Rules for AI, before the auditor demands them.

A governance framework for AI systems that fits the EU AI Act and data protection and works in daily practice.

The situation

Once AI agents or models work with real data and real decisions, informal use is no longer enough. The EU AI Act classifies applications by risk, data protection requires a legal basis for processing, and internally someone has to be accountable when a system makes a mistake.

Many companies either have no rules at all, which creates risk, or a policy nobody reads because it has nothing to do with daily practice. We build a framework of a few clear rules: which use cases are allowed, who approves them, which data may be used, and how to respond if something goes wrong.

The result isn't a document for the drawer, but a process that runs automatically with every new use case: risk classification, approval, documentation.

Deliverables

  • Risk classification

    Classification of your AI use cases according to the EU AI Act's risk categories.

  • Approval process

    A clear process for who reviews and approves new AI use cases before they go live.

  • Data protection framework

    Rules for handling personal and confidential data in prompts and training data.

  • Responsibilities

    Naming who is functionally and technically accountable for which AI system.

  • Documentation template

    A template that documents each use case in a few minutes, instead of tying up a compliance department.

  • Training for responsible parties

    Short, practical briefing for the people who grant approvals or operate systems.

Our approach

  • 01

    Take stock of use cases

    We capture which AI systems are already in use, officially or unofficially.

  • 02

    Classify risk

    We assign each use case to the EU AI Act's risk categories.

  • 03

    Design the framework

    We design the approval process, data protection rules, and responsibilities together with leadership and compliance.

  • 04

    Anchor it in the company

    We train the responsible parties and embed the process where new use cases arise.

Typical clients

AI usage is growing without rules

Our approach: A lean framework creates control without slowing down innovation

Advisory board or investor asks about governance

Our approach: A solid answer with documentation instead of an ad-hoc explanation

Several portfolio companies with different levels of AI maturity

Our approach: A shared minimum standard every company can implement

Outside our scope

We're not a law firm and don't give binding legal advice on the EU AI Act. We build the operational framework and work with your legal department or external counsel as needed, rather than replacing their role.

Frequently asked questions

EdTech company, PE-financed

Ausgangslage

PE-financed EdTech company, technical picture unclear before the investment.

Umsetzung

Tech DD, greenfield architecture, AI agents in production, AI-assisted engineering organization.

Ergebnis

The company runs AI in day-to-day operations, not just in pilot projects.

EdTech company, customer service

Ausgangslage

Customer service answered recurring questions manually from scattered knowledge.

Umsetzung

AI agent with access to the knowledge base, with clear escalation to humans.

Ergebnis

Recurring inquiries run productively through the agent, complex cases stay with the team.

Initial call: 30 minutes, concrete.

We show what a lean governance framework could look like for your AI use cases.