# AI Governance

> Compaia helps SMEs set up AI governance: responsibilities, usage rules, AI policy, human oversight, training, register and evidence to control AI systems.

## Summary

Compaia helps move from scattered AI uses to readable, actionable AI governance proportionate to an SME.

## Key points

- AI governance must clarify who may use what, for which purpose and with which safeguards.
- For an SME, AI governance should start with simple rules, a living register, adapted training and evidence.
- It must connect internal policies, register, training and incident follow-up.
- A framework that is too heavy will not be applied; a framework that is too vague will not protect.

## Minimum building blocks

Proportionate governance starts with a few robust building blocks, then grows with usage.

- Internal AI policy and generative AI usage rules.
- AI usage register.
- AI literacy training.
- New use approval process.
- Incident tracking and periodic reviews.

## Frequently asked questions

### Does AI governance only concern high-risk systems?

No. High-risk systems require more measures, but common generative AI uses must also be governed.

### How should an SME start AI governance?

Start with the Compaia diagnostic, map real AI uses, create a short AI policy, train exposed people and keep evidence in the register.

## Sources

- [European Commission - AI Act](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai)

## Related resources

- [AI compliance tool for SMEs](https://compaia.eu/outil-conformite-ia)
- [Free AI Act assessment](https://compaia.eu/diagnostic)
- [AI policy generator for SMEs](https://compaia.eu/generateur-politique-ia)
- [AI Register](https://compaia.eu/registre-ia)
- [AI Literacy](https://compaia.eu/litteratie-ia)
- [AI Act Compliance for SMEs](https://compaia.eu/conformite-ai-act)
