Engagement type

Setting up an AI governance framework that is proportionate

Justas Butkus is a fractional AI officer based in Vilnius, Lithuania, working with mid-market companies and scale-ups across the UK, EU and US. Every engagement begins with a fixed-scope diagnostic, runs on written milestones rather than hours, and leaves accounts and documentation in the client's hands throughout.

Short answer

AI governance for a mid-market company needs four things: an inventory, a named owner per system, a defined response when a system is wrong, and a record that lets you reconstruct a decision later. Everything beyond that is either enterprise overhead or theatre until your risk profile earns it.

What does proportionate AI governance actually require?

Governance fails in two directions. Too little and you cannot answer a customer, auditor or regulator. Too much and nothing ships, which is its own kind of failure because the business keeps using unapproved tools anyway.

  • An inventory. What AI is in use, who introduced it, what data goes through it. Almost every company underestimates this list.
  • A named owner per system. Not a committee. A person who accepts that this system is running.
  • A defined wrong-answer path. What happens when it is wrong, who is told, how it is corrected, and whether it can be rolled back.
  • A reconstructable record. Enough logging that you can explain, months later, why a specific output happened on a specific day.

What can a mid-market company safely leave out?

Enterprise AI governance templates are built for organisations with a risk function. Copying one wholesale is how governance becomes paralysis.

  • A standing AI ethics board, until there is enough decision volume to convene one meaningfully.
  • Formal model risk management documentation, unless you are in a sector that already requires it.
  • Certification against a standard, unless a customer is actually asking for it.

The test is whether a specific person is asking for it – a regulator, an insurer, a customer, an auditor. If nobody is, it is overhead you are volunteering for.

Where does the EU AI Act fit?

The Act does not require a governance framework as such, and it does not require appointing an AI officer. What it creates is accountability that has to sit somewhere, plus specific obligations depending on what your systems do.

In practice the framework earns its keep long before a regulator appears: it is what lets you answer a procurement questionnaire or an insurer's renewal form without a three-week scramble.

Frequently asked questions

What should an AI governance framework include?

For a mid-market company: an inventory of AI in use, a named owner for each system, a defined path for when a system produces a wrong answer, and enough logging to reconstruct a decision later. Beyond that, add only what a specific party is actually asking for.

Does the EU AI Act require an AI governance framework?

Not as such, and it does not require appointing an AI officer. It creates obligations that need to sit with someone, which is why most organisations build a light framework and name a responsible person.

How much governance is too much?

When it stops things shipping while staff continue using unapproved tools anyway. That combination is worse than either extreme, because the risk stays and the visibility disappears.

If this is the piece you need

It is a bounded piece of work with a defined deliverable, which makes it quick to scope.