Cibernetica.io

Compliance

AI Governance

Work out what applies to you, and put something defensible in place.

Two separate questions sit under AI governance, and organisations often conflate them. The first is whether regulation applies to an AI system you build or deploy. The second is how you control staff use of AI tools already in the business — which is usually further along than anyone realises.

Regulation, standards, and the tools already in use

The EU AI Act takes a risk-based approach, with obligations scaling from minimal to prohibited depending on what a system does. Most business software falls into low-risk categories with limited obligations. A smaller set — systems used in recruitment, credit decisions, education, or employment management — carries substantially more. Obligations phase in over time, and scope depends on your role: provider, deployer, importer, or distributor. ISO 42001 is the management system standard for AI, structurally similar to ISO 27001 — scope, risk assessment, controls, documented operation, certification by an accredited body. It is new enough that certified organisations are relatively few, which is precisely why it currently carries signalling value in procurement. The more immediate issue for most SMEs is internal use. Staff are already putting information into AI tools, frequently including customer data, contract terms, and code. Without a policy, you have no basis to say what is acceptable and no record of what has left the organisation. This is usually the cheapest and highest-value place to start. AI governance also arrives through procurement. Customers increasingly ask how you use AI, whether their data trains models, and what oversight exists. Being unable to answer is now a commercial problem.

Who needs it

  • Organisations building or deploying AI systems that may fall in scope of the EU AI Act
  • Companies whose staff use AI tools without a policy governing what may be entered
  • Businesses receiving customer questionnaires about AI use and data handling
  • Firms considering ISO 42001, either for procurement advantage or as a governance framework

What you get

A scope assessment first

Which regulation applies, in what role, and at what risk tier. Many organisations discover their obligations are narrower than feared — but need the analysis to say so with confidence.

Acceptable use policy for AI tools

What staff may put into which tools, what is prohibited, and how it is monitored. The fastest way to reduce real exposure.

Consultants with actual AI governance experience

The field is new and crowded with generalists who have added AI to their offering. We match on demonstrable work in this area.

Frequently asked questions

Does the EU AI Act apply to us?

It depends on what your systems do, your role in the chain, and whether you operate in or supply into the EU. Many organisations using ordinary AI-enabled business software fall into low-risk categories with limited obligations. Systems used in recruitment, credit, education, or employment decisions carry considerably more. A scope assessment early is worth more than assuming either extreme.

What is ISO 42001?

The management system standard for artificial intelligence — a structure for governing how AI is developed and used, comparable in shape to ISO 27001. Certification comes from an accredited body independent of whoever helped you prepare, on the same basis as ISO 27001. Its main current value is procurement signalling, since relatively few organisations hold it.

Our staff already use ChatGPT. What should we do first?

Write a policy covering what may and may not be entered into AI tools, decide which tools are approved, and communicate both. This costs little and addresses the most immediate exposure — customer data, contract terms, and source code leaving the organisation through channels nobody is tracking. Formal frameworks can follow.

Customers are asking how we use AI. What do they want to know?

Typically whether their data is used to train models, where it is processed, which sub-processors are involved, whether humans review AI-generated decisions, and what happens when a system gets something wrong. Having documented answers ready is now a normal part of enterprise sales rather than an unusual request.