AI Governance Checklist for Founders

You are probably using at least one AI tool right now with customer data flowing through it and no written record of who approved that, who owns the data, or what your privacy notice says about it. That is not a hypothetical risk. The EU AI Act classifies obligations by use case, not by company size, which means a five-person firm running AI-assisted HR screening carries the same legal classification as a large enterprise running the same thing.
The paper trail problem is not what you think
The sharpest objection to governance documentation goes like this: if you write down your AI tools incorrectly, listing the wrong risk category or misidentifying data types, you have created a paper trail that a regulator can use against you. Silence, the argument goes, is neutral. A written mistake is not.
This objection is worth taking seriously. It is also wrong about the starting position. A founder who uses an AI tool connected to customer data with no written record of it, no assigned data owner, and no updated privacy notice is not in a neutral position. When a data incident occurs, there is no documentation of due diligence at all. The FTC's enforcement record shows that actions turn on whether a firm took reasonable steps, not on whether those steps were legally perfect. An incorrect inventory is evidence of an attempt. Nothing written is evidence of nothing.
The checklist below is a stopgap. It does not replace legal counsel for high-risk use cases like automated credit assessment or employee screening. What it does is close the four failure modes that produce the highest-probability enforcement exposure before you have the capacity to address them properly.
Four steps, one working session
Start with a tool inventory. List every AI tool your team uses, the vendor name, what data it touches, and whether that data includes anything personal. Customer emails run through an AI writing assistant count. A chatbot connected to your CRM counts. An AI feature embedded in your accounting software counts. If you cannot name the data type, write "unknown" and flag it for follow-up. An incomplete inventory is more useful than no inventory.
Assign a data owner to each tool on the list. This is a person's name, not a job title. The data owner is responsible for knowing what the tool does with the data, reviewing the vendor's data processing terms, and flagging changes. AWS prescriptive security guidance frames this as the foundation of data classification: without a named owner, no one reviews access, no one notices drift, and no one is accountable when something changes in the vendor's terms of service.
Update your privacy notice. If your notice does not mention AI tools and your firm is using them to process personal data, your notice is inaccurate. The EU AI Act's transparency obligations for deployers require that individuals know when AI is involved in decisions affecting them. A privacy notice update does not need to be long. It needs to name the category of AI use and describe what data is involved.
Turn on access logging for any AI tool that touches personal or confidential data. AWS guardrails documentation describes logging as the minimum control that makes everything else auditable. Without a log, you cannot answer the basic question a regulator will ask: who accessed what, and when. Most SaaS tools with enterprise tiers offer this natively. If yours does not, that is itself a finding worth documenting.
What the EU AI Act actually requires from you
The staged enforcement timeline running from 2024 through 2028 means some obligations are already active. Deployers, which is the classification that applies to a founder subscribing to an AI tool built by someone else, carry affirmative duties including transparency, human oversight, and data governance. The risk classification is use-case driven. A firm using AI for content generation sits in a different category than a firm using AI for HR screening or customer credit profiling. The checklist above does not resolve that classification question. It does produce the documentation you need to answer it accurately when the question arrives.
A tool inventory with named data owners and a current privacy notice is not a compliance program. It is the minimum that shows a regulator you knew what you were running and who was responsible for it. That distinction, between a firm that documented its AI use and a firm that did not, is where enforcement proportionality gets decided.

Read next

AI as Strategy
Four AI Guardrails Every Small Business Needs Now
Most small businesses run AI tools on informal rules or none at all. Here are four specific controls that close the failure points where real harms occur.
3 min read

AI as Strategy
Your AI Policy Fits on One Page
Most small businesses use AI daily without written rules. Here's a time-bound checklist covering data handling, approved tools, and oversight for lean teams.
3 min read

AI as Strategy
AI Governance Checklist for Small Teams
A lightweight AI governance policy covering acceptable use, data boundaries, output verification, and escalation ownership — built for teams without legal or IT
3 min read