Skip to content

Services / AI Governance

AI governance services for the EU AI Act era

AI governance is how organisations deploy AI lawfully and safely: an inventory of AI systems, risk classification under the EU AI Act, and the policies, registers and technical documentation that regulators, customers and boards now expect to see.

Why AI governance is now a board-level obligation

Binding law, staged deadlines

The EU AI Act is in force and its obligations arrive in stages — prohibitions and AI literacy first, general-purpose AI and high-risk obligations following. Waiting for the final deadline leaves no time to build evidence.

GDPR still applies

Wherever AI touches personal data, GDPR duties — lawful basis, DPIAs, transparency, data subject rights — run in parallel with AI Act obligations. One governance programme should produce evidence for both.

Customers ask first

Procurement and vendor-risk teams already ask for AI usage policies, system inventories and risk classifications. Good governance answers questionnaires before they stall your deals.

AI governance as a service

Not every organisation needs an in-house AI governance function. AI governance as a service delivers the same outcomes on an ongoing, retainer basis: we stand up and then operate your AI system inventory, keep risk classifications current as the EU AI Act’s staged obligations arrive, maintain the policies, registers and technical documentation those classifications require, and sit alongside your team when customers, auditors or regulators ask questions. Engagements are fixed-scope — a defined review cadence, a named specialist, and deliverables your board and procurement teams can actually use — so you get continuous governance without hiring for it.

Our approach is aligned with ISO/IEC 42001, the international standard for AI management systems, so the governance you build with us maps onto the framework customers and auditors increasingly reference — with certification an option, never a prerequisite.

Works alongside your privacy and security programme

Privacy Impact Assessments (PIA / DPIA)

DPIAs remain mandatory where AI processes personal data — AI Act duties sit alongside them, not instead of them.

GDPR Compliance Audits & Gap Analyses

Most AI governance findings trace back to data governance. An audit baselines both at once.

Initial Cybersecurity Audit

Article 15 of the AI Act expects accuracy, robustness and cybersecurity — evidence starts here.

Questions, answered

What is AI governance?

AI governance is the set of policies, roles, registers and controls an organisation uses to deploy AI systems lawfully and safely. In the EU and UK it now has a hard legal edge: the EU AI Act imposes binding obligations by risk class, and the GDPR continues to apply wherever AI processes personal data.

Does the EU AI Act apply to my organisation?

If you place AI systems on the EU market, deploy them in the EU, or their outputs are used in the EU, the Act can apply — including to providers and deployers established outside the EU. Obligations depend on whether a system is prohibited, high-risk, limited-risk or minimal-risk.

How does AI governance relate to GDPR compliance?

They overlap but neither replaces the other. Where an AI system processes personal data you typically need a DPIA under the GDPR and, separately, AI Act obligations tied to the system's risk class. We run both from a single inventory of your AI systems so evidence is produced once and reused.

What does an AI governance service include?

A typical engagement covers an inventory of the AI systems you build, buy or embed; classification of each against the EU AI Act's risk categories and your role for it (provider, deployer, importer); the policies, registers and technical documentation those classifications require; and an operating cadence of reviews, training and updates as obligations phase in. It can run as a one-off assessment or as an ongoing retainer.

When do EU AI Act obligations apply?

In stages. Prohibitions and AI literacy duties have applied since 2 February 2025, and general-purpose AI model obligations since 2 August 2025. From 2 August 2026 the Article 50 transparency rules apply — chatbots must disclose they are AI and AI-generated content must be identifiable. Stand-alone high-risk (Annex III) obligations follow on 2 December 2027, and rules for AI in regulated products on 2 August 2028.