The pilot worked. That was never the hard part
Most AI work stalls between the pilot and the day job, and most policies were written before anyone read the regulation. We handle both ends: what to build, and what has to be true before it runs.

Two problems that are usually treated as one
The first is adoption. Everest Group's 2026 mid-market research found 57 percent of firms sitting in the pilot stage and 15 percent with something genuinely operationalised. That gap is not a technology gap. A pilot runs on curated data with an enthusiast watching the output. Production runs on whatever the source system holds that day, with someone who has a queue to clear and no reason to check.
The second is governance, and it usually arrives as a surprise. Staff are already using AI tools with company data. Nobody wrote a policy, so there is no record of what went into which tool. Then a customer or an auditor asks a question that requires one.
These get treated as one problem and they are not. Governance without adoption is a document nobody reads. Adoption without governance is a liability that compounds quietly. The work is to do both at a pace the business can actually absorb.
The regulatory position is also more specific than most current commentary suggests, and getting it wrong in either direction costs money. Rushing to comply with a requirement that has moved wastes budget. Assuming the whole regime was postponed misses obligations that are already live.
What the work covers
Shadow AI discovery
What staff are already using, with what data, and under what terms. This is almost always the first finding and it is usually larger than expected. Nothing else can be designed sensibly until it is known.
Use case selection
Assessed against an operational outcome you already measure, and against the cost of being wrong. High volume with low cost of error is where this works. The reverse is where pilots go to die.
Usage policy and human oversight
What may and may not go into which tools, what must be reviewed by a person before it acts, and who owns the output when it is wrong. Written short and specific enough to actually be followed.
Regulatory obligations
Where the EU AI Act applies, which duties are live now and which have moved. Transparency and disclosure obligations, plus data protection interaction under GDPR or DPDP depending on where you operate.
Data readiness and integration
What the process needs, where it sits, what state it is in and who may see it. Frequently this is the whole project, and it is worth doing whether or not the AI part proceeds.
Pilot to production path
Exit criteria agreed before the pilot starts, including the criteria that mean you stop. That clause is the one most pilots are missing, which is why so many neither ship nor die.
What you end up holding
Named artefacts, handed over. Not a slide deck summarising them.
- Shadow AI inventory covering tools, data exposure and contractual terms
- Use case shortlist scored against operational value and cost of error
- Written usage policy with named accountable owners and review points
- Applicability assessment against EU AI Act duties, with dates that are current
- Redesigned process showing where the AI step sits and where a human reviews
- Pilot design with exit criteria in both directions, then the production build
When to call us
Any one of these is enough. You do not need a defined project first.
- Staff are already using AI tools with company data and there is no policy covering it.
- You have run a pilot that worked and nobody can explain why it has not been rolled out.
- A customer or insurer has asked what AI you use and you had to go and find out.
- You deploy a chatbot or generate synthetic content and have not checked the transparency obligations that took effect in August 2026.
- A vendor has quoted for an AI module and you cannot assess whether it does anything your process needs.
- The board has asked what your AI strategy is and the honest answer is a list of experiments.
- Licences are spread across several teams and nobody can total the AI spend or say what it produced.
- When an AI step gets something wrong in a live workflow, no one owns the correction, the audit trail or the rollback.
How the readiness audit runs
Where the starting point is an unclear picture rather than a defined project, we run a four week audit first. Fixed scope, fixed price, and a handover to whoever owns AI from week five.
Readiness scan
Interviews with function heads, a tool inventory and a governance review across the business. This is where shadow usage surfaces.
Priority deep dives
Two or three functions go further, with workflow walkthroughs and sessions with the people actually doing the work.
Playbook drafting
Usage policy, the governance framework with named owners and review points, and a 90 day roadmap the board can track.
Synthesis and handover
Board readout, then handover to the appointed owner. You end up holding a report and a playbook, not a slide deck.
The audit works where there is real usage, a mandate from the top and someone appointed to own the outcome. If the mandate has not been established yet, it is too early and a call is the better starting point.
An assessment, not a proposal
Two to four weeks at a fixed price, delivered as a decision document. You own the output whether or not you carry on with us.
Start with an assessmentWe are an independent consulting firm. Software vendors do not pay us, so our recommendations come with the scoring behind them.
Related reading
Written from the same work. Free, and none of it asks you to talk to us first.
AI use case register template
A register recording where AI already runs, who owns each use and which obligations attach.
EU AI Act timeline
What applies now, what moved to December 2027 and what the Digital Omnibus left untouched.
AI marketing readiness assessment
Where the data, governance and audit trail have to be in place before a model touches a live workflow.