Skip to content

Most AI policies die in legal because they try to cover everything. The one that gets signed is short, specific and forces a handful of real decisions. We write that one, and we build the register and controls around it so that governance is something your organisation does rather than something it has.

We start with the decisions that matter: which tools are approved, what data may go into them, who signs off outputs that leave the building, and what happens when something goes wrong. The policy that results is usually five pages, and it is written for the people who have to follow it rather than for the lawyers who have to approve it.

Around the policy we set up a proportionate risk register, data-handling and retention rules, and the review cadence that keeps them current as tools and law change. Where UK GDPR, the Data (Use and Access) Act 2025 or the EU AI Act bear on what you are building, we say so plainly and design to it.

We are practitioners, not lawyers, and we say so. Where a matter needs a legal opinion we work alongside your own advisers, and the documents we produce are written to make that review quick.

What you get

  • An acceptable-use policy for AI that your board can sign and your staff can follow
  • A proportionate AI risk register with owners and controls
  • Data handling, retention and vendor rules for AI tooling
  • A review cadence and a template for assessing new use cases

Who this is for

Boards and leadership teams who need to say yes to AI responsibly — often prompted by a client questionnaire, an insurer, a regulator's guidance, or staff already using tools without a policy.

Got a process that's costing you hours?

Tell us about it. The first call is free, and we'll say plainly whether it's worth automating — and whether we're the right people to do it.

Start a conversation