AI governance
Two AI Act duties already apply to ordinary organisations: the Article 4 AI literacy requirement since February 2025, and Article 50 transparency since August 2026. The heavier high-risk regime was deferred to December 2027, which is a working window rather than an exemption. Beyond that, most AI risk in an organisation isn't the exotic stuff. It's the internal tool someone built to be helpful that quietly ended up handling more sensitive data than anyone signed off on. Governance is about knowing where that's happening before it becomes a problem, not a policy binder nobody reads.
What's actually involved
- AI use inventory — what's actually running across your organisation, not what's on a slide deck.
- Four-gate risk classification — sorting each use by how much scrutiny it actually needs, from personal productivity to external-facing.
- Controls anchored to NIST AI RMF for structure and the EU AI Act for obligations, sized to your organisation rather than a formal enterprise programme.
- Ongoing reclassification as tools and usage change, since this is the part that usually gets missed after the first pass.
Who this is for
- Organisations already using AI tools with no framework for what's safe
- Teams that need something usable now, not a formal governance programme in six months
- Organisations that filed AI compliance under "2027 problem" and want to know what is already in force
How it starts
Same as anywhere else on this site: a real reply, not a funnel. The first conversation is a scoping conversation, not a pitch. Nothing starts until you've agreed the scope and cost.