Governance

Small Firms Can Do AI Governance Faster and Better than Enterprise Firms

Most large enterprises will run over 1,600 AI agents each this year and seven in ten executives say their governance is slowing them down.

Briefing 8 min read

A company of two thousand people can't put everyone on the same AI plan this quarter. You can.

Almost everything published on this subject in 2026 describes a coordination failure that gets worse with headcount, then prescribes a platform to contain it. If you run a studio or a professional practice, you're being sold the containment strategy for a problem you're positioned to avoid.

DefinitionAI governance is the set of practices that determine which AI tools and agents a business runs, on what data, under whose ownership, with what permissions, and at what cost.

At two thousand people it becomes a software category, because coordinating two thousand independent decisions requires software. At twenty people it's a set of choices an owner can make this week.

What the enterprise numbers describe

You already know most of what follows, because you have watched a version of it in your own business. Somebody found a tool that helped, told nobody, and left. The enterprise numbers are that, at a scale where nobody can see it happening.

IBM's Think 2026 research found that most large enterprises will be running more than 1,600 AI agents each by the end of 2026, and seven in ten executives say the limits of their existing AI governance are slowing their AI transformation. Only 18% of organizations maintain a current and complete AI inventory.

A June 2026 PagerDuty survey of 1,250 office professionals at large companies found that two thirds had used AI tools at work they believed company policy did not allow. In a company of two thousand, that is roughly 1,300 people working outside any agreement the company has signed, on tools it doesn't administer. Some of what they paste into those tools is customer information. Some of it is financial. In a professional practice, some of what your people paste in is privileged.

The expensive part is what happens next. Some of those private experiments worked. Somebody found a faster way to turn a messy client brief into a usable scope, and nobody else in the company will ever know, because the work happened in a personal account on a tool the business can't see, in a workflow nobody wrote down.

OutSystems' 2026 survey of 1,900 IT leaders measures the response: 36% of organizations have a centralized AI strategy, and 12% use a centralized platform to manage AI sprawl. Deloitte's State of AI, surveying 3,235 leaders across 24 countries, finds 74% expecting to use AI agents at least moderately by 2027, while about one in five organizations reports a mature governance model. Gartner expects more than 40% of agentic AI projects to be canceled by the end of 2027, citing escalating costs, unclear business value and inadequate risk controls.

These read as technology failures, but together they are coordination failures.

Why the difference is structural, not a matter of degree

You have a governance problem. It's real, and if half your team is running personal accounts with client information in them, it's urgent. What you don't have is the enterprise version of it, and the difference is structural.

You can centralize because there are few enough people to move. Putting a team on one administered plan with proper data handling is a purchasing decision and a short setup. At two thousand people it's a change management program with a budget, a steering committee, and a rollout schedule that runs longer than the model generation it was designed for.

You can change a workflow the week you decide to. When a better approach appears, you can adopt it while a larger competitor is still evaluating it.

Your people aren't competing with each other for credit. A large part of why successful AI experiments stay private inside big companies is that visibility is currency, and nobody is rewarded for handing an edge to another department. In a firm where everyone can see the same client work, a person who finds something that works has every reason to show the colleagues it would help.

You have fewer stakeholders defending existing software. When a small automation does what a subscription service was doing, you can cancel the subscription. Most firms carry software they no longer need, which is tech debt, because cancelling it requires someone to step up, make the case to stakeholders, and evaluate. A small business can look at the results, look at the tools, and make the call to lower its overhead in a much faster manner.

What doing it properly means

Three things, and a platform is not among them.

A shared, secured plan. An administered team plan with the data handling terms your client work requires, so the material your team is already putting into models is covered by an agreement your business has read. This is the security floor and the most urgent of the three.

A context library. The information your team can point a model at: how you scope, how you spec, how you price, what you have learned about the vendors you use, what the last three projects taught you. This is what makes AI output sound like your business rather than like the internet. Building it forces the decision about what stays out, which is client confidential material, nonpublic information, and anything privileged. That boundary is the discipline, and drawing it is most of the work.

A skill library that scales across the team. When somebody builds something that works, it becomes a thing everyone can use rather than a thing one person knows. This is where the enterprise loses the most value, and where a small team can capture it.

They are also the sequence. The plan is a purchase, the context library is the work, and the skill library is what the work makes possible.

Does a twenty person firm need AI governance?

Yes, though not the enterprise version. The requirement is a shared secured plan, a written context library with a clear boundary around confidential material, and a place where working approaches get shared. A platform is not required at this size, and buying one is usually a mistake.

Is this the same as an AI policy?

A policy states what people may do. The three items above are what makes a policy followable. Most small firm AI policies fail because they prohibit personal accounts without providing the shared plan that replaces them, which pushes the same behaviour further out of view.

What is shadow AI?

Informal use of AI tools outside any approved process. A June 2026 PagerDuty survey found two thirds of office professionals at large companies had used AI tools they believed their company did not allow. In a small firm it is usually somebody solving a real problem with the fastest tool available, which means the response is provision rather than prohibition.

Why do agentic AI projects get canceled?

Gartner expects more than 40% to be canceled by the end of 2027, citing escalating costs, unclear business value and inadequate risk controls. All three are scoping and ownership questions, which makes them governance questions.

How we read this

The governance conversation has been written by and for large organizations, and it carries their assumptions: that AI adoption is a risk to be contained, and that containment requires infrastructure. For a business of two thousand, that is fair. For a business of twenty, it describes the wrong problem.

We'd frame it the other way. The three items above are the operating system a small business would want whether or not AI existed: one place the team works from, one written account of how the business does things, one library of approaches that get better as people use them. AI is what makes building them urgent enough to do, and the security is a consequence of doing them well rather than the reason to start.

There is a second return that rarely gets counted, which is the tech debt above. We'd review the subscription list alongside the tool list, in the same sitting, for that reason.

This is a structural advantage a small business holds over a large one, and it has a window on it. It stays an advantage until enterprises learn to be nimble.

What you can do this week

Ask your team one question: which AI tools are you using, and on which account. Not as an audit, and say so, because a question that reads as an audit gets an incomplete answer. Ask because you want to put everyone on something better.

You'll learn two things. Which client information is sitting in systems you have no agreement with, which tells you how urgent the shared plan is. And which people have already built something that works, which is where your skill library starts. Most owners never think to ask the second question.

Working together

Flow State Found works with a limited number of businesses to make their best work their baseline. Most firms we speak with know half the team is on personal accounts and have not found a week to deal with it. We put the plan, the context library and the skill library in together, so security arrives as a consequence of the work.

We take on limited engagements, so it starts with a conversation.

Start a conversation

For Deeper Context

  1. IBM Think 2026, agent governance and inventory findings, May 11, 2026
  2. PagerDuty, shadow AI workplace survey of 1,250 office professionals, June 11, 2026
  3. OutSystems, State of AI Development 2026, survey of 1,900 IT leaders, April 2026
  4. Gartner, on over 40% of agentic AI projects being canceled by the end of 2027, press release, June 25, 2025
  5. Deloitte, State of AI in the Enterprise 2026, survey of 3,235 leaders across 24 countries

All Governance Briefings