By Rafael Luque Ocaña

The first 30 days of AI governance: a realistic roadmap

Not a year-long project, not an afternoon checklist: a well-sequenced month leaves an SME with an inventory, a classification, a policy, recorded training and its first transparency evidence. Week by week, this is what can genuinely be done.

The most common question from anyone who decides to take AI governance seriously isn't "what does the law require?" — it's "where do I start?". And the answers doing the rounds tend to fail at both extremes: the twelve-month transformational project that never gets off the ground, or the afternoon checklist that doesn't survive the first serious question. The operative truth sits in between: a well-sequenced month leaves an SME with the foundations laid and real evidence in hand. This is the roadmap, week by week, with no promise of arrival — with a promise of method.

Week 1 — Know what you have

Everything starts where we've spent months insisting it should: the inventory. Bring the area leads together for an hour and ask the uncomfortable question: which AI tools does each team use — including the ones nobody formally authorised? The module that switched on with the last CRM update, the assistant someone uses on their own initiative, the chatbot in the booking software. For each system, the minimum record: what it does, who uses it, what data it touches, who the provider is.

Close the week with an honest snapshot of where things stand. If you want a structured shortcut for that first snapshot, the free diagnostic gives it to you in a few minutes: which obligations apply to you based on what you already use. The snapshot isn't the evidence — but it tells you where to look first.

Week 2 — Know what each thing requires of you

With the list in front of you, classify. No advanced degree needed: most systems at an SME fall clearly into minimal risk (AI-assisted office tools, forecasting, internal tools), a few trigger transparency (anything that converses with customers or generates content), and the warning sign is always the same: systems that evaluate or decide on people — candidates, employees, customers. Those are the ones that call for immediate rigour: a data protection impact assessment, guarantees of human intervention, and their slot on the high-risk calendar.

The week's deliverable isn't the classification on its own: it's the classification with its reasoning written down. "This system is X because it does Y" — one sentence per system. That's the difference between an opinion and auditable evidence.

Week 3 — Set the rules and train (with a record)

Two pieces done together because they feed each other. The AI use policy: one or two pages covering what matters — which systems are authorised, what's prohibited (starting with pasting confidential data into unassessed tools), what to do when a result looks anomalous, how a new tool gets brought in. And Article 4 training, which doesn't require buying anything: a free baseline resource plus an internal session on your systems and your newly written policy. All of it recorded: who, what, when. For due-diligence purposes, training without a record doesn't exist.

Week 4 — Transparency and first evidence

The final week turns what's been built into visible compliance: verification of the chatbot's disclosure (with its division of roles), a labelling criterion for generated content, an editorial workflow for published text, and the ten AI vendor due-diligence questions sent to your two or three main providers. And the final gesture that ties it all together: an evidence folder — physical or digital, it doesn't matter — where every record generated this month lives, dated.

Day 31

Let's be honest about what you have at the end: not "total compliance" — that phrase doesn't mean anything, and anyone who promises it is selling you smoke. You have something better, and real: a living inventory, a reasoned classification, an operating policy, recorded training, verified transparency and a folder that proves it. That is: the ability to answer anyone who asks with confidence, and the foundations on which everything else — the deeper assessments, high risk when its calendar arrives, agents when they arrive — gets built without starting from zero.

On day 31, governance isn't finished; it's under way and under control, which is the only state in which governance genuinely exists. And someone coordinates it, named and mandated — because next month there'll be a new tool, a provider that changes its model, and a regulatory date drawing closer. Method over heroics. Always.

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.