Enterprise AI governance frameworks assume a compliance function, a legal team and a risk committee. Most companies deploying AI have none of these, conclude governance is not for them, and end up with no answer when a customer's security review arrives.
The practical version is much smaller than the frameworks suggest. It is roughly eight questions, answered in writing, kept current.
The eight questions
1. What AI systems are we using, and for what? A list. Every tool, what it does, which part of the business relies on it. Most companies cannot produce this, and cannot begin anything else without it.
2. What data goes into them? Per system: what categories of data, whose, and how sensitive. Specifically: does customer data leave our environment, and to whom.
3. What is the vendor's data commitment? Is your data used for training? Retained how long? Accessible to whom? This should be in the contract, not in a blog post, and you should have read it.
4. Where can the system act without a human? The autonomy boundary, written down. Which actions are automatic, which require approval, and who approves.
5. What do we record? For any consequential AI-assisted decision: what was recorded, where, retained how long. If you cannot reconstruct how a decision was made six months later, you have a problem that surfaces at the worst moment.
6. How do people know they are interacting with AI? Your disclosure position for customer-facing systems. There is no universal right answer; there is a wrong answer, which is not having thought about it.
7. What happens when it is wrong? The correction path. Who is told, how it is fixed, how the customer is made whole, and how the failure feeds back into the system.
8. Who owns this? A named person. Not a committee. Governance without an owner is a document.
What this is for
Three concrete purposes, none of them ceremonial.
Customer security reviews. Increasingly standard in any B2B sale of size. A company that can answer these eight questions in an afternoon closes deals that a company that cannot will lose or delay by months.
Insurance and contracts. Cyber and professional liability policies increasingly ask about AI use. Contracts increasingly include AI provisions. Both require knowing what you actually do.
Your own decision-making. The most valuable purpose. Companies that write these answers down routinely discover something they would not have chosen — a tool with an unacceptable data policy, an autonomous action nobody approved, a decision nobody can reconstruct.
The regulatory horizon
AI regulation is arriving unevenly by jurisdiction and sector, and specifics will vary. But every framework proposed anywhere so far asks for a recognizable subset of these eight things: an inventory, a data map, a human oversight statement, and records.
A company with honest answers to these questions will find compliance with most future requirements a documentation exercise. A company without them will find it a project.
How to do it in a day
Get the people who actually use these tools in a room — not the executives, the users, who know about the tools nobody registered. Build the inventory first; it is the hardest part and everything depends on it. Answer the remaining questions per system. Assign the owner. Set a quarterly review.
It fits in a document of a few pages. The value is not in the document's sophistication. It is in the fact that the answers exist and are true.