. For a small business, that can mean employees using personal AI accounts, adopting unapproved applications, or connecting AI tools to business systems without the company understanding what information or permissions are involved.
What does GRC mean for AI?
GRC stands for Governance, Risk, and Compliance. For a small business using AI, governance establishes who makes decisions and what the rules are, risk management identifies what could go wrong and how the business will respond, and compliance considers the legal, regulatory, contractual, insurance, client, or industry obligations relevant to the use case. A small business can use those principles without building a large corporate GRC department.
Is the NIST AI Risk Management Framework required for small businesses?
No. The NIST AI RMF is voluntary guidance. It gives organizations a structured way to think about AI risk through Govern, Map, Measure, and Manage, and it is designed to be adaptable to organizations of different sizes and industries. I use the framework as a useful reference for thinking about AI risk, not as a claim that every small business is required to implement NIST AI RMF.
Can AI affect cyber insurance?
Potentially, but the answer depends on the policy. AI related losses may interact with cyber insurance, professional liability, general liability, or other coverage depending on what happened and how the policy is written. Some insurance products are beginning to address AI explicitly while other policies remain silent. I recommend asking the broker about the company's actual AI use and reviewing the current policy language rather than assuming AI related losses are automatically covered or excluded.
AI Governance Should Help You Use AI, Not Stop You From Using It
I think small businesses are going to continue finding valuable ways to use AI, and I do not see governance as something that should stand in the way of that. Good governance should make it easier for the business to say yes to the right use cases because the owner understands what is being used, what information is involved, what controls are in place, and where the remaining risk sits.
The part I want business owners to avoid is allowing AI to become another piece of technology that grows quietly inside the company until nobody can explain how it is being used. That is how Shadow AI develops, how personal accounts become business dependencies, how integrations get connected without enough review, and how sensitive information can end up moving through systems the business never formally evaluated.
GRC gives us a practical way to prevent that without turning a small company into a compliance department. Establish ownership. Understand the technology and the use case. Identify the risks. Determine which requirements apply. Implement reasonable controls. Document important decisions. Review them as the environment changes.
That is how I want to approach AI with the small businesses I support. The goal is not to make AI complicated. The goal is to make sure the business stays in control of how it is being used.
If your business is already using AI or preparing to expand it across your team, SNL Tech Services can help you understand the technical environment, evaluate AI tools and business use cases, put appropriate controls around access and data, and document the technical side of your AI governance process.
ADDITIONAL RESOURCES
National Institute of Standards and Technology: Artificial Intelligence Risk Management Framework (AI RMF)
NIST's current AI risk management framework and information about the revision now underway. The AI RMF is voluntary and designed for organizations across industries and sizes.NIST Artificial Intelligence Risk Management Framework
National Institute of Standards and Technology: NIST AI RMF Playbook
The current companion resource for applying the Govern, Map, Measure, and Manage functions of AI RMF 1.0. NIST emphasizes that the Playbook is voluntary and is not intended to be a universal checklist.NIST AI RMF Playbook
National Institute of Standards and Technology: Generative Artificial Intelligence Profile
NIST's companion resource for applying AI risk management concepts specifically to generative AI, including risks involving confabulation, data privacy, information security, human AI interaction, intellectual property, and other areas.NIST Generative Artificial Intelligence Profile
National Institute of Standards and Technology: Cybersecurity Framework 2.0 Small Business Quick Start Guide
NIST guidance specifically designed to help small and medium sized businesses begin managing cybersecurity risk using CSF 2.0.NIST CSF 2.0 Small Business Quick Start Guide
National Institute of Standards and Technology: Cybersecurity, Enterprise Risk Management, and Workforce Management Quick Start Guide
Published in March 2026, this NIST resource connects cybersecurity risk management with broader enterprise risk management and workforce decisions.NIST CSF 2.0 Cybersecurity, Enterprise Risk Management, and Workforce Management Guide
OpenAI: Business Data Privacy, Security, and Compliance
Current information about how OpenAI handles organizational data across its business products, including its current statement that business data from listed business offerings and the API is not used to train models by default.OpenAI Business Data Privacy, Security, and Compliance





Comments