Does my startup need AI governance?
If your team uses AI tools or your product calls an LLM, you need some AI governance. The question is how much. Answer five questions and see whether a one-page policy and an inventory are enough, or whether you need a documented programme or a full AI management system.
Yes, if your team uses AI tools or your product is built on an LLM, though how much depends on what you do. Most startups need a one-page AI use policy, an inventory of AI tools and features, and vendor terms that stop providers training on your data. Add documented risk assessments when customers send AI questionnaires, and a full AI management system when AI makes decisions about people.
Result
Customers are sending AI questionnaires, so you need written answers backed by evidence: a policy, an inventory of AI features and the models behind them, vendor terms on training and retention, a risk assessment for each feature, and how you test outputs. With EU users, an AI chatbot or generated content also brings the Article 50 duty to disclose AI and mark synthetic content, in force since 2 August 2026.
- Policy: a one-page AI use policy: which tools are approved, what data may never go into them, and who signs off a new one.
- Inventory: a list of every AI tool and AI feature: vendor, owner, purpose, data it sees, and whether customers are affected.
- Vendors: check each AI provider's terms: whether it trains on your inputs, how long it retains them, where it processes them. Use business or API terms that exclude training, and add the provider to your subprocessor list.
- Answer: publish an AI section on your trust page so questionnaires can point to it.
- Next: when a buyer asks for a certificate, see the ISO 42001 checker.
What AI governance means for a startup
For most startups, AI governance is four documents and a habit: a short AI use policy, an inventory of AI tools and features, the vendor terms for each model provider, and a risk note for each customer-facing AI feature. The habit is updating them when a new tool or feature appears. Larger programmes add evaluations, bias testing, incident handling and management review, which is what a certifiable AI management system such as ISO 42001 formalises. See AI governance.
Training on your data
The commonest question in an AI questionnaire is whether customer data is used to train models. The answer depends on your provider's terms, which often differ between consumer apps, business plans and the API. Record which terms apply to each tool, prefer ones that exclude training and set short retention, and list model providers as subprocessors when they process customer personal data.
What the law requires
The EU AI Act is the one broad AI law in force. For a typical startup it means AI literacy (Art. 4, since 2 February 2025): take measures so staff who use or operate AI understand it; and transparency (Art. 50, since 2 August 2026): tell people they are talking to an AI and mark generated content. High-risk duties apply only to uses such as hiring and credit scoring, from 2 December 2027. Privacy law (GDPR, CCPA, DPDP) applies to the personal data you send to models. US state AI laws are changing quickly, so check each one's current text.
Voluntary frameworks
The NIST AI RMF is free and voluntary, organised around Govern, Map, Measure and Manage, with a Generative AI Profile (NIST AI 600-1). ISO/IEC 42001 is voluntary and certifiable, and it is the one buyers ask for by name. Neither is required by law, and neither gives conformity with the EU AI Act. See ISO 42001 vs NIST AI RMF.
Sources
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), EUR-Lex
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex
- European Commission: AI literacy questions and answers
- NIST: AI Risk Management Framework
- Colorado General Assembly: SB24-205, Consumer Protections for Artificial Intelligence
- Colorado General Assembly: SB25B-004, delaying SB24-205
Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.
The things people ask us
Does a startup need an AI policy?
Yes, if anyone uses AI tools at work. A one-page policy listing approved tools, the data that must never go into them and who approves new ones covers most of the risk and answers the first questionnaire question.
What should an AI use policy include?
Approved tools and accounts, data that is banned from AI tools (customer data, secrets, credentials), rules for checking AI output before it is used, who approves new tools, and how to report a problem.
What is an AI system inventory?
A list of every AI tool and AI feature in use, with its vendor, owner, purpose, the data it sees and whether customers are affected. It is the starting point for the EU AI Act, ISO 42001 and customer questionnaires.
Does OpenAI or Anthropic train on my company's data?
It depends on the product and terms you use. Business plans and API terms often exclude training, and consumer apps may not. Check the current terms for each tool and account you use, and record the answer.
Is AI literacy training mandatory under the EU AI Act?
Article 4 requires providers and deployers to take measures to support their staff's AI literacy, and has applied since 2 February 2025. No specific level or certificate is required; the Commission says an internal record of training is enough.
Is the NIST AI RMF mandatory?
No. NIST describes the AI RMF as intended for voluntary use. It is a common way to structure AI risk work, especially for US buyers.
Do I need ISO 42001 for AI governance?
No. ISO 42001 is voluntary. It is worth certifying when AI is central to your product and enterprise buyers ask for evidence of AI governance; until then a policy, an inventory and documented risk assessments are enough.
When does the Colorado AI Act take effect?
SB25B-004 moved the Colorado AI Act's requirements to 30 June 2026. The law has been amended since it passed, so check its current status with the Colorado General Assembly before relying on a date.
See what applies to you, and track it.
TryTrustable maps your controls to every framework you need and keeps the evidence current.