Mid-market companies are adopting AI through Salesforce, Microsoft 365, NetSuite, HubSpot, and a dozen point tools—often without a single inventory of what was turned on. Responsible AI is not a philosophy seminar. It is an operating cadence: what systems exist, what data they touch, who can approve new use cases, and how you shut one down.
A governance model that fits 200–2,000 employees
Skip the ceremonial committee that meets twice a year. Create a small AI review circle: IT security, a business process owner, legal/HR as needed, and finance if ledgers are in scope. Meet monthly for 45 minutes with a living register.
- System name and vendor
- Data classes (public, internal, confidential, restricted)
- Whether prompts or files leave your tenant
- Human review required? Write-back allowed?
- Owner, residual risk, next review date
Risk tiers you can explain to the CEO
Tiered controls beat one giant policy nobody reads
| Tier | Examples | Approval | Minimum controls |
|---|---|---|---|
| Low | Grammar in marketing drafts | Manager | No customer PII in prompts |
| Medium | Support copilot on help center | IT + process owner | Citations, red-team prompts, logs 90 days |
| High | ERP posting suggestions, resume screening | Review circle + exec sponsor | DPIA-style note, SoD, appeal path |
| Banned | Covert recording analysis, biometric HR scoring | N/A | Block in contracts and CASB |
Vendor questions that surface reality
- Is our data used to train foundation models? Get the answer in the DPA, not a slide.
- Where is inference hosted, and can we pin a region?
- How do we export logs for an incident or audit?
- What is the subprocessors list for the AI feature specifically—not the core SaaS app from 2019?
Conclusion
Mid-market AI governance should be boring: an inventory, three risk tiers, named owners, and contractual clarity on training data. That lightweight system lets you move faster than enterprises stuck in policy theater—and safer than startups that paste customer contracts into a public chatbot.