Service · typically 4–8 weeks

AI governance that gets projects approved, not shelved.

The EU AI Act and the GDPR do not stop you from using AI and agents. Not knowing what you run, who is responsible and where the risks sit does. We build the register, the risk classification, the oversight and the policies that let your legal team, your data protection officer and your works council approve AI instead of postponing it.

01

Why governance now

Every company that uses ChatGPT, Copilot or an agent in production is already a deployer under the EU AI Act. Most have not written down what that means.

The EU AI Act entered into force in August 2024 and applies in phases through 2026 and 2027. Prohibited practices and the AI literacy duty have applied since February 2025, the obligations for general-purpose AI models since August 2025, and the high-risk rules follow later. Timelines may still shift, so we verify the current status with you rather than working from a slide.

The GDPR, meanwhile, has applied all along. Any agent that reads customer emails, HR files or CRM records processes personal data and needs a legal basis, a purpose and, often, a data protection impact assessment.

Governance turns these obligations into something operational: a register of what you use, a classification of each use case, defined roles, documented decisions and a policy your employees actually read. Done well, it makes the next AI project faster to approve, not slower.

To be clear: we are consultants, not lawyers. We structure the facts, draft the documents and design the controls, working alongside your legal counsel and your data protection officer, who own the legal assessment.

  • FormatWorkshops, inventory, written framework, templates
  • DurationTypically 4–8 weeks, then optional support
  • ForManagement, legal, DPO, IT security, works council
  • OutcomeAI register, risk classification, policies, oversight design
Read our EU AI Act guide for companies →
02

What you get

The building blocks of a governance framework that fits a company your size. Nothing is added because a standard lists it; everything is added because you will use it.

i.

AI inventory and register

One list of every AI system, model and agent in use, from sanctioned tools to the shadow tools in marketing, with purpose, data, provider, owner and status per entry. It becomes the single source for audits and future decisions.

ii.

Risk classification under the EU AI Act

Each use case sorted into the Act's categories: prohibited, high-risk, limited risk with transparency duties, or minimal risk, with a note on any general-purpose AI models involved. The reasoning is written down so your lawyers can confirm or challenge it.

iii.

Deployer and provider obligations

Which role you play for each system. Buying and using a tool makes you a deployer; substantially modifying it or placing your own system on the market can make you a provider, with a much longer list of duties. We map both.

iv.

Human oversight and transparency

Oversight designed into the workflow rather than promised in a policy: who reviews what, when an agent must stop and hand over, how users learn they are dealing with AI, and how outputs are labelled where the Act requires it.

v.

GDPR and DPIA support

Structured input for your data protection officer: data flows, legal bases, retention, transfers and a draft data protection impact assessment (Datenschutz-Folgenabschätzung) for the use cases that need one.

vi.

AI usage policy and literacy plan

A short, readable policy on which tools are allowed for which data, and a plan for the AI literacy duty under Article 4 that fits your workforce rather than a generic e-learning module.

03

How it works

  1. Inventory

    Interviews with department heads and IT, a pass through procurement and licence lists, and a collection of what people actually use. The resulting register usually surprises management.

    Weeks 1–2
  2. Classification and gap analysis

    Each system is classified under the EU AI Act and checked against the GDPR. We show where obligations are already met, where documentation is missing and where a use case should change or stop.

    Weeks 2–4
  3. Framework design

    Roles, approval paths, oversight checkpoints, logging and documentation standards, vendor assessment criteria and the usage policy, aligned with ISO/IEC 42001 as a reference framework where that helps you later.

    Weeks 4–6
  4. Alignment with legal, DPO and works council

    We take the framework through your legal counsel, your data protection officer and, in Germany, your works council. Objections are handled here, once, rather than in every future project.

    Weeks 6–7
  5. Handover and embedding

    Management sign-off, templates for new use cases, a briefing for whoever maintains the register, and a review rhythm so the framework keeps pace with the law and your systems.

    Week 8
04

Who this is for

  • Companies already using AI without a framework

    Copilot licences, a few agents in production and a growing list of tools nobody approved. Governance here starts with the register and a pragmatic classification, then adds only the controls you need.

  • Mittelstand companies with a works council and a busy DPO

    Owner-managed companies need something a lean organisation can keep running: a framework that fits on a few pages, and a works council that gets the information it needs early. See Mittelstand.

  • Corporates and regulated industries

    Financial services, insurers and businesses close to healthcare face sector rules on top of the AI Act. We design governance that plugs into existing risk, compliance and security structures instead of competing with them. See financial services.

  • Software companies building AI into their products

    If you ship AI features to customers, you may be a provider, not only a deployer. We help you tell the difference and prepare the documentation your enterprise customers will ask for. See software & SaaS.

05

How we approach governance

  • Proportionate, not maximal

    An agent that summarises tickets and a tool that pre-screens applicants do not need the same controls. We size obligations to actual risk, which is what the Act intends.

  • Built into the workflow

    Oversight checkpoints, logging and approvals live inside the agent design, not in a document nobody opens. See guardrails for AI agents.

  • Standards as a reference, not a badge

    We align frameworks with ISO/IEC 42001 and, where useful, the NIST AI Risk Management Framework. We certify no one, and we tell you honestly whether certification is worth pursuing for a company your size.

  • Consulting, not legal advice

    We prepare, structure and draft. The legal assessment stays with your counsel and your DPO, and because the EU AI Act is still evolving, we recommend checking its current status regularly.

06

Standards and tools we work with

  • EU AI Act
  • GDPR
  • ISO/IEC 42001
  • NIST AI RMF
  • DPIA templates
  • AI register templates
  • Model cards
  • Langfuse
  • Microsoft Purview
  • Microsoft Copilot Studio

Standards are frameworks we align with, not certifications we hold. Products are tools we evaluate and work with, without reseller or partnership agreements.

07

Frequently asked questions

Does the EU AI Act apply to us if we only use ChatGPT or Microsoft Copilot?

In most cases, yes. Using an AI system at work makes you a deployer under the Act, and the AI literacy duty applies to every company that uses AI, whatever the tool. How much else applies depends on the use case, not the product: drafting marketing copy is usually minimal risk, while pre-screening applicants or scoring creditworthiness is high-risk. We classify your actual uses; your legal advisers confirm the assessment.

What does the AI literacy duty in Article 4 require?

Since February 2025, providers and deployers must ensure that the people using AI systems on their behalf have sufficient AI literacy for their role and context. The Act prescribes neither a format nor a certificate. We define what is proportionate for your workforce and deliver it through our AI training, which is designed to support compliance; whether it is sufficient in your case remains a legal judgement.

Do we need a data protection impact assessment for every AI use case?

No. A DPIA is required where processing is likely to result in a high risk to individuals. Many AI use cases with personal data meet that threshold; many do not. Your data protection officer makes the call. We prepare the input, from data flows and purposes to legal bases, risks and mitigations, so the assessment is faster and more consistent.

Does the works council need to be involved?

In Germany, often yes. The Works Constitution Act gives the works council co-determination rights where technical systems could monitor employee behaviour or performance, and many AI tools touch that, often unintentionally. Involving the council early, with clear documentation of what a system records and what it does not, tends to turn a blocker into an ally. We prepare that documentation; the legal assessment stays with your counsel.

What happens after the framework is delivered?

The register needs maintaining, new use cases need classifying and the law keeps moving. Most clients choose one of three paths: an internal owner runs it with our templates and a quarterly review; a fractional Chief AI Officer owns it as part of a wider mandate; or the logs and documentation come out of managed AI operations as a by-product.

08

Related services

Next step

Let's find the first workflow worth automating.

A 30-minute intro call, no slides and no obligation. We listen, ask about your processes, and tell you honestly where AI agents would pay off and where they would not.