AI governance for startups: the minimum viable policy

You do not need a 50-page policy. You do need a clear, written stance on data, models, and risk that a customer can read in five minutes.
Data handling first
Document what data goes to which model and why. Customers ask, and regulators are starting to.
Model registry
List every model in use, its provider, and its purpose. When a vendor changes terms, you need to know what is affected.
Human in the loop
Define which decisions require human review. Codify it; do not leave it to culture.



