Justin McKelvey

Justin McKelvey

Fractional CTO · 15 years, 50+ products shipped

AI for Business • 5 min read •

AI Governance Framework (2026): What NIST and the EU AI Act Actually Ask of a Business Your Size

The short answer

An AI governance framework is the set of rules for how your company picks, uses and checks AI: who owns it, which tools are approved, what data can go in, who reviews what comes out, and how often you look again. As of September 2026 the reference framework in the US is NIST's AI Risk Management Framework, which is voluntary, organized around four functions (Govern, Map, Measure, Manage) and currently being revised. The EU AI Act, the one with legal teeth, has applied since August 2, 2026.

Most of what ranks for this phrase is written for a bank with a risk department. If you run a company of 10 to 200 people, you do not need that. You need the same four ideas on two pages, with a name next to each one. That is what this is.

The reference framework: NIST's AI RMF in one paragraph each

NIST released the AI Risk Management Framework (AI RMF 1.0) on January 26, 2023 and describes it as "intended for voluntary use." Its core is four functions. From NIST's own document:

  • Govern. "A culture of risk management is cultivated and present." Policies, roles, accountability. NIST calls it "a cross-cutting function" that runs through the other three, which is why it sits in the middle of their diagram.
  • Map. "Context is recognized and risks related to context are identified." For each AI use: what is it for, who does it affect, what goes wrong if it is wrong.
  • Measure. "Identified risks are assessed, analyzed, or tracked." Testing, spot checks, error rates.
  • Manage. "Risks are prioritized and acted upon based on a projected impact." Fix, limit, or stop.

Two lines in the document matter more than the diagram. NIST says the actions "do not constitute a checklist," and that after putting Govern in place, "most users of the AI RMF would start with the MAP function." Translation: decide who is in charge first, then list what you are actually using. Everything else follows from that list.

What changed in 2026, and why the date on your template matters

If you downloaded an AI governance template last year, three things on it are probably stale:

  • NIST is rewriting the framework. NIST's AI RMF page now says "The AI RMF 1.0 is being revised as part of the White House AI Action Plan." It also added a Generative AI Profile (NIST-AI-600-1, July 26, 2024) and, on April 7, 2026, a concept note for a critical-infrastructure profile. Anything built on 1.0 still works, but expect the wording to move.
  • The EU AI Act is live. It entered into force on August 1, 2024 and became applicable on August 2, 2026, which is also when the EU's AI Office and national authorities started enforcing it.
  • The high-risk deadlines moved. The "AI Omnibus," which entered into force on July 27, 2026, pushed the rules for high-risk uses in sensitive areas (the list includes employment, education and critical infrastructure) to December 2, 2027, and for AI built into regulated products to August 2, 2028. A lot of 2025 content still tells you August 2026 for all of it.

Two EU obligations did not move and have applied since February 2, 2025: the ban on the nine prohibited practices, and the AI literacy obligation. If you sell into the EU, "our people have been trained on the AI they use" is already a requirement, not a best practice.

The version a 10 to 200 person company can run

Here are NIST's four functions turned into five things you can finish this quarter. The shape maps cleanly onto the reference framework if a bigger customer ever asks, and it does not need a compliance team.

What you write down NIST function What it looks like at 50 people
1. One named owner Govern A person, not a committee. Usually the COO or whoever already owns vendor decisions. Their name is on the policy.
2. The tool inventory Map Every AI tool in use, who uses it, what data it touches, which plan you are on. Expect to find tools nobody approved.
3. Data rules Govern / Map Three tiers: fine to paste, only in approved business-plan tools, never. Customer and employee personal data usually lands in the last two.
4. A review step Measure / Manage Anything AI-drafted that reaches a customer, a contract or a hiring decision gets a named human reviewer first.
5. A quarterly check Manage Thirty minutes: update the inventory, read the incident log, change one rule. Put it on the calendar now.

Item 3 and item 4 are what employees actually read, so they belong in your AI acceptable use policy, the one document everyone signs. The other three live with the owner.

What the framework documents do not tell you

Every framework assumes someone has time to run it. That is the part that fails in mid-size companies. The policy gets written, the committee meets twice, and six months later the tool inventory is fiction because three teams bought their own AI subscriptions on a card.

The fix is not a better template. It is one owner with a small, fixed amount of time, and a rule that new AI tools get added to the inventory before anyone pays for them. If you are big enough that this is a real job, that is when the chief AI officer question becomes serious. Below that, it is a few hours a month for someone who already has the vendor list.

ISO/IEC 42001 also exists as a management-system standard for AI. If a customer ever requires it, you will know, because it will be in the contract. Until then, a NIST-shaped two-pager is the one that gets used.

Where to start this week

Name the owner. Then have them send one message to every team lead: "List every AI tool your team used this month and what you put into it." That list is your Map step, and it is almost always the most surprising document in the whole exercise.

If you lead the company and want the executive view of where AI fits before you govern it, my guide to AI for executives covers that. If you want outside help, read what to ask an AI consultant before you sign anything. And if you want the inventory, the risk map and a written roadmap done for you, that is exactly what my AI Readiness Assessment produces ($2,500, delivered in two weeks).

Free Resource Justin McKelvey

Get the Free AI Content Toolkit

The exact system I use to turn one idea into a month of content — atomization framework, voice template, prompt library, weekly system.

Frequently Asked Questions

What is an AI governance framework?
It is the set of rules and roles for how a company chooses, uses and checks AI. In practice that means five things: a named owner, an inventory of the AI tools in use, rules for what data can go into them, a review step for what comes out before it reaches a customer, and a schedule for checking all of it again. Published frameworks like NIST's AI Risk Management Framework give you the structure; the framework you actually run is those five things written down for your company.
What are the four functions of the NIST AI Risk Management Framework?
Govern, Map, Measure and Manage. Govern builds the culture, policies and accountability and runs across the other three. Map identifies the context and risks of each AI use. Measure assesses, analyzes or tracks those risks. Manage prioritizes them and acts on them. NIST says the actions are not a checklist and not necessarily in order, but that after Govern most users start with Map.
Is the NIST AI RMF mandatory?
No. NIST describes the AI RMF as intended for voluntary use. It was released on January 26, 2023, a Generative AI Profile (NIST-AI-600-1) followed on July 26, 2024, and as of September 2026 NIST says the framework is being revised as part of the White House AI Action Plan. It is still the reference most US buyers, auditors and enterprise customers point to.
Does the EU AI Act apply to my business?
It can if you sell into the EU or your AI system's output is used there. The Act entered into force on August 1, 2024 and became applicable on August 2, 2026. Prohibited practices and the AI literacy obligation have applied since February 2, 2025. After the AI Omnibus that entered into force on July 27, 2026, the high-risk rules for areas like employment and education apply from December 2, 2027, and for AI built into regulated products from August 2, 2028.
What is the difference between an AI governance framework and an AI policy?
The policy is one document that tells employees what they may and may not do with AI. The framework is the system around it: who owns AI decisions, how new tools get approved, how risks are checked, and when the policy gets revised. A policy without a framework is a PDF nobody enforces. A framework without a policy has no rules for the people using the tools every day.
Does a small business need an AI governance framework?
It needs a small one. Once more than a handful of people use AI tools with company or customer data, you need a named owner, a list of approved tools, data rules, a human review step for customer-facing output and a quarterly check. That fits on two pages. A 40-page framework copied from an enterprise template is governance theater; nobody at a 30-person company will read it.

More on AI for Business

ChatGPT Business vs Plus (2026): Which One a Small Business Should Actually Pay For

ChatGPT Plus vs Business, as of September 2026: Plus is $20 a month for one person and OpenAI may train on your chats unless you opt out; Business is $20 a seat billed annually or $25 monthly, two seats minimum, with no training by default, admin controls, shared projects for groups, and the Company Knowledge plugin. The side-by-side from OpenAI's pages, and three owner scenarios with a verdict each.

6 min

ChatGPT for Customer Service (2026): What Works, What Breaks, and What It Costs a Small Business

ChatGPT for customer service, as of September 2026: it drafts replies, answers policy questions from your own documents, and triages an inbox for $20 to $25 a seat a month on ChatGPT Business. It can't look up an order, issue a refund, or remember a customer unless you connect the system that holds them. The honest capability line, the plan you need, a setup in six steps, the failure modes, and the point where a real agent takes over.

7 min

ChatGPT Pulse (2026): What It Was, Why OpenAI Retired It, and How to Get the Morning Brief for Your Business

ChatGPT Pulse, the daily research cards OpenAI previewed for Pro users in September 2025, was sunset on June 17, 2026 with a 14-day wind-down. What it did, which plans ever had it, why scheduled tasks replaced it, and how an owner rebuilds the morning brief on a Plus or Business seat without handing ChatGPT the wrong things.

7 min

Claude Science (2026): What It Is, Who Gets It Free, and What Stays on Your Machine

Claude Science is Anthropic's beta workbench app for researchers, not a new model. It runs analyses on your own laptop or cluster, comes with Pro and up, and verified academic labs can get Team seats at no cost to start. Here is what it does, what it costs, and what actually leaves your machine, as of September 2026.

4 min
Justin McKelvey, Fractional CTO and AI consultant in Austin, TX

Written by

Justin McKelvey

Fractional CTO & AI consultant in Austin, TX. 15 years building software, 50+ products shipped, $53M+ in client revenue generated. I help $1M–$50M founders ship production software and automate operations with AI — without hiring a full-time executive team.

Work with me

If this was useful, here are two ways I can help: