EU AI Act — timeline reshaped by the digital omnibus
Prohibitions and GPAI duties already apply. The provisional omnibus agreement moves Annex III high-risk obligations to 2 Dec…
Governance, risk and technology advisory for organisations navigating regulation, transformation and growth. We help boards, founders, investors and specialist teams turn complex obligations and emerging technologies into practical decisions, operating models and controls.
EU and Polish core, working perspective across UK, US and APAC — with local counsel where formal opinions are required.
Prohibitions and GPAI duties already apply. The provisional omnibus agreement moves Annex III high-risk obligations to 2 Dec…
Directly applicable from 10 July 2027: harmonised CDD, 25% UBO threshold, €10,000 cash cap, expanded obliged entities. One…
Operational in Frankfurt, publishing technical standards and preparing to directly supervise selected high-risk financial entities from 2028.
Applicable since January 2025: ICT risk management, incident reporting, resilience testing and register of ICT third-party arrangements. Supervisory…
Risk management measures, incident reporting and management accountability — with national implementations, including Poland’s amended KSC Act, now…
From 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents (24h early warning). Full secure-by-design…
Advisory built around the questions that decide outcomes — regulatory, organisational and technological at once.
We help organisations translate legal, regulatory and ethical expectations into clear responsibilities, proportionate controls, reliable evidence and management information.
We support organisations in designing and improving risk-based financial crime frameworks that connect customer risk, controls, data, escalation and management oversight.
We help organisations identify, govern and evidence the responsible use of AI across strategy, procurement, development, deployment and oversight.
We help owners, boards and management teams build decision structures, information flows and accountability mechanisms suited to the organisation’s stage, risk and ownership model.
We help organisations establish practical risk, control and resilience arrangements that support decisions, ownership and recovery — not only reporting.
We help organisations understand and strengthen the ownership, contractual, governance and risk foundations of technology, data and intangible assets.
We help investors and growth companies identify material governance, regulatory, IP, data and technology risks before and after investment.
Engagements are scoped precisely — you always know what is in scope, what is out of scope and what you will receive.
Decision-ready information, clear accountability and independent challenge — without drowning in paper.
Governance proportionate to your stage — enough to pass diligence and win enterprise clients, not enough to slow you down.
Material risks identified before the deal — and turned into a plan after it.
Specialist capacity for teams that own the programme but lack the hands, mandate or independent view.
We do not publish client names. Snapshots are generalised, approved before publication and reviewed for re-identification risk.
Published with documented consent, attribution limited to a non-identifying role and category.
Briefings, analysis and checklists in three languages — dated, sourced and reviewed as the rules move.
The provisional omnibus agreement moves Annex III high-risk obligations to 2 December 2027 and product-embedded systems to August 2028. It does not move everything — here is the map.
Regulation (EU) 2024/1624 applies from 10 July 2027. The organisations that will cross that date calmly are doing three unglamorous things now:…
Read →From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents — 24-hour early warning included. The rest of the…
Read →Chain of title, contractor assignments, open-source licences and data provenance — fixed before the term sheet, not after. A practical sequence.
Read →We start from the decision you need to make — not from document production. Scope, owners and success criteria come first.
Obligations, risks, evidence and gaps — assessed against what actually applies to your organisation, with sources on the table.
Operating models, policies, controls and plans proportionate to your scale — built to be run by real teams, not admired.
Implementation support, documentation, training and handover — the engagement ends with a working arrangement, not a slide deck.
A concise update on regulation, technology and governance — sent when there is something worth your time, at most twice a month.
A first conversation is free of charge, confidential and without obligation.