Turn AI risk into a policy your team will actually follow.
We assess your AI use against the regulations and standards that matter — the EU AI Act, NIST AI RMF, ISO 42001, and sector rules — and build a clear, usable AI policy and compliance plan. Not boilerplate: a policy fitted to how your company really uses AI, including in marketing and customer-facing work.
What is an AI compliance & policy assessment?
It is the step between knowing your AI risk and operating safely: a gap assessment against applicable regulation and standards, plus a written AI use policy and compliance plan your team can adopt. We define acceptable use, approval workflows, disclosure and data rules, and vendor requirements — and make them specific enough to follow.
From regulatory gaps to a policy people use.
Assess against the rules that apply
We map your AI use to the EU AI Act, NIST AI RMF, ISO 42001, and any sector-specific obligations, and identify the gaps.
Draft a usable AI use policy
Acceptable use, human oversight, disclosure, data handling, and approval workflows — written for your team, not copied from a template.
Set vendor and procurement standards
Clear requirements for evaluating and approving AI vendors, so new tools do not reopen the risks you just closed.
Build disclosure and data rules
Especially where AI meets customer data and marketing: what must be disclosed, what data can be used, and how.
Make it operational
Rollout guidance, training points, and an owner for each policy area so the policy changes behavior instead of sitting in a wiki.
Answered.
Do we need an AI policy if we are small?
Yes. Small teams adopt AI fastest and often with the least oversight, so a clear, lightweight policy prevents the most common early mistakes without slowing anyone down.
What does an AI use policy cover?
Acceptable and prohibited uses, human oversight and review, disclosure requirements, data and privacy rules, vendor approval, and who owns each area. We fit it to how you actually work.
How does this relate to the EU AI Act?
The EU AI Act classifies AI uses by risk tier and imposes obligations accordingly. We assess which tier your uses fall into and build policy that meets the relevant requirements, with plain-language explanations.
Can you cover AI in our marketing specifically?
Yes. We address AI-generated content disclosure, use of customer data in AI tools, and brand safety, and can align it with governed, compliant marketing agents where you use them.
Is this legal advice?
No — we deliver a practical compliance assessment and policy your team can adopt, and recommend legal counsel for binding legal interpretation. We make compliance concrete and actionable.