What we do
AI Governance & Digital Regulation
We help organisations identify, govern and evidence the responsible use of AI across strategy, procurement, development, deployment and oversight.
When organisations call us
- Employees use generative tools without consistent rules; nobody owns the inventory of AI uses.
- The organisation buys or builds AI systems and must allocate provider and deployer responsibilities.
- A system may affect people — access to services, employment, safety or business-critical decisions.
- Rights to data, content, models or outputs are unclear across vendors and teams.
- A counterparty, investor, board or authority asks for evidence of AI governance — not intentions.
Questions we help answer
- Which of our AI uses require formal governance — and which genuinely do not?
- What does the EU AI Act timeline, as amended by the digital omnibus agreement, mean for our roadmap?
- How do we evidence human oversight, data quality, monitoring and change control?
- What should we require from AI vendors before we sign?
How we can support
- AI inventory and triage — discovery of uses, owners and a defensible risk classification.
- EU AI Act readiness — role determination (provider/deployer), obligations map and a phased plan aligned to the current legislative timeline.
- AI governance framework — policies, roles, approval gates, model documentation and incident routes.
- Human oversight design — real intervention points with trained, mandated people.
- Vendor assessment — questionnaires, contractual requirements and evidence standards for AI suppliers.
- Interplay with GDPR, DORA, NIS2 and sector rules — one architecture instead of parallel silos.
Typical work products
AI use inventory, risk classification memo, AI policy and usage standards, governance operating model, oversight and escalation procedures, technical documentation templates, vendor due-diligence pack, board briefing on AI exposure and readiness roadmap.
Insights
The AI Act after the digital omnibus: what the new 2027–2028 dates change — and what still bites in 2026
The provisional omnibus agreement moves Annex III high-risk obligations to 2 December 2027 and product-embedded systems to August 2028. It…
Read →Bring clarity to the next decision.
A first conversation is free of charge, confidential and without obligation.