
Blog Post
AI Governance When You Have No Authority to Compel
September 6, 2026
Guidance for small organizations tends to offer a compressed version of the enterprise program. A one-page acceptable use policy instead of a twenty-page one, a spreadsheet instead of a platform, three vendor questions instead of a questionnaire. All of it sensible and all of it addressing the wrong constraint.
Somebody holding AI governance alongside another job can write a policy in an afternoon. What they cannot do is refuse a deployment the chief technology officer wants, require engineering to change a pipeline, or get a business unit to answer anything. The limit is authority rather than time, and a program designed for the second constraint fails on the first.
What Can a Program Do Without the Power to Compel?
Four things, and none requires anyone to attend a meeting or answer a request.
Record decisions rather than approve them. A person who cannot block a deployment can still create a dated record naming who decided to proceed and on what basis. It stops nothing and moves the accountability to the person who decided, which is the only leverage available and is frequently sufficient.
Change defaults rather than run reviews. A blocked destination, a tenant restriction or a conditional access rule operates continuously without anyone convening. Configuration works where process does not, because it does not depend on cooperation after the initial change.
The Other Two Borrow Somebody Else's Authority
Attach to existing gates rather than creating new ones. Procurement already stops purchases and legal already reviews contracts, so adding two AI questions to a gate somebody else enforces costs nothing and inherits their standing. Then publish a short prohibition list, since a list of things nobody may do is easier to get approved once than a review process is to sustain weekly.
How Do You Build an Inventory Without Asking Anyone?
From systems already running, because a survey is exactly the instrument a small function cannot make people complete.

Three reads produce a usable register in a morning. Expenditure records name the AI tools somebody is paying for. The identity provider names which applications people sign into. Network or browser telemetry names the destinations being reached. None requires a conversation, and between them they cover most of what a survey would have found more slowly and less completely. An AI data fabric performs the same three reads continuously rather than once.
What Does That Miss?
AI arriving inside products the organization already bought, which no expenditure line records because the invoice predates the feature. The category is genuinely hard for a large team and impossible for a small one to catch by asking, and an AI Interaction Data Fabric surfaces it by observing the traffic rather than the procurement record.
Which Systems Deserve the Attention?
The consequential minority, because comprehensive coverage is not available and pretending otherwise produces a register nobody maintains.
Two questions sort most estates. Does the system influence a decision about a person, covering hiring, credit, pricing, access or anything affecting a customer. Second, does it reach regulated or confidential data. Anything answering yes to either gets a named owner and a recorded assessment. Everything else gets an inventory line and nothing more.
Why Not Assess Everything Lightly?
Because a uniform light touch produces a register of equal-looking entries where the important ones are indistinguishable from the trivial ones. A small function's scarcest resource is attention, and spreading it evenly guarantees it is thin where it matters, which is the same reasoning that applies to routing human review by consequence rather than uniformly.
Which Obligations Do Not Scale Down?
Several, and this is where a minimum program has to stop being minimal. Regulatory duties attach to the activity rather than to the size of the team managing it.

A deployer of a high-risk AI system in Europe owes human oversight by competent people with authority, input data controls, log retention for a defined period and worker notification, whatever its headcount. Transparency obligations for interactive systems apply now. State-level requirements attach where affected individuals live rather than where the company sits. None of those has a small business exemption of the kind that exists for some data protection duties.
Where Does Size Help?
On penalties rather than on obligations. Some regimes cap fines for smaller organizations at the lower of two figures rather than the higher, so the exposure is materially smaller than the headline suggests even where the duty is identical. Worth knowing before quoting a maximum penalty to a board that will discover the qualification later, and the transparency obligations already in force include exactly that inversion.
What Should the Prohibition List Contain?
Three or four entries, specific enough to enforce and short enough that people remember them without looking. A long list is a policy document, and policy documents need the authority this function lacks.
Categories of data that may never reach an external model, named by classification rather than described. Decision types that always require a human determination, named by the decision rather than the system. Then any tool category the organization declines outright, which is easier to state than to justify case by case. Each entry needs a technical enforcement point rather than a paragraph, since a prohibition nobody can enforce is a preference, and an acceptable use policy runs into the same problem at greater length.
Why Does Brevity Matter So Much Here?
Because the list is the one instrument a small function can get approved once and rely on indefinitely. Length invites negotiation, exceptions and eventual revision, all of which consume the attention the function does not have. Three entries that hold beat fifteen that get relitigated, and prohibitions as the strongest available power applies more sharply where there is no committee at all.
What Belongs Outside the List?
Anything requiring judgment about a particular case, since that is a review and reviews are what this design avoids. The list handles the absolute cases and the recorded-decision approach handles everything else, which keeps the function out of the approval business it has no standing to conduct.
What Kills a One-Person Program?
The person leaving, and it is the most predictable failure in this whole category. A program held in somebody's head, their inbox and their unshared spreadsheet stops when they do.
Everything above is worth doing badly and written down rather than well and remembered. The register in a shared location rather than a personal drive. The prohibition list published where anyone can find it. The decisions recorded with names and dates rather than recalled. A successor inheriting a rough documented program is in a far better position than one inheriting a thorough undocumented one.
What Is the Minimum That Survives a Handover?
Four artifacts. The inventory with owners. The prohibition list. The record of decisions taken and who took them. Then a note stating which obligations apply and why, since a successor who has to re-derive the regulatory position loses months. Producing evidence on somebody else's timeline is impossible where the only copy left with the previous holder.
How Do You Get a Decision Made at All?
Attach a number to it, because a small function has no positional authority and a figure argues on its own.
A policy statement that a practice is risky invites a discussion about appetite. An estimate of what it would cost invites a decision about whether to spend less than that preventing it. The second conversation is shorter and reaches an outcome, which matters disproportionately when the person raising it has no standing to insist. AI risk quantification is the substitute for authority that a one-person function otherwise lacks.
Does That Require a Platform?
Not to start. A rough order-of-magnitude figure derived from the records involved and the applicable penalty regime is enough to change a conversation, and it is defensible provided the assumptions are stated. Precision matters less than having a number at all, since the alternative is an adjective.
Design for the Constraint You Have
Small-team AI governance guidance mostly compresses the enterprise program, which addresses time and ignores authority. A function that cannot compel anyone should record decisions rather than approve them, change defaults rather than convene reviews, attach to gates other people already enforce, and publish a short prohibition list. The inventory comes from expenditure, identity and traffic rather than from a survey nobody will complete. Attention goes to systems touching people or regulated data and nowhere else. All of it gets written down, because the most likely cause of failure is the person moving on. Kovrr's AI Security and Governance Platform builds the inventory from telemetry rather than from questionnaires, which is the part a small function cannot do by asking. Building the inventory is where most programs start and stall.
To see an AI inventory assembled from your own systems rather than from a survey, book a demo mapped to your own estate.
Small Team AI Governance FAQs
Speak to an ExpertWhat is the real constraint on a one-person AI governance function?
Authority rather than time. Somebody holding AI governance alongside another job can write a policy in an afternoon. What they cannot do is refuse a deployment senior engineering wants, require a pipeline change, or get a business unit to answer anything. Most small-team guidance offers a compressed enterprise program, which addresses the time constraint and ignores the authority one, so a program designed for the second fails on the first.
What can such a function do instead?
Four things, none requiring anyone to attend a meeting. Record decisions rather than approve them, since a dated record naming who decided and on what basis moves accountability to the decider. Change defaults rather than run reviews, because a blocked destination or conditional access rule operates continuously without convening anyone. Attach AI questions to gates procurement and legal already enforce, inheriting their standing. And publish a short prohibition list, which is easier to get approved once than a review process is to sustain.
How do you build an AI inventory without a survey?
From systems already running, since a survey is precisely the instrument a small function cannot make people complete. Three reads produce a usable register in a morning. Expenditure records name the tools somebody is paying for, the identity provider names which applications people sign into, and network or browser telemetry names the destinations being reached. What that misses is AI arriving inside products already bought, where the invoice predates the feature, which requires observing traffic rather than procurement records.
Which systems deserve attention when coverage is impossible?
The consequential minority, sorted by two questions. Does the system influence a decision about a person, covering hiring, credit, pricing, access or anything affecting a customer. Second, does it reach regulated or confidential data. Anything answering yes to either gets a named owner and a recorded assessment, while everything else gets an inventory line and nothing more. A uniform light touch produces a register where important entries are indistinguishable from trivial ones.
Do regulatory obligations scale down with team size?
Mostly not, since duties attach to the activity rather than the headcount managing it. A deployer of a high-risk system in Europe owes human oversight by competent people with authority, input data controls, log retention and worker notification whatever its size. Transparency obligations for interactive systems apply now. Size helps on penalties rather than on obligations, since some regimes cap fines for smaller organizations at the lower of two figures rather than the higher.
What is the most likely way a small program fails?
The person leaving. A program held in somebody's head, their inbox and an unshared spreadsheet stops when they do. Everything is worth doing roughly and written down rather than thoroughly and remembered. Four artifacts survive a handover: the inventory with owners, the prohibition list, the record of decisions and who took them, and a note stating which obligations apply and why, since a successor who has to re-derive the regulatory position loses months.




