DS Consulting logoDS Consulting
Strategy to Systems. Delivered.

The pilot worked. That was never the hard part

Most AI work stalls between the pilot and the day job, and most policies were written before anyone read the regulation. We handle both ends: what to build, and what has to be true before it runs.

AI governance and adoption for mid-market companies

Two problems that are usually treated as one

The first is adoption. Everest Group's 2026 mid-market research found 57 percent of firms sitting in the pilot stage and 15 percent with something genuinely operationalised. That gap is not a technology gap. A pilot runs on curated data with an enthusiast watching the output. Production runs on whatever the source system holds that day, with someone who has a queue to clear and no reason to check.

The second is governance, and it usually arrives as a surprise. Staff are already using AI tools with company data. Nobody wrote a policy, so there is no record of what went into which tool. Then a customer or an auditor asks a question that requires one.

These get treated as one problem and they are not. Governance without adoption is a document nobody reads. Adoption without governance is a liability that compounds quietly. The work is to do both at a pace the business can actually absorb.

The regulatory position is also more specific than most current commentary suggests, and getting it wrong in either direction costs money. Rushing to comply with a requirement that has moved wastes budget. Assuming the whole regime was postponed misses obligations that are already live.

What the work covers

Shadow AI discovery

What staff are already using, with what data, and under what terms. This is almost always the first finding and it is usually larger than expected. Nothing else can be designed sensibly until it is known.

Use case selection

Assessed against an operational outcome you already measure, and against the cost of being wrong. High volume with low cost of error is where this works. The reverse is where pilots go to die.

Usage policy and human oversight

What may and may not go into which tools, what must be reviewed by a person before it acts, and who owns the output when it is wrong. Written short and specific enough to actually be followed.

Regulatory obligations

Where the EU AI Act applies, which duties are live now and which have moved. Transparency and disclosure obligations, plus data protection interaction under GDPR or DPDP depending on where you operate.

Data readiness and integration

What the process needs, where it sits, what state it is in and who may see it. Frequently this is the whole project, and it is worth doing whether or not the AI part proceeds.

Pilot to production path

Exit criteria agreed before the pilot starts, including the criteria that mean you stop. That clause is the one most pilots are missing, which is why so many neither ship nor die.

What you end up holding

Named artefacts, handed over. Not a slide deck summarising them.

  • Shadow AI inventory covering tools, data exposure and contractual terms
  • Use case shortlist scored against operational value and cost of error
  • Written usage policy with named accountable owners and review points
  • Applicability assessment against EU AI Act duties, with dates that are current
  • Redesigned process showing where the AI step sits and where a human reviews
  • Pilot design with exit criteria in both directions, then the production build

When to call us

Any one of these is enough. You do not need a defined project first.

  • Staff are already using AI tools with company data and there is no policy covering it.
  • You have run a pilot that worked and nobody can explain why it has not been rolled out.
  • A customer or insurer has asked what AI you use and you had to go and find out.
  • You deploy a chatbot or generate synthetic content and have not checked the transparency obligations that took effect in August 2026.
  • A vendor has quoted for an AI module and you cannot assess whether it does anything your process needs.
  • The board has asked what your AI strategy is and the honest answer is a list of experiments.
  • Licences are spread across several teams and nobody can total the AI spend or say what it produced.
  • When an AI step gets something wrong in a live workflow, no one owns the correction, the audit trail or the rollback.

How the readiness audit runs

Where the starting point is an unclear picture rather than a defined project, we run a four week audit first. Fixed scope, fixed price, and a handover to whoever owns AI from week five.

Week 1

Readiness scan

Interviews with function heads, a tool inventory and a governance review across the business. This is where shadow usage surfaces.

Week 2

Priority deep dives

Two or three functions go further, with workflow walkthroughs and sessions with the people actually doing the work.

Week 3

Playbook drafting

Usage policy, the governance framework with named owners and review points, and a 90 day roadmap the board can track.

Week 4

Synthesis and handover

Board readout, then handover to the appointed owner. You end up holding a report and a playbook, not a slide deck.

The audit works where there is real usage, a mandate from the top and someone appointed to own the outcome. If the mandate has not been established yet, it is too early and a call is the better starting point.

An assessment, not a proposal

Two to four weeks at a fixed price, delivered as a decision document. You own the output whether or not you carry on with us.

Start with an assessment

We are an independent consulting firm. Software vendors do not pay us, so our recommendations come with the scoring behind them.

FAQs

Was the EU AI Act postponed?
Partly, and the distinction matters. Regulation (EU) 2026/1744, the Digital Omnibus on AI, came into force on 27 July 2026 and moved the high-risk obligations for Annex III systems from August 2026 to 2 December 2027, and Annex I systems to 2 August 2028. The Article 50 transparency obligations were not deferred and have applied since 2 August 2026. Reading the Omnibus as a general reprieve is the most common current mistake.
Which obligations are actually live right now?
The transparency duties under Article 50. In practice that means telling people when they are interacting with an AI system rather than a person, marking AI-generated synthetic content in machine-readable form, and disclosing deepfakes and AI-written text in the situations the Article covers. Systems already on the EU market before 2 August 2026 have until 2 December 2026 for the machine-readable marking requirement specifically.
We are not in the EU. Does any of this apply?
Possibly, depending on whether your systems are used in the EU or their output reaches people there. It is worth checking rather than assuming, and the check is quick. Separately, most of the governance work has value regardless of jurisdiction, because customers and insurers are asking these questions ahead of regulators.
Do you build models?
Rarely, and only where nothing available fits. For most mid-market operational use cases the model is a commodity and the value sits in data access, process design and accountability. If someone is quoting you for a bespoke model, it is worth asking why.
Are you tied to a particular AI platform?
No. We take no commissions, referral fees or partner incentives from any vendor, including AI vendors. Platform choice is assessed the same way as any other systems selection.
What if the answer is that AI is not the right tool here?
Then that is the recommendation. A meaningful share of proposed AI use cases are better solved by fixing the data, the process or an existing system's configuration. Those answers are cheaper and they hold up better.
How long does the readiness audit take?
Four weeks end to end. Week one is a readiness scan across functions, week two is deep dives into two or three of them, week three is drafting the policy and roadmap, week four is the board readout and handover. The scope is fixed before it starts, so it does not drift.
How is this different from generic AI consulting?
The scope is defined and the deliverables are named before the work begins. The focus is governance, data readiness and the path to production, not model selection or tool implementation. Most AI work in mid-market businesses stalls on governance and data access rather than on the model.
Do you provide legal advice on compliance?
No. We build the operational side: the inventory, the policy, the oversight design and the evidence. Where a question turns on legal interpretation we will say so plainly and you should take it to a lawyer.