AI governance consulting · EU AI Act · GDPR · NIS2

AI you can defend in front of a regulator.

Independent AI governance consulting for governments, municipalities and enterprises: risk classification, oversight, documentation and operating models that let ambitious AI reach production and stay there.

City systems represented as a governed digital model

Six areas of AI governance

01

EU AI Act readiness

Classify every AI use case by risk tier, document intended purpose, and build the technical file, conformity and human-oversight evidence obligations demand — before a regulator or procurement panel asks.

02

GDPR-aligned data protection

Lawful basis, purpose limitation, data minimisation and DPIAs applied to models and training data, so analytics and automation stay defensible across jurisdictions.

03

NIS2 resilience

Security governance, incident reporting and supply-chain assurance for essential and important entities running AI in critical services.

04

Agentic workflow accountability

Guardrails, escalation paths, audit logging and human-in-the-loop design for autonomous agents that act on real systems and real citizens.

05

Model and vendor assurance

Evaluation criteria, contractual controls and monitoring for third-party models, so accountability does not evaporate at the vendor boundary.

06

Operating model & training

An AI governance board, clear roles, decision rights and practical workshops that move policy from a document into daily delivery.

What you receive

Documents that survive audit.

Each engagement is scoped to your obligations and delivery calendar, not to a fixed template.

  • AI use-case inventory with risk classification
  • Gap assessment against the EU AI Act, GDPR and NIS2
  • AI governance policy and decision-rights framework
  • Human-oversight and escalation design
  • DPIA and conformity documentation templates
  • Board-level reporting and KPI set
  • Procurement clauses for AI suppliers
  • Implementation roadmap with owners and sequencing
Portrait of Andrew Rippon
Andrew Rippon · Genoa, Italy

Why this advisor

Governance written by someone who has run the systems.

Thirty years across Europe, the Middle East and Asia: AI-enabled city control systems, a city operating brain, autonomous mobility in live service, and the governance framework for European blockchain infrastructure spanning fourteen member states. Policy and delivery, from the same hand.

See past projects

Common questions

Who needs AI governance consulting?

Public bodies, municipalities, master developers and enterprises that deploy AI in services touching citizens, infrastructure or regulated data — particularly anyone placing or using AI systems in the EU market.

How does this differ from generic AI strategy work?

Strategy decides what to build. Governance decides how it stays lawful, auditable and operable once it is live — the part that determines whether a pilot ever reaches production.

Where does an engagement usually start?

With a short assessment: an inventory of AI use cases, their risk tiers and the concrete gaps against the AI Act, GDPR and NIS2, followed by a prioritised roadmap.

Start with an AI governance assessment.

A concise, no-obligation Project Approach Brief covering your AI use cases, obligations and the first moves.