AI governance sounds like a binder that slows AI down. Like forms, approvals, and a legal team that says no. In reality, governance is what makes AI usable in operations. Because the alternative to governed AI is not no AI. It is AI that is already running, only without anyone steering it.
Friday, 4 p.m.
An employee has to send out a quote by the end of the day. She pastes the customer list and the last three contracts into an AI tool and has it write a draft. Twenty minutes later she is done. Nobody allowed her to. Nobody forbade it. Nobody decided at all.
This scene is the normal state of AI in most companies: not forbidden, not governed, just happening.
The thinking error about governance
Most leaders ask the wrong question. They ask: should we allow AI or not? And because allowing sounds like risk and forbidding sounds like a competitive disadvantage, they postpone the decision.
Only: while the decision waits, AI is already in the building. In the private accounts of employees, in the Copilot that came with the Office subscription. The real question is therefore not whether, but under which rules. Governance is the answer to the second question.
And that answer does not slow things down. It does the opposite. Only when it is clear which tools are allowed and which data may go in can employees use AI without an uneasy feeling at every step. Clarity is faster than uncertainty.
Governance is not a binder, but three questions
Governance sounds bigger than it needs to be. At its core it answers three questions, and none of them needs a committee.
Which tools are allowed? A short list of approved AI tools. Everything else is not approved for now, not meant as a ban, but as a deliberate choice.
Which data may go in? The most important question. Customer data, personnel data, figures from the accounts, trade secrets do not belong in a public AI tool. The rest may.
Who reviews the result? AI writes convincingly, even when it is wrong. Before an AI answer goes into a quote or a contract, a person looks it over.
These three answers fit on one page. And that one page is more governance than most Swiss SMEs have today.
What the law says about it
From 2026, the EU AI Act takes effect in stages. It sorts AI applications by risk, and that grid is a useful compass even without a legal obligation.
Most applications in an SME sit at the bottom of the pyramid. A tool that drafts emails or summarises minutes carries minimal risk. It gets sensitive higher up, where AI decides about people: pre-screening job applications, credit scoring, anything that can disadvantage someone. For those cases the law requires traceability and human oversight.
Switzerland is not directly bound by the AI Act. Anyone serving EU clients is bound indirectly, and the Federal Council is watching the development. More important than the legal question is the reflex the grid trains: for every AI application, first ask how strongly it decides about people. The stronger, the more oversight.
Why a PDF is not enough
The common reflex is to write governance down once. A policy, approved, filed, done. Six months later it is out of date: new tools, new use cases, and people who never saw the policy.
Governance drifts, just as company knowledge drifts. It therefore does not belong in a binder, but in ongoing operation, on a fixed rhythm.
Once a quarter, the round: which AI tools are new? Do the rules still hold? Was there an incident we can learn from? It is not a big exercise. But it keeps governance as current as the tools it governs.
It is the same idea as with the operating layer: AI in the company is not a project with an end date, but something that is operated. Governance is the part of it that makes sure you can trust the system.
What you can start this week
You need neither a policy nor a consultant to start. Three steps show you within a week where your business stands on AI governance.
1 — Make the inventory visibleAsk the team openly and without consequence which AI tools are being used right now, including the private ones. The list is almost always longer than expected. It is the honest starting point.
2 — Write the one pageThree headings: allowed tools, data that must not go in, who reviews results. Fill them with what should already apply today. The first version needs no more than that.
3 — Sort your data by traffic lightTake the kinds of data in your business and split them into three tiers: open for any tool, only for approved ones, for none. This split answers the question your employees face every day.
What you gain from it
Governance has a bad reputation because people confuse it with bureaucracy. What it actually brings is speed with a clear conscience. Employees who use AI without quietly moving data around. And a business that does not flinch at the next data incident, because it is clear who reviewed which results.
That is no contradiction to fast AI adoption. It is its precondition.