Who it is for
Companies of 5 to 200 people that use AI tools and need to show they have governed them.
Knowing which rules apply is step one. What a regulator or an enterprise customer actually asks for is written evidence, and that is work somebody has to sit down and do.
What is inside
- AI Acceptable Use Policy, ready to circulate to staff
- Article 50 disclosure notices, the actual wording for chatbots and AI media
- AI system inventory and risk register, in Excel
- Prohibited practices and high risk screening worksheets
- 45 minute AI literacy training plan and attendance log
- Vendor assessment and incident response procedures
- Customer due diligence answer bank, pre written answers to the AI questions in enterprise security questionnaires
How it arrives
AI GOVERNANCE STARTER KIT
13 documents, every one in PDF and Word, registers in Excel.
Questions people ask
We are not in the EU. Does this apply to us?
Possibly. The Act reaches you if you place an AI system on the EU market, or if the output of your AI system is used in the EU. A US company with EU customers using its AI powered product can be in scope.
We just use ChatGPT and a few tools. Is that regulated?
You are a deployer, which is the lighter category. Your realistic duties are AI literacy for staff, avoiding prohibited uses, and transparency if you run a chatbot or publish AI content. Being able to show you have covered it is increasingly what enterprise customers ask for.
Is this legal advice?
No. These are operational templates, not a legal opinion on your circumstances, and they do not by themselves make you compliant. Where the stakes are high, use them to prepare and then have a qualified lawyer review your position.
This is not legal advice. These are operational templates, not a legal opinion on your circumstances, and they do not by themselves make you compliant. Where the stakes are high, use them to prepare and then have a qualified lawyer review your position.