Free tool · AI governance

Does my startup need AI governance?

If your team uses AI tools or your product calls an LLM, you need some AI governance. The question is how much. Answer five questions and see whether a one-page policy and an inventory are enough, or whether you need a documented programme or a full AI management system.

Short answer

Yes, if your team uses AI tools or your product is built on an LLM, though how much depends on what you do. Most startups need a one-page AI use policy, an inventory of AI tools and features, and vendor terms that stop providers training on your data. Add documented risk assessments when customers send AI questionnaires, and a full AI management system when AI makes decisions about people.

Answer for your organisation

Pick the deepest use. A company that builds on an LLM almost always has staff using AI tools too.
The EU AI Act applies to providers selling into the EU and to deployers in it, wherever the company is based.
Hiring or managing workers, credit, insurance, education, housing or access to essential services.
Worked example: a SaaS startup with EU customers whose product calls an LLM API

Result

An indication from your answers, not legal advice. Applicability turns on facts a form cannot see; confirm it with counsel or your auditor before you rely on it.
Likely required: a documented programme customers can review

Customers are sending AI questionnaires, so you need written answers backed by evidence: a policy, an inventory of AI features and the models behind them, vendor terms on training and retention, a risk assessment for each feature, and how you test outputs. With EU users, an AI chatbot or generated content also brings the Article 50 duty to disclose AI and mark synthetic content, in force since 2 August 2026.

Tell users they are interacting with AI; mark synthetic contentAI Act Art. 50 (EU)
AI literacy for staffAI Act Art. 4 (EU)
Lawful basis, DPA and subprocessor terms for personal data sent to model providersGDPR Arts. 6, 28
  • Policy: a one-page AI use policy: which tools are approved, what data may never go into them, and who signs off a new one.
  • Inventory: a list of every AI tool and AI feature: vendor, owner, purpose, data it sees, and whether customers are affected.
  • Vendors: check each AI provider's terms: whether it trains on your inputs, how long it retains them, where it processes them. Use business or API terms that exclude training, and add the provider to your subprocessor list.
  • Answer: publish an AI section on your trust page so questionnaires can point to it.
  • Next: when a buyer asks for a certificate, see the ISO 42001 checker.
01

What AI governance means for a startup

For most startups, AI governance is four documents and a habit: a short AI use policy, an inventory of AI tools and features, the vendor terms for each model provider, and a risk note for each customer-facing AI feature. The habit is updating them when a new tool or feature appears. Larger programmes add evaluations, bias testing, incident handling and management review, which is what a certifiable AI management system such as ISO 42001 formalises. See AI governance.

02

Training on your data

The commonest question in an AI questionnaire is whether customer data is used to train models. The answer depends on your provider's terms, which often differ between consumer apps, business plans and the API. Record which terms apply to each tool, prefer ones that exclude training and set short retention, and list model providers as subprocessors when they process customer personal data.

03

What the law requires

The EU AI Act is the one broad AI law in force. For a typical startup it means AI literacy (Art. 4, since 2 February 2025): take measures so staff who use or operate AI understand it; and transparency (Art. 50, since 2 August 2026): tell people they are talking to an AI and mark generated content. High-risk duties apply only to uses such as hiring and credit scoring, from 2 December 2027. Privacy law (GDPR, CCPA, DPDP) applies to the personal data you send to models. US state AI laws are changing quickly, so check each one's current text.

04

Voluntary frameworks

The NIST AI RMF is free and voluntary, organised around Govern, Map, Measure and Manage, with a Generative AI Profile (NIST AI 600-1). ISO/IEC 42001 is voluntary and certifiable, and it is the one buyers ask for by name. Neither is required by law, and neither gives conformity with the EU AI Act. See ISO 42001 vs NIST AI RMF.

05

Sources

Questions

The things people ask us

Does a startup need an AI policy?

Yes, if anyone uses AI tools at work. A one-page policy listing approved tools, the data that must never go into them and who approves new ones covers most of the risk and answers the first questionnaire question.

What should an AI use policy include?

Approved tools and accounts, data that is banned from AI tools (customer data, secrets, credentials), rules for checking AI output before it is used, who approves new tools, and how to report a problem.

What is an AI system inventory?

A list of every AI tool and AI feature in use, with its vendor, owner, purpose, the data it sees and whether customers are affected. It is the starting point for the EU AI Act, ISO 42001 and customer questionnaires.

Does OpenAI or Anthropic train on my company's data?

It depends on the product and terms you use. Business plans and API terms often exclude training, and consumer apps may not. Check the current terms for each tool and account you use, and record the answer.

Is AI literacy training mandatory under the EU AI Act?

Article 4 requires providers and deployers to take measures to support their staff's AI literacy, and has applied since 2 February 2025. No specific level or certificate is required; the Commission says an internal record of training is enough.

Is the NIST AI RMF mandatory?

No. NIST describes the AI RMF as intended for voluntary use. It is a common way to structure AI risk work, especially for US buyers.

Do I need ISO 42001 for AI governance?

No. ISO 42001 is voluntary. It is worth certifying when AI is central to your product and enterprise buyers ask for evidence of AI governance; until then a policy, an inventory and documented risk assessments are enough.

When does the Colorado AI Act take effect?

SB25B-004 moved the Colorado AI Act's requirements to 30 June 2026. The law has been amended since it passed, so check its current status with the Colorado General Assembly before relying on a date.

Book a walkthrough

See what applies to you, and track it.

TryTrustable maps your controls to every framework you need and keeps the evidence current.