Trust, Security & Regulation

How do SMEs set up practical AI governance?

What AI governance actually means for an SME

Governance is not bureaucracy but a set of clear decisions: who may use which AI tool, for what purpose, with which data - and how the output gets checked? For an SME this does not mean copying enterprise frameworks, but building a workable version that fits the team and is actually followed.

The pressure is real. Without rules, shadow AI appears: staff paste customer data, contracts or source code into free chatbots without knowing where the data goes. At the same time, the revised Data Protection Act (FADP) and the extraterritorial EU AI Act increasingly require demonstrable diligence. Lightweight governance protects against both - data leakage and non-compliance - and makes AI value predictable rather than accidental.

Roles: who owns AI governance in a small team

You do not need a Chief AI Officer. You need one named, accountable person and a few clearly assigned tasks. The key is accountability: a specific person keeps the inventory current, answers questions and approves new use cases. Everything else can stay distributed and lightweight.

  • Sponsor (management): sets the frame, provides budget and backing, holds ultimate responsibility.
  • AI owner (often IT lead or founder): maintains policy and inventory, vets new tools, is the point of contact.
  • Data protection contact: checks personal-data implications; in an SME often the same person, involved on FADP-relevant matters.
  • Users (all staff): follow the policy, label AI output and report incidents.

The one-page AI policy: what to include

A good SME policy fits on one page and gets read because it is short and concrete. It answers the questions that actually come up day to day: which tools are allowed, which data must never go in, who stays responsible, and how AI use is made transparent.

  • Allowed and disallowed tools - a short list of approved services plus the rule to get anything new approved first.
  • Data classification - clearly name what must never be entered: personal data, trade secrets, credentials, confidential client content.
  • Human accountability - AI assists, it does not decide; staff remain responsible for the output.
  • Transparency - where sensible or required, label AI-generated content, internally and externally.
  • Review duty - check outputs for facts, bias and confidentiality before they leave the building or support a decision.

Human oversight: keep a person in the loop

Not every AI use needs the same control. A draft of an internal email is different from screening job applications. The rule of thumb: the greater the impact on people, the more binding the human review. The EU AI Act explicitly requires effective human oversight for high-risk systems - a good benchmark even where you are not (yet) legally obliged.

  • Always review by a human: decisions on hiring, credit, dismissal, pricing, health or safety, and anything legally binding.
  • Sampling suffices: for low risk such as internal drafts or brainstorming, occasional checks are enough.
  • No blind trust: reviewers must be able to override AI output and must not defer to it automatically (automation bias).

Documentation: the AI inventory as backbone

The only document you truly need is a simple AI inventory - a spreadsheet, not a binder. It shows at a glance where AI is used across the business, with which data and who is responsible. This register is the basis for risk review, vendor due diligence and the demonstrability the FADP and EU AI Act require.

  • Per use case, record: tool, purpose, data types used, responsible person, risk level, status of the data-processing agreement.
  • Vendor due diligence: hosting location, sub-processors, whether inputs are used for training, and a suitable DPA.
  • For personal data: assess whether a data protection impact assessment is needed and log the activity in the record of processing.

Lightweight risk review and the Swiss legal frame

Before a new use case goes live, a short triage of a few minutes is enough: which data is involved, who is affected by the output, and what happens if it fails? The EU AI Act thinks in risk tiers - unacceptable, high, limited, minimal - and the same logic helps SMEs steer effort where it counts. Most SME uses are minimal or limited risk; the few sensitive ones you catch early.

For Swiss SMEs, two reference points apply in parallel. First, the revised FADP, supervised by the FDPIC - not the GDPR, even if much is similar. Second, the EU AI Act, which applies extraterritorially once outputs are used in the EU or you serve EU customers. Think of both early and you avoid retrofitting later. Programmes like Innosuisse and Swiss models around ETH and EPFL (such as Apertus) also show that privacy-friendly, local AI options are increasingly available.

Ready in 90 days: a realistic roadmap

  • Days 1-30: name the AI owner, survey existing use including shadow AI, and populate the inventory for the first time.
  • Days 31-60: adopt the one-page policy, decide the approved tools and run a short team training.
  • Days 61-90: apply risk triage to current use cases, check DPAs and schedule a fixed quarterly review.
  • Ongoing: keep the inventory current, approve new use cases, log incidents and refresh the policy annually.

Frequently asked questions

Does an SME really need AI governance?

Yes, as soon as AI tools are in use - and they usually already are, often unnoticed as shadow AI. Without rules you risk data leakage and breaches of the FADP or EU AI Act. The effort is small: one responsible person, a one-page policy and an inventory are enough to start.

Does a Swiss SME fall under the EU AI Act?

Possibly. The EU AI Act applies extraterritorially: it can apply once the output of an AI system is used in the EU or you serve EU customers - regardless of where you are based. Assess case by case your role (e.g. provider or deployer) and the risk tier of the application.

What is the difference between the FADP and the GDPR for us?

For Swiss matters the revised FADP applies, supervised by the FDPIC - not the GDPR. Both share similar principles such as transparency, data minimisation and data-subject rights, but differ in detail and jurisdiction. If you also process EU personal data, the GDPR may apply as well; when in doubt, consult legal advice.

May staff use ChatGPT or similar tools at work?

Yes, if clear guardrails exist. Define which tools are approved, which data must never be entered (personal data, secrets, credentials) and that outputs are reviewed before use. Also check the provider's settings, such as whether inputs are used for training, and sign a DPA where needed.

How long does setup take and who should own it?

A working baseline is in place in about 90 days: inventory and owner in month one, policy and training in month two, risk review and quarterly cadence in month three. It should be owned by a single named person - often the IT lead or the founder - with management backing.

What is the most common mistake in SME AI governance?

Too much or too little. Too much means a 40-page rulebook nobody reads that smothers the value of AI. Too little means no rules at all, hence shadow AI. The middle path for SMEs: a short, lived policy, a current inventory and one clearly responsible person - lightweight but binding.

Key terms in the glossary

← Back to overview

Practical AI for your business

From idea to implementation – we show you what is concretely possible in your case.

Request a demo