Insights

The Biggest AI Governance Challenges Facing SMEs (and How to Overcome Them)

Oct 9, 2026

Artificial intelligence can help SMEs improve efficiency, analyse data and develop new products and services. But adopting AI also introduces governance challenges that can be difficult for smaller organisations to manage.

The problem is not necessarily a lack of awareness.

Research into 200 AI-active South African SMEs suggests that some of the biggest AI governance challenges for SMEs are structural: limited capital, fragmented data, unclear accountability, gaps around consent and weak post-deployment monitoring.

Six challenges stand out.

1. AI governance is a financing problem

Governance requires resources.

SMEs often have to prioritise operational spending, while compliance functions, specialist skills, data management and technical infrastructure compete for limited capital.

The GSMA research found that businesses with a dedicated compliance budget were much more likely to assess AI risks regularly. Among surveyed organisations with high AI capacity, 68% reported regularly assessing AI risks as part of a defined process.

This suggests that the barrier is not simply whether businesses understand the importance of governance. It is whether they have the resources to act on that understanding.

2. Consent may not cover new AI uses

One of the clearest findings across the four case studies was a consent gap.

Businesses and institutions may have collected data legitimately for one purpose, only to later introduce an AI application that uses that same data differently.

The report found that consent frameworks and data-sharing agreements in all four case studies predated the AI applications subsequently built on the data.

This creates a fundamental question: if data was originally collected for one purpose, can it automatically be used for another?

The research suggests this is not simply an issue individual organisations can solve. It is a structural challenge created when AI is layered onto existing data relationships.

3. Accountability can disappear across the value chain

AI systems rarely operate in isolation.

A data holder may provide information. A technology company may process it. Another organisation may deploy the AI system. A third party may ultimately deliver the service.

This can create an AI accountability gap.

The JUMO case study illustrates the issue particularly clearly. Its AI-powered credit products operate through relationships involving mobile network operators, JUMO's AI engine and licensed lending partners. Responsibility for governance can therefore be distributed across multiple actors.

When something goes wrong, the important question is not simply who participated in the system, but who is accountable for the outcome.

4. Bias testing is often missing

AI systems learn from data. If the data does not adequately represent the people a system is intended to serve, the resulting system can reproduce or deepen existing gaps.

The GSMA report found that none of the four case-study organisations had publicly documented systematic bias testing for their South African-specific AI deployments. It also found that populations least served by the systems were also least represented in their training data.

This is particularly significant for SMEs developing solutions intended to reach underserved populations.

Responsible AI therefore requires businesses to ask not only whether a model works, but for whom it works, and who may be left out.

5. AI governance often stops at launch

Another major challenge is the post-deployment AI monitoring gap.

Governance discussions frequently focus on what happens before an AI system goes live. But AI systems can change over time as the data and environments around them change.

Model drift can cause performance to deteriorate, potentially leading to inaccurate predictions or decisions.

The report identifies post-deployment monitoring as one of the least-developed safeguards across the organisations examined.

For SMEs, this means governance should not be treated as a launch checklist. Systems need appropriate ongoing review.

6. Skills and data quality compound the problem

Even when an SME understands what good governance should look like, it may not have the technical capacity to implement it.

The research identifies several practical barriers to data use, including high storage and processing costs, fragmented data systems, dependence on large platforms, limited technical infrastructure and inconsistent data formats.

These problems reinforce one another.

Poor-quality data can affect AI performance. Limited technical capacity makes it harder to identify the problem. Fragmented systems make data management more difficult. Limited resources make it harder to hire the expertise required to address these issues.

What can SMEs do about these challenges?

The answer is not to avoid AI.

Instead, SMEs need governance that reflects their size and circumstances.

The research found that technical tooling and financial support were among the most effective forms of assistance identified by surveyed SMEs. Standard templates, regulatory clarification and practical guidance were also identified as useful measures.

The broader lesson is that responsible AI needs to be practical as well as principled.

Frequently Asked Questions

What are the biggest AI governance challenges for SMEs?

The research identifies six major patterns: financing constraints, consent gaps, accountability gaps, limited bias testing, weak post-deployment monitoring, and skills and data-quality challenges.

Why is AI governance a financing problem?

SMEs may understand governance requirements but lack the capital, technical tools and specialist skills needed to implement them.

Why might existing consent not cover AI?

Data may have originally been collected for a purpose that existed before the AI application. A later AI use may therefore raise questions about whether the original consent or data-sharing arrangement covers the new purpose.

Who is accountable when AI makes a harmful decision?

It depends on the structure of the AI value chain. Where multiple organisations share responsibility, accountability can become difficult to allocate and enforce.

Why is post-deployment monitoring important?

AI performance can change as data and circumstances change. Monitoring can help identify model drift, declining accuracy and emerging risks.

Conclusion

The biggest lesson from the South African research is that AI governance challenges for SMEs are not caused by one problem.

They emerge from the interaction between money, data, technology, skills, regulation and organisational responsibility.

Addressing these challenges therefore requires more than telling SMEs to “use AI responsibly”. They need practical tools, appropriate guidance, resources and governance structures that match the realities of smaller organisations.

Based on research by Tanvi Deshpande and Emma Leering, GSMA Mobile for Development, with contributions from Robin Miller and Alim Ladha , Axum , GSMA Intelligence and research conducted by Axum and the Global Center on AI Governance, published in Scaling AI for SMEs: Insights Into South Africa’s AI Data Governance Environment (2026).