AI governance and compliance
Most AI compliance failures begin in the same place: the organisation cannot say what it is running.
Start with an inventory
Not a policy. An inventory.
The systems you know about are rarely the problem. The problem is the AI feature switched on inside a platform you already licence, the tool a team adopted without procurement, the capability a vendor added in an update, and the model someone is using through a personal account because the approved one is slower.
This is usually a shorter exercise than people expect — a few weeks rather than a project — and it is the only basis on which anything else can be done. You cannot assess a risk you have not found.
Then classify
Not every system needs the same treatment, and treating them all alike is how governance becomes an expensive irrelevance.
Then do what is proportionate
Most published AI governance material is written for enterprises and is useless to a business of forty people. What proportionate actually looks like:
The UK position, briefly
There is no UK AI Act. Regulation runs through existing law and existing regulators — principally the ICO under data protection law, with Ofcom and the FCA in their sectors.
The Data (Use and Access) Act 2025 rewrote the rules on automated decision-making, requiring meaningful information about the logic, human review and a right to contest. The ICO is under a statutory duty to produce a Code of Practice on AI and automated decision-making — the enabling regulations came into force on 12 May 2026, and the Code is expected in 2027.
What we do
Run the inventory exercise with you. Classify what it finds. Set out what applies to each category. Advise on what proportionate looks like for an organisation your size. And do the specific pieces — DPIAs, vendor terms, hiring process review — that the inventory shows are needed.
What it costs
An AI inventory and risk review is a fixed fee, quoted before we begin and scaled to the size of the organisation. Everything that follows is quoted separately once we know what there is.
Ongoing governance work sits within our business counsel arrangement.
Questions
Questions businesses ask us
Where do we start?
An inventory. Most organisations cannot list what they are running, including features enabled inside tools they already licence. Everything else depends on it.
Do we need an AI policy?
Eventually, and it is not the first step. A policy written before you know what you are running addresses the wrong things.
Should we wait for the ICO Code?
No. The Code is expected in 2027 and the underlying obligations — data protection, automated decision-making, discrimination — apply now. An organisation that did nothing because guidance was pending will have a poor answer.
How much governance does a 40-person company need?
Less than the published material suggests. An inventory, one accountable person, a short usable policy, DPIAs where required, and a record of your reasoning. That is a defensible position.
Our staff are using AI tools we did not approve. Is that a problem?
Potentially a significant one, particularly if confidential or personal data is going into systems nobody has assessed. It is also extremely common, and finding out is the point of the inventory.
Related
The hub
Also in this area
Also in this area
Start with a conversation
A free 20-minute call. Tell us what has happened and we will tell you whether we can help, what it would involve and roughly what it would cost.
No charge
A free 20-minute call
Tell us what has happened and we will tell you whether we can help, what it would involve and roughly what it would cost. No advice is given on this call and there is no charge for it.
£350 plus VAT
A paid strategy session
One hour with a partner, followed by a written summary of your position and options. For people who want proper advice without instructing a firm yet. Credited in full against your fees if you go on to instruct us.
Or reach us directly
We answer enquiries the same working day.