AI GOVERNANCE · EU AI ACT AND BEYOND

You shipped the AI. Can you explain how it decides?

Governance obligations do not ask whether your model is good. They ask what it is for, what data it uses, who can override it, what it logged, and who is accountable. Most teams cannot answer those questions about systems already in production.

Aug 2026

Transparency obligations operational

Dec 2027

High-risk AI obligations (revised)

11–14%

Of enterprise AI pilots reach production scale

Get your free readiness score5 minutes · no call required
THE RECURRING PATTERN

Nobody knows how many AI systems are in production.

AI adoption did not go through architecture review. It arrived through individual teams, vendor features and API keys on a corporate card. The result is a set of systems making real decisions, with no inventory, no owner, no documentation and no log of what they did. Governance starts with finding them.

No inventory of what is running

Team-level and vendor-embedded AI never reaches a central register, so it is never assessed.

Personal data reaching model providers

A policy exists. Nothing technically prevents it, and nobody is monitoring whether it happens.

Human oversight is nominal

Someone can override the system in theory. In practice the override is never used and no one is accountable for the outcome.

No usable record of decisions

Inputs and outputs are not retained, so when a decision is challenged there is nothing to examine.

WHAT WE BUILD

Five workstreams, shipped into your stack

Workstream 01

Inventory and ownership

A complete register of AI systems and use cases, including the ones nobody declared, each with a named accountable owner.

  • Discovery across teams and vendors
  • Model, version and dependency tracking
  • Accountability mapped per system
Workstream 02

Risk classification

Each system assessed against a defined framework, with a pre-deployment gate so new use cases are classified before they go live.

  • Tiering against EU AI Act categories
  • People-affecting decisions flagged
  • Assessment gate in the delivery process
Workstream 03

Data controls

Technical enforcement of what data may enter a model, plus the ability to honour an erasure request across a pipeline.

  • Egress controls to model providers
  • Training and prompt data lineage
  • Erasure across derived stores and indexes
Workstream 04

Documentation and oversight

Technical documentation that survives an audit, and human oversight with real authority rather than a nominal sign-off.

  • Purpose, data, limitations, testing
  • Override paths that are actually used
  • Disclosure where users interact with AI
Workstream 05

Monitoring and incidents

Event logging retained and queryable, post-deployment monitoring for drift and biased outcomes, and a defined incident path.

  • Input and output logging
  • Drift and outcome monitoring
  • Serious incident reporting route
Ongoing

Governance operations

Frameworks keep changing and models keep drifting. Documentation and evidence have to be maintained, not written once.

  • Quarterly review of inventory and tiers
  • Documentation refresh as rules change
  • Incident drills and monitoring review
HOW CLASSIFICATION WORKS

What tier your system lands in decides everything else

TierTypical ExamplesWhat It Requires
ProhibitedSocial scoring, manipulative or exploitative systemsCannot be deployed
High riskHiring, credit, education access, essential services, biometricsRisk management, technical documentation, logging, human oversight, post-market monitoring
Limited riskChatbots, generated contentDisclosure that the user is interacting with AI or AI output
Minimal riskInternal productivity tooling, spam filteringNo specific obligations, but inventory and data controls still apply

Most organisations discover at least one system in a higher tier than they assumed. Classification is confirmed with your counsel; we assess and evidence it.

HOW WE ENGAGE

Three ways in, depending on how far along you are

Start small if you need to prove the value internally first. Most clients begin with a sprint and move up.

Start here

AI inventory sprint

Two weeks

One business unit

Find every AI system actually running, classify it, and produce a prioritised risk list. Credited in full against a full assessment booked within 30 days.

Start Scorecard First
Most chosen

Governance assessment

Four weeks

Organisation-wide

Full inventory, risk tiering, data lineage review, documentation and oversight gap analysis, and a remediation plan sequenced against your deadlines.

Start Scorecard First
The full programme

Build and operate

Eight to sixteen weeks

Then ongoing operations

Implementation of controls, documentation and logging, then continuous governance operations so evidence stays current as models and rules change.

Start Scorecard First
WHAT YOU RECEIVE

Comprehensive Tangible Deliverables

AI system register

Every system, owner, model dependency and risk tier.

Risk classification record

The assessment and its reasoning, ready to defend.

Technical documentation

Purpose, data, limitations and testing per high-risk system.

Oversight design

Who can override what, and how that is evidenced.

Logging specification

What is captured, retained and queryable.

Board summary

Two pages your directors will actually read.

WHO THIS IS FOR

Teams with AI already in production

Companies selling into the EU or the UK, regulated sectors where a model influences decisions about people, enterprises whose customers have started sending AI governance questionnaires, and any organisation running AI over personal data of Indian users.

80+ engineers
20+ years in enterprise systems
Hosted in India
7+ patents filed
Nasscom AGI Roadmap contributor
CASE STUDY

Governance for an AI system in a regulated workflow

How we inventoried the models in use, classified them, and built the logging and oversight needed to evidence every decision.

Read the case study
QUESTIONS WE GET ASKED

Before you book a call

Find out where you actually stand

Fifteen questions across inventory, risk classification, data controls, oversight and monitoring. You get a score, a sector benchmark and a two-page report. No call required.

Free · 5 minutes · results on screen