Skip to main content

What are you looking for?

Explore our services and discover how we can help you achieve your goals

AI governance for mid-market companies: a practical starter

A mid-market company can govern AI without a large compliance team. Start with an inventory of every AI use, rate each one by risk, name an owner, write short rules for data and human oversight, check your suppliers, and secure agents and integrations. Then check which EU AI Act dates apply to your role and markets.

Book a solution review See security and compliance

Reviewed by David (CEO) · Updated 17 Sep 2026 · 9 min read

star

This guide is for CEOs, CTOs, COOs, compliance and data protection leads in companies of roughly 50 to 2,000 people that already use AI in products or operations, or are about to. It explains why governance reaches mid-market companies now, what the EU AI Act asks and when, which frameworks help, a ten-step governance baseline, controls for AI agents, and how to answer the AI questions in customer questionnaires. It is part of our technology trends 2026 series. It is practical guidance, not legal advice.

In this guide

Why governance reaches mid-market companies now

Three things arrived at the same time.

Regulation with dates. The EU AI Act is the first comprehensive AI law, and its obligations apply in phases through 2028. It can reach companies outside the EU when their AI systems or outputs are used in the EU.

Customers ask. Enterprise buyers now send AI sections in their supplier questionnaires: where do you use AI, on which data, with which models, who reviews the output? A company without answers loses deals before any regulator calls.

AI can act. Agents that call tools and APIs turn a wrong answer into a wrong action. Postman's 2025 State of the API report found that 51% of developers name unauthorised or excessive API calls from AI agents as their top security concern.

Most mid-market companies are deployers: they use AI systems built by others, or build features on top of commercial and open-weight models. Deployers have lighter duties than providers of high-risk systems, but not none, and customers expect governance whatever the legal minimum.

What the EU AI Act asks, and when

Date What applies What a mid-market deployer should check
2 February 2025 Prohibited AI practices, general provisions No prohibited use, such as social scoring or emotion recognition at work; staff who use AI are trained
2 August 2025 Obligations for general-purpose AI models and governance bodies Your model suppliers' documentation and terms
2 August 2026 General application of the Act, including transparency duties People know when they interact with AI; AI-generated content is identifiable where required
2 December 2027 High-risk systems in sensitive areas, such as employment, education and critical infrastructure Whether any AI use falls into a high-risk area, and the deployer duties if it does
2 August 2028 High-risk AI embedded in regulated products Only relevant if you make or integrate such products

The last two dates come from the AI Omnibus, which entered into force on 27 July 2026 and moved the high-risk deadlines; it also extended simplified obligations beyond SMEs to small mid-cap companies. Check the European Commission's pages for the current text before you act.

Frameworks that help

ISO/IEC 42001. The international standard for an AI management system: policy, roles, risk assessment, impact assessment, controls over the AI lifecycle and continual improvement. It fits companies that already run ISO 27001 for information security, because the structure is similar.

NIST AI Risk Management Framework. A voluntary framework organised in four functions: govern, map, measure and manage. It is a practical vocabulary for risk conversations, wherever you are based.

OWASP Top 10 for LLM Applications. A security list for applications built on language models, including prompt injection and excessive agency, with mitigations engineers can apply directly.

You do not need all three at once. Use the EU AI Act to know what is required, ISO/IEC 42001 or the NIST framework to organise the management system, and OWASP to secure what you build.

The governance baseline in ten steps

  1. Inventory every AI use

    List products, internal tools, supplier features and experiments, with the model, the data and the owner of each.

  2. Classify your role and risk

    For each use, note whether you are provider or deployer and rate the risk: prohibited, high-risk area, transparency duty or minimal.

  3. Name owners

    One accountable owner per AI use, and one person who owns the governance baseline as a whole.

  4. Write a short AI policy

    Allowed and forbidden uses, approval before new uses, and what staff may paste into AI tools.

  5. Set data rules

    Which data may reach which model, retention, personal data handling and where data is processed.

  6. Define human oversight

    Which outputs need review, which actions need approval, and how a person can override or stop the system.

  7. Check suppliers

    Model and tool suppliers' documentation, data terms, security practices and change notices.

  8. Secure the system

    Least privilege, input and output checks, logging and testing against prompt injection.

  9. Monitor and handle incidents

    Track quality and errors, and have a route to report, investigate and fix AI incidents.

  10. Train people

    Give staff who use or build AI the literacy to use it responsibly, matched to their role.

Our enterprise AI readiness assessment helps judge whether data, skills and governance are ready before a larger programme.

Controls for AI agents and integrations

Agents and AI features wired into business systems need controls beyond a policy document:

  • Narrow tools. Give each agent only the tools and data its task needs, with read-only access first.
  • Approval for impact. Payments, refunds, price changes, customer messages and data deletion need a person's approval until the error rate is proven low.
  • Scoped credentials. Agents use their own identities and scopes, never shared admin keys.
  • Rate limits and monitoring. Watch agent calls like any new client, and alert on unusual volumes.
  • Decision logs. Record inputs, tool calls and outcomes per case, so failures can be traced and explained.
  • A manual fallback. Every automated process keeps a way to hand the case to a person.

Our comparison of AI agents and workflow automation explains when an agent is worth that overhead, and our agentic commerce readiness guide applies the same controls to shopping agents.

Answering AI questions in customer questionnaires

Buyers' questionnaires usually ask five things. Prepare the answers once and keep them current:

  • Where AI is used. From your inventory, in plain language.
  • Which data it sees. From your data rules, including whether customer data trains any model.
  • Which models and suppliers. From your supplier checks.
  • Who reviews outputs. From your oversight rules.
  • How incidents are handled. From your incident route, with the contact point.

Service firms and agencies meet these questions most often; see our professional services industry page for the operating context.

How Netbase governs its own AI delivery

Netbase applies the ISO/IEC 42001 AI management system framework to its own AI delivery practice. That is how we run our work, not a claim about a client's system. It sits on top of the security practices used on every project: secure code review and version control, TLS in transit and AES at rest, role-based access control, MFA for admin dashboards, vulnerability scanning and penetration testing, and NDAs and DPAs on request. Netbase holds ISO 27001 certification and a SOC 2 Type II attestation for its own operations.

See security and compliance

We work with the major commercial and open-weight AI models and choose per project, which keeps governance about the use case rather than one vendor. Our delivered AI includes 4over4's recommendation engine, part of an engagement in which 4over4 reported revenue up 82% within six months, and anonymised projects for clients who are not named, such as a RAG knowledge assistant. Governance is built into our responsible AI and MLOps and quality and security services.

Limitations of this guide

  • This is general guidance, not legal advice. Obligations depend on your role, sector and markets.
  • EU AI Act dates reflect the European Commission's pages as read in September 2026, after the AI Omnibus; they can change again.
  • Summaries of ISO/IEC 42001, the NIST framework and OWASP describe their purpose, not their full requirements.
  • Nothing here implies that following the baseline makes any system compliant.

Plan the next step with a Netbase consultant

Frequently asked questions

It can, when AI systems or their outputs are placed on the market or used in the EU. Check your role with legal counsel.

Not by law. It is a useful structure when customers ask how AI is governed, especially if you already run ISO 27001.

Usually a senior leader such as the COO or CTO, with a named owner for each AI use and support from security and data protection.

With the inventory. You cannot rate, secure or explain AI uses you have not listed.

How this guide was made

The Netbase Editorial Team wrote this guide from the European Commission's AI Act pages, the ISO, NIST and OWASP references and Netbase's verified security and AI facts. David (CEO) reviewed every Netbase statement. Drafting used AI assistance (Claude).

Next step

Share your AI inventory, or the questionnaire a customer sent you, and we will book a solution review to set a proportionate baseline. You can also see how we build digital products with governance inside, explore digital transformation consulting, read about retail and ecommerce, or browse more Netbase insights.

AI-assisted quality and security built into every release AI-assisted quality and security built into every release

Netbase provides software quality and security services for teams that cannot afford a broken release or an exposed customer record. We build testing, performance and security into delivery, with AI helping to generate tests and triage findings, instead of leaving them to a launch-stage inspection. This family covers quality engineering and testing, and application security assurance for the products we build and run.

Learn More
line
Responsible AI and MLOps for AI in production Responsible AI and MLOps for AI in production

MLOps and responsible AI are how an AI feature stays trustworthy after launch. Netbase's practice for monitored, governed AI in production covers evaluation before every release, versioning of models, prompts and data, monitoring of quality and cost, and incident controls with a named owner. It is a growth capability, backed by an MLOps pipeline delivered for a client that is not named.

Learn More
line
Digital product accelerators for SaaS, mobile and AI products Digital product accelerators for SaaS, mobile and AI products

Digital product accelerators are Netbase-built modules and delivery patterns that help founders and product teams launch SaaS, mobile and AI products faster. Instead of rebuilding accounts, billing, workflows and integrations from scratch, you reuse proven components, spend engineering time on what makes your product different, including the AI features buyers now expect, and own the custom code built for you.

Learn More
line
Contact Netbase

Discuss a project

Netbase JSC helps organizations design, build, modernize, and operate digital products and AI-enabled business systems.
Project enquiries

[email protected]

WhatsApp

+84 937 869 689

Office address

91 Nguyen Chi Thanh, Dong Da, Hanoi, Vietnam

Get in touch

Tell us what you want to build, modernize, or operate.

Tell us what you want to build, modernize, or operate.

Contact Netbase