Without an agreed, high-standard way to govern and secure solutions, even light-touch AI stalls at stakeholder level. We grade every use case before production and run two clear reviews — a security review and a compliance review — that approve AI rather than block it.
We grade each use case on agency (how autonomously it acts) against data sensitivity. The grade dictates exactly which controls apply — joining data governance to security operations, so approvals become fast and repeatable instead of bespoke and slow.
It was sharpened in highly regulated industries and fintech, and maps to the standards that matter.
| Agency ↓ / Data → | Low | Med | High |
|---|---|---|---|
| Fully autonomous | Enhanced | Strict | Maximum |
| Acts with approval | Standard | Enhanced | Strict |
| Drafts & suggests | Light | Standard | Enhanced |
| Read-only / public | Minimal | Light | Standard |
Most AI-built apps end up exposed to the public internet through a login page. None of these checks is heavy — and together they are the difference between a prototype and something you can trust with real data.
Who can log in, how, and what each role sees. SSO via Microsoft Entra or Google Workspace does the heavy lifting when configured correctly.
A focused review of the public surface for common vulnerabilities. Often a half-day of work for real assurance.
Ideally with repo access — catches hardcoded keys, weak input validation, exposed endpoints. The same agentic tools that wrote the code can review it.
Models are locked down so they never train on your data, permissioned to the right people, tied into your identity and Microsoft 365, and rolled into a security operation that monitors what is used and shared. Security is part of how we build, not a final-stage checkbox.
The EU AI Act came into force on 2 August 2024 with phased application. Most SMB uses — drafting, summarising, internal tools — fall well below the "high-risk" threshold and trigger limited obligations beyond basic transparency.
Bans on "unacceptable risk" systems take effect; AI literacy obligations begin.
Rules for general-purpose AI models, governance and penalties take effect.
Most of the Act becomes fully applicable, including high-risk system requirements.
Final tranche covers AI embedded in regulated products.
Credit scoring, employment screening, critical infrastructure, medical decisions and biometric ID carry serious requirements and penalties up to €35m or 7% of global annual turnover. If your use is genuinely lower-risk — and most is — your burden is manageable.
What ISO 27001 is to information security, 42001 is to AI: a certifiable framework resting on five pillars — transparency, accountability, human oversight, data governance and continual improvement — mapping cleanly onto the EU AI Act.
Formal certification is overkill for most SMBs. What matters: someone owns the AI inventory, decisions are documented, customer-data flows are mapped, and a human is in the loop for anything consequential.
The agent expanding its remit beyond what was intended. The EU AI Act explicitly requires drift tracking for higher-risk autonomous systems.
Reconstruct what the agent did and why. Log every consequential action, hard guardrails, human approval on material decisions.
Governance fears are the single most common reason organisations delay starting at all. The answer is not to build governance before you build anything — it is to build governance in step with what you are doing. An AI inventory once you have more than one tool live; a human-in-the-loop policy at first agentic deployment; formal frameworks when scale or sector demands.
Discovery that turns ideas into a prioritised, costed, fundable roadmap.
Explore →Your embedded build capability, from prototype to production.
Explore →AI-ready data and generative BI built from your systems.
Explore →We will grade your priority use cases, run the security and compliance reviews, and give you a repeatable framework mapped to the EU AI Act and ISO 42001.