EU AI Act · GDPR · AI governance

Where your business stands on AI, and what comes next.

Know what applies before you commit budget, build, or buy.
Move forward with evidence.

Start with five questions or see what's in the brief

For clients

Who I work with.

To thrive, you have to think ahead. Becoming a trustworthy company for your clients — keeping the ones you have and attracting new ones — means taking care of your data and theirs.

As the use of AI becomes more widely adopted, governance becomes more important. Integrate it from the start and you benefit from it while staying focused on your core business.

Not a luxury. It's where being ready to use AI starts.

Start-ups

Build governance in before complexity compounds.

Practical guardrails around AI while your product, processes and customer commitments are still taking shape.

Scale-ups

Turn AI already in use into a clear baseline.

A register of what is running, what it is likely to attract, and what to deal with first — before a client or a regulator asks.

MKB (SME)

Proportionate AI governance.

A focused, proportionate baseline for the AI you use, the decisions you need to make, and the actions worth taking now.

Boards & C-level

One focused half-day working session.

Leadership in one room to settle oversight, priorities, ownership, and the next decisions on AI adoption.

Services

Two ways to start.

A baseline for your organisation, or a working session for the people who need to decide.

Both produce a written output, not just a conversation — from a consistent method, applied to the facts of your organisation.

For your organisation

Core offer

AI Governance Baseline Brief

Know where your AI stands — before someone else asks. One organisation, one written brief for the board.

Without months of discovery, a panel of lawyers, or an invoice that outgrows the problem.

What you get

01

Your AI tools

Systems and vendors in use, their purpose, and accountable owners.

02

What matters for each tool

What is likely to apply under the EU AI Act and GDPR — for each tool, not in general.

03

Your current status

· · ·

Tap a status to see what it means.

04

Your next actions

Priority actions, accountable owners, and first steps.

05

Decisions to make

The decisions required before AI is bought, used, launched, or scaled.

Plus a one-page leadership summary of key issues, decisions, and next steps.

Delivered as a confidential, version-stamped working paper for leadership discussion. See a sample brief →

Why this is different

No single score

AI Act risk and GDPR exposure answer different questions — so they are assessed separately.

Dates, not drama

What applies now is separated from what applies later.

No invented certainty

If evidence is missing, the brief says “not assessed”.

Sources you can check

Every material finding cites the relevant legal source or framework.

The honest version of where you stand — made usable.

Scope and boundaries

What it is

  • A structured, source-cited working brief
  • A view of material governance priorities
  • A basis for informed internal decisions

What it is not

  • A certification
  • A formal legal opinion
  • A substitute for your organisation's judgement
  • A verification of your documentation — the assessment works from what you provide
  • A transformation programme you did not ask for
From €3,500 · scope and price agreed after a short introduction meeting

Discuss your baseline

Ongoing support

DPO & AI governance

When you need governance capacity, not another one-off answer.

Same method, same honesty — on retainer rather than once.

  • DPO and AI governance advisory
  • DPIAs and AI governance assessments
  • Governance framework maintenance
  • Policies, contracts, and documentation
Monthly retainer, scoped at intake

For your room

Three formats, same half day. A guided discussion on AI governance in relation to data and privacy protection — the do's, the don'ts, the ethics. This is how you get people talking.

Format A

Client event

Invite your top-tier clients for a round table, a golf clinic and time to network. No golf experience needed.

  • Four hours — one dagdeel (half a day)
  • Groups of 4 to 12 people
Per session · venue at cost
Format B

Boardroom round table

Your company is about to adopt a new AI application, or has already invested in AI, and the board wants a guided discussion before the decision rather than after it.

  • Four hours — one half day
  • Groups of 4 to 12 people
Per session
Format C

Network event

For CEOs, CIOs, COOs and other C-level. Peers in one room, working through the same questions they are each facing separately.

  • Four hours — one half day
  • Groups of 4 to 12 people
Per session
Self-check

Five questions.

Not a compliance score — five questions about evidence: whether you could show someone, today, what you have. Self-ratings run high; evidence is what counts.

Evidence readiness

Answer the five questions.

Your own read, not an assessment. The baseline brief looks at documentary evidence — what you could actually hand over — and it usually lands lower than a self-rating. The output is the written brief described above: a governance diagnostic, not a legal opinion.

Wherever you landed: the baseline brief starts from evidence, not self-ratings.

Discuss your baseline

YOUR ANSWERS NEVER LEAVE THIS PAGE · NO EMAIL REQUIRED

What applies when

The dates that bind.

The Digital Omnibus deferred Annex III high-risk obligations by sixteen months, and Annex I by twenty-four. It did not defer the transparency duties. Most organisations read the headline and drew the wrong conclusion.

IN FORCE · Reg. (EU) 2026/1744 — OJ 24 July 2026, effective 27 July 2026
02 AUG 2026 · EU AI Act Art. 50 transparency duties
02 DEC 2026 · EU AI Act Art. 50(2) marking for systems already in service
02 DEC 2027 · Annex III standalone high-risk
02 AUG 2028 · Annex I embedded high-risk
Applies now

Transparency

If your system talks to people, generates or manipulates content, or categorises biometrics: EU AI Act Art. 50 has applied since 2 August 2026. Systems already in service have until 2 December 2026 to mark synthetic content in a machine-readable format.

Applies now · since February 2025

Prohibited practices

Social scoring, workplace or school emotion recognition, and untargeted face scraping — among others — are banned outright rather than regulated. Two further prohibitions added by the Omnibus, covering AI that generates non-consensual intimate imagery or child sexual abuse material, apply from 2 December 2026.

December 2027

High-risk

Systems deciding about people — hiring, credit, education, essential services, safety components — now fall due on 2 December 2027 for standalone Annex III systems, and 2 August 2028 where embedded in regulated Annex I products. The deferral does not touch GDPR, which applies to the personal data in those systems today.

Ongoing

Everything else

Internal tooling carries few EU AI Act duties directly. GDPR applies in full wherever personal data goes in or comes out, and a minimal-risk tool that generates customer-facing content can still pull you into Art. 50.

Orientation, not a legal classification. Tiers turn on the specific purpose and context of a system, and one deployment can sit in more than one. The Omnibus changed these dates in July 2026 — check the consolidated text, then get a proper assessment.

Last verified: 24 August 2026 — re-verify whenever this page is edited.

What it costs

Clear scope, written price.

The baseline brief starts at €3,500 for one organisation. Where it lands depends on how many systems you run and how much evidence already exists, so the rest is scoped rather than listed. What is fixed is how the figure is reached: agreed at the introduction meeting, quoted in writing before anything starts, and never changed without your agreement.

AI Governance Baseline Brief from €3,500

Scoped to your organisation at the introduction meeting. What drives it: how many AI systems and vendors are in use, how many entities and countries they sit across, whether a register and DPAs already exist, and how many people I need to speak to.

Boardroom or network session Agreed at intake

The working session for decision-makers, described above. A half-day session for 4 to 12 participants.

Interim DPO / AI governance Agreed at intake

Retainer covering an agreed monthly scope. One-year agreement, scope fixed at intake; work beyond it at an agreed hourly rate.

Detailed assessment, per system Agreed at intake

A full article-level assessment of one system, for the systems the baseline identifies as material. Quoted separately, per system.

Golf clinic & round table Agreed at intake

Round table, golf clinic and networking. Green fees and clinic charged at cost, agreed in advance.

Scope in writing before anything starts. No open-ended engagements, either way.

We begin with a short introduction meeting. Together we establish what is in scope, what information is available, and what the brief needs to answer. I then confirm the scope, price and deliverables in writing, before the work starts.

All amounts exclude VAT.

If the answer is that you need less than this, I will say so.

What I need from you

  • A list of the AI tools and vendors you know about — a spreadsheet is fine
  • Access to the two or three people closest to how they're used
  • Existing contracts, DPAs or policies, if they exist

Without the list, the first hour goes on building it, and there is less time for the part you're paying for.

Outside this scope

  • Legal advice or a legal opinion — the brief is a governance diagnostic.
  • Implementing the fixes, writing policies, or completing the register.
  • Certification, conformity assessment, or compliance sign-off.
  • Technical testing, code review, or model evaluation.

If the work becomes materially larger than agreed, we discuss the change before it continues. I then re-quote in writing. You will never receive an invoice you did not agree to — and I will not absorb work neither of us saw coming.

About

Advice that survives scrutiny.

Proportionate guidance grounded in the EU AI Act, GDPR and practical governance — not generic checklists, and not a transformation programme you did not ask for.

A background in law and compliance, applied so that governance helps an organisation be better, sustainable, and trustworthy to its customers.

Engagements have ranged from e-tourism to international corporates: data protection impact assessments for internal programmes, including employee healthcare schemes, and assessments of whether external vendors meet their obligations as sub-processors.

Client examples are not published here. The organisations I work with disclose their AI registers, their vendor contracts and their open findings, information of this kind does not belong on a website, anonymised or otherwise. References are available on request, with the client's consent.

Credentials
  • AIGP badgeArtificial Intelligence Governance Professional (AIGP) — IAPPverify
  • CIPP/E badgeCertified Information Privacy Professional/Europe (CIPP/E) — IAPPverify
  • CIPM badgeCertified Information Privacy Manager (CIPM) — IAPPverify
  • MIT Sloan badgeArtificial Intelligence: Implications for Business Strategy — MIT Sloan Executive Educationverify
Contact

Get in touch.

Tell me what you have deployed and what worries you about it. If I'm not the right person, I'll say so.