tuesday, october 6, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · running the business

AI governance for a team of three

Write the one page that says where AI touches your money, who actually checks its output, and what you do when a vendor retires the model underneath you.

Published 2026-09-05 · Updated 2026-09-05 · Read 9 min · Reviewed by Rami Steitieh

Verified 2026-09-05 · Rami
on this page · 0 / 0 checked

Nobody sat down and decided to put AI in your business. It arrived one tool at a time. A drafting assistant for awkward emails. A widget on the contact page that answers the same four questions. A saved prompt someone uses to reply to support tickets. An automation that summarises a call and sends the summary to the client before anyone reads it. None of that was a decision, and all of it is now load-bearing. If one piece produced something confidently wrong on a Tuesday morning, you would hear about it from a customer rather than from a dashboard.

Governance is a word that sounds like a committee and a document nobody opens. At your size it is one page, revisited four times a year. This guide is for a business of one to about ten people that already has AI touching customer-facing or money-touching work. It is not for a company with a compliance function, which needs more than a page, and it is not for anyone building a product that makes automated decisions about people at scale, which needs a lawyer.

You are a deployer, and two obligations already reach you

The EU’s AI Act entered into force on 1 August 2024 and became applicable on 2 August 2026, with some exceptions [1]. Most of its machinery is aimed at providers of high-risk systems, and that part lands later: high-risk systems in the sensitive areas of Annex III apply from 2 December 2027, and high-risk systems embedded in regulated products from 2 August 2028 [1]. You are almost certainly not a provider. You are a deployer, which is the plain case of using someone else’s system inside your own work.

Two obligations reach deployers early. The first is AI literacy, applicable since 2 February 2025 [1]. Article 4 requires providers and deployers to take measures supporting AI literacy among their staff and anyone operating the systems on their behalf, weighed against those people’s technical knowledge, experience, education and training, the context the system runs in, and the people it is used on [2]. It stops short of requiring you to guarantee any particular level for any individual [2]. In practice that is a low bar with a real edge: the person using the tool should know what it does and where it fails, and you should be able to point at something you did about that.

The second is transparency, in effect since August 2026 [1]. Article 50 requires that people be “informed that they are interacting with an AI system” unless that is obvious to a reasonably informed observer [3]. Deployers of deepfakes have to disclose that the content was artificially generated or manipulated, with a lighter form of that disclosure for work that is “evidently artistic, creative, satirical, fictional or analogous” [3]. And deployers who publish AI-generated text “with the purpose of informing the public on matters of public interest” must disclose it, unless the text went through “human review or editorial control” and a person “holds editorial responsibility” for it [3]. That last carve-out is the one most publishing operators land in, and it is worth noticing that the exemption is earned by doing the review, not by intending to.

Whether the Act reaches you at all depends on where you and your users sit, and the Commission’s page is where to check rather than a summary. The same page notes that the omnibus amendments extended the simplified requirements already granted to SMEs, including lighter technical documentation, to small mid-cap companies as well [1].

Your vendors already wrote half your policy

Now read the usage policy of whichever model your work sits on, which almost nobody does after the checkbox.

Anthropic’s Usage Policy, effective 15 September 2025, names a set of high-risk domains: legal, healthcare, insurance, finance, employment, housing, academic testing and journalism [5]. Inside those, “a qualified professional in that field must review the content or decision prior to dissemination or finalization” [5]. If model outputs are shown to individuals or consumers, you must disclose that you are using AI, “at a minimum at the beginning of each session”, and any consumer-facing chatbot must tell users they are interacting with AI rather than a human [5].

OpenAI’s usage policies, effective 29 October 2025, forbid the “automation of high-stakes decisions in sensitive areas without human review”, listing education, housing, employment, financial activities and credit, medical and legal among them [6]. They separately forbid the “provision of tailored advice that requires a license, such as legal or medical advice, without appropriate involvement by a licensed professional” [6].

Two competitors, writing independently, arrived at the same floor. That is the single most useful fact here, because it is not aspiration or best practice. It is a term you already accepted. If your intake form scores leads, if your bot answers questions about refunds or contracts, if a saved prompt produces something a reader would take as advice, you are inside those clauses today. The gap between what small teams have agreed to and what they have implemented is usually the whole distance.

The map is most of the governance

NIST’s AI Risk Management Framework was released on 26 January 2023, is intended for voluntary use, and organises the job into four functions: Govern, Map, Measure and Manage [4]. You can ignore the framework document and still steal the order. Map comes before Manage because nothing else works on a system you have not written down, and AI spreads by accretion rather than by procurement, so the writing down is the part that never happens by itself.

Do it in one sitting. Make a row for every place an AI output reaches a customer, moves money, feeds a decision about hiring or firing someone, produces a legal, medical or financial statement, or generates a number you will act on without recomputing it. Five columns per row: the use, the tool and the plan it runs on, what data goes in, who checks the output before it counts, and what you do if it stops working.

The rows people expect are the obvious ones, the chatbot and the report generator. The rows that matter are the small ones nobody flagged because they felt like typing: the saved prompt that drafts support replies in your name, the automation that summarises a client call and sends it onward, the spreadsheet formula somebody pasted from a chat window in March. Those are load-bearing and unowned, which is the exact combination that produces a bad week.

NIST also publishes a companion Playbook and a Generative AI Profile, released on 26 July 2024, if you want more structure than a table gives you [4]. At this size, you probably do not.

Oversight a rubber stamp cannot fake

Sort the map into two piles. Outputs where being wrong is cheap and reversible can run with a light touch. Outputs where being wrong costs money, a client relationship, or a person’s day need a human reading them before they count, every time.

The pile boundary is not where teams fail. They fail at the reviewer who approves because the model is usually right, which turns oversight into a signature and manufactures confidence that nothing is checking. A check is real when the reviewer can say what they would have caught. If the honest answer is “I read it and it looked fine”, that is a rubber stamp with extra steps. Give every reviewed use one specific thing to look for: the figure, the date, the claim about what the contract says, the sentence that promises a customer something.

Then price it, because oversight is hours and hours are the thing you have least of.

calculator
Oversight you have promised
— h / week

Checked outputs × minutes each. Computed in the page; nothing is sent anywhere.

If that number is bigger than the time anyone actually has, the promise is fiction and something has to move. The fix is usually fewer outputs going out unreviewed rather than a faster read, because a review compressed to 20 seconds is the rubber stamp again, now with a calculation behind it.

What leaves your walls, and what deleting does not delete

The question is never whether a tool is secure. It is what the policy on your specific plan says happens to what you paste, and the answers sit in support articles rather than anywhere you would think to look.

Google’s page for Gemini Apps Activity is a fair worked example. Activity auto-deletes after 18 months by default, and you can change that to 3 or 36 months or switch auto-delete off [7]. With Keep Activity turned off, chats are still retained for 72 hours so the service can respond to you and protect users [7]. A subset of chats are reviewed by human reviewers, including Google’s trained service providers, and those reviewed chats are retained for up to three years and “are not deleted when you delete your activity” [7]. Google’s own instruction on the same page is direct: “Please don’t enter confidential information that you wouldn’t want a reviewer to see or Google to use to improve our services” [7].

None of that is scandalous. It is simply not what most people assume, which is that turning a setting off and deleting a thread removes it. Read the equivalent page for whichever assistant you use, on the plan you are actually on, because consumer and business plans differ and the defaults move.

The governance action is small. Write the plan name in the map, not just the tool name, and re-open that page once a quarter. Two categories stay out regardless of any policy: credentials of any kind, and anything you would not want read back to you in a dispute, because a record exists on the vendor’s side whatever the training setting says.

The tool retires on a published schedule

Continuity is usually filed under things that might happen. For AI it is a calendar with dates on it.

Anthropic notifies customers with active deployments of upcoming retirements and gives at least 60 days’ notice before retiring a publicly released model, sorting models into Active, Legacy, Deprecated and Retired [8]. That is a promise you can plan against and also a warning about what planning against it means. Claude Opus 4.1 was deprecated on 5 June 2026 and retired on 5 August 2026; Claude Opus 4 and Claude Sonnet 4 were both deprecated on 14 April 2026 and retired on 15 June 2026 [8]. Anything that named one of those models in a configuration file stopped working on the retirement date, notice or no notice.

So the last column of each row is the one people skip and need most. Name the person who can switch this use off, the steps they take, and the fallback that keeps the work moving while it is off. Then run it once, in calm conditions, the way you would test a smoke alarm. A switch nobody has ever pulled is a theory, and the morning your support bot starts inventing refund policies is a poor time to test a theory.

checklist
The quarterly hour
0 of 8 · saved in this browser only

What still goes wrong

Dates and terms move. Every figure and quotation above was read from the source on 4 September 2026, and vendor policies in particular have changed more than once a year. Treat the specifics as a snapshot to re-check rather than a standing fact, which is the reason the quarterly hour exists at all.

The page can also become the work. A tidy record with a review date and no consequence attached is compliance theatre at a very small scale, and it is worse than nothing because it feels like protection. The test is whether any row has ever changed behaviour: an output that now gets read, a plan that got downgraded, an automation that got deleted. If the page has never cost you anything, it is decoration.

The deeper limit is structural, and no page fixes it. In a team of three the reviewer and the doer are frequently the same person, so oversight is self-oversight, and self-oversight catches typos far better than it catches a fluent, plausible, wrong answer that agrees with what you already believed. Governance does not make the model right. It only ensures somebody was supposed to be looking, and narrows the set of places where nobody was. That is a smaller claim than the word suggests, and it is still worth the hour.

sources
  1. 01European Commission — AI Act regulatory framework and application timelinedigital-strategy.ec.europa.eu
  2. 02EU AI Act, Article 4 — AI literacy (Regulation (EU) 2024/1689 text)artificialintelligenceact.eu
  3. 03EU AI Act, Article 50 — Transparency obligations (Regulation (EU) 2024/1689 text)artificialintelligenceact.eu
  4. 04NIST — AI Risk Management Frameworknist.gov
  5. 05Anthropic — Usage Policyanthropic.com
  6. 06OpenAI — Usage policiesopenai.com
  7. 07Google — Gemini Apps Activitysupport.google.com
  8. 08Anthropic — Model deprecationsplatform.claude.com
next guide
Putting an AI to work in your team chat
10 min · verified 2026-09-05
related guides