Around 200 employees, something shifts. You are no longer small enough for one person to know what every team is doing, and not yet large enough to have dedicated functions for everything. AI governance in a mid-size organisation lands in that gap. Multiple departments are adopting AI tools at different speeds, supplier relationships are multiplying, and nobody has a clear picture of what is actually running or who approved it. That is where most of the risk lives.
Why 200 People Is the Awkward Size
Smaller organisations can often manage AI governance through proximity. The leadership team knows what is being used because they are close enough to see it. Larger enterprises have compliance teams, procurement controls, and IT governance frameworks that catch most things. At 200 people, you tend to have neither. Department heads are making tool decisions independently. Finance is using one AI platform, marketing another, and operations a third. Nobody has mapped it, and nobody owns the question.
This is not a criticism. It is just what happens when an organisation grows faster than its governance structures. The problem is that AI does not wait for the governance to catch up.
What a Mid-Size Organisation Typically Gets Wrong
The most common mistake is treating AI governance as an IT problem. It is not. IT can manage licences and access controls, but the decisions about what data goes into which tool, what outputs get acted on, and what risks are acceptable are business decisions. They belong to the people running the business, not the people running the servers.
The second mistake is assuming that because nobody has raised a problem, there is no problem. Most organisations have no real visibility of AI usage at this size, because the tooling and the oversight processes simply do not exist yet. Absence of a reported incident is not the same as absence of risk.
The third mistake is buying a policy template, circulating it once, and considering the job done. A policy that nobody reads, that covers no specific tools, and that has no mechanism for enforcement is not governance. It is paperwork.
Supplier Sprawl Is a Real Problem at This Scale
At 200 people, you typically have more AI suppliers than you think. Some are obvious: a contracted AI writing tool, a CRM with built-in AI features, a customer service platform that uses language models. Others are less visible: the AI features quietly enabled inside tools you already use, the browser extensions staff have installed, the free-tier tools departments are using to get work done faster.
The hidden supplier risks in enterprise AI are particularly acute at this scale because procurement oversight is often light. A department head can sign up for a tool on a credit card without it ever going through a formal approval process. That tool may be processing customer data, employee data, or commercially sensitive information, and you may have no contractual protections in place at all.
No Single Owner Is the Structural Problem
Ask most mid-size organisations who owns AI governance and you will get a pause. Then you will get a list of people who each own a bit of it. The COO thinks IT handles it. IT thinks compliance handles it. The compliance lead thinks it falls under the data protection officer. The DPO is already stretched across GDPR obligations and has not looked at AI specifically.
This is not laziness. It is a structural gap that organisations at this size have not yet filled. But the gap has consequences. When something goes wrong, and eventually something will, the question of who was responsible becomes very uncomfortable very quickly. The ICO has published guidance specifically on AI and data protection, and regulators in general are increasingly clear that governance accountability cannot be left unassigned.
What a Programme That Scales Actually Looks Like
A governance programme that works at 200 people does not need to be complex. It needs to be clear. That means a named owner with actual authority, a short list of approved tools with documented approval decisions, a policy that is specific enough to be useful, and a process for reviewing new tools before adoption rather than after.
It also means building the habit of review into the calendar. AI governance drifts when nobody is watching it. Tools change, staff turn over, use cases expand beyond what was originally approved, and the controls that made sense six months ago no longer match what is happening. Why AI governance drifts over time is worth understanding before the drift becomes a problem rather than after.
The goal is not perfection. It is proportionate, documented, and maintained. Those three things put a mid-size organisation in a substantially better position than most of its peers.
Where to Start if You Are Starting From Scratch
Start with visibility. You cannot govern what you cannot see. Spend a week asking each department head what AI tools their team is using and for what. You will almost certainly be surprised by the answer. That list becomes the foundation for everything else: risk assessment, supplier review, policy drafting, and ownership assignment.
From there, the priority is not speed. It is sequence. Getting the basics right in the right order matters more than moving fast. A governance programme built on a clear picture of current usage will hold. One built on assumptions will not.
If you want a structured view of where your organisation currently stands, the AI Governance Gap Assessment identifies exactly where the gaps are and what to address first.