EU AI Act · GDPR · AI governance

Know what applies before you build, buy, or scale AI.

Get the evidence for your next decision.

Start with five questions or see what the report contains

For clients

Who I work with.

To thrive, you have to think ahead. Becoming a trustworthy company for your clients — keeping the ones you have and attracting new ones — means taking care of your data and theirs.

As the use of AI becomes more widely adopted, governance becomes more important. Integrate it from the start and you benefit from it while staying focused on your core business.

Not a luxury. It's where being ready to use AI starts.

Start-ups

Build governance in before complexity compounds.

Practical guardrails around AI while your product, processes and customer commitments are still taking shape.

Scale-ups

Turn AI already in use into a clear baseline.

A register of what is running, what it is likely to attract, and what to deal with first — before a client or a regulator asks.

MKB (SME)

Proportionate AI governance.

A focused, proportionate baseline for the AI you use, the decisions you need to make, and the actions worth taking now.

Boards & C-level

One focused half-day working session.

Leadership in one room to settle oversight, priorities, ownership, and the next decisions on AI adoption.

Services

Two ways to start.

A baseline for your organisation, or a working session for the people who need to decide.

Both produce a written output, not just a conversation — from a consistent method, applied to the facts of your organisation.

For your organisation

Core offer

AI Governance Assessment Report

Know where your AI stands — before someone else asks. One organisation, one confidential assessment report for leadership.

Without months of discovery, a panel of lawyers, or an invoice that outgrows the problem.

What you get

01

Your AI tools

Systems and vendors in use, their purpose, and accountable owners.

02

What matters for each tool

What is likely to apply under the EU AI Act and GDPR — for each tool, not in general.

03

Your current status

· · ·

Tap a status to see what it means.

04

Your next actions

Priority actions, accountable owners, and first steps.

05

Decisions to make

The decisions required before AI is bought, used, launched, or scaled.

Plus a one-page leadership summary of key issues, decisions, and next steps.

Delivered as a confidential, version-stamped working paper for leadership discussion. See a sample brief →

Why this is different

No single score

AI Act risk and GDPR exposure answer different questions — so they are assessed separately.

No invented certainty

If evidence is missing, the report says “not assessed”.

The honest version of where you stand — made usable.

Scope and boundaries

What it is

  • A structured, source-cited working brief
  • A view of material governance priorities
  • A basis for informed internal decisions

What it is not

  • A certification
  • A formal legal opinion
  • A substitute for your organisation's judgement
  • A verification of documents not provided for review — the assessment works from what you supply
  • A transformation programme you did not ask for
From €3,500 · scope and price agreed after a short introduction meeting

Discuss your assessment

Ongoing support

DPO & AI governance

When you need governance capacity, not another one-off answer.

Same method, same honesty — on retainer rather than once.

  • DPO and AI governance advisory
  • DPIAs and AI governance assessments
  • Governance framework maintenance
  • Policies, contracts, and documentation
Monthly retainer, scoped at intake

How it works

  1. Introductory meeting. We establish what is in scope, what information exists, and what the assessment needs to answer.
  2. Written proposal. Scope, deliverables, timing, exclusions and a fixed price, before anything starts.
  3. Evidence-led review. I review what you provide and speak to the people closest to how the systems are used.
  4. Assessment report. Delivered for leadership discussion, with priority actions and open decisions.

For your room

A guided discussion on AI governance in relation to data and privacy protection — the do's, the don'ts, the ethics. This is how you get people talking.

ALL THREE FORMATS · FOUR HOURS, ONE DAGDEEL · 4 TO 12 PEOPLE · PER SESSION

Format A

Client event

Invite your top-tier clients for a round table, a golf clinic and time to network. No golf experience needed.

Per session · venue at cost
Format B

Boardroom round table

Your company is about to adopt a new AI application, or has already invested in AI, and the board wants a guided discussion before the decision rather than after it.

Per session
Format C

Network event

For CEOs, CIOs, COOs and other C-level. Peers in one room, working through the same questions they are each facing separately.

Per session
Self-check

Five questions.

Not a compliance score — five questions about evidence: whether you could show someone, today, what you have. Self-ratings run high; evidence is what counts.

Evidence readiness

Answer the five questions.

Your own read, not an assessment. The assessment report reviews documentary evidence — what you could actually hand over — and it usually lands lower than a self-rating. The output is the assessment report described above: a governance assessment, not a legal opinion.

Wherever you landed: the report starts from evidence, not self-ratings.

Discuss your assessment

YOUR ANSWERS NEVER LEAVE THIS PAGE · NO EMAIL REQUIRED

What applies when

The dates that bind.

The Digital Omnibus deferred Annex III high-risk obligations by sixteen months, and Annex I by twenty-four. It did not defer the transparency duties. Most organisations read the headline and drew the wrong conclusion.

IN FORCE · Reg. (EU) 2026/1744 — OJ 24 July 2026, effective 27 July 2026
02 AUG 2026 · EU AI Act Art. 50 transparency duties
02 DEC 2026 · EU AI Act Art. 50(2) marking for systems already in service
02 DEC 2027 · Annex III standalone high-risk
02 AUG 2028 · Annex I embedded high-risk
Applies now

Transparency

If your system talks to people, generates or manipulates content, or categorises biometrics: EU AI Act Art. 50 has applied since 2 August 2026. All of Article 50 applies from that date. Only one obligation has a transition: providers of systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the Art. 50(2) machine-readable marking requirement.

Applies now · since February 2025

Prohibited practices

Social scoring, workplace or school emotion recognition, and untargeted face scraping — among others — are banned outright rather than regulated. Two further prohibitions added by the Omnibus, covering AI that generates non-consensual intimate imagery or child sexual abuse material, apply from 2 December 2026.

December 2027

High-risk

Systems deciding about people — hiring, credit, education, essential services, safety components — now fall due on 2 December 2027 for standalone Annex III systems, and 2 August 2028 where embedded in regulated Annex I products. The deferral does not touch GDPR, which applies to the personal data in those systems today.

Ongoing

Everything else

Internal tooling carries few EU AI Act duties directly. GDPR applies in full wherever personal data goes in or comes out, and a minimal-risk tool that generates customer-facing content can still pull you into Art. 50.

Orientation, not a legal classification. Tiers turn on the specific purpose and context of a system, and one deployment can sit in more than one. The Omnibus changed these dates in July 2026 — check the consolidated text, then get a proper assessment.

Compliance is not a state you achieve and file away. It is an ongoing practice — one you should be able to evidence at any time.

Primary sources: consolidated EU AI Act (CELEX 02024R1689) · Regulation (EU) 2026/1744 · consolidated GDPR

Last verified: 24 August 2026 — re-verify whenever this page is edited.

What it costs

Clear scope, written price.

The assessment report starts at €3,500 for one organisation. Where it lands depends on how many systems you run and how much evidence already exists, so the rest is scoped rather than listed. What is fixed is how the figure is reached: agreed at the introduction meeting, quoted in writing before anything starts, and never changed without your agreement.

Assessment Report from €3,500

Scoped to your organisation at the introduction meeting. What drives it: how many AI systems and vendors are in use, how many entities and countries they sit across, whether a register and DPAs already exist, and how many people I need to speak to.

Boardroom or network session Agreed at intake

The working session for decision-makers, described above. A half-day session for 4 to 12 participants.

Interim DPO / AI governance Agreed at intake

Retainer covering an agreed monthly scope. One-year agreement, scope fixed at intake; work beyond it at an agreed hourly rate.

AI System Assessment Agreed at intake

A full article-level assessment of one system, for the systems the baseline identifies as material. Quoted separately, per system.

Golf clinic & round table Agreed at intake

Round table, golf clinic and networking. Green fees and clinic charged at cost, agreed in advance.

Scope in writing before anything starts. No open-ended engagements, either way.

We begin with a short introduction meeting. Together we establish what is in scope, what information is available, and what the brief needs to answer. I then confirm the scope, price and deliverables in writing, before the work starts.

All amounts exclude VAT.

If the answer is that you need less than this, I will say so.

What I need from you
  • A list of the AI tools and vendors you know about — a spreadsheet is enough
  • Access to the two or three people closest to how they're used
  • Existing contracts, DPAs or policies, if they exist

Without the list, the first hour goes on building it, and there is less time for the part you're paying for. If your documentation is incomplete, that is itself a useful finding.

Outside this scope
  • Legal advice or a legal opinion — the report is a governance assessment.
  • Implementing the fixes, writing policies, or completing the register.
  • Certification, conformity assessment, or compliance sign-off.
  • Technical testing, code review, or model evaluation.

If the work becomes materially larger than agreed, we discuss the change before it continues. I then re-quote in writing. You will never receive an invoice you did not agree to — and I will not absorb work neither of us saw coming.

About

Advice that survives scrutiny.

Proportionate guidance grounded in the EU AI Act, GDPR and practical governance — not generic checklists.

The person who reviews your materials is the person who writes and signs your report.

A background in law and compliance, applied so that governance helps an organisation be better, sustainable, and trustworthy to its customers.

Engagements have ranged from e-tourism to international corporates: data protection impact assessments for internal programmes, including employee healthcare schemes, and assessments of whether external vendors meet their obligations as sub-processors.

Client examples are not published here. The organisations I work with disclose their AI registers, their vendor contracts and their open findings, information of this kind does not belong on a website, anonymised or otherwise. References are available on request, with the client's consent.

Credentials
  • AIGP badgeArtificial Intelligence Governance Professional (AIGP) — IAPPverify
  • CIPP/E badgeCertified Information Privacy Professional/Europe (CIPP/E) — IAPPverify
  • CIPM badgeCertified Information Privacy Manager (CIPM) — IAPPverify
  • MIT Sloan badgeArtificial Intelligence: Implications for Business Strategy — MIT Sloan Executive Educationverify
Contact

Get in touch.

Tell me what AI you use, what you are planning, and the decision you need to make. If I am not the right person to help, I will say so.