How to set up an AI committee in your company (without losing your mind): a practical guide for SMEs and mid-sized companies

You do not need 50 people or a new department. You need an AI Steering Committee with clear roles, a system of gates and a policy that fits on two pages. We explain how to set it up step by step.

AI is already in your company. You may not have decided it, but your employees are using ChatGPT, Copilot or Gemini to do their work faster. 76% of organisations report using unauthorised AI. And when something goes wrong —a data leak, content containing fabricated information or an automated decision without traceability— the question is always the same: who is responsible?

The answer should be: the AI Steering Committee, the AI committee. The body that turns principles and risks into evidence-based decisions. But most SMEs and mid-sized companies do not have one because they think it is only for large corporations.

It is not. A minimum viable AI committee can work with four or five people, meet for 90 minutes a month and radically change the way your company adopts AI: from chaotic to governed, from eternal pilots to fast decisions backed by evidence.

In this guide, we explain how to set it up step by step, what functions it must perform, who should be involved, how the Gate system works and how to write an AI policy that is not a dead document.

Why your company needs an AI committee (even if you only have 20 employees)

Without governance, AI becomes three things: a bottleneck, a risk and waste. These are the specific problems an AI committee solves:

Uncontrolled Shadow AI

Your teams use AI tools on their own, without a policy, approval or knowing which data they may share. The committee detects these uses, assesses them and decides whether to regularise or stop them.

Eternal pilots without criteria for moving forward

Someone launched an AI test six months ago and nobody has decided whether to continue, stop or scale it. Without a gate system with clear criteria (GO/FIX/KILL), pilots become zombies that consume resources without generating value.

Bureaucracy that slows innovation

When there is no clear channel for proposing and approving AI uses, teams either bypass the controls (Shadow AI) or become frustrated and give up. The committee creates a fast, safe path for innovation to flow.

Growing regulatory risk

The AI Act is in force. The GDPR was already in force. NIS2 is coming into play. AI Act penalties can reach €35 million or 7% of global turnover. An AI committee ensures that every project complies from day one, turning compliance into a reputational asset rather than a cost.

Key fact: 43% of large companies lack AI risk frameworks despite widespread adoption. In SMEs, the figure is even higher. Setting up an AI committee is not a luxury: it is an operational necessity.

What an AI committee does (and what it must never do)

The most common confusion is thinking that the AI committee designs models, programmes algorithms or executes projects. No. The committee decides, arbitrates and ensures traceability. It is the governing body, not the execution team.

What it DOES do

  • Prioritises and approves use cases: Evaluates proposals using value, feasibility and risk criteria. Decides GO (proceed), FIX (adjust) or KILL (discard).
  • Assigns owners: Appoints a Product Owner and a Data Owner for each approved case.
  • Controls quality and evidence: Checks that each project has grounding (anchoring to sources), HITL (human oversight), PII protection and documented usage limits.
  • Manages the move to production: Verifies SLAs, an incident runbook, rollback capability and robustness assessments before giving the GO to Gate 2.
  • Monitors operations: Monitors data drift, model degradation, incidents and the real adoption of deployed tools.
  • Manages exceptions and Shadow AI: Applies the regularisation or cessation protocol and manages urgent requests outside the normal cycle.
  • Oversees external providers: Requires due diligence (factsheet, DPA and reversibility clauses) before approving any AI provider.

What it must NOT do

  • Design AI models or write code.
  • Execute projects or manage sprints.
  • Replace the technical team in architecture decisions.
  • Become a bureaucratic approval committee that slows everything down.

Golden rule: If the committee takes more than two weeks to approve a proposal, something is wrong with the process. Governance should be an accelerator, not a brake.

Minimum viable composition: who should be on the committee

You do not need to hire anyone new. The committee is formed with people already in your company, assigning clear roles. For an SME or mid-sized company, the minimum viable committee has four to six people:

  1. Executive sponsor (CEO / Managing Director): Defines business objectives, unlocks resources and approves the case portfolio. This person is accountable to the board or partners. On the committee, they have the final say on investment and risk decisions.
  2. Head of AI Transformation (COO / Operations or Technology Director): Leads the operating model. Standardises templates, coordinates initiatives and is responsible for identifying quick wins. This person is the committee’s engine.
  3. Data lead (Data Owner / Senior Analyst): Ensures data quality, controlled access and dataset sustainability. Assesses whether the available data is sufficient for each use case.
  4. Legal / Compliance: Ensures legal bases, the DPIA-lite, transparency and usage limits. This does not have to be an internal position: it can be an external adviser who joins key meetings.
  5. Business representative (Marketing, Sales or Operations): Brings the perspective of the end user and the customer. Validates that use cases solve real problems and measures adoption.
  6. IT / Security (optional but recommended): Assesses technical feasibility, integration with existing systems and security requirements.

In companies with fewer than 30 people, one person can cover two roles (for example, the COO can also be the Head of AI Transformation). What matters is that each function is covered, not that there is one person per role.

Recommended frequency: A 90-minute monthly meeting with a fixed agenda: portfolio review, Gate status, new proposals and resolution of exceptions. For urgent matters, an agile channel (Slack, Teams) with a response within 48 hours.

The Gate system: the committee’s common language

Gates are the control points that structure the life cycle of any AI project. They are the mechanism that prevents eternal pilots and evidence-free decisions. Each Gate requires minimum artefacts (documents, metrics and assessments) and ends with a clear decision.

Gate 0: Ideation

This is the entry point. Before investing a single euro or hour, the team presents:

  • Use-case sheet with a measurable value hypothesis.
  • Initial risk assessment and classification (minimal, limited or high according to the AI Act).
  • Minimum available data and gap analysis.
  • Identified sponsor.

Decision: GO (move to the pilot) | FIX (adjust the proposal) | KILL (discard it and document why).

Gate 1: Pilot with real data

The team has built an MVP and tested it with real users. It presents:

  • DPIA-lite (a pilot-version data protection impact assessment).
  • FRIA (fundamental rights impact assessment) if applicable.
  • Grounding controls and model versioning.
  • Quality metrics against the original hypothesis.
  • Factsheet / Model Card for the model used.

Decision: GO (scale to production) | FIX (iterate on the pilot) | KILL (withdraw it with lessons documented).

Gate 2: Production and scaling

The model is ready to operate in production. The following is required:

  • Complete technical file (mandatory for high-risk systems under the AI Act).
  • Incident runbook with escalation protocol.
  • Verified rollback / Kill Switch test (MTTR < 15 minutes).
  • Operating SLAs and continuous monitoring plan.
  • Training and change-management plan.

Decision: GO (operation with HITL and continuous improvement) | FIX (correct before scaling) | KILL (retire the model).

“Gates and evidence are the common language of AI governance. Without them, there is no traceability, no possible audit and no regulatory compliance.”

The traffic-light system: how to make fast decisions

Once a model is in production, the committee cannot review every decision manually. This is what the traffic-light system is for: it automates the decision logic:

  • Green (GO): All KPIs are within limits. Normal operation. The committee only receives a monthly report.
  • Amber (FIX/HOLD): Soft threshold exceeded. Moderate deviation. Action is required from the Product Owner and technical lead. The committee is informed and may intervene.
  • Red (STOP): Hard threshold exceeded. Serious risk. Immediate cessation, rollback or activation of the Kill Switch. The committee intervenes directly.

This system allows management to intervene only when there is real risk, without becoming an operational bottleneck.

Lite AI Policy: the document that holds everything together

The committee needs a written reference framework: the Lite AI Policy. It is not a 200-page manual. It is a clear, concise document that sets out:

  • What can be done with AI and under which conditions.
  • Who decides when there is uncertainty.
  • What evidence is required at each Gate.
  • The five operating principles: proportionality to risk, single accountability and traceability, grounding in sources, continuous observability and reversibility (Kill Switch).
  • Approved AI tools and data that may never be shared.
  • Shadow AI regularisation protocol.

The policy must fit on two pages and be understandable to every employee. If you need more than ten minutes to explain it, it is too complex.

The seven most common mistakes when setting up an AI committee

  1. Creating a committee without an executive sponsor. Without someone with decision-making power and a budget, the committee becomes a discussion forum with no ability to act.
  2. Overloading the committee with too many members. With more than eight people, meetings become assemblies. Four to six is the optimum number for fast decisions.
  3. Not defining what counts as an “AI system”. If you do not clarify what falls under the committee’s umbrella (chatbots, automations, predictive models and AI extensions), you will have governance gaps.
  4. Meeting without an agenda or artefacts. Each meeting must have a fixed agenda and each proposal must arrive with its completed case sheet. Without artefacts, there is no decision.
  5. Approving everything without risk criteria. A committee that says GO to everything is as useless as one that blocks everything. The AI Act risk criteria (minimal, limited and high) provide the necessary structure.
  6. Ignoring change management. Approving a project does not mean it will be adopted. Without training, procedures and usage metrics (FAR > 30% in four weeks), the technology is deployed but nobody uses it.
  7. Not measuring the committee’s own impact. The committee must be accountable: number of cases assessed, average approval time, cases in production, incidents managed and value generated by the portfolio.

Template to start tomorrow: your first AI committee in five steps

  1. Day 1: Define the charter. A one-page document with the committee’s mission, its members, meeting frequency and scope (what counts as an “AI system” in your company).
  2. Days 2–3: Write the Lite AI Policy. Two pages covering the five principles, approved tools, prohibited data and the Shadow AI protocol.
  3. Days 4–5: Prepare the case sheets. Create the standard template for proposing a use case (value hypothesis, minimum data, risk and sponsor). Distribute it to the teams.
  4. Day 7: First committee meeting. Review the current AI inventory (including detected Shadow AI). Prioritise the first two or three use cases with the Impact-Effort matrix. Decide GO, FIX or KILL for each one.
  5. Day 30: First review. Assess the progress of approved cases. Review the metrics. Adjust the policy if necessary. Repeat the cycle.

Practical advice: Start by publishing the Gates document internally (who approves which AI projects). That artefact alone accelerates adoption and gives the entire organisation clarity.

The conclusion: governing AI does not stop it, it scales it

The AI Steering Committee is not an obstacle to innovation. It is precisely the opposite: it is the mechanism that allows you to innovate quickly, safely and with evidence. It turns ethical and regulatory principles into traceable operational decisions.

You do not need a new department. You do not need a million-euro budget. You need four to six committed people, a Gate system, a Lite AI Policy and the discipline to meet once a month with artefacts on the table.

The companies that win in the AI era will not be those that adopt the most tools, but those that govern their decisions better.

Do you want to set up your AI committee but do not know where to start? At Impulsa3, we support you in designing the AI Steering Committee, policy and Gate system adapted to your company.

Sources and references

  • European Institute of Postgraduate Studies — Master’s documentation on AI Transformation: Governance and Operating Model
  • Partnership on AI — Enterprise AI Steering Committee Framework
  • Gartner — AI Governance Predictions (2026–2030)
  • Deloitte — AI Board Governance Roadmap
  • OneTrust — Establishing an AI Governance Committee
  • AI Act (European Artificial Intelligence Regulation)
  • NIST AI Risk Management Framework (AI 100-1)



What we have learned from governing AI without creating bureaucracy


At Impulsa3, we have transferred the logic of an AI committee into a living operating model. CEO sponsorship, criteria for moving from pilot to production, accountability for each capability and review of results are all part of I3OS. This experience has shown us that an SME does not need to copy the structure of a large corporation: it needs a simple way to prioritise, decide and learn, with enough authority to ensure that adoption does not remain a voluntary initiative.