AI Governance
AI Governance Consulting - Control Over AI You Can Evidence
AI governance is the framework of policies, controls, and accountability that keeps AI systems safe, compliant, and trustworthy - covering acceptable use, data handling, model risk, human oversight, and audit trails. We build it: system inventory and risk classification, policy and control design, AI-specific security testing, and mapping to the EU AI Act, NIST AI RMF, and ISO/IEC 42001.
What We Deliver
Two forces have made this urgent at once. Regulation arrived: the EU AI Act entered into force in 2024 with obligations phasing in through 2026–2027, and reference frameworks like the NIST AI Risk Management Framework and ISO/IEC 42001 are becoming the standards buyers and auditors ask about. And shadow AI use became universal - your staff are using AI tools right now, with or without a policy. Governance is how you replace assumption with evidence.
AI System Inventory and Risk Classification
You cannot govern what you haven’t cataloged. We inventory the AI in use - sanctioned and unsanctioned, built and bought, embedded in vendor products - and classify each by risk. Nearly every inventory we run surfaces AI systems leadership didn’t know existed, most often embedded inside SaaS tools nobody thought of as AI.
Policy and Control Design
Acceptable-use policy people will actually follow, data-handling boundaries, human-oversight requirements by risk tier, logging and retention standards, and vendor AI assessment criteria for procurement.
Regulatory Mapping
Where your systems sit against EU AI Act risk tiers and obligations, and how your controls map to NIST AI RMF functions and ISO/IEC 42001 requirements - so one control set serves multiple obligations rather than building a program per regulation.
AI-Specific Security Testing
The risks traditional application security doesn’t cover: prompt injection through user input, documents, or retrieved web content; sensitive data leakage through model outputs, retrieval scope, or logs; agent permission review of what your agents can actually do; jailbreak and misuse testing under adversarial pressure; and model supply-chain provenance and integrity.
Governance Operating Model
Who owns AI risk, which forum decides, how new systems get approved, and how incidents are handled. Governance without named owners is a document, not a control.
Building the AI Inventory
Governance starts with an inventory, and the inventory is always larger than expected. Where AI hides:
Embedded in SaaS you already buy. Features added to existing tools, often enabled by default. Most organizations have significantly more AI in use than they have AI projects.
Shadow use by staff. Consumer AI tools used with company data on personal accounts. Near-universal, rarely disclosed voluntarily, and invisible to procurement.
In vendor delivery. Suppliers and agencies using AI to produce work you receive - with implications for confidentiality and IP that are worth a contract clause.
Built internally. Scripts, automations, and prototypes built by capable people outside engineering governance.
Legacy ML. Models built years ago, still running, often unmonitored and unowned, whose original builders have left.
We inventory through a combination of procurement review, network and identity telemetry where available, structured interviews, and an amnesty-framed staff survey - the framing matters, because punitive discovery drives usage further underground where you have no visibility at all.
Prompt Injection, Explained Properly
The AI-specific risk most under-tested, and the one that most surprises security teams who understand traditional application security well.
Direct injection is a user instructing the system to ignore its rules. Well known, and partially mitigated by guardrails.
Indirect injection is the serious one: malicious instructions hidden in content the AI system retrieves - a web page, an uploaded document, an email, a support ticket. The user is legitimate; the attack arrives through the data. An agent that reads a document containing hidden instructions may follow them, using the permissions of the person who asked.
This matters most for agents with tool access, because the potential impact scales with what the agent can do. Mitigations we implement and test: treating all retrieved content as untrusted input, permission boundaries enforced outside the model so a compromised prompt cannot exceed them, output filtering before actions execute, human approval for consequential actions, and adversarial testing with injection payloads embedded in realistic content.
No current technique fully prevents prompt injection. Any vendor claiming otherwise is overstating. The discipline is limiting what a successful injection can accomplish.
Do you know how many AI systems your organization runs?
We’ll inventory your AI use, classify the risk, and show you the three gaps most likely to cause a problem.
Governance That People Follow
Policies fail through unusability rather than ignorance. What works: a short, specific acceptable-use policy naming approved tools and prohibited data categories in plain language; sanctioned tools that are genuinely good enough that nobody needs to route around them; a fast approval route for new tools, because a six-week review process guarantees shadow use; role-specific guidance rather than a single generic document; and an amnesty when introducing governance, since punishing past use buys you concealment rather than compliance.
Frequently Asked Questions
An attack where malicious instructions are hidden in content an AI system retrieves - a web page, document, email, or ticket - rather than typed by the user. The system may follow them using the requesting user’s permissions. It’s the most serious AI-specific risk for agents with tool access, and no current technique fully prevents it.
Embedded in SaaS tools you already buy, in staff use of consumer AI on personal accounts, in vendors using AI to produce your deliverables, in internal scripts built outside engineering governance, and in legacy ML models still running unowned.
AI governance is the set of policies, controls, roles, and processes that ensure AI systems are used safely, lawfully, and accountably - spanning acceptable use, data handling, model risk management, human oversight, logging, and incident response.
It applies broadly to providers and deployers of AI systems whose output is used in the EU, including organizations outside the EU - with obligations scaled by risk tier and phasing in through 2026–2027. Given the pace of implementation guidance, confirm your specific position with counsel; our role is mapping your systems and controls against the obligations.
Prompt injection (including indirect injection via retrieved content), sensitive-data leakage through outputs, over-permissioned agents taking unintended actions, and model supply-chain risk. Each requires testing that conventional application security doesn’t perform.
Through a clear, usable acceptable-use policy, sanctioned tools that are genuinely good enough that people don’t route around them, technical controls where appropriate, and training. Prohibition alone reliably fails - it moves the usage to personal devices where you have no visibility at all.
ISO/IEC 42001 is the international standard for AI management systems, providing a certifiable framework for governing AI responsibly - structurally comparable to ISO 27001 for information security, and increasingly requested by enterprise buyers.
Yes. Third-party AI assessment - security testing, data-flow review, and control gap analysis - is a common engagement, particularly before renewals or before expanding a system’s scope.