AI governance before something goes wrong.

Your team is already using Claude, ChatGPT, and Copilot. Nobody has written rules for it. We build the AI policy, data guardrails, and acceptable-use standards your legal, HR, and security teams can stand behind.

Your team is already using AI. The question is whether you have any rules around it.

  1. Policy before incident.

    Most companies write their AI policy after something goes wrong. We write it before — covering what tools are approved, where company data can go, and who is accountable when the AI is wrong.

  2. Rules people will actually follow.

    An AI policy nobody reads is worse than none at all. We write guardrails in plain language, map them to roles, and build them into onboarding so the standard sticks instead of sitting in a shared drive.

  3. Built for how AI actually works.

    Generic governance frameworks were not written for large language models. We cover the risks specific to generative AI — hallucination, data leakage, model vendor changes, and prompt injection — not just the broad strokes.

Start now

What AI governance covers

AI policy writing

A clear, plain-language policy covering approved tools, data handling, acceptable use, and accountability — reviewed with your legal and HR teams.

Data classification

Rules for what category of data can go into which AI tool, on which tier, under what conditions.

Vendor risk review

We assess every AI tool your team uses against your data posture, security requirements, and industry obligations.

Audit trail setup

Logging and documentation so you can show regulators, clients, or your board exactly how AI is being used inside the company.

Employee standards

Role-specific acceptable-use guidance — what each department can do with AI, what requires review, and what is off-limits.

Ongoing compliance support

As models change and regulations evolve, we update your governance framework so you are never caught behind.

How it works.
Four weeks to a signed, working governance framework.

  1. We audit what your team is already doing.

    We map every AI tool in use, how data is flowing into them, and where the gaps are between current behavior and what your security and legal teams would approve.

  2. We write the policy and guardrails.

    A plain-language AI policy, data classification rules, vendor assessments, and acceptable-use standards — drafted with your legal, HR, and security teams, not handed to them cold.

  3. We roll it out and make it stick.

    Governance that lives in a drawer is not governance. We build the policy into onboarding, train each role on what it means for their work, and set up the audit trail that lets you prove compliance.

This is for you if:

  • Your team is already using AI tools and nobody has written rules for it.
  • Legal, HR, or a client has asked how you govern AI use.
  • You are in a regulated industry and need documentation before you scale AI.

This is not for you if:

  • You have not started using AI yet and need strategy first.
  • You want a one-page policy with no implementation support.
  • Your governance needs are fully covered by an existing legal team.

In partnership with

  • Anthropic
  • Zo
  • Make

FAQs

What is AI governance?
AI governance is the set of policies, standards, and controls that determine how your organization uses AI tools — what is allowed, where company data can go, who is accountable, and how you prove compliance. Without it, your team's AI use is ungoverned, which creates legal, security, and reputational risk.
Do we need an AI policy if we are a small or mid-market company?
Yes, and especially if your team is already using tools like Claude, ChatGPT, or Copilot. The risk is not size-dependent — data leakage, hallucination liability, and vendor lock-in affect a 50-person company the same as a 5,000-person one. The policy just needs to be proportionate to your operation.
What regulations does AI governance need to cover?
It depends on your industry. GDPR and CCPA govern how personal data can be processed by AI tools. SOC 2 and HIPAA add security and privacy requirements for certain sectors. The EU AI Act introduces risk-based obligations for companies using AI in consequential decisions. We assess which frameworks apply to your business and build the policy around the ones that matter.
How is this different from a generic compliance checklist?
Generic checklists cover broad data protection principles but were not written for large language models. We cover the risks specific to generative AI — what happens when the model hallucinates, who is liable when the output is wrong, how to handle prompt injection, and what your vendor contract actually says about your data.
What does AI governance consulting cost?
A foundational engagement — policy, data classification, vendor assessment, and rollout — starts at $8,000. Ongoing compliance support is available monthly. We scope it once we understand your industry, team size, and current AI footprint.

The fastest way to know whether we're the right fit, is a conversation.

STEP 1/2 · ABOUT YOU