AI governance and the EU AI Act
AI governance for a company means four written things: an internal AI policy that legal signs off, a data protection impact assessment where personal data is involved, a classification of each AI use case under the EU AI Act, and training by role so people know what they may and may not do. Obligations under the EU AI Act for high-risk uses apply from August 2026, and GDPR applies to every piece of data an employee pastes into a model today.
What we deliver
- AI policy: which tools are approved, what data may go where, who approves new use cases, how incidents are reported. Written so your legal department signs it, not so it sits in a drawer.
- Data protection impact assessment (DPIA) and data-processing agreements (DPA) for the AI layer and its subprocessors.
- EU AI Act classification: each use case sorted by risk category with the obligations that follow, and a register you keep current.
- Role-based training: built on your team's actual tasks, not generic slides. Different for finance, sales, IT and management.
- A data-handling map: where prompts, files and logs are processed, how long they are kept, which subprocessors are involved, per component.
The security checklist we build against
- Data processing according to the chosen deployment, including full EU residency where required.
- A contractual ban on training models on your data.
- Audit of every request: who, when, what, at what cost.
- Automatic masking of personal data before anything is sent to the model.
- Sign-in with company accounts and immediate revocation of access.
- Infrastructure with ISO 27001 and SOC 2 certification.
- Data-processing agreement and data protection impact assessment.
- Internal AI policy and classification under the EU AI Act.
Why governance comes with implementation, not after it
A policy written before the AI layer exists describes a system nobody uses; a policy written afterwards describes a system nobody can change. We write the policy while the architecture is being decided, so sign-in, audit, masking and approval gates are in the system rather than in a document about the system. That is also what makes the documented exit possible: how agents are stopped, credentials revoked and processes returned to manual operation, agreed before go-live.
Questions we get asked
Does the EU AI Act apply to a company that only uses ChatGPT or Claude?
Using a general-purpose model in ordinary office work is mostly low risk, but the obligations depend on what the model is used for. Use in hiring, credit decisions, safety-relevant processes and similar areas falls into higher categories with obligations from August 2026. That is why each use case is classified separately.
Is a DPIA always required?
Not always, but whenever personal data is processed in a new way with a likely high risk to the people concerned. For a company assistant that reads customer and employee data, we treat it as required and produce it as part of the implementation.
Can you train our people?
Yes, by role and on real tasks from your daily work: what finance may put into the assistant, how sales uses CRM context, what IT sees in the audit, what management approves. Not a generic AI course.
We already have an AI policy. Do we need a new one?
Often not. We review it against the actual system: whether it names the approved tools, the data rules, the approval path for new use cases and incident reporting, and whether the controls it describes exist in the system. Gaps are closed, not rewritten.
Talk to us.
A 30-minute consultation on your scenarios. You will leave with a concrete assessment, whether we work together or not.