# What does a responsible AI policy look like for a mid-market company?
Responsible AI policy for mid-market firms: what it must contain, how to classify risk and what the EU AI Act means for your obligations in 2025.
Published: 2025-08-18
Author: Rodan Analytics
 Most mid-market companies are already using AI. The question is whether anyone has written down what that means — what is permitted, what is prohibited and who is accountable when something goes wrong.

 The mistake most organisations at this stage make is treating responsible AI as a compliance exercise. They wait for regulation to crystallise, delegate it to legal or IT and produce a document that nobody reads. Meanwhile, the business is making consequential decisions — in credit, in hiring, in customer communications — using models nobody has fully audited.

 The cost of that gap is not hypothetical. It shows up in regulatory exposure under the EU AI Act, in reputational damage when an automated decision is challenged and in the practical chaos of trying to retrofit governance onto systems that have already been embedded in operations.

 This article sets out what a responsible AI policy actually needs to contain for a company of your scale, why the standard enterprise frameworks do not fit and how to build something that governs real decisions rather than imaginary ones.

---

## Why enterprise AI governance frameworks do not scale down

 The responsible AI frameworks published by large consultancies and technology vendors are written for organisations with dedicated AI ethics teams, model risk functions and legal resources to match. They are thorough, well-intentioned and largely irrelevant to a £700m manufacturer or a private equity-backed services business trying to govern AI across fifteen operational systems with a three-person data team.

 The problem is not ambition — it is abstraction. Enterprise frameworks ask you to map your AI inventory, classify models by risk tier, conduct algorithmic impact assessments and appoint an AI ethics board. All of that is correct in principle. None of it tells you what to do on Monday morning when your finance director wants to know whether the churn prediction model feeding the renewal team is covered by your data protection obligations.

 Mid-market companies need governance that is precise about the decisions that matter, lightweight enough to be maintained without dedicated resource and specific enough that a non-technical senior leader can apply it without a translator.

 That requires a different starting point: not "what do best practice frameworks recommend?" but "what AI-enabled decisions are we actually making, and which of them carry material risk?"

---

## Start with a decision inventory, not a technology inventory

 The instinct is to catalogue your AI tools. Resist it. A list of software licences tells you nothing about risk. What matters is the decisions those systems influence or automate, and the consequences of those decisions being wrong.

 A practical starting point is a decision inventory — a structured register of every consequential decision in the business that is currently informed or automated by a model, an algorithm or an AI-enabled system. For each decision, you need to capture four things:

- **What is the decision?** (e.g. credit limit assignment, candidate shortlisting, dynamic pricing, content moderation)

- **Who or what is affected by it?** (employees, customers, third parties, the business itself)

- **What happens if the system is wrong?** (financial loss, discrimination, regulatory breach, reputational damage)

- **Is a human reviewing the output before action is taken?**

 That last question is the most revealing. In many mid-market businesses, the honest answer for at least some decisions is no. The model outputs, a workflow triggers and nobody reviews the logic. That is where governance needs to focus first.

 Take a logistics company using a routing optimisation model that also influences driver performance scoring. The company thinks of it as an operational efficiency tool. But if that scoring feeds into disciplinary or redundancy decisions — even indirectly — it is a high-risk AI system under the EU AI Act's current framework. Governing it as a low-risk operational tool creates material exposure.

---

## What your responsible AI policy must actually contain

 A policy that governs real decisions at mid-market scale needs six substantive components. It does not need to be long. It needs to be specific.

 **1. Scope and definitions.** Define what counts as "AI" for the purposes of this policy. This matters because people will argue about it. A statistical model in your pricing engine is in scope. A rules-based workflow in your ERP probably is not. Be explicit.

 **2. Risk classification.** Assign every system in your decision inventory to one of three tiers: high risk (decisions affecting individuals' rights, employment, credit, access to services), medium risk (decisions with material business consequences but no direct regulatory exposure) and low risk (everything else). Your governance obligations differ by tier.

 **3. Accountability.** Name a role — not a team, a role — responsible for each high and medium-risk system. This person owns the decision to deploy, the obligation to monitor and the authority to pause or withdraw a system if something goes wrong. Without named accountability, governance is theoretical.

 **4. Human oversight requirements.** Specify the minimum level of human review required before an AI-influenced decision is acted upon, by risk tier. High-risk systems should require documented human sign-off. Medium-risk systems should have a review mechanism even if it is not case-by-case. Low-risk systems can operate autonomously with periodic audit.

 **5. Data and model integrity.** Set minimum standards for how models are trained, validated and monitored. This does not require a full MLOps framework. It requires answers to: what data was used, when was the model last validated against live outcomes, and who knows if performance has degraded?

 **6. Incident and escalation process.** Define what constitutes an AI-related incident and how it gets reported. A pricing model that behaved unexpectedly during a promotional campaign is an incident. A candidate screening tool that produced a demographically skewed shortlist is an incident. The business needs to know these happened and have a process for investigating them.

---

## The EU AI Act is closer than most mid-market firms think

 The EU AI Act is already in force. Prohibitions on certain AI practices applied from February 2025. Obligations for high-risk AI systems begin applying through 2025 and 2026. If you sell into the EU, employ people in the EU or use AI systems that affect EU residents, you have regulatory obligations that are not conditional on your headquarters location.

 Most mid-market firms are underprepared for this. The Act's high-risk categories include AI systems used in employment and workforce management — which covers more than most HR teams realise — as well as systems used in credit, insurance and access to essential services.

 The practical implication is that your responsible AI policy is not purely an internal governance document. Parts of it are the evidence base for regulatory compliance. That means the policy needs to be dated, versioned, signed off at board or executive level and reviewed at least annually. A document produced in response to a regulatory enquiry has far less credibility than one that was in place before the enquiry arrived.

---

## Building the policy without building a bureaucracy

 The goal is a policy that governs real decisions, not one that generates paperwork. For a mid-market company, that means keeping the core document to fewer than ten pages and building the operational substance into existing management processes rather than creating parallel governance structures.

 Embed AI risk into your existing risk register. Add AI oversight as a standing item in the relevant operational governance meetings — not a separate AI ethics committee that nobody attends. Make the decision inventory a living document owned by the CDO or equivalent, reviewed quarterly and updated whenever a new system goes into production.

 The companies that get this right treat responsible AI policy as operational infrastructure, not as a statement of values. The policy does not exist to signal that you take ethics seriously. It exists so that when a decision goes wrong — and eventually one will — the business knows what happened, who was accountable and what the process was.

---

## Act now, before a decision goes wrong

 The organisations that will struggle are not the ones that moved fast on AI adoption. They are the ones that moved fast without recording what they deployed, why, and how it was supposed to be governed.

 At your scale, you do not need a large programme to fix this. A focused diagnostic — typically four to six weeks — can produce a decision inventory, a risk classification and a draft policy that is fit for purpose and defensible to regulators. The cost of not having that in place is measured in the remediation work after an incident, not in the effort it takes to build governance before one.

 If you want a clearer picture of where your AI exposure sits today, Rodan's AI readiness assessment is designed for exactly this situation: a structured diagnostic that maps your current AI use, identifies governance gaps and gives you a prioritised plan to close them.

 [Book a diagnostic with Rodan](https://rodan.io)

---

 **Meta description:** Responsible AI policy for mid-market firms: what it must contain, how to classify risk and what the EU AI Act means for your obligations in 2025.
HTML: https://rodan.io/insights/what-does-a-responsible-ai-policy-look-like-for-a-mid-market-company
