ADAM PULSE Knowledge Base
AI Governance · Small Business · NIST AI RMF · CSF 2.0

AI governance framework for small and mid sized businesses

Short answer

You do not need an enterprise GRC stack to govern AI. You need a named owner, a short acceptable-use policy that points at a living approved-tool list, data classes you already use, an intake for Shadow AI, literacy so the paste rule survives a deadline, and a hard rule that agents do not get write access until identity, allowlists and a tested stop exist.

NIST AI RMF 1.0 (Govern, Map, Measure, Manage) and NIST CSF 2.0 (including Govern) are voluntary. NIST says organizations are not required to use the AI RMF. This page uses them as grouping language, not as a filing. Completing it does not make you CMMC Level 2 certified, FedRAMP authorized, or EU AI Act conformant.

This is the operating-model cut of AI agent security for business. The document the policy slot needs is How to create a corporate AI acceptable use policy. The expansion pack is the 40-control checklist.

Six pieces a small team can keep

Map to voluntary frameworks without pretending they are a certificate.
PieceJobClosest grouping
OwnerOne executive, in writingAI RMF Govern; CSF 2.0 Govern
PolicyShort AUP + living approved listGovern
InventoryApproved / restricted / blocked, datedMap; CSF Identify
ClassificationExisting labels mapped to toolsMap
LiteracyOnboarding + agent moduleGovern; EU Art. 4 if in scope
Agent ruleNo write until the 12 safeguardsManage; technical controls

1. Owner, not a committee with no teeth

Name one person who can say no. They can ask IT, legal, and operations to do the work. They cannot delegate the “we did not know” answer. If the only artifact is a steering committee deck, the program is still a slide.

2. Policy that people will read

Twelve sections, a few pages, living tool list off to the side. Purpose, scope, approved AI, prohibited data mapped to existing classification, human verification, labeling, agents, integrations, Shadow AI intake, IP, security, training. Sample block: corporate AI acceptable use policy. A policy with an empty approved list is a ban. A ban without a sanctioned path recreates Shadow AI on personal phones.

3. Inventory you will actually update

Fields and cadence: How to build an enterprise AI inventory. Discovery methods: What is Shadow AI and how do you find it? Microsoft Shadow AI in the admin center is one feed, not the list.

Start with what you cannot yet answer

The Shadow AI Risk Assessment is a scored questionnaire. No account, answers stay in the browser, not a network scan. Use it before you write the approved-tool list.

Run the assessment →

4. Classification you already have

Do not invent “AI-sensitive.” Public, Internal, Confidential, and CUI if you use them. Each approved tool gets a written list of classes it may receive. A prompt is a data transfer. This article does not use health-record examples; if you are a covered entity, your existing privacy program owns that mapping.

5. Literacy without a fake certificate

EU AI Act Article 4 has applied since 2 February 2025 to in-scope providers and deployers. Regulation (EU) 2026/1744 (in force 27 July 2026) restated the duty as measures that support the development of AI literacy — not a guaranteed individual proficiency level, and not a named certificate. Article 50 transparency has applied since 2 August 2026. Neither is an automatic US employer duty. For everyone else, put the paste rule, the approved list, and the Shadow AI intake in onboarding. People who operate agents complete an extra module before the agent is enabled.

6. Agents are a different control set

A chatbot returns text. An agent calls tools. Instructional controls (this framework) tell people what should happen. Technical controls (identity, allowlists, orchestrator approval, logs, kill switch) are what actually happens. Never rely on the model to enforce permissions. The twelve numbered safeguards are on the pillar. The Microsoft 365 cut is How to secure AI agents connected to Microsoft 365. Incidents fold into the playbook you already have: AI incident response plan.

A quarterly cadence that fits a mid-market calendar

  1. Owner reviews the approved / restricted / blocked list (30 minutes, not a workshop).
  2. OAuth grants and new AI destinations since last quarter.
  3. One department interview you skipped last time.
  4. Kill-switch test on a non-production agent, if you have any that can act.
  5. Policy examples updated if an incident or intake taught you something.

That is Measure and Manage in AI RMF language, without buying a GRC platform to hold the minutes.

Frequently asked questions

Does adopting NIST AI RMF certify us?

No. NIST states the AI Risk Management Framework is voluntary. NIST does not certify organizations against it. CSF 2.0 is likewise not a certification scheme. Completing this framework does not make you CMMC Level 2 certified or FedRAMP authorized.

Do US small businesses have to comply with the EU AI Act?

Not automatically. Article 4 literacy has applied to in-scope providers and deployers since 2 February 2025. Article 50 transparency has applied since 2 August 2026. Those duties apply in the Union market. A US-only company with no EU nexus should still treat literacy and labeling as good practice; do not invent a US legal duty from those articles.

What is the smallest governance program that is still real?

One named owner, a short acceptable-use policy pointing at a living approved-tool list, data classes mapped to that list, an intake for Shadow AI, and a rule that agents do not get write access until identity, allowlists and a tested stop exist. That is enough to start. The 40-control checklist is the expansion pack.

Do we need a responsible-AI committee?

Not as a substitute for an owner. A committee with no decision rights is how nothing ships and nothing is refused. The owner can ask others; they cannot delegate the “we did not know” answer.

Should we invent AI-specific data classes?

No. Map AI use to Public, Internal, Confidential, and CUI if you have it. A parallel taxonomy is how the policy diverges from how people already label files.

Where do agents fit in an SMB framework?

As a separate rule, not a chatbot footnote. Agents take actions. The 12-safeguard pillar is the agent-access list; this page only requires that write stays off until those safeguards exist.

Is training a certificate?

No. EU Regulation (EU) 2026/1744 restated Article 4 as measures that support the development of AI literacy, not a guaranteed proficiency level and not a named certificate. For everyone else, training is how the paste rule survives a deadline.

Where should we start this week?

Name the owner in writing, run the Shadow AI Assessment, and publish a one-page policy that points at an approved-tool list even if that list currently has one row. Empty lists are bans; bans without a path recreate Shadow AI on phones.

References

  1. NIST — AI RMF FAQs— the framework is voluntary; organizations are not required to use it.
  2. NIST AI 100-1 — AI RMF 1.0 (26 January 2023)— Govern, Map, Measure, Manage. Not a certification scheme.
  3. NIST AI 600-1 — Generative AI Profile (July 2024)— voluntary companion profile.
  4. NIST CSWP 29 — CSF 2.0 (26 February 2024)— Govern as a sixth function. Voluntary.
  5. Regulation (EU) 2024/1689— Article 4 (2 February 2025); Article 50; Article 113 dates.
  6. European Commission — Article 50 FAQ— Article 50 from 2 August 2026.
Prepared by ADAM Pulse (USA Telecom Consulting LLC)

Managed network and communications services, SDVOSB. Governance that fits a Tuesday, not a GRC brochure. This is not a CMMC or FedRAMP certificate. Support: (888) 989-4872 · support@adampulse.us