7 min read

AI Governance in Small and Medium-Sized Enterprises: Role Model and 4-Week Plan

AI Governance: Role Model & 4-Week Plan | prodot
13:22

41 percent of German companies use AI, but only 21 percent have a strategy. And only 37 percent have clearly defined responsibilities. Starting August 2, 2026, the EU AI Office will actively enforce the AI Act. Companies that do not have governance in place by then risk fines, “shadow AI” damage, and a loss of control. This article presents a streamlined role model for small and medium-sized enterprises (SMEs) and a 4-week plan for implementation.

Current Situation: 63 percent manage AI without clear responsibilities

The figures from the 2026 Bitkom study are clear: 41 percent of German companies are using AI productively, and another 48 percent plan to do so. Yet only 21 percent have a formal AI strategy in place. The implementation gap has long been evident. AI is widely used, but poorly managed.

The picture is even more dramatic when it comes to responsibilities. The KPMG study “Generative AI in the German Economy 2026” shows that only 37 percent of companies have clearly defined responsibilities and governance structures for generative AI. Fewer than 10 percent have implemented a comprehensive governance model. Deloitte reaches a similar conclusion in its 2026 analysis: Of the companies that plan to introduce agent-based AI in the next two years, only 21 percent currently have a mature governance model for AI agents.

McKinsey quantified the cost of this in its 2026 report: Organizations with clearly assigned governance roles achieve a maturity score of 2.6, while organizations without clear accountability remain at 1.8. In other words: fewer governance incidents, faster AI deployments, and lower regulatory risk.

What happens when governance is lacking: Shadow AI and fines

The consequences of a lack of governance are not theoretical. In 2026, they will measurably affect companies on three levels.

Shadow AI: 66 percent of employees use AI without authorization. IBM and other analysts report that by 2026, 66 percent of all office workers in large companies will be using AI tools without official authorization. In small and medium-sized businesses (100 to 999 employees), the rate is 61 percent. Particularly alarming: 27 percent of all enterprise employees have already entered confidential company data into public AI tools—including customer lists, financial figures, and internal strategy documents. The IBM “Cost of a Data Breach Report 2026” estimates the additional damage per incident involving shadow AI at $670,000.

EU AI Act: Active enforcement begins August 2, 2026. As of this date, active enforcement by the EU AI Office will take effect. Fines for violations of high-risk rules can reach up to 15 million euros or 3 percent of global annual revenue. Among other things, AI systems for mass biometric surveillance, social scoring, and emotion recognition in the workplace are prohibited. High-risk systems (hiring, lending, security components) are subject to extensive documentation and oversight requirements. Anyone who has not yet registered their AI systems does not even know where their risks lie.

Governance roles without a mandate. A study by NEXperts (Handelsblatt-Verlag) shows that many small and medium-sized enterprises have appointed AI managers or AI officers, but these individuals lack formal decision-making authority. They are expected to play a strategic, operational, and coordinating role, but have neither a budget nor the authority to approve projects. In their 2026 SME study, Cancom and ServiceNow even report that unclear governance actively hinders the scaling of AI projects.

prodot KI-Governance Mittelstand Rollenmodell

What AI governance is in the SME sector. And what it isn’t.

Before we get to the role model, let’s clear up three misconceptions that prevent SMEs from establishing a governance framework.

AI governance is not a 200-page framework. Anyone who confuses governance with compliance bureaucracy is missing the point. A lean role model with clear approval processes and an AI registry beats any unread set of rules. For SMBs, 15 to 30 pages of policy plus a RACI matrix are typically sufficient.

AI governance doesn’t need a Chief AI Officer. For 90 percent of SMEs, a dedicated C-level role for AI is excessive. What’s needed are clear responsibilities within existing roles. Whoever is responsible for data protection today will also be responsible for AI data protection tomorrow. Whoever heads IT today is responsible for technical AI security.

AI governance is not the same as AI monitoring. Monitoring detects technical errors in running systems. Governance answers the question: Who decides on its use? Who bears responsibility? Who shuts down a system if it goes off the rails? Monitoring is the tool. Governance is the hand that guides it.

The Lean 3-Role Model for Small and Medium-Sized Businesses

In consulting practice, a model with three basic roles has proven effective for small and medium-sized enterprises. It is scalable from 100 to 2,000 employees and, in most cases, can be staffed using existing roles.

ux-consulting1. The Sponsor
Based at the executive or divisional management level. Holds the mandate and the budget. Defines the strategic direction: Which business goals should AI support? What risks are acceptable? The sponsor is not an operational role, but without a sponsor, any AI governance remains ineffective. Time commitment: 1 to 2 hours per month.

2. The AI Committee
Three to five people from IT, data protection, and relevant business units. Expanded as needed to include compliance, the CISO, and the works council. Meets monthly, decides on new use cases, classifies risks, and approves pilot projects and production rollouts. The committee is the operational heart of governance. Time commitment: 2 to 4 hours per month per member.

3. The Use Case Owner
There is exactly one person responsible for each use case. The use case owner formulates the business case, reviews the data, is responsible for the quality of the results, and reports incidents. In most medium-sized companies, this role is filled by the department head or a designated project manager. Time commitment: variable, typically 4 to 8 hours per month per use case.

Optional: The AI Officer. For companies with 500 or more employees, it is worthwhile to assign an additional role with 20 to 50 percent capacity to prepare the committee, maintain the AI registry, and serve as the liaison to the compliance department. In smaller companies, this task is handled by the data protection officer with an AI focus.

The key point: All roles require a written mandate. Who decides what, and within what framework? Who is authorized to halt a use case? Who escalates to whom? Without this clarification, even the best-conceived model will remain ineffective.

The 4-Week Plan: Establishing Governance Without a Full-Time Project

The role model alone is not enough. You need an implementation plan that runs alongside day-to-day operations. The following plan works in companies with 100 to 1,500 employees.

image 2Week 1: Create an AI registry and take inventory.
Record every AI application currently in use at the company: ChatGPT, Microsoft 365 Copilot, Deepl, GitHub Copilot, chatbots, and specialized business applications. For each entry, include: purpose, data source, affected groups of people, provider, and person responsible. Result after Week 1: a structured Excel or SharePoint list with typically 15 to 40 entries. You’ll be surprised at how much is already in use.

Week 2: Define roles and formalize their mandates in writing.
Who is the sponsor? Who sits on the committee? Who has what decision-making authority? A brief mandate (one A4 page per role) is sufficient. It’s important that the sponsor signs it. At the same time: Send out invitations for the first committee meeting in Week 3. Prepare the three to five riskiest entries from the register as the first cases.

Week 3: Pilot the approval process.
The committee meets for the first time. On the agenda: the three most critical use cases from the registry. Have they been classified (according to the EU AI Act: minimal, limited, high, prohibited)? Have the data protection issues been clarified? Is there a use case owner? Result: first documented approval decisions. Not perfect, but robust.

Week 4: Document and roll out the process.
Document how a new use case will be submitted, reviewed, and approved from now on. A form, an email distribution list, a regular meeting. Communicate the process throughout the company. From now on, every new AI application must go through the committee. Existing applications will be retroactively classified over the next two quarters.

After four weeks, you’ll have: an AI registry, a fully staffed committee, a documented approval process, and the first classifications. This isn’t perfect governance. But it’s significantly more than 63 percent of your competitors have.

The 5 Most Common Mistakes When Establishing AI Governance

1. An AI officer without decision-making authority. The most common mistake, according to the NEXperts study. An AI officer without a formal mandate becomes a figurehead. A sponsor’s signature on the mandate is not a mere formality—it is a prerequisite for effectiveness.

2. A committee without a data protection officer. AI systems process personal data in almost all cases. A committee without a data protection officer regularly makes decisions without this critical perspective. The result: approvals that fail audit.

3. No AI registry. If you don’t know what’s in use, you can’t manage it. The registry isn’t just a chore—it’s a prerequisite for any prioritization. Without a registry, there’s no risk classification; without classification, there’s no compliance with the EU AI Act.

4. Centralize all decision-making. If every prompt test has to go through the committee, governance slows down progress. The approval process should have clear criteria for when an application requires approval. Standard use of Copilot with approved data does not require a case-by-case decision.

5. Governance without monitoring. Those who grant approvals but do not monitor production systems lose control after go-live. Governance approval and ongoing monitoring go hand in hand. Our dedicated page on AI monitoring shows which questions technical AI monitoring answers in practice and how we set it up together with customers.

L1140684

How prodot supports you in establishing AI governance

prodot has been supporting medium-sized companies with digital transformation and compliance for over 20 years. When it comes to establishing AI governance, we bring three key elements to the table that form the foundation of your 4-week plan.

Governance Workshop: Over the course of two days, we’ll work with you to develop the AI registry, a tailored role model, and the approval process. You’ll leave the workshop with mandates ready for signature and the first draft of the registry.

Monitoring as a Governance Tool: Together with you, we set up a suitable AI monitoring system. It provides the technical foundation for monitoring, audit trails, and the mandatory logging requirement of at least six months for high-risk systems. This ensures that governance decisions and technical implementation are seamlessly integrated.

Alignment with the AI Strategy: Building governance without a strategy leads to uncontrolled growth. In a joint AI workshop, we’ll work with you to integrate strategy, use case selection, and governance into a consistent approach.

Conclusion: Governance is the difference between AI deployment and AI management

The numbers speak for themselves. 41 percent use AI, 21 percent manage it with a strategy, and 37 percent have clear lines of responsibility. Starting August 2, 2026, the rules of the game will change. Those who have a registry, a committee, and an approval process in place by then are in the “yellow zone.” Those still at square one are playing roulette.

Small and medium-sized enterprises (SMEs) have a structural advantage: short decision-making paths, well-defined roles, and direct communication. What takes 18 months in a large corporation can be up and running in four weeks at an SME—provided the role model is streamlined, the mandate is clear, and governance isn’t confused with compliance bureaucracy.

The good news: If you start today, you’re on time. If you start in the fourth quarter of 2026, you’ve already lost.


Do you want to establish AI governance but don’t know where to start? Talk to us. In a free initial consultation, we’ll assess your current situation and outline the right roadmap for your company.

Sie haben Fragen zur KI-Governance?
Wir helfen Ihnen gerne weiter.