AI governance and compliance

Most AI compliance failures begin in the same place: the organisation cannot say what it is running.

Start with an inventory

Not a policy. An inventory.

The systems you know about are rarely the problem. The problem is the AI feature switched on inside a platform you already licence, the tool a team adopted without procurement, the capability a vendor added in an update, and the model someone is using through a personal account because the approved one is slower.

What to record for each: what it does, who owns it internally, what data goes in, what decisions it informs or makes, whether those decisions affect individuals, who supplied it, and whether anyone has assessed it.

This is usually a shorter exercise than people expect — a few weeks rather than a project — and it is the only basis on which anything else can be done. You cannot assess a risk you have not found.

Then classify

Not every system needs the same treatment, and treating them all alike is how governance becomes an expensive irrelevance.

Does it make or inform decisions about people? Recruitment, performance, credit, access to services. This is the category that carries real legal exposure — data protection, discrimination and, where the EU Act applies, high-risk obligations.
Does it process personal data? Then UK GDPR applies, and a data protection impact assessment is likely to be required.
Does it touch the EU? Outputs affecting people located in the EU bring the EU AI Act into play.
Is it a drafting or productivity tool with no decisions about people? Lower risk — though confidentiality and accuracy still matter.

Then do what is proportionate

Most published AI governance material is written for enterprises and is useless to a business of forty people. What proportionate actually looks like:

At 20 people. An inventory. One named person accountable. A short usage policy people will actually read. DPIAs where required. A rule about what must not go into a public model.
At 200 people. The above, plus classification and a lightweight approval route for new tools, documented human review where decisions affect people, vendor terms reviewed before signature, and outcome testing where systems touch hiring or staff.
At 2,000 people. Formal governance, defined roles, regular review, audit, and training with records.
The through-line at every size: one accountable person, a written record of decisions, and evidence that someone thought about it. A modest set of measures with a clear record of reasoning does better than an extensive policy suite with no evidence of thought.

The UK position, briefly

There is no UK AI Act. Regulation runs through existing law and existing regulators — principally the ICO under data protection law, with Ofcom and the FCA in their sectors.

The Data (Use and Access) Act 2025 rewrote the rules on automated decision-making, requiring meaningful information about the logic, human review and a right to contest. The ICO is under a statutory duty to produce a Code of Practice on AI and automated decision-making — the enabling regulations came into force on 12 May 2026, and the Code is expected in 2027.

Waiting for the Code is not a strategy. The underlying obligations apply now.

What we do

Run the inventory exercise with you. Classify what it finds. Set out what applies to each category. Advise on what proportionate looks like for an organisation your size. And do the specific pieces — DPIAs, vendor terms, hiring process review — that the inventory shows are needed.

What it costs

An AI inventory and risk review is a fixed fee, quoted before we begin and scaled to the size of the organisation. Everything that follows is quoted separately once we know what there is.

Ongoing governance work sits within our business counsel arrangement.

Questions

Questions businesses ask us

Where do we start?

An inventory. Most organisations cannot list what they are running, including features enabled inside tools they already licence. Everything else depends on it.

Do we need an AI policy?

Eventually, and it is not the first step. A policy written before you know what you are running addresses the wrong things.

Should we wait for the ICO Code?

No. The Code is expected in 2027 and the underlying obligations — data protection, automated decision-making, discrimination — apply now. An organisation that did nothing because guidance was pending will have a poor answer.

How much governance does a 40-person company need?

Less than the published material suggests. An inventory, one accountable person, a short usable policy, DPIAs where required, and a record of your reasoning. That is a defensible position.

Our staff are using AI tools we did not approve. Is that a problem?

Potentially a significant one, particularly if confidential or personal data is going into systems nobody has assessed. It is also extremely common, and finding out is the point of the inventory.

Start with a conversation

A free 20-minute call. Tell us what has happened and we will tell you whether we can help, what it would involve and roughly what it would cost.

No charge

A free 20-minute call

Tell us what has happened and we will tell you whether we can help, what it would involve and roughly what it would cost. No advice is given on this call and there is no charge for it.

£350 plus VAT

A paid strategy session

One hour with a partner, followed by a written summary of your position and options. For people who want proper advice without instructing a firm yet. Credited in full against your fees if you go on to instruct us.

Or reach us directly

We answer enquiries the same working day.

Scroll to Top