Organising your AI work isn't governing it.
A clean set of folders for your AI work — one place per project, sensitive material walled off, every hand-off easy to follow — looks like control. It is worth having. But it is the wrong thing mistaken for the right one. A tidy tree earns the posture of governance; it discharges none of its duties. The gap between the two has a name, a cost, and a fix — an AI management system — and it is smaller than it sounds.
The folder fallacy.
Put your AI work in good order and a reassuring feeling follows: we've got this under control. The feeling is the trap. Organisation buys you real things — you can see what you're running, keep confidential material apart, and follow who did what. Those are the conditions for governance. They are not governance. The folder generates none of the evidence a regulator, a buyer or your own future self would ask for: no risk assessment, no named owner, no record of who approved what, no log of what happened when it went wrong.
It is the same shape of error we flag in two neighbours. “We used a risk atlas, so we're covered” — a good tool helps you name a risk; it never discharges the duty to manage it. “We run the model ourselves, so we're compliant” — a genuine data-control win, over-read into a guarantee it never made (that one is its own guide: running your own AI isn't compliance). Folder-first is the third of the family: organised is not governed.
Organise like the method; govern like the frameworks; never mistake the first for the second.
Seven duties a folder can't touch.
Strip the frameworks back to what they ask for and you get a short, concrete list. Each duty is anchored in a real rule or standard; each is something a directory tree is simply silent about. This is the gap, in full.
| # | The duty | Where it's anchored | What a tidy folder does about it |
|---|---|---|---|
| 1 | A risk-management system | EU AI Act Art. 9 · ISO/IEC 23894 · NIST AI RMF | Holds a register; it never assesses, scores or treats the risk. |
| 2 | Accountability & roles | EU AI Act Art. 26 · ISO/IEC 42001 | No owner, escalation path or “who can stop it” lives in a directory tree. |
| 3 | Data protection — DPIA / RoPA | GDPR Arts. 35, 30, 5(2) · AI Act Art. 27 | Isolation is not a lawful basis, a DPIA or a record of processing. |
| 4 | Security controls | ISO/IEC 27001 · AI Act Art. 15 · NIS2 | A folder name is not identity, encryption or vulnerability handling. |
| 5 | Logging & monitoring | EU AI Act Arts. 12, 72 | Saved files are not event logs, drift monitoring or an audit trail. |
| 6 | Transparency to affected people | EU AI Act Art. 50 | Nothing — and this duty has no clean standard to lean on. |
| 7 | AI literacy & competence | EU AI Act Art. 4 | A tidy workspace does not make the people using it competent. |
A fair question: do all seven bind everyone? No. Several (Arts. 9, 12, 15) are duties the law places on the provider of a high-risk system. A small business that simply uses third-party AI is usually a deployer, and not legally bound by all of them — the line between the two is its own guide. The point is not that every box is mandatory; it is that organisation answers none of them, and you should know which ones you've actually met.
Make governance something the folders hold.
The fix is not to throw away the folders — it's to put something in them that the tree can't generate on its own. An AI management system is, at heart, a small set of owned, signed documents: one per duty, each mapped to the rule it answers. A living risk register. An accountability map. A record of processing. A statement of transparency. Most are documents a working business half-owns already — a privacy policy, a tool list — pulled into one place and made to carry their weight.
What turns a pile of sensible files into a system is borrowed from how software teams govern code in plain files: three things a folder cannot carry, added by lightweight habit rather than expensive tooling.
Mutation control
Who is allowed to change what — recorded, not assumed. A folder lets anyone move anything; governance names an owner for each document and a rule for who may alter it.
Sign-off
Who approved this, and when. A file sitting in the right folder is not an approved file. A dated approval line is the signature; an empty one means “still a draft”, and a draft is a tracked gap, not a discharged duty.
Audit trail
What changed, when and why — kept, not reconstructed from memory. A running governance log carries the decisions; superseded versions are archived, never quietly overwritten.
That's the whole move: mutation control, sign-off and an audit trail, carried by an owner field, an approval date and a running log. No platform to buy, no committee to convene — the discipline does the work the directory tree can't.
Proportionate, not enterprise.
The word “management system” conjures a department, a binder and a quarterly committee. For a small business that is exactly the wrong picture. A proportionate AIMS is different in scope, not a shrunken copy of a corporate one. You don't need a committee; you need the duties met at the size of your firm.
Three things keep it honest without making it heavy. Know your role. If you use third-party AI rather than building and selling your own, you're almost certainly a deployer — a manageable set of duties, not a manufacturer's full obligations. Don't assume the small-business exemptions reach you. The record-of-processing relief for firms under 250 people falls away once you handle personal data regularly — which most client work does — so a one-page record per activity is usually still owed. Name the function, even when one person fills it. Writing down “human overseer” and “data-protection function” when they're all you is what makes the system real, and what makes it trivial to hand over the day you grow. For an advisory firm, professional secrecy (Article 458 of the Luxembourg Criminal Code) is the confidentiality control that sits on top of all of it.
Folder-first is necessary infrastructure for governance — and not sufficient governance in itself, because it generates none of the evidence.
We built one for ourselves first.
The most credible thing an AI-governance advisor can show is its own governance, filled in — so before this was a service, it was our own house in order. Kramer Consulting keeps a working AIMS for its own use of AI, built from exactly the parts above. Here is the shape of it (the structure and the verdict — never the confidential internals):
One register that is also the gap tracker
A single duty map that lists each of the seven duties, the document that discharges it, where that document lives — and, honestly, which ones are not finished yet.
A filled risk register
Real risks for a solo deployer — confidential data entered into the wrong tool, a hallucinated citation, over-reliance on an agent — each with the control against it and the residual risk that remains.
An accountability map
Every governance function named — accountable owner, risk owner, human overseer, data-protection function — even though, in a one-person firm, the same person currently fills them all.
A green-amber-red tool register
Every AI tool sorted by where its data goes: local-only tools cleared for confidential material, controlled-cloud tools for internal work, consumer tools for public content only.
A live transparency page
A public statement of how this very site is made — what the AI does, what stays human — kept current, not asserted once and forgotten.
An honest list of open gaps
The unsigned document, the record of processing still to confirm. We publish the structure and the verdict, never the confidential internals — and we do not pretend the work is finished when it is not.
Note the last card. A governance system that hides its open gaps isn't being governed — it's being marketed. Ours names them, because the standard we'd ask of a client is the one we hold ourselves to. The same architecture, scaled to an organisation, is the question of who owns AI governance; the wider picture of what can go wrong is the risks of AI, mapped.
The framework stack.
You don't invent governance from scratch; you stand it on established frameworks. The pragmatic stack we recommend for a small business — and run on ourselves — has four layers.
| Layer | Choice | Why |
|---|---|---|
| Operational spine | NIST AI RMF 1.0 | Public-domain and flexible — the cost-effective default for a small business and for designing the process itself. |
| Management system | ISO/IEC 42001:2023 | Optional. A certifiable standard, adopted only where a buyer or regulator actually asks for it — powerful, but not a shortcut. |
| Legal backbone | EU AI Act · GDPR · Art. 458 (LU Criminal Code) | The rules that bind, plus Luxembourg professional secrecy — Article 458 of the Criminal Code, which binds anyone entrusted with confidential information by virtue of their profession, and so reaches an approved training and advisory provider handling client material. Sector rules apply where applicable. Article references are structural, not advice for a specific system. |
| People layer | The four-competency model | Delegation · Direction · Evaluation · Ownership — the AI-literacy duty (Art. 4) made into a working habit. |
One honest caveat, because it matters for what you can claim. As at 30-06-2026, no harmonised AI Act standard has yet been cited in the Official Journal, so certifying to ISO/IEC 42001 is a credible market signal — not a legal safe harbour. The 2027 deferral of the high-risk obligations is now settled: the Digital Omnibus was adopted by the Council on 29-06-2026, confirming 02-12-2027 for stand-alone systems and 02-08-2028 for embedded ones — formally in force once published in the Official Journal, expected within days. We track these so a date never goes stale on the page — the failure we warn clients about. The shape of the law itself is its own guide.
We build the system we live by — at your size.
We start from the AI you actually use, sort which of the seven duties genuinely bind you, and build the small set of owned documents that meets them — proportionate to a firm your size, not a corporate template you'll never maintain. Then we build the capability in your team to keep it running, because a system no one owns decays. When there's a regulatory clock on it, that work runs through the AI Act Compliance Accelerator; when it's about the operating model, through the governance advisory.
Tidy isn't the same as governed. Let's see which you've got.
Thirty minutes, an honest read of where your AI use is organised and where it's actually governed. No pitch.
Book a discovery call →Related guides
Who owns AI governance?
It isn’t a person you hire, a policy you write or a framework you buy — it’s an operating model: who decides, who checks, who can stop it, and where the evidence lives. The four accountability zones, and why you can’t hire your way to governance.
Read the guide Local & sovereign AIRunning your own AI isn’t compliance
Running the model yourself — on-device, on-premise, on sovereign EU infrastructure — is a real win for data control. But where a model runs answers residency, not conformity: the EU AI Act regulates the use, wherever inference happens. The traps, and where sovereign AI genuinely pays off.
Read the guide