Skip to content

YOUR OWN LIST, AND WHO OWNS IT

AI Governance & Compliance

You get an inventory of what is already running, a classification you can defend, a policy people actually follow, and processes that survive an audit. We build it with you and hand it over, so governance is something you run rather than something you commission. Calm about the rules, serious about the operation.

THE THESIS

Compliance is an operating capability, not a document.

Most AI governance fails the same way AI pilots fail: unowned, unintegrated, unused. The policy is written and shelved. The impact assessment is bought as a PDF. The risk classification is done once and never maintained. Then the organisation changes, the systems change, the rules change, and the binder stays where it was.

We deliver governance the way we deliver systems: designed with the people who will own it, run together until it holds, and transferred. Your organisation ends up with a capability, not a subscription. That is what separates AI governance consulting that transfers from the kind that renews itself: we earn nothing from your compliance staying complicated.

FIVE PARTS, ALL WITH OWNERS

What AI governance actually contains.

01

The inventory.

You cannot govern what you have not listed. Every engagement starts with the AI inventory: the systems you bought, the systems you built, and the AI embedded in standard software you may not think of as AI. Most organisations are surprised by their own list.

02

The classification.

Which risk category each system actually sits in. For most organisations, most systems land in the lighter categories, and knowing that is the point: it tells you where the real duties are, and frees you from worrying about the wrong things.

03

The policy people actually follow.

A good AI policy is not a ban. It tells your people what they can do, with which data, in which tools, and who to ask when the answer is unclear. The alternative to a workable policy is not compliance. It is quiet, ungoverned use that nobody sees until it becomes a problem.

04

Processes with owners.

Risk management, incident handling, documentation, and where the law requires it, a fundamental rights impact assessment built as a working process. Every process gets a named owner, because a process without one is a document.

05

Competence, the whole ladder.

The Article 4 duty to take measures supporting AI literacy starts where accountability sits. We deliver leadership sessions in the management team, and role-specific programmes for the wider organisation through AIUC, our education arm.

TWO FIXED-PRICE ENGAGEMENTS

Two engagements, packaged and fast.

Packaged, fixed-price and fast, because the questions they answer are the most common ones on the calendar right now. The dates themselves live on our [EU AI Act page](/eu-ai-act).

One honesty the market rarely offers: no harmonised standards are published yet, so our methodology tracks them as they land. We will never sell you a presumption that does not yet exist.

  1. 01

    Transparency readiness

    A small, fast, fixed-price review: which of your systems interact with people or generate content, what disclosure and marking each requires, and which of those you already meet. You get the gap list and the fix plan. Weeks, not months.

  2. 02

    High-risk runway programme

    For organisations with use cases on the high-risk list: risk management, quality management, the impact assessment as a working process, and documentation built to survive both an audit and a handover. Delivered in calm tempo against the calendar: the head start, never the panic.

HOW WE DELIVER IT

Built with you. Then yours.

We design the processes with the people who will own them, run the first cycle together, and hand over: documented, owned, running. There is no compliance retainer and no subscription.

When the rules change materially, and they will, you can bring us back for a defined review. But the capability is yours, and the documentation is written so that any competent partner can take it forward. Including one that isn't us.

PROOF

Delivered where it counts.

Our work spans AI policy and governance frameworks for private-sector clients, and risk classification built into the AI pre-studies we delivered for Arbetsgivarverket and Trygghetsstiftelsen. The consultant who leads your engagement is the person who delivered those.

QUESTIONS

Before you build AI governance.

AI governance is how an organisation governs its own use of AI: which systems exist, what risk they carry, what people are allowed to do with them, and who is accountable for each part. In our work it has five parts: an inventory, a classification, a policy people actually follow, processes with a named owner, and AI literacy at every level. It is an operating capability, not a document, and the difference shows the first time someone asks you to prove what you run.

The EU AI Act asks four things of most organisations: an inventory of your AI systems, a risk classification, a policy people actually use, and measures for AI literacy under Article 4. The transparency duties in Article 50 apply from 2 August 2026. High-risk duties follow on 2 December 2027 for Annex III and 2 August 2028 for Annex I.

High risk under the EU AI Act follows the area of use, not how advanced the technology is. Annex III lists areas such as recruitment, creditworthiness assessment, education, essential services and law enforcement, with duties from 2 December 2027. Annex I covers AI embedded in regulated products, from 2 August 2028. Most systems already in operation carry transparency duties at most.

The EU AI Act applies to you as well when the AI arrived inside standard software, but the work scales to what you have. Embedded AI belongs in the inventory, the AI literacy duty in Article 4 has applied since 2 February 2025 regardless of how the AI got in, and transparency duties may apply from 2 August 2026 depending on use. For light use this is quick work, right-sized on purpose.

ISO/IEC 42001 is not enough on its own to comply with the EU AI Act. It is an AI management system standard and can be a useful instrument, but it is not a harmonised standard under the regulation and gives no presumption of conformity. While no harmonised standards are published, conformity is shown with your own documentation. We build that documentation so it can follow the standards once they land.

AI governance should not sit with IT alone. Accountability belongs in the business and the leadership team, with legal, security and IT supporting. The AI literacy duty in Article 4 of the EU AI Act, in force since 2 February 2025, points the same way: this is a leadership matter. Part of our work is settling the roles and naming an owner per process, because a process without one is a document.

Under the EU AI Act, a public-sector body must bring its existing high-risk systems into conformity by 2 August 2030 at the latest, under Article 111(2). That deadline holds whether the systems change or not: the relief tied to leaving a system substantially unchanged applies to other deployers, not to public authorities. New systems follow the ordinary calendar, so 2 December 2027 for Annex III. What else applies to agencies, municipalities and regions sits on our public and social sector page.

AI governance builds on your GDPR work rather than replacing it. Data protection never went away, and much of what the EU AI Act asks for connects to processes you already run: impact assessments, records, information duties. The Swedish Authority for Privacy Protection supervises AI that processes personal data, and the Swedish Post and Telecom Authority holds a temporary mandate as national competent authority until 31 December 2026. We design the AI processes to reuse that machinery, not duplicate it.

Know what you have. Then govern it.

One conversation settles the two questions that matter: what your AI inventory actually contains, and which duty is nearest. If the honest answer is that you are already fine, that is the answer you will get.