Skip to content

Services

AI Transformation

Deploy it because it works, and because you can defend it.

Deploy it because it works, and because you can defend it.

Two things are usually true at the same time. Your teams are already using generative AI, often through tools nobody approved. And the projects that have been formally proposed are stuck, because nobody can say whether they are allowed.

This practice resolves both. We inventory what is actually in use, classify each system under the AI Act, and set up governance light enough that it does not become the reason nothing ships. Then we build: a scoped pilot on your data, evaluated against a measured baseline, with access control and logging from the first day rather than added before go-live.

The security work is not a separate phase. An assistant connected to your document store inherits every permission mistake in it. An agent with credentials is an access decision. We treat them that way from the start.

AI Transformation

Strategy and governance

Where AI is worth the effort, and the rules that keep it defensible.

  • AI and data maturity assessmentTypical duration: 3–6 days

    Where you actually stand on data, skills, governance and tooling, including an honest inventory of the shadow AI your teams are already using.

    You receive

    • Maturity scoring across five dimensions
    • Shadow AI inventory
    • Readiness gaps by capability
    • Priorities for the next two quarters
  • AI strategy and roadmapTypical duration: 8–15 days

    A portfolio of use cases ranked by value and feasibility, sequenced into a roadmap with the platform and governance work that has to happen alongside it.

    You receive

    • Use-case portfolio with value estimates
    • Prioritisation and sequencing
    • Target platform and skills plan
    • Investment case and roadmap
  • AI governance frameworkTypical duration: 5–10 days

    Roles, approval gates, an AI register and review criteria, aligned with ISO 42001 and the AI Act so that governance and compliance are one piece of work.

    You receive

    • AI policy and roles
    • AI system register
    • Approval gates and review criteria
    • Alignment map to ISO 42001 and the AI Act
  • Executive and business enablementTypical duration: 4–16 hours

    Working sessions that leave leaders able to judge an AI proposal: what these systems do well, where they fail, and what the regulation asks of them.

    You receive

    • Executive briefing session
    • Business team workshops
    • Use-case identification output
    • Internal communication material

Use cases and delivery

From a scoped use case to a system in production, with the risk work done alongside.

  • Use-case scoping with AI Act risk analysisTypical duration: 3–6 days

    A use case defined precisely enough to build — data, users, success measures — with its AI Act classification settled before any budget is committed.

    You receive

    • Use-case specification
    • Data availability and quality check
    • AI Act classification and obligations
    • Build or buy recommendation
  • Generative AI pilotTypical duration: 15–40 days

    A working pilot — retrieval-augmented search, an internal assistant or document automation — built on your data, evaluated against a measured baseline, with access control and logging from day one.

    You receive

    • Working pilot in your environment
    • Evaluation set and measured results
    • Access control, logging and guardrails
    • Production readiness assessment
  • AI agents and process automationTypical duration: 20–50 days

    Agents that act on systems, built with the permission model and the human checkpoints defined first, because an agent with broad credentials is an access risk before it is a productivity gain.

    You receive

    • Process analysis and automation design
    • Agent permission and tool model
    • Human-in-the-loop checkpoints
    • Deployment with monitoring
  • Secure roll-out of Copilot, ChatGPT Enterprise, Gemini or ClaudeTypical duration: 5–12 days

    The work that has to happen before a company-wide assistant is switched on: permission cleanup, data classification, tenant configuration, logging and user guidance.

    You receive

    • Permission and oversharing remediation
    • Tenant and data controls configuration
    • Usage policy and user guidance
    • Adoption and monitoring plan
  • MLOps and LLMOpsTypical duration: 15–40 days

    The engineering that turns a promising pilot into a system you can operate: versioning, evaluation in the pipeline, cost control, monitoring and a rollback that works.

    You receive

    • Model and prompt versioning
    • Automated evaluation in CI
    • Monitoring, cost and quality dashboards
    • Release and rollback process

Trustworthy and secure AI

The assurance layer: risk assessment, data protection, and audit of what is already running.

  • AI risk assessment and fundamental rights impact assessmentTypical duration: 5–12 days

    Risk assessment of an AI system across safety, bias, robustness and rights, including the fundamental rights impact assessment the AI Act requires from certain deployers.

    You receive

    • AI risk assessment report
    • Bias and robustness testing results
    • Fundamental rights impact assessment
    • Mitigation plan and residual risk
  • Data security in AI projectsTypical duration: 5–15 days

    Controls for the data an AI system touches: minimisation, pseudonymisation, retention in vector stores, tenant isolation and the contractual position with your model provider.

    You receive

    • Data flow and retention map
    • Minimisation and pseudonymisation design
    • Vector store and isolation controls
    • Provider contract and DPA review
  • Audit of an existing AI systemTypical duration: 8–20 days

    An independent review of a system already in production: how it performs, how it fails, what it logs, and whether its documentation would survive a regulator's question.

    You receive

    • Performance and failure mode analysis
    • Documentation and logging review
    • Compliance gap assessment
    • Remediation plan
  • AI for cybersecurity and complianceTypical duration: 8–20 days

    Applying AI where it genuinely helps our own field: alert triage, evidence gathering, policy drafting and supplier questionnaire handling, with a human decision at the end.

    You receive

    • Opportunity assessment in security and compliance
    • Pilot implementation
    • Human oversight design
    • Measured effect on workload

AI Act Check

Every AI system inventoried, classified and dated, with the obligations that follow.

Duration
3–4 weeks
Price
€6,000 to €12,000
excl. VAT, indicative

Discuss this pack — AI Act Check

GenAI Secure Launch

An assistant rolled out to the whole company without opening the whole file server with it.

Duration
4–6 weeks
Price
€12,000 to €25,000
excl. VAT, indicative

Discuss this pack — GenAI Secure Launch

Outsourced AI officer (vCAIO)

The person who owns your AI register, reviews each new use case against the AI Act, and keeps governance moving at the speed your teams are actually adopting these tools.

What is included

  • AI register ownership
  • Use-case review and approval
  • AI Act and ISO 42001 tracking
  • Vendor and model assessments
  • Quarterly governance report
AICompliance

Discuss this service — Outsourced AI officer (vCAIO)

Compliance-as-a-Service

Your compliance obligations run continuously: evidence collected as it is produced, internal audits on schedule, regulatory changes watched, and the audit answered without a scramble.

What is included

  • Annual compliance calendar
  • Continuous evidence collection
  • Internal audit programme
  • Quarterly compliance report
  • Regulatory change watch

Available tiers

  • One framework
  • Two frameworks
  • Multi-framework
Compliance

Discuss this service — Compliance-as-a-Service

Start with the inventory

AI Act Check takes three to four weeks and tells you what you are running, what it is classified as, and what is owed from when.