Fast, but not careless.
AI moves quickly. Accountability has to move with it.
Governance is not paperwork you add before an audit. It is the difference between an agent that earns its place in your business and one that quietly costs you money, data or trust. We build it in from the first sprint — and we will check what you have already shipped.
The risk isn’t the model. It’s everything around it.
Almost none of the damage being done by AI right now comes from a model behaving strangely. It comes from nobody deciding who owns it, what it may touch, and how anyone would know if it went wrong.
of breached organisations had no policy in place to govern AI use or manage shadow AI.
IBM · Cost of a Data Breach 2026of organisations that suffered an AI-related breach lacked adequate access controls around the AI itself.
IBM · Cost of a Data Breach 2026of security incidents now involve shadow AI — tools adopted with no oversight. Double last year’s share.
IBM · Cost of a Data Breach 2026of agentic AI projects are forecast to be cancelled by the end of 2027 — on cost, unclear value and weak risk controls.
Gartner · 2025None of these are model failures. They are governance failures — no inventory, no access boundaries, no named owner, no audit trail. Every one of them is cheaper to prevent than to explain afterwards.
The clock already started
The EU AI Act’s heaviest obligations were pushed back in July 2026 — but the transparency rules were not. If you sell into the EU, part of this applies to you today.
Prohibited practices
Banned uses took effect, alongside the AI literacy duty on anyone deploying AI systems.
In forceTransparency obligations
Article 50 duties apply: people must be told when they are dealing with AI, and synthetic content must be marked.
Live nowLegacy systems + new bans
Marking duties extend to systems already on the market, and further prohibited practices come into effect.
Months awayHigh-risk obligations
Annex III systems — hiring, credit, education, essential services — face the full regime. Embedded systems follow in Aug 2028.
Deferred, not droppedSixteen months is preparation time, not a pause. The Digital Omnibus moved the high-risk deadline from August 2026 to December 2027 because the standards and national authorities were not ready — not because the obligations went away. Conformity documentation, human-oversight design and technical files take longer to build than the extension you were given.
Regulation (EU) 2026/1744 · in force 27 July 2026Six principles we don’t bend
These shape how we scope, build, test and hand over every product — even when doing the responsible thing takes more time.
Start with the problem
Build something worth building.
Use AI to solve a real user problem — not simply because you can.
Keep humans in the loop
AI assists. People decide.
Design clear points for human judgement, intervention and accountability.
Test before you trust
Prototype fast. Validate properly.
AI-generated code and outputs need testing, review and real-world validation before they become production systems.
Know what you’re shipping
No black boxes.
Understand your models, data, dependencies, permissions and limitations — and make them visible to the people who need to know.
Build securely and sustainably
Fast shouldn’t mean careless.
Protect data, minimise unnecessary complexity and compute, and consider the environmental impact of what you build.
Own what you build
Responsibility doesn’t end at launch.
Monitor performance, fix issues, learn from users and keep improving as the product, technology and risks evolve.
Find out where you actually stand
Four ways in, depending on whether you are worried about something already running or something you are about to build.
Governance readiness check
Six weighted domains, one honest picture of where you would struggle if a customer or auditor started asking.
Free · 5 minutes
- Scored across six GUARD domains
- Your weakest domain named, not averaged away
- A short report you can share internally
- No call required to get the result
Agent health check
For an agent already in production. What it costs, where it fails quietly, and what it is getting wrong that nobody has caught.
from £1,200 · 5–7 working days
- Permissions, tool access and blast radius mapped
- Prompt injection and data-leak probes
- Failure and hallucination sampling against real traffic
- Token and infrastructure cost breakdown
- Findings ranked by severity, with fixes
GUARD compliance check
A full review against the EU AI Act and your own obligations, with the documentation you would need to evidence it.
from £2,400 · 2–3 weeks
- AI inventory and risk classification
- Article 50 transparency gap analysis
- Risk register, AUP and human-oversight design
- Vendor and model dependency review
- Remediation roadmap with owners and dates
Governance partner
For teams shipping AI continuously, where the risk picture changes every time you deploy.
from £600 · per month, rolling
- Risk register and inventory kept current
- Review of each significant release
- Regulatory changes tracked and translated
- Quarterly re-score against GUARD
- Named contact for procurement questions
Rather do it yourself?
The AI Governance Starter Kit (£99) gives you the readiness assessment, AUP template, risk register, vendor checklist and roadmap. The AI Trust & Compliance Pack (£299) covers EU AI Act deployer obligations end to end.
Prices exclude VAT. We are not a law firm — our work evidences and documents your position; it does not replace legal advice where you need it.
Get ahead of the question.
Thirty minutes now gives you a credible answer when the customer, auditor or procurement team comes knocking.