Adoption moved faster than the structure built to hold it, and closing that gap is a smaller job than most mid-size leaders assume.
Most employees are already trusting AI outputs more than their company’s oversight can actually support. KPMG’s 2025 global trust study found 58% of U.S. workers admit to relying on AI-generated output at work without properly evaluating it first. This piece lays out what a lightweight, genuinely usable governance approach looks like for a mid-size company, not a case for enterprise-grade compliance: the questions it needs to answer, who owns it when there’s no dedicated team, and a starting point you can put in place this quarter, not next year.
Picture a 180-person insurance brokerage on an ordinary Tuesday. The head of client services mentions, almost as a side note, that the renewals team has been using an AI tool to draft policy renewal emails for the last three months. The COO asks who approved that.
Nobody answers right away. The tool works well enough that nobody flagged it, and well enough that nobody thought to check.
That’s the actual shape of the AI governance gap at most mid-size companies. That’s not because leadership rejected the idea of oversight, or because nobody cares about risk. AI simply got useful faster than anyone wrote down the rules for using it, and once a tool starts saving people real time, nobody wants to be the one who slows it down by asking questions.
You’ll see the same pattern in finance, HR, and legal, wherever someone found a shortcut and kept it because it worked. The gap is trust moving faster than the structure built to hold it, nothing more mysterious than that.
The research backs up what that scene suggests. In KPMG’s 2025 global study on trust and use of AI, 58% of U.S. workers admit to relying on AI-generated output at work without properly evaluating it first.[1] Fifty-nine percent believe someone at their company is actually accountable for overseeing AI use, which leaves roughly four in ten who either don’t know who that is or don’t think the role exists at all.[1]
That’s more than half a workforce treating an AI answer the way they’d treat a fact from a trusted coworker, not something that needs a second look.
If nobody in the room can say who approved an AI use case, you don’t have oversight. You have a habit that hasn’t gone wrong yet.
The fix isn’t a 40-page policy nobody reads. Most mid-size companies don’t have a governance gap because they’re missing a framework. They have one because nobody sat down and wrote out the three or four questions that AI use at their company actually needs answered.
That’s a smaller job than it sounds. It’s what the rest of this piece walks through.
Here’s a hypothetical, and it’s easy to picture because some version of it is probably happening in your building this week. A finance analyst at a 90-person manufacturer is behind on a board deck. She pastes last quarter’s unreleased revenue numbers into a public AI chatbot to get help reformatting them into talking points.
She’s not being reckless. Nobody ever told her not to, and nobody set up an approved alternative that’s just as fast.
This is where most mid-size leaders freeze. They hear “AI governance” and picture an enterprise compliance department: a standing committee, a risk taxonomy, quarterly audits, maybe a chief AI officer with a dedicated budget. That version is real at large enterprises, and it’s genuinely the wrong size for a 60 to 400 person company.
Good enough governance for a company that size answers three things: what data can go where, who checks an AI output before it reaches a customer or a regulator, and who’s accountable when it doesn’t. Call it the PAC check: Purpose, Access, Consequence. What is this tool for, what can it actually touch, and what happens if it’s wrong.
If your policy can’t answer those three in a paragraph each, you’re looking at an announcement, not governance.
Worth being honest about how far even large, well-resourced organizations are from finished on this. The IAPP and Credo AI’s 2025 AI Governance Profession Report found 77% of surveyed organizations actively working on some form of AI governance, climbing to near 90% among organizations already using AI in production.[2] Most of those respondents work inside large enterprises that already have dedicated privacy or compliance teams in place.
That detail matters for a smaller company specifically. If organizations with the budget for full compliance departments still treat this as unfinished work rather than a solved problem, a mid-size company doesn’t need to solve it perfectly either. It needs to solve it enough to answer the three questions above, honestly, in writing.
| Question | Score 1 if true |
|---|---|
| More than one team uses an AI tool nobody selected or approved | 1 |
| No one could name, today, who signs off on a new customer-facing AI use case | 1 |
| Someone has pasted client, financial, or HR data into a public AI tool in the last month | 1 |
| You don’t know how many AI tools are in active use across departments | 1 |
| Nobody has looked at an AI output and asked how you’d know if it were wrong | 1 |
Score 3 or more and the gap is already operational, not theoretical. At that point it’s a next-quarter priority, not a compliance exercise.
This is close to what we’ve written about before as shadow AI, the tools people adopt on their own because the sanctioned path is slower or doesn’t exist yet. Most of it happens because nobody wrote the rule down, not because anyone’s trying to get around one. Our guide to shadow AI covers the fuller pattern of how and why it spreads.
A governance approach that actually gets used answers a short list of concrete questions, not abstract principles. “We’re committed to responsible AI” means nothing to the analyst deciding whether to paste a client contract into a chatbot at 4pm on a Friday. What she needs is a specific answer to a specific question.
These are the ones worth writing down first:
None of these questions require a lawyer to answer, though a lawyer should weigh in if you have one. They require someone to sit down, probably for less than a day, and actually decide.
If you haven’t mapped out what to plan for before rolling anything else out, that’s a related but separate job. Our AI Adoption Checklist covers what to think through before the rollout. This is what happens after something is already live and people are using it.
| Field | Example answer |
|---|---|
| Approved tools | Microsoft Copilot and Claude, on company-licensed accounts. Personal or free accounts not approved for company data. |
| Data that can never go into an AI tool | Client PII, unreleased financials, anything under NDA, employee health or HR records |
| Human check required before external use | Any AI-drafted content going to a customer, regulator, or the board |
| Who owns this policy | Ops lead, with IT/security and legal counsel as reviewers |
| How to request a new tool | One-line request to the ops lead, reviewed within five business days |
| Review cycle | Every quarter, or immediately after any incident |
Copy this structure into a shared document with your own answers filled in. A one-pager people actually read beats a policy nobody opens.
Once those six fields have real answers, most companies have more usable governance in place than a good number of organizations twice their size.
In a company with a dedicated AI governance team, this question doesn’t come up. In a 120-person company, it comes up constantly, usually in the form of someone asking whether this is even on anyone’s plate.
It usually lands on someone without “AI” anywhere in their title, and that’s normal, as long as it’s named out loud rather than left to whoever raises a concern first.
A few roles tend to split the work, and they don’t split it the same way:
If none of those exist as dedicated roles at your company, the responsibility usually still lands on whoever already owns operational risk day to day. That’s frequently the ops lead or the COO, not a new hire, and not necessarily whoever is most enthusiastic about AI.
Someone at your company already owns the risk of a bad customer email or a mishandled dataset. That person owns AI risk too, whether or not it’s written on their business card.
Getting agreement across departments on who owns what is its own small project, and it’s easy to underestimate. If you haven’t lined up buy-in from the teams that can slow this down before you finalize anything, it’s worth reading Stakeholder Engagement for AI Adoption first.
Once ownership is named, the next question is where the line actually sits between what the AI does and what a person still has to check.
| What AI does | What the human still owns | How it gets checked |
|---|---|---|
| Drafts a client renewal or proposal email | Whether the numbers, tone, and commitments are accurate | Named reviewer reads it before it sends; spot-checked monthly |
| Summarizes a contract or policy document | Legal interpretation and the final risk call | Legal counsel or the ops lead confirms before anyone acts on it |
| Screens or ranks job applicants | The actual hiring decision, and a bias check on the rankings | HR reviews rankings against a fairness spot-check before shortlisting |
| Answers routine customer questions | Escalation for anything outside a defined script | Logged conversations reviewed weekly for drift or errors |
Use this as a template. List your own top four or five AI use cases and fill in the middle and right columns before you approve a fifth.
None of this needs to wait for a steering committee, a new hire, or a line item in next year’s budget. It needs someone to block out an afternoon.
Governance built for a Fortune 500 legal team will sit unopened in a shared drive at a 200-person company. Match the governance to the company you actually run, not the one in the compliance textbook.
Start with a record of what’s actually in use before you write another rule. You can’t govern what you can’t see, and most mid-size companies genuinely don’t know how many AI tools are live across departments until someone asks directly.
| Use case | Tool | Data touched | Owner | Human check | Last reviewed |
|---|---|---|---|---|---|
| Draft renewal emails | Copilot | Client name, policy terms | Client services lead | Reviewed before send | Q3 2026 |
| Summarize vendor contracts | Claude | Contract text, no PII | Ops lead | Legal counsel confirms terms | Q3 2026 |
Start this in a shared spreadsheet with your two riskiest use cases. Add a row every time a new one appears instead of trying to build the whole thing at once.
From there, the sequence is short:
Writing any of this down usually isn’t what trips up mid-size teams. Getting legal, IT, and department heads to agree on the same answers, in the same room, without the conversation dragging on for two months, is the harder part.
That’s the part an expert-led workshop is actually built for. A focused half-day session with the right people in the room can get a one-pager and a use case register signed off across departments in an afternoon, instead of the draft sitting in someone’s inbox until an incident forces the issue. You can absolutely start with the internal version above. A workshop just compresses the buy-in step that otherwise eats months.
Pick one thing from the list above and do it this week, even if it’s just the one-pager in a shared doc with three real answers filled in. That’s the whole first move.
It means a working answer to three things: what data your AI tools can touch, who checks the output before it goes anywhere that matters, and who’s accountable when something goes wrong. It isn’t a mission statement about responsible innovation. A useful test is whether a new hire could read your governance approach and know, within five minutes, what they’re allowed to paste into an AI tool and who to ask if they’re unsure. If it can’t pass that test, you have a document, not governance.
Yes, though formal doesn’t mean what it does at an enterprise. You need a written answer to what data is off-limits, who reviews outputs before they reach a customer, and who owns the decision when something breaks. Run the scored checklist earlier in this piece: if you score three or more, the gap is already operational rather than theoretical, and it’s worth addressing this quarter rather than after a mistake forces the conversation.
It usually falls to whoever already owns operational risk day to day, most often an ops lead or a COO, with IT or security controlling data access and legal counsel, in-house or on retainer, weighing in on contracts and liability. A CFO typically ends up owning vendor risk and tool spend. The person’s title rarely says AI anywhere in it, and that’s normal. What matters is that the responsibility is named in writing rather than left to whoever happens to raise a concern first.
At minimum: what data a tool is allowed to see and what’s explicitly off-limits, which use cases need a human check before anything goes external, who is the named person accountable if an AI-assisted decision is wrong, how someone requests a new tool instead of adopting one quietly, and what gets logged so you can reconstruct later which tool touched which decision. The starter one-pager earlier in this article has a filled-in example of all six fields.
A usage policy is the written rules, the front door: what’s allowed, what isn’t. Governance is the ongoing system around it: ownership, a review cadence, a register of what’s actually in use, and a clear answer for who’s accountable when something goes wrong. A usage policy with nobody maintaining it tends to get circulated once and never opened again. Governance is what makes people actually follow the policy six months later.
The two statistics anchoring this piece come from primary sources checked directly at the publisher on 31 August 2026. The 58% and 59% figures are from KPMG’s own press release summarizing its “Trust, Attitudes and Use of Artificial Intelligence: A global study 2025,” a survey of over 48,000 people across 47 countries, including 1,019 in the U.S., conducted with Melbourne Business School and published April 29, 2025. We used the U.S.-specific figures rather than the global ones, which run higher, closer to two-thirds, because mixing global and national numbers in the same paragraph tends to overstate precision for a piece aimed at U.S. and similarly structured mid-size companies. The 77% and near-90% figures are from the IAPP and Credo AI’s “AI Governance Profession Report 2025,” based on a spring 2024 survey of more than 670 professionals across 45 countries. Worth flagging plainly: that survey’s respondent base skews toward larger organizations with existing privacy or compliance functions, which is exactly why it’s used here as a caveat about the scale of the challenge rather than as a benchmark for what a mid-size company should build. No widely circulated AI governance statistic was excluded during research for failing verification; the two used here were the ones that held up cleanly against their original publisher.