P-01
Shadow AI
Your employees already use AI — on private accounts, with company data. Without rules you have no control over what leaves your house.
GDPR, the EU AI Act, ISO 42001, liability: most companies do not know where to start. That is exactly what this stage is for. At the end you have a foundation on which every further AI decision stands safely. It is the first stage on the way to the AI-first company.
PROBLEM / 01
Without governance one of two things happens: either nobody uses AI — or everybody does, uncontrolled. Both cost you money; the second also costs trade secrets and, in the worst case, the liability question in court.
P-01
Your employees already use AI — on private accounts, with company data. Without rules you have no control over what leaves your house.
P-02
Who is accountable for AI decisions? Who checks results? As long as nobody can answer that, every AI use is an unpriced risk.
P-03
The EU AI Act applies — with staged deadlines and substantial fines. If you have not classified your AI applications, you do not know your obligations.
APPROACH / 02
Three pillars carry every AI adoption that scales: AI management, data management, AI governance. Our audit covers all three — the build-out follows in plannable, individually measurable steps.
Where does your company really stand? We capture the current state: AI tools in use (including the unofficial ones), data flows, responsibilities, existing policies.
Benchmarked against ISO/IEC 42001, ISO/IEC 27001, GDPR and the EU AI Act. You receive a prioritised list of gaps — what is critical, what can wait, what is already fine.
AI is only as good as the process and the data beneath it. We assess data quality, data flows and process maturity — and optimise both for AI before AI is put on top. Anything else just automates the chaos.
We build your AIMS in line with ISO/IEC 42001: AI policy, roles and responsibilities, risk register, approval processes for new AI applications.
Every AI application is classified according to the EU AI Act risk categories — including the obligations that follow and the documentation auditors expect to see.
Nobody has time to teach themselves AI on top of the day job — so we take the learning curve off your teams: focused training per department, with concrete use cases for their actual work and clear objectives. Instruct, implement, accompany.
If certification is the goal, we prepare you for it: documentation, internal audits, management review. Without paper mountains nobody reads.
DELIVERABLES / 03
Not a slide deck. Working documents and processes that survive an audit.
STANDARDS / 04
ISO/IEC 42001
The standard for AI management systems and our home turf — our own certification is in preparation.
ISO/IEC 27001
Your AI adoption integrates into your existing security organisation — or we build both together.
EU AI ACT
Risk classes, transparency duties, deadlines. We translate the regulation into concrete to-dos for your company.
GDPR
Self-hosted first: your data stays with you. Where cloud is necessary, with a sound legal basis and data processing agreement.
The foundation from stage 1 only holds once it reaches into practice: into the rollout, into the toolchain and down to the IT infrastructure, with every stakeholder involved. That is exactly how we introduce AI in the development process — in an orderly way, without shadow AI, with training instead of dependency.
NEXT STEP / 05
In an initial consultation we walk through your situation and tell you honestly whether stage 1 will take weeks or months in your case.
FAQ
Not with the tool, but with the foundation: what are you allowed to do (GDPR, EU AI Act), what do you need (policies, responsibilities), where is it worth it (process analysis)? That is exactly what stage 1 of our approach settles. Our readiness check gives you a first indication in five minutes — free, with no data transferred.
That depends on which AI you use and what for. The EU AI Act sorts applications into risk categories — from minimal (hardly any obligations) to high (extensive documentation, transparency and control duties), with staged deadlines and substantial fines. The first step is always an inventory and classification of your AI applications — after that you know exactly which obligations apply to you.
Not necessarily the certificate — but the principles behind it. An AI management system to ISO/IEC 42001 answers exactly the questions AI adoptions fail on: responsibility, risk, approval, monitoring. Whether you pursue the certificate is decided by market requirements — tenders, or customers from regulated industries. We build your AIMS so that certification is reachable at any time.
Your company — which is why this question is the core of all governance. The answer consists of clear responsibilities (who approves, who checks), human control at the critical points, and documented decision paths. That is exactly what we establish in stage 1, before AI enters productive processes.
Yes, but a solvable one. When AI is used uncontrolled through private accounts (shadow AI), design knowledge or customer data quickly flow into third-party models — bypassing IT, data protection and governance. The answer is not a ban but order: we bring the usage into the company, with approved tools, clear guardrails and — where needed — self-hosted. That turns shadow AI into a controlled, productive use you can be accountable for.