AI Consulting

Data & AI governance

Who owns which data, who may see it, how long you keep it, and what the GDPR and the EU AI Act require of every AI use. Set up so it does not stall your roadmap.

What it is

Governance starts with the data, not the model. We map where each dataset comes from, who owns it, who may see it, how long you are allowed to keep it and where it flows next. Most companies discover here that the same customer record lives in four systems under three different retention rules, and that is the finding that makes the rest of the work possible.

On top of that we classify your AI use cases under the EU AI Act, set up the risk assessments and documentation each class requires, and write the policies that matter for your exposure: personal-data handling and the GDPR basis for it, human oversight, model documentation, incident response. The engagement starts with an inventory of every AI system, use case and vendor tool in play, including the unofficial ones your teams already use. The checks are wired into your existing delivery process, not into a parallel bureaucracy.

What changes: your compliance and legal teams get evidence they can hand to auditors or to a data protection authority, and your engineers get clear rules instead of case-by-case escalation. New AI initiatives clear governance in days rather than weeks, because the gates, the data map and the templates already exist and everyone involved knows how to use them.

Why it works

01

A map of your data, not a policy binder

Every dataset traced to its source, its owner, its retention window and the systems it flows into. That map is what makes every later compliance question answerable in minutes.

02

GDPR and the EU AI Act in one pass

Personal-data obligations and AI risk classification handled together, per use case, because in practice they land on the same systems and the same teams.

03

Audit-ready documentation

Model cards, data lineage and decision logs kept as living artifacts, produced during delivery rather than reconstructed later.

04

Vendor risk covered

Third-party AI tools and APIs get the same classification and review as in-house systems, closing the most common blind spot.

05

Scales past the first project

Templates and gates make the tenth AI initiative as well governed as the first, without re-litigating policy each time.

AI Consulting

How we run it

01

Map the data

Where each dataset comes from, who owns it, who has access, how long it is kept and which systems it flows into, including the spreadsheets nobody admits to.

02

Classify

Each item is classified under the EU AI Act and your internal risk appetite, with obligations mapped per class.

03

Implement

Policies, templates and review gates are written and wired into your delivery process, with owners assigned.

04

Operationalize

We train the people running the gates, run the first reviews together, and hand over a playbook your team maintains.

What you get

Data map: sources, owners, access, retention and downstream flows
AI system inventory with EU AI Act risk classification
Governance playbook with policies and review gates
GDPR records of processing and privacy impact assessments for AI uses
Model documentation and data lineage templates
Human oversight and incident response procedures
Compliance evidence pack for audits

Common questions

Does the EU AI Act even apply to us?

If you operate in the EU and use AI in products, hiring, credit, safety or anything customer-facing, parts of it almost certainly do. The inventory and classification give you a definitive answer per use case instead of a general worry.

Will governance slow our delivery down?

Done badly, yes. That is why we wire the gates into your existing workflow and size them by risk. Low-risk uses get a lightweight checklist, and heavy review is reserved for the few systems that genuinely warrant it.

We already have a compliance team. Why involve engineers?

Because the obligations land in code: logging, oversight hooks, documentation, evaluation evidence. We translate legal requirements into technical controls your compliance team can verify, which is the part most policy documents skip.

Is this about the AI Act or about the GDPR?

Both, and separating them wastes your time. An AI use case almost always processes personal data, so it needs a lawful basis, a retention rule and an access model under the GDPR, and a risk classification with its documentation under the AI Act. We work through them together, per use case, and you end up with one set of evidence instead of two projects that contradict each other.

Start with the data map

Book a call to scope the data map and the AI inventory. It is the fastest way to learn your real exposure under both the GDPR and the EU AI Act.

Scope the data map