Direct answer: AI governance is the set of decisions and records that let you say, credibly, which AI your company uses, what each use could get wrong, who is accountable for it, and what rules apply. For a startup it is not a department or a framework. It is five concrete things: an inventory of where AI is used, a risk classification for each use, a named owner or small committee that makes the calls, a short policy set, and an honest view of where the standards that are starting to matter, ISO 42001 and the EU AI Act, sit relative to all of that.
An AI inventory: know what you use
Governance starts with knowing what you are governing, and most companies cannot list their AI uses accurately on the first try. Three categories hide here. The AI tools people chose deliberately, such as assistants and copilots. The AI features embedded in software you already pay for, which people do not think of as AI and therefore do not report. And the AI in your own product, if you build on top of a model. The inventory is a living list of each use, what data it touches, and who owns it. It is unglamorous and it is the foundation, because every other part of governance refers back to it. Our shadow AI risk checker is a fast way to surface the uses you did not know you had.
Risk classification: not every use is equal
Once you can see the uses, classify them by what happens if they go wrong, because treating a meeting-notes summariser the same as a model that screens job applicants is how governance becomes theatre. Most startup uses are low risk: drafting, summarising, writing code a human reviews. A smaller number are higher risk because they make or heavily influence a decision about a person, such as hiring, credit, access to a service, or anything touching health. The EU AI Act formalises exactly this instinct with its risk tiers, from minimal through limited and high-risk to a small set of prohibited uses. You do not need the Act to apply to you to borrow its logic: spend your governance effort where the impact is, and let the low-risk majority run under a light policy.
Free weekly email
Get The Compliance Brief every Tuesday
One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.
Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.
Someone who owns it
Governance is a set of decisions, and decisions need an owner. In a large company that is a committee with a charter. In a startup it is one or two people, usually whoever owns security or privacy plus someone from the product or engineering side, meeting on a set cadence to look at the inventory, the new uses people want to add, and anything that changed risk. The failure mode is diffusion: everyone assumes AI decisions are being made somewhere, and nobody is actually accountable for the one that goes wrong. Naming the owner, even if it is a part-time hat, is most of the work. The cadence can be quarterly until something forces it to be more often.
The policy set
Governance is written down in a small number of documents, not a binder. The core one is an AI acceptable use policy that tells your people which tools are allowed, what data must never go into a model, and who is accountable for what a model produces. Around it sit the pieces it points to: your data classification, so the data rules mean something; AI vendor assessment, so you know how the tools you rely on handle your data; and a human-in-the-loop rule for the higher-risk uses, so a model never makes a consequential decision unreviewed. For most startups that is the whole policy set, and it is enough.
Where ISO 42001 and the EU AI Act sit
Two things get invoked whenever AI governance comes up, and it helps to be precise about what each is. ISO 42001 is a management system standard for artificial intelligence, structured like ISO 27001 but aimed at how an organization governs its AI. It is certifiable by an accredited certification body, and it is a sensible destination once your governance is real and a buyer or a board wants third-party proof of it. It is not where you start, because certifying an absence of governance is not possible. If it is on your roadmap, our ISO 42001 readiness page covers what adopting it involves.
The EU AI Act is law, not a standard, and it is extraterritorial in the way privacy law taught everyone to expect. It can reach a company outside the EU when the output of an AI system is used there, and it classifies uses by risk, with obligations that scale from transparency duties up to strict requirements for high-risk systems and outright prohibition for a small set. For most Canadian startups the Act is a thing to classify against rather than comply with in full today, which is why the risk classification step earlier is the one that pays off: if you know your uses and their risk, you already know your likely exposure. Our EU AI Act classifier gives a first read on which tier a given use falls into.
What a startup actually does first
The order is the point. Build the inventory, because you cannot govern what you cannot see. Classify the uses, so effort goes where the risk is. Name an owner, so decisions have a home. Write the short policy set, starting with the acceptable use policy. Only then look at ISO 42001 or a formal EU AI Act programme, and only if a buyer, a board or the law is actually asking. Governance that grows in that order stays proportionate, which is the whole trick for a company that does not have a compliance department and should not pretend to.
If you want the broader picture of how much of a framework is worth adopting early and which parts buyers ask about, we cover that in AI governance for startups without a compliance department.
Is AI governance just an AI policy?
No. The policy is one of five parts and the most visible, but a policy with no inventory behind it governs nothing, because you do not know what the policy is meant to cover. The inventory and the risk classification are what make the policy real.
Do we need ISO 42001 to have AI governance?
No. ISO 42001 is a way to certify that your governance meets a standard. You can have working governance without it, and most startups should, pursuing the certification only when someone external requires the proof.
Does the EU AI Act apply to a Canadian startup?
Sometimes. It can apply when your AI system or its output is used in the EU, regardless of where you are. The practical move is to classify your uses against its risk tiers so you know whether you are in scope before you assume you are not.
Want governance that fits your size? We help startups build the inventory, the risk classification and the policy set, and run a Phase 1 gap analysis from $3,500 against ISO 42001 or the EU AI Act when you are ready for it.
Score your governanceOr book a call