For Organisations that want to govern AI use
Your staff are already using ChatGPT, Copilot and a dozen tools nobody signed off. Nobody can say what’s running, or what happens to the client data going into them.
Then a customer’s procurement team sends a due-diligence questionnaire, and the deal waits behind it until you can answer in writing.
“The organisations that can prove control close the deal, pass the audit, and get asked fewer questions next time”
– Alan Bates, Founder, 10 Kinds
Two reasons it might, and most organisations have both. Some AI use carries legal duties. The rest gets asked about anyway.
UK GDPR already binds how you use AI the moment personal data is involved, and it almost always is. Someone pasting a customer email into ChatGPT is a processing decision nobody approved, in a tool nobody checked.
Potential fines
€15m / 3% turnover
for breaching the EU AI Act’s transparency rules, law since 2 August 2026. But most internal AI use triggers none of them.
Source: EU AI Act, Article 99
Shadow AI usage
71%
of UK employees have used AI tools at work without approval, and 51% do so every week.
The transparency rules in Article 50 apply since 2 August 2026. They’re narrower than most of the coverage suggests, so here’s the plain version of what they require and who they bind (this isn’t legal advice).
2 August 2026
Article 50 transparency obligations apply from this date
Providers of AI systems that interact directly with people have to build them so those people know they’re dealing with an AI, unless that’s already obvious.
Providers of systems that generate synthetic audio, image, video or text have to mark the output in a machine-readable format so it can be detected as artificially generated.
Deployers of emotion recognition or biometric categorisation systems have to tell the people exposed to them that the system is running.
Deployers have to disclose deepfakes, and label AI-generated text published to inform the public on matters of public interest.
Using Copilot or ChatGPT internally to draft documents triggers none of the four. Article 50 governs what you tell people when they’re seeing or speaking to AI. The obligations that do reach internal use come from UK GDPR, and from the customers whose due-diligence questionnaires ask harder questions than Article 50 does.
We don’t tell you your legal classification. That’s a question for a solicitor, and you’d be right to want it in writing from one.
What we build is the machinery underneath: the AI inventory, the risk process, the documentation and the human oversight controls that Article 17 would require of you if you turn out to be in scope, and that a customer’s questionnaire asks for either way. When the legal answer arrives, you’re not starting from zero. With the high-risk obligations now deferred to 2 December 2027, there’s runway to build it properly rather than in a panic.
Source: European Commission guidelines on Article 50, adopted 20 July 2026
Four sources, and most organisations are carrying all four at once. Each one boils down to the same two questions: what AI is running here, and what happens to the data once it gets there.
A customer's procurement team sends an AI due-diligence questionnaire, and the deal sits behind it until you can answer it in writing.
Staff pasting corporate & client data into consumer AI tools, with no register of what's being used or where the data goes.
Every AI-enabled tool you've brought in carries the vendor's governance gaps as well as your own.
UK GDPR already binds how you use AI, with or without the EU AI Act in play. The ICO doesn't need Brussels to enforce it.
Let's talk and start your journey. Book a free call
These are the five questions almost every AI due-diligence questionnaire is built around, whatever words it uses to ask them.
Do you know what AI is in use across your business, including tools nobody signed off?
Is there a human in the loop for decisions that affect the customer, and is that documented rather than assumed?
What happens to the customer's data once it touches an AI system, and does any of it leave your control?
If something goes wrong, is there a known process, or does it get handled ad hoc?
Who is accountable for AI risk internally, by name, not by department?
Answer those five with confidence and you can answer most of what's in a typical questionnaire.
Get the free checklistGovernance is the Discover and Foundations part of how we work. Find what’s running, change how people use it, then build the evidence.
Sanctioned tools are the tip of it. We run a use-case inventory across your business, including the shadow AI nobody officially approved, so you have one accurate register instead of a guess.
We write the acceptable use policy, then run the workshop that gets leadership to sign off on it. What’s approved, what’s off-limits, what needs a human, and who owns the call.
A policy nobody has been taught changes nothing. This is where the value is unlocked: everyone trained, desk to board, on what’s allowed and how to use these tools well. It’s also the competence an auditor asks you to evidence. How training works.
A customer’s due-diligence questionnaire, a regulator and an auditor all ask the same underlying thing: can you show this is controlled? We run our ISO/IEC 42001 gap assessment and build the inventory, records and oversight controls that answer it, whichever way your regulatory classification goes.
Most organisations don’t build AI, they buy it. You get a third-party and vendor risk assessment covering every AI-enabled tool you’ve bought, including the exposure that never shows up in your own audit.
A management system needs internal audit, management review and fresh evidence every year. You get all three on an annual cycle, plus surveillance audit prep, so the next visit isn’t a scramble. We stay on as the retainer rather than handing over a folder that goes stale.
What this gives you
Governance is usually the first step. Once your people are working differently and the evidence is in place, we build the tools and workflows that make AI pay.
Your regulatory classification is a question for a solicitor, and you should want it in writing from one. We build the inventory, risk process, documentation and oversight controls that hold up whichever way the answer goes, and hand you the short list of questions worth paying a lawyer to settle.
Certification is done by an accredited certification body, and no consultancy can both advise and certify. We build the management system and get you ready for that audit.
ISO/IEC 42001, the EU AI Act and UK GDPR/ICO guidance. We leave out NIST's AI RMF because it's US-focused and adds little to a UK engagement. A longer framework list isn't a better one.
Each one is a fixed price against a written scope agreed before we start. Stop after any of them. Training is priced separately on the [training page](/training/).
Govern
Each engagement is quoted at a fixed price against a scope agreed in writing before we start. No day-rate creep, and no surprise on the invoice.
You get the documents listed on each engagement at the end of it, so you can put them straight in front of a customer, an auditor or your board.
Nothing here is a bundle or a prerequisite. Come for training, a prototype or a retainer on its own if that's what you need, and stop whenever you're done.
Everything you tell us stays between us, on the free call as much as in a paid engagement, and we'll sign your NDA beforehand if you'd rather have it in writing.

Free download
Twelve questions every leadership team should be able to answer about the AI already running in their business. It covers similar ground to a paid discovery engagement, condensed into something you can work through yourself in about ten minutes.
That’s the most common way people find us. Book a free call and bring it with you: we can discuss it, and what it would take to close the gaps.
Yes, though usually not because of the EU AI Act. Article 50’s transparency duties mostly bind the people who build and supply AI systems, and drafting documents internally with Copilot triggers none of them.
What reaches you is UK GDPR, your customers’ due-diligence questionnaires, and the risk sitting in tools you’ve bought in: an unmanaged register of AI use, a policy nobody’s read, a vendor whose own controls you haven’t checked. That’s the ground we cover.
No. Your legal classification is a question for a solicitor, and you should want that answer in writing from one rather than from a consultancy.
What we do is build the machinery it depends on: the AI inventory, the risk process, the documentation and the human oversight controls. That work is useful whichever way the classification goes, and a customer’s questionnaire asks for it either way. We’ll also hand you the specific questions worth putting to a lawyer, so the legal spend is short and targeted.
There’s real overlap. UK GDPR already covers a lot of what ‘AI governance’ means in practice. We’re clear about where your existing data protection work already answers the question, and where AI adds a distinct one.
Not necessarily. Certification only pays off if you’re regularly asked to prove it, most often because a customer’s procurement team demands it. We’ll give you a straight read on whether it’s worth pursuing or whether a lighter governance setup covers your actual risk.
Yes. Everything you tell us stays between us, on the free call as much as in a paid engagement, and we’ll sign your NDA before the first conversation if you’d rather have it in writing.
Nobody gets named in a case study, a talk or a post without asking you first. Most of what we’re shown is the same handful of gaps we see everywhere, so there’s nothing to be embarrassed about in any case.
We work from the minimum we need to do the job, on our own equipment, and we hand back or delete what we hold at the end of an engagement.
Your documents and business data never get fed into public AI models to train them. Anything we build for you runs on infrastructure scoped to your organisation and sees only the data you point it at.
It contributes. ISO/IEC 42001 asks you to show the people working with AI are competent to do so, and training is how you get there. Keeping the records is your side of it, and we’ll tell you what to keep. Training alone doesn’t get you certified, and nothing we do makes the certification decision for you.
Book a free 30-minute call. If a questionnaire’s what brought you here, bring it along and we can discuss it. We’ll give you a straight read on where you stand and what the right next step looks like.
Half an hour on where you stand: what AI is running, how well your people use it, and what would be worth automating. Bring a customer questionnaire if that’s what brought you here.
You'll leave with a clear position on where you stand and what to fix first, whether or not you hire us.