Three Questions That Replace a Compliance Team

Ninety-five percent of small-business owners expect difficulties complying with rules that require AI disclosure, risk assessments, and human oversight of consequential decisions. That figure comes from U.S. Chamber of Commerce research, and it describes a fear that is mostly about overhead, not obligation. The actual obligations, for a founder using a chatbot for customer support or a generative text tool for marketing copy, are structurally lighter than the fear suggests.
What the frameworks actually require from you
The OECD G7 taxonomy classifies most small businesses as "AI novices" using off-the-shelf tools in isolated workflows. Not integrated systems. Not bespoke models. A founder scheduling posts with an AI writing tool sits in a different risk category than a hospital deploying a diagnostic algorithm. The EU AI Act includes explicit proportionality provisions for SMEs precisely because regulators recognized this distinction. NIST's AI Risk Management Framework applies to small businesses through targeted measures, not the full enterprise stack.
The three obligations that appear consistently across NIST, the EU AI Act's SME provisions, and the OECD Recommendation on Artificial Intelligence are: knowing what data your tools touch, maintaining human oversight of consequential outputs, and having a named person accountable when something goes wrong. These are not aspirational ethics. They are the operational minimum.
The policy that fits on one page
Write down which AI tools access which data. Not a technical audit. A plain list: your CRM connects to your email AI, your customer support chatbot reads your ticketing system, your generative text tool does not touch payroll. That list forces a decision about every tool you add. It also gives you something to show a customer or regulator who asks how you handle their information.
Write down which outputs require a human to review before they go out. Anything that affects a hiring decision, a customer refusal, a financial recommendation, or a legal communication belongs on that list. The EU AI Act's human oversight obligations are most stringent around consequential decisions. A simple approval gate, even an informal one where a named employee reads the output before it sends, satisfies the documented intent of the requirement for most off-the-shelf use cases.
Write down one name next to "accountable if this goes wrong." Not a department. A person. The OECD Recommendation calls for traceability across datasets and decisions so organizations can analyze outputs and respond to questions. A named accountability owner is the minimum viable traceability structure. It also changes behavior. When someone knows their name is attached to AI failures, they read the outputs differently.
The objection worth taking seriously
A policy document without operational controls does not prevent harm. It documents intent. A founder who writes down that a named employee is accountable for AI failures has not built a mechanism that catches those failures before they reach a customer. That criticism is accurate and the research names it directly.
Where it breaks down: the criticism assumes the alternative is a more rigorous set of operational controls the founder would actually implement. The same research shows 86% of small-business owners believe proposed technology regulations harm their ability to grow. A governance standard calibrated for large organizations running integrated AI systems, applied to a founder using a generative text tool, does not produce better protection. It produces paralysis followed by no compliance at all.
The three-point policy works for the specific population the data describes: AI novices using off-the-shelf tools in isolated workflows. Founders whose use cases move toward higher-risk applications, automated hiring screens, credit decisions, medical triage, need to treat this as a floor and build upward from it.
Where the trust problem actually lives
Less than half of respondents in a global study cited by OECD expressed willingness to trust AI, even though roughly two-thirds already used it regularly. Adoption outpaced trust-building, and that gap is where legal and reputational risk accumulates for small businesses. A written policy does not close that gap by itself. What it does is create a documented record of decisions made before something went wrong, which is what every regulator and customer dispute resolution process asks for first.
The three questions are not a compliance certificate. They are the decisions you were already going to face, written down before the incident forces you to reconstruct them from memory.

Read next

AI as Strategy
Four AI Guardrails Every Small Business Needs Now
Most small businesses run AI tools on informal rules or none at all. Here are four specific controls that close the failure points where real harms occur.
3 min read

AI as Strategy
AI Governance Framework for Board Directors
Most AI board papers bury risk and dodge accountability. A one-page governance framework gives directors the map they need — exposure, controls, and named…
4 min read

Data as a Decision Infrastructure
Ten Data Rules Before Your First AI Model Ships
59% of early AI adopters struggle to enforce data governance. Here's a ten-point policy built for founders without compliance staff.
5 min read