AI governance

EU AI Act compliance for SMBs: let your team use AI, safely.

Your team already uses ChatGPT and AI inside its software. We set clear rules so they keep using it without risking client data or your reputation, and tell you what the AI Act requires of you, if anything.

Is this for you?

Where most companies stand with AI.

  • Staff use ChatGPT with client dataAnd there is no rule yet on what they may share with it.
  • A customer asks how you control your AI useIn a security questionnaire or a contract clause.
  • You use AI to make decisions about peopleHiring, credit, access to services: the AI Act sets stricter rules here.
  • You build AI into your own productThen the AI Act may treat you as a provider, with more duties.

Opportunity and guardrails

AI is useful. It needs three guardrails.

Used well, AI saves your team hours every week. Used without rules, it can leak client data or put wrong answers in front of customers.

Three guardrails cover most of the risk. Data: what may and may not go into an AI tool. Approved tools: which ones staff may use, and with which accounts. A human check before anything AI-generated reaches a client. The AI Act then adds duties that depend on how you use AI. For most companies, the main one is helping staff understand the tools they use.

What you get

Four starting points, depending on how you use AI.

Your team uses AI tools

For companies using Copilot, ChatGPT or AI inside their software. A map of where AI is used, an AI use policy, staff awareness matched to their roles, a check that no use is banned, and basic checks on your AI suppliers.

You use AI to decide about people

Credit scoring, recruitment, patient triage, education, public services. A check against the high-risk rules, the fundamental rights impact assessment, human oversight that works and the records you will be asked for, ahead of the December 2027 deadline.

You build AI products

For software vendors and start-ups selling AI systems in the EU. The risk, data and documentation processes the AI Act requires of providers, then conformity assessment, CE marking and EU registration.

You build on large AI models

For teams building chatbots, copilots or agents on models such as OpenAI, Anthropic, Google or Mistral. Model choice and testing, protection against prompt injection, checks on your model provider, the right AI disclosures and an AI incident plan.

Who does what

We set the rules. Your teams and suppliers run the AI.

What we lead

  • Map your AI use and sort it into the AI Act categories
  • Write the AI policy and the list of approved tools
  • Design human oversight and the AI incident process
  • Train staff on the tools they use
  • Prepare the evidence you will be asked for

What stays with your IT provider

  • Configure and run the AI tools
  • Apply the access and data settings we specify
  • Keep the logs and records the plan requires

We do not build, deploy or configure AI systems.

How it works

Five steps, starting with a map of your AI use.

  1. 01

    Map and classify

    1–2 weeks

    Every AI system you use or build, your role under the AI Act, and which rules apply. This sets the scope of everything that follows.

  2. 02

    Risks and gaps

    After the map

    An AI risk assessment for each system in scope, the gaps against the AI Act, and a plan with the legal deadlines mapped to your timeline.

  3. 03

    Rules and controls

    The main phase

    AI policy, roles, staff AI literacy, supplier checks and an AI incident runbook, plus the documents your route requires. Everything maps to ISO/IEC 42001, so certification later is assembly, not rework.

  4. 04

    Check and sign-off

    Before handover

    An internal review against your obligations, the evidence pack and a sign-off pack for management.

  5. 05

    Keep it current

    Optional, monthly

    Updates as the AI Act changes, an annual review and support if an AI incident happens.

How it starts

A fixed fee, scoped to how you use AI.

After the free call we size the work to your AI use, the number of systems in scope and the rules that apply. Keeping it current afterwards is an optional monthly fee.

Price
Fixed fee
Duration
First results in 1–2 weeks

Fixed quote after the free call.

book a free 25-minute consultation

For your IT manager, DPO or CFO

Multi-framework. Multi-role. One engagement.
FactorCyber-Management AI governanceTraditional alternative
Methodology coverageEU AI Act, ISO/IEC 42001, ISO/IEC 23894, OWASP LLM Top 10, MITRE ATLAS, ENISA, woven into one engagementOne framework at a time: legal counsel for the AI Act, a security consultancy for OWASP, an ISO consultancy for 42001
Time to start1–2 weeks from first conversationOften weeks of scoping with large firms or a law firm
Cost structureFixed-fee engagement, scoped to your AI use; transparent in the proposalOpen-ended legal fees; enterprise-tier day rates
ISO 42001 readinessEvery Phase 3 deliverable maps to ISO 42001 clauses: certification is assembly work, not reworkAI Act compliance and ISO 42001 readiness as separate, sequential projects
Practitioner credentialsCISSP and PECB ISO/IEC 42001 and ISO/IEC 27001 Lead Auditor, held by the consultant who leads and delivers your engagementOften legal counsel without security depth, or security firms without regulatory depth
EU regulatory groundingEU practice: CNIL, ANSSI, ENISA and EDPB guidance (Opinion 28/2024); regulatory analysis, not legal adviceOften US-imported methodology (NIST AI RMF) that does not map cleanly to EU obligations
vCISO add-onAvailable: the security overlay folds into your existing vCISO controls (about 20% less)Each engagement bespoke; integration with a fractional CISO is unusual

FAQ

What IT, data and product teams ask us about AI.

What's the difference between AI governance and ISO 42001 certification?
AI governance is the engagement: risk, governance, controls, security and AI Act compliance for the AI you use or build. ISO/IEC 42001 certification is the follow-on: the same work wrapped into a certifiable AI management system, taken through Stage 1 and Stage 2 with the certification body you choose. Phase 3 deliverables already map to ISO 42001, so certification is assembly work, not rework.
We don't build AI, we just use ChatGPT, Copilot and AI inside our software. Do we still need this?
Yes: you're a deployer under the AI Act. Article 4 (AI literacy) and the original Article 5 prohibitions bind every deployer from February 2025; the two prohibitions the Omnibus added, on non-consensual intimate imagery and child sexual abuse material, bind from 2 December 2026. If your AI use touches recruiting, credit decisions, emergency patient triage, education or any other Annex III high-risk category, Article 26 deployer obligations also bind from 2 December 2027 (post-Omnibus). The first starting point (your team uses AI tools) is built for this: AI literacy, an AI use policy, supplier checks and an Article 5 screen of every use case.
How is the engagement priced?
A fixed fee scoped to your AI use. The first phase sets the scope: your starting point, the number of AI systems, the rules that apply (GDPR, NIS2, DORA, sector) and the countries involved. Keeping it current afterwards is a separate monthly fee. Both figures are in the proposal, before you commit. No hourly billing.
Can AI governance be delivered as part of a vCISO engagement?
Yes, at roughly 80% of the standalone price. The security overlay folds into your existing vCISO controls: your vCISO already runs your security management, risk register, incident response and supplier security, and we extend them to your AI use. If you already run our training programme, AI literacy can reuse it.
Why is NIST AI RMF not in the methodology?
NIST AI RMF is a US voluntary framework. It does not map cleanly to the EU rules your obligations sit under: the AI Act, ISO/IEC 42001, ISO/IEC 23894 and EDPB Opinion 28/2024. For security we use the OWASP Top 10 for LLM Applications, MITRE ATLAS and ENISA's AI threat landscape guidance, which pair with the European regulatory inputs.
What if the AI map finds something prohibited under Article 5?
We flag it and walk you through the way out, usually winding down the use or changing it substantially. Article 5 prohibitions (social scoring, certain biometric categorisation, emotion recognition at work or in education, untargeted facial-image scraping and others) carry the heaviest AI Act fines: up to €35M or 7% of global turnover under Article 99 (for an SME, whichever is lower). Most SMB uses are not prohibited, and the screen runs in the first phase to surface them early.
Do we need a fundamental rights impact assessment?
The Article 27 assessment is mandatory for public-sector bodies and certain private deployers using high-risk Annex III AI that affects people. We determine whether it applies during the first phase, and it is a Phase 3 deliverable when it does. It is built to work alongside your GDPR impact assessments without duplicating them.
Do you work with our region or sector?
We work across France (mainland and overseas regions), Belgium, Luxembourg, Switzerland and the wider EU, in English and French, remotely and on-site as needed. Typical sectors: financial services (DORA overlay), healthcare, public sector, professional services (recruiting and HR AI) and B2B software (AI providers and teams building on large models).