Your team uses AI tools
For companies using Copilot, ChatGPT or AI inside their software. A map of where AI is used, an AI use policy, staff awareness matched to their roles, a check that no use is banned, and basic checks on your AI suppliers.
AI governance
Your team already uses ChatGPT and AI inside its software. We set clear rules so they keep using it without risking client data or your reputation, and tell you what the AI Act requires of you, if anything.
Is this for you?
Opportunity and guardrails
Used well, AI saves your team hours every week. Used without rules, it can leak client data or put wrong answers in front of customers.
Three guardrails cover most of the risk. Data: what may and may not go into an AI tool. Approved tools: which ones staff may use, and with which accounts. A human check before anything AI-generated reaches a client. The AI Act then adds duties that depend on how you use AI. For most companies, the main one is helping staff understand the tools they use.
What you get
For companies using Copilot, ChatGPT or AI inside their software. A map of where AI is used, an AI use policy, staff awareness matched to their roles, a check that no use is banned, and basic checks on your AI suppliers.
Credit scoring, recruitment, patient triage, education, public services. A check against the high-risk rules, the fundamental rights impact assessment, human oversight that works and the records you will be asked for, ahead of the December 2027 deadline.
For software vendors and start-ups selling AI systems in the EU. The risk, data and documentation processes the AI Act requires of providers, then conformity assessment, CE marking and EU registration.
For teams building chatbots, copilots or agents on models such as OpenAI, Anthropic, Google or Mistral. Model choice and testing, protection against prompt injection, checks on your model provider, the right AI disclosures and an AI incident plan.
Who does what
We do not build, deploy or configure AI systems.
How it works
1–2 weeks
Every AI system you use or build, your role under the AI Act, and which rules apply. This sets the scope of everything that follows.
After the map
An AI risk assessment for each system in scope, the gaps against the AI Act, and a plan with the legal deadlines mapped to your timeline.
The main phase
AI policy, roles, staff AI literacy, supplier checks and an AI incident runbook, plus the documents your route requires. Everything maps to ISO/IEC 42001, so certification later is assembly, not rework.
Before handover
An internal review against your obligations, the evidence pack and a sign-off pack for management.
Optional, monthly
Updates as the AI Act changes, an annual review and support if an AI incident happens.
How it starts
After the free call we size the work to your AI use, the number of systems in scope and the rules that apply. Keeping it current afterwards is an optional monthly fee.
Fixed quote after the free call.
book a free 25-minute consultation| Factor | Cyber-Management AI governance | Traditional alternative |
|---|---|---|
| Methodology coverage | EU AI Act, ISO/IEC 42001, ISO/IEC 23894, OWASP LLM Top 10, MITRE ATLAS, ENISA, woven into one engagement | One framework at a time: legal counsel for the AI Act, a security consultancy for OWASP, an ISO consultancy for 42001 |
| Time to start | 1–2 weeks from first conversation | Often weeks of scoping with large firms or a law firm |
| Cost structure | Fixed-fee engagement, scoped to your AI use; transparent in the proposal | Open-ended legal fees; enterprise-tier day rates |
| ISO 42001 readiness | Every Phase 3 deliverable maps to ISO 42001 clauses: certification is assembly work, not rework | AI Act compliance and ISO 42001 readiness as separate, sequential projects |
| Practitioner credentials | CISSP and PECB ISO/IEC 42001 and ISO/IEC 27001 Lead Auditor, held by the consultant who leads and delivers your engagement | Often legal counsel without security depth, or security firms without regulatory depth |
| EU regulatory grounding | EU practice: CNIL, ANSSI, ENISA and EDPB guidance (Opinion 28/2024); regulatory analysis, not legal advice | Often US-imported methodology (NIST AI RMF) that does not map cleanly to EU obligations |
| vCISO add-on | Available: the security overlay folds into your existing vCISO controls (about 20% less) | Each engagement bespoke; integration with a fractional CISO is unusual |
FAQ