Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

What AI Governance Actually Means for a Startup

Direct answer: AI governance is the set of decisions and records that let you say, credibly, which AI your company uses, what each use could get wrong, who is accountable for it, and what rules apply. For a startup it is not a department or a framework. It is five concrete things: an inventory of where AI is used, a risk classification for each use, a named owner or small committee that makes the calls, a short policy set, and an honest view of where the standards that are starting to matter, ISO 42001 and the EU AI Act, sit relative to all of that.

An AI inventory: know what you use

Governance starts with knowing what you are governing, and most companies cannot list their AI uses accurately on the first try. Three categories hide here. The AI tools people chose deliberately, such as assistants and copilots. The AI features embedded in software you already pay for, which people do not think of as AI and therefore do not report. And the AI in your own product, if you build on top of a model. The inventory is a living list of each use, what data it touches, and who owns it. It is unglamorous and it is the foundation, because every other part of governance refers back to it. Our shadow AI risk checker is a fast way to surface the uses you did not know you had.

Risk classification: not every use is equal

Once you can see the uses, classify them by what happens if they go wrong, because treating a meeting-notes summariser the same as a model that screens job applicants is how governance becomes theatre. Most startup uses are low risk: drafting, summarising, writing code a human reviews. A smaller number are higher risk because they make or heavily influence a decision about a person, such as hiring, credit, access to a service, or anything touching health. The EU AI Act formalises exactly this instinct with its risk tiers, from minimal through limited and high-risk to a small set of prohibited uses. You do not need the Act to apply to you to borrow its logic: spend your governance effort where the impact is, and let the low-risk majority run under a light policy.

Free weekly email

Get The Compliance Brief every Tuesday

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

Someone who owns it

Governance is a set of decisions, and decisions need an owner. In a large company that is a committee with a charter. In a startup it is one or two people, usually whoever owns security or privacy plus someone from the product or engineering side, meeting on a set cadence to look at the inventory, the new uses people want to add, and anything that changed risk. The failure mode is diffusion: everyone assumes AI decisions are being made somewhere, and nobody is actually accountable for the one that goes wrong. Naming the owner, even if it is a part-time hat, is most of the work. The cadence can be quarterly until something forces it to be more often.

The policy set

Governance is written down in a small number of documents, not a binder. The core one is an AI acceptable use policy that tells your people which tools are allowed, what data must never go into a model, and who is accountable for what a model produces. Around it sit the pieces it points to: your data classification, so the data rules mean something; AI vendor assessment, so you know how the tools you rely on handle your data; and a human-in-the-loop rule for the higher-risk uses, so a model never makes a consequential decision unreviewed. For most startups that is the whole policy set, and it is enough.

Want a read on where you stand? Our AI governance assessment scores your inventory, your risk classification and your policy set, and our Phase 1 gap analysis starts from $3,500 if you want it done properly. AI governance assessment

Where ISO 42001 and the EU AI Act sit

Two things get invoked whenever AI governance comes up, and it helps to be precise about what each is. ISO 42001 is a management system standard for artificial intelligence, structured like ISO 27001 but aimed at how an organization governs its AI. It is certifiable by an accredited certification body, and it is a sensible destination once your governance is real and a buyer or a board wants third-party proof of it. It is not where you start, because certifying an absence of governance is not possible. If it is on your roadmap, our ISO 42001 readiness page covers what adopting it involves.

The EU AI Act is law, not a standard, and it is extraterritorial in the way privacy law taught everyone to expect. It can reach a company outside the EU when the output of an AI system is used there, and it classifies uses by risk, with obligations that scale from transparency duties up to strict requirements for high-risk systems and outright prohibition for a small set. For most Canadian startups the Act is a thing to classify against rather than comply with in full today, which is why the risk classification step earlier is the one that pays off: if you know your uses and their risk, you already know your likely exposure. Our EU AI Act classifier gives a first read on which tier a given use falls into.

What a startup actually does first

The order is the point. Build the inventory, because you cannot govern what you cannot see. Classify the uses, so effort goes where the risk is. Name an owner, so decisions have a home. Write the short policy set, starting with the acceptable use policy. Only then look at ISO 42001 or a formal EU AI Act programme, and only if a buyer, a board or the law is actually asking. Governance that grows in that order stays proportionate, which is the whole trick for a company that does not have a compliance department and should not pretend to.

If you want the broader picture of how much of a framework is worth adopting early and which parts buyers ask about, we cover that in AI governance for startups without a compliance department.

Is AI governance just an AI policy?

No. The policy is one of five parts and the most visible, but a policy with no inventory behind it governs nothing, because you do not know what the policy is meant to cover. The inventory and the risk classification are what make the policy real.

Do we need ISO 42001 to have AI governance?

No. ISO 42001 is a way to certify that your governance meets a standard. You can have working governance without it, and most startups should, pursuing the certification only when someone external requires the proof.

Does the EU AI Act apply to a Canadian startup?

Sometimes. It can apply when your AI system or its output is used in the EU, regardless of where you are. The practical move is to classify your uses against its risk tiers so you know whether you are in scope before you assume you are not.

Want governance that fits your size? We help startups build the inventory, the risk classification and the policy set, and run a Phase 1 gap analysis from $3,500 against ISO 42001 or the EU AI Act when you are ready for it.

Score your governanceOr book a call

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.