AI Governance Baseline Brief
Know where your AI stands — before someone else asks. One organisation, one written brief for the board.
Without months of discovery, a panel of lawyers, or an invoice that outgrows the problem.
What you get
Your AI tools
Systems and vendors in use, their purpose, and accountable owners.
What matters for each tool
What is likely to apply under the EU AI Act and GDPR — for each tool, not in general.
Your current status
· · ·
Tap a status to see what it means.
Your next actions
Priority actions, accountable owners, and first steps.
Decisions to make
The decisions required before AI is bought, used, launched, or scaled.
Plus a one-page leadership summary of key issues, decisions, and next steps.
Delivered as a confidential, version-stamped working paper for leadership discussion. See a sample brief →
Why this is different
No single score
AI Act risk and GDPR exposure answer different questions — so they are assessed separately.
Dates, not drama
What applies now is separated from what applies later.
No invented certainty
If evidence is missing, the brief says “not assessed”.
Sources you can check
Every material finding cites the relevant legal source or framework.
The honest version of where you stand — made usable.
Scope and boundaries
What it is
- A structured, source-cited working brief
- A view of material governance priorities
- A basis for informed internal decisions
What it is not
- A certification
- A formal legal opinion
- A substitute for your organisation's judgement
- A verification of your documentation — the assessment works from what you provide
- A transformation programme you did not ask for