Not a committee. Three roles, all part-time, all named.
The accountable executive. A director (often the COO, CFO or, in smaller firms, the MD). They sign the policy, approve tier 3 use cases and are the person the board asks. This is the accountability principle in the UK framework, the Govern function in NIST, and the first thing ISO/IEC 42001 auditors look for.
The AI lead. The operational owner, usually from IT, operations or digital, with credibility with both leadership and users. They keep the approved-tools list and the use-case register, run the monthly spot-checks, triage questions and organise training. Half a day a week is a fair estimate for a 200-person company once things are running.
Champions. One per team or function, chosen because they are already the person colleagues ask. They are not enforcers. They collect use cases, show what good looks like, spot tier 2 work that has quietly become tier 3, and feed back what the policy gets wrong. A 150-person company might have six to ten.
If you have a DPO or data protection lead, they are consulted on tiers 2 and 3 but they should not be the AI lead. Governance owned by compliance alone becomes a list of no.