Home · Blog
GRC

AI governance in an SME: who leads the artificial intelligence?

July 15, 2026 · 8 min read · ODCUS

Artificial intelligence has long been inside most SMEs. Accounting uses an AI assistant, marketing drafts with ChatGPT, a chatbot runs in customer service, and in Microsoft 365 Copilot is one click away. What is missing is not the technology. What is missing is the answer to three questions: which AI do we use deliberately, who is accountable for it, and which data do we hand over in the process?

AI governance is the frame a company uses to decide which artificial intelligence it deploys, who is accountable for it and how the risks are controlled. It keeps AI from staying a blind spot in operations and turns it into a deliberate decision with clear ownership.

TLDR

AI governance settles which AI a company uses, who owns it and how the risks are controlled. For an SME this is not a new speciality but the existing security and compliance leadership, extended to AI as a new asset class. It becomes relevant twice over: through your own risks such as data leakage and bad decisions, and through regulation, because the EU AI Act reaches Swiss companies too and Switzerland is preparing its own bill by the end of 2026.

Does an SME really need AI governance?

Yes, as soon as AI influences decisions or works with personal data. That is the case in almost every company, often without anyone having deliberately approved it. The reason is two kinds of risk that cannot be delegated away.

The first is operational. Staff upload customer data, contracts or source code into tools whose providers sit somewhere outside Switzerland. An AI model pre-selects job applications or credit decisions without anyone knowing the criteria. When something goes wrong, accountability lands with the board, not with the model. The second is regulatory, and it is closer than many assume.

What belongs to AI governance?

AI governance consists of a few understandable building blocks. It is not about a thick rulebook, it is about the following things existing and being maintained.

None of this requires a department of its own. It requires someone who keeps the overview and holds the threads together.

The thinking error: AI governance is not a new discipline that needs a new position or a new tool. It is lived security leadership, extended to AI. Anyone already running a risk register, an asset inventory, access controls and reporting to the management team already owns the apparatus. AI is a new asset class inside it, not a new continent. More control comes from extending what exists, not from buying a second governance landscape.

What does the EU AI Act change for Swiss SMEs?

The EU AI Act applies to Swiss companies as soon as the output of their AI is used in the EU. What counts is not where the company is registered but where the effect lands (Article 2). Swiss software with an AI feature and EU customers falls under it, regardless of Switzerland not being an EU member.

On timing, some pressure is off: certain AI practices have been banned in the EU since February 2025, while the obligations for high-risk AI were postponed to 2 December 2027 with the Digital Omnibus (provisional agreement on 7 May 2026). Postponed is not cancelled. Source: EU AI Act Service Desk, implementation timeline.

In parallel Switzerland is preparing its own rules. On 12 February 2025 the Federal Council decided to regulate AI in a way that makes ratification of the Council of Europe AI Convention possible, with a consultation draft by the end of 2026 covering transparency, data protection, non-discrimination and supervision. Source: Federal Council press release. For an SME that means the basic structure you build now carries into both rulebooks.

If you want to know what such a leadership role looks like on a mandate, the basics are in what is a fractional CISO. How a mandate starts is shown in the typical process: stocktake first, measures after.

Frequently asked questions

Who should own AI governance in an SME?

Ideally the person or role that already leads information security, because AI risks need the same toolbox: risk register, data classification, access control, reporting. In many SMEs that role does not exist internally in full depth. Then a fractional CISO takes it on as part of a mandate, instead of creating a new position.

Is an AI policy enough?

A policy is a good start, but on its own it does nothing. A document nobody knows and nobody enforces changes no behaviour. What counts is lived practice: that new AI use really does get approved, that the register stays current, and that someone steps in on critical cases. Governance is what happens, not what is written down.

Do we need ISO 42001 straight away?

In most SMEs, not immediately. ISO 42001 is the standard for an AI management system and can make sense once customers or a supervisory body demand formal evidence. To begin with it is enough to embed AI cleanly into the existing security and compliance system. You take the step to certification when there is a concrete reason, not as a precaution.

Not sure whether a fractional CISO fits your company?

In a free intro call we work out whether senior security leadership on a mandate makes sense for your company, and in what form. Honest answer included, even when it is "not yet".

Book a free intro call