Most companies find their AI exposure is narrower than feared and concentrated in one or two systems. The work starts with knowing what is in use and what it actually touches.
AI governance is the framework that determines how an organization acquires, deploys, and monitors AI systems, and who is accountable when those systems touch personal data or make decisions about people. It covers the inventory of what is in use, the risk classification of each system, the assessments that sit behind deployment, and the policies and controls that govern ongoing use.
Any company deploying AI against customer or employee data needs it, and it becomes non-negotiable where the EU AI Act applies, where automated decision-making triggers obligations under GDPR or US state privacy laws, or where enterprise customers are asking the question in diligence.
Usually the business has moved faster than the governance. Tools have been adopted across functions without central oversight, and no one can produce a complete list of what is in use, what data it touches, or what was agreed with the vendor.
The trigger is typically a customer or investor questionnaire the company cannot answer, a board or leadership directive to get ahead of AI risk, an audit or regulatory finding, or a specific deployment that has stalled because no one is willing to approve it.
A scoping call to establish the AI footprint, the jurisdictions in play, and whether the driver is regulatory, contractual, or internal.
Interviews across legal, infosec, IT, procurement, HR, product, and the business functions actually using the tools, alongside a review of existing policies, vendor contracts, and data processing.
Capturing each system, its purpose, the personal data involved, the vendor and contractual position, and whether there is automated decision-making or profiling.
Risk classify each use case against applicable regulation and assess high-risk deployments, including AI-specific impact assessments and DPIAs where required.
Develop the AI use policy, acceptable use and intake standards, an approval and review workflow with clear ownership, vendor diligence criteria, and human oversight requirements.
Circulate to stakeholders for review, finalise, train the people who have to operate it, and hand over an SOP for maintaining the inventory and reassessing systems as they change.
The Act reaches you if you place an AI system on the EU market, or if the output of your system is used in the EU, regardless of where you are established. Obligations depend on the risk tier: a small set of prohibited practices, high-risk uses carrying substantial requirements around risk management, data governance, documentation, human oversight, and conformity assessment, limited-risk uses attracting transparency duties, and everything else largely unregulated.
Employment, credit, education, and essential services uses are the ones that most often land in the high-risk tier without the business expecting it. Obligations phase in on staggered dates through the implementation period, with prohibitions and AI literacy first and high-risk requirements later.
The first step is not compliance work — it is an inventory and a classification, because most companies find their EU exposure is narrower than feared and concentrated in one or two systems.
The inventory is the usual failure point. It is built once from what IT can see, it misses everything procured on a corporate card or embedded inside a tool the company already owns, and it is out of date within a quarter.
Policies get drafted as prohibitions that the business quietly ignores rather than as workable intake and approval routes. Risk classification gets applied to the vendor rather than to the use case, so the same tool is treated identically whether it is drafting marketing copy or screening job applicants.
Companies also lean on vendor assurances without reading what the contract actually permits regarding training on their data. The result is a framework that exists on paper while shadow deployment continues underneath it.
At a multinational property management company with US and EU operations, AI adoption was moving quickly across functions with no central framework governing how tools were approved or used. I developed the organization's AI guidelines and built an AI risk assessment process, giving the business a defined route to bring a use case forward, a consistent basis for classifying risk, and clear criteria for escalation and human oversight. AI use moved from ad hoc adoption to a governed process, with legal and compliance visibility over what was being deployed and against what data.
The work is privacy and compliance advisory. Where a deployment requires technical validation, I will tell you what needs to be tested and what evidence the framework expects, but the testing itself sits with your engineering team or a specialist provider.
Yes, if you place an AI system on the EU market, or if the output of your system is used in the EU, the Act reaches you regardless of where you are established. The starting point is an inventory and a classification — most companies find their EU exposure is narrower than feared and concentrated in one or two systems.
Discrete pieces — assessing a single high-risk deployment or drafting an AI use policy — are considerably shorter and priced accordingly. A full program build is for organizations that need the inventory, risk classification, framework, workflows, and training all built out. The scoping call establishes which applies.
Applying classification to the vendor rather than the use case means the same tool is treated identically whether it is drafting marketing copy or screening job applicants. The use case determines the regulatory tier and the obligations that follow from it — the vendor's own assurances do not change that.
The engagement delivers an SOP for maintaining the inventory and reassessing systems as they change, and the people who have to operate the framework are trained before handover. Ongoing maintenance is available under retainer for organizations that want continued oversight.
A scoping call establishes the AI footprint, the jurisdictions in play, and whether the driver is regulatory, contractual, or internal. You know the number before anything starts.
A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.
We use Google Analytics 4 to understand how this site is used and to measure our advertising. These set cookies on your device. Nothing loads until you choose. How we handle your data.