For Organisations Using AI

Your staff are pasting company data into ChatGPT. Nobody is governing it.

Client emails, contracts and customer records get pasted into ChatGPT every day, usually on personal accounts, with no policy and no record of it. The problem is not that your staff use AI. It is that nobody governs how. We show you what is really happening, then put simple governance in place.

  • Free 30 minute call, nothing to prepare
  • Written report within 24 hours
  • No pitch, no obligation
Experience with teams at NEOM GR8 Connect STC Phaidon

Experience spanning technology, telecoms, energy, professional services and government, across international teams.

Where It Starts

Your Teams Use AI Every Day. Nobody Sees What Goes Into It.

The tools are already in use. The questions are which ones, what company and customer data goes into them, whether anything is scoring or deciding, and who answers when a client or regulator asks. In most organisations, nobody can say.

What your people are already doing with it
Summarising documentsDrafting customer repliesAnalysing spreadsheets Writing proposals and bidsScreening applicationsMeeting notes and actions Research and due diligenceGenerating code
What Good Looks Like

What Changes When You Get Control Of AI

The same gaps show up in nearly every organisation. Once they are closed, the difference in control, and in what you can put in front of a customer, is felt within weeks.

Control and Visibility

  • A live register of every AI tool in use across the business
  • A clear approval route before teams adopt a new one
  • Shadow AI brought into the open, not driven onto personal devices

Risk You Can Evidence

  • Personal and confidential data handled to a written standard
  • AI-assisted decisions documented, with real human oversight
  • Obligations understood in each market where you operate

Confident, Capable Teams

  • Everyone working to the same clear AI rules
  • Approved prompts and patterns shared across functions
  • People who use AI well, and still hit their numbers

A Commercial Advantage

  • A ready answer to the AI section of any tender or questionnaire
  • Customer and company data you can account for
  • The contract kept, rather than lost to a supplier that had an answer
How It Works

How We Help An Organisation, Step by Step

Select any stage to see what it includes. You start free and only go further when it makes commercial sense for the business.

Assess Audit Implement Adopt
What it includes
  • A relaxed 30 minute conversation about how AI is really used across your teams
  • Which AI tools are genuinely in use, sanctioned or not, and on whose accounts
  • What company, client and personal data is going into them
  • Whether anything scores, ranks or decides, and who actually reviews it
  • Whether a policy exists, and whether a single person follows it
  • A written report within 24 hours, seven areas rated, yours to keep

No cost, no obligation, and no pitch on the call. The report is yours either way.

Get My Free AI Risk Assessment →
What it includes
  • Short interviews across operations, technology and leadership
  • A complete inventory of the AI tools and use cases across the business
  • What is already switched on inside your existing systems that nobody switched on
  • Every point AI influences a decision about a person, mapped and named
  • Data protection, confidentiality and automated decision rules, in plain English
  • Obligations in each market you operate in, including the EU AI Act where it reaches you
  • Customer contract and tender exposure reviewed
  • A risk rating for each area and a written report for leadership
  • A 60 minute board meeting to present the findings

You end with a document you could hand to a customer’s procurement team without flinching.

Discuss the Audit →
What it includes
  • An AI and acceptable use policy your teams will actually read
  • A managed company AI account, configured, replacing personal logins
  • A live AI register recording every tool, model and use case
  • Bias and fairness checks, plus impact assessments where decisions affect people
  • Human review built into the workflow, not asserted in a document
  • Transparency wording for your privacy notice and customer communications
  • A simple approval route before anyone adopts a new tool
  • A clear accountability structure, with named owners
  • An evidence pack that answers the customer AI questionnaire

Controls that survive contact with a working business, not a policy nobody opens.

Discuss Implementation →
What it includes
  • An AI adoption assessment across each team and function
  • Training built around live work and real documents, on site or remote
  • Approved workflows and a tested prompt library for the tasks that matter most
  • AI champions identified in each team and trained to sustain it
  • Responsible AI training on data, bias and human judgement
  • Leadership workshops and a twelve month adoption roadmap
  • Clear measurement of adoption, plus ongoing support

Ban AI and people simply move onto their phones. This is the half that keeps them fast and safe.

Discuss Adoption →
Rather start with something you can book today? A half day AI briefing for your leadership team: what your people are already doing with company data, where the risk sits, and what good AI use looks like day to day. No assessment needed first.
Half day
On site or remote
Book the Briefing →

Most organisations then continue with Ongoing AI Risk & Governance Support, a rolling retainer that keeps the register current, handles customer AI questionnaires when they land, and keeps teams trained as tools and rules change. Scope is agreed after your free AI Risk Assessment. No day rates, and no locked in contracts.

The Rules, Straight

What actually applies
to an organisation using AI

Check Where You Stand →
Live · Feb 2025 Some AI uses are banned outright Article 5 of the EU AI Act prohibits practices including emotion inference in the workplace. The Article 4 duty to make sure your staff are AI literate applies from the same date.
Live · Aug 2026 You must say when it is AI The EU AI Act transparency rules applied from 2 August 2026 and were not deferred. They cover telling people they are dealing with AI and marking synthetic content.
Live · 2026 The US is now a patchwork Texas has had a comprehensive AI law in force since 1 January 2026, alongside California measures. Several states treat alignment with the NIST AI Risk Management Framework as evidence of reasonable care.
2 Dec 2027 The heavy EU regime lands High risk obligations moved from 2 August 2026 to 2 December 2027, and to 2 August 2028 for AI built into regulated products. Whether they reach you depends on what your systems do.

The delay is real, but it is narrower than the headlines suggested. The prohibitions, the AI literacy duty and the transparency rules are all live now. What moved is the heaviest documentation regime, and it moved to a fixed date rather than an open one. Organisations that use the window are the ones who answer a customer’s AI questionnaire without flinching. Discrimination and data protection law applies throughout, whatever any AI rule says.

Sources: EU AI Act (Regulation (EU) 2024/1689), Articles 4, 5 and 50; the Digital Omnibus on AI (Regulation (EU) 2026/1744), signed 8 July 2026, published in the Official Journal 24 July 2026 and in force from 27 July 2026, which deferred Annex III high risk obligations to 2 December 2027 and Annex I to 2 August 2028; the Texas Responsible Artificial Intelligence Governance Act, in force 1 January 2026; NIST AI Risk Management Framework 1.0; ISO/IEC 42001:2023. The EU AI Act can reach organisations outside the EU where the output of an AI system is used there. Positions are correct at the date of publication and confirmed at the point of engagement. We are not a law firm and this is not legal advice.

In the room with your teams

We Work With Your Teams, Not Around Them

Online training is easy to ignore, and a policy emailed round on a Friday is ignored by Monday. A core part of every engagement is delivered live with your people, on site where you are within reach and remotely where you are not, led by Sohaib Chohan, founder of Telo AI.

  • Hands-on workshopsPractical sessions run on your real work and real documents, not slides.
  • Team by teamSessions built around what each function actually does day to day.
  • Return visitsWe come back to reinforce the habit and keep momentum going.
Sohaib Chohan Founder, Telo AI

I have sat on both sides of this: selling into organisations and watching how work actually gets done inside them. I know what someone does at five o’clock with a document that has to go out, and I know why they open ChatGPT to do it. That is what this is built around. A framework written for a regulator does not survive contact with a working team. I am not a lawyer and I will tell you when a question needs one.

The Risk Gap

Why Most Organisations Are Exposed

Published research and buyer behaviour show the same pattern. The gap is not the technology, it is the controls around it. That is the gap we close.

The problem

Your teams already use AI you never approved

Microsoft research found most workers have used unapproved AI tools for work, over half of them weekly, while almost all executives believe they have full visibility.

71%Workers using shadow AI
The exposure

The rules are live, and they reach across borders

The EU AI Act’s prohibitions and AI literacy duty have applied since February 2025, and its transparency rules since August 2026. It can reach organisations outside the EU where the output of an AI system is used there. Meanwhile the US has become a patchwork of state law rather than one regime.

2027When the heavy EU regime lands
The upside

AI questions now decide who wins the contract

AI due diligence is now a scored category in enterprise supplier questionnaires, and ISO/IEC 42001, the first international standard for AI management systems, is moving from differentiator to baseline expectation. When procurement asks how you control data in AI tools, the supplier with an answer keeps the contract.

42001The standard buyers now ask for

Sources, 2026: Microsoft shadow AI research; the EU AI Act (Regulation (EU) 2024/1689), under which the Article 5 prohibitions and the Article 4 AI literacy duty have applied since 2 February 2025 and the Article 50 transparency obligations since 2 August 2026; the Digital Omnibus on AI (Regulation (EU) 2026/1744), in force 27 July 2026, which deferred Annex III high risk obligations to 2 December 2027 and Annex I to 2 August 2028; the Texas Responsible Artificial Intelligence Governance Act, in force 1 January 2026; NIST AI Risk Management Framework 1.0; ISO/IEC 42001:2023, published December 2023.

What this looks like inside an organisation

A modelled scenario, based on the research above and typical operations.
Before
14 AI tools in use, mostly unapproved
0 Recorded in any AI register
None With a named owner or real oversight
After controls
100% Tools registered, owned and reviewed
1 Policy everyone has read and follows
Tender ready Evidence pack on file for customer questionnaires

Illustrative scenario for guidance only, not a client result. Modelled from published research on shadow AI and typical operations, and deliberately conservative. Figures vary by organisation. Your free AI Risk Assessment gives you the equivalent picture for your own business.

Specialist Services

Other Ways We Help You Go Further

Focused engagements you can bring in at any point, alongside a programme or on their own.

Shadow AI Discovery

Find out exactly which AI tools your people use, what company and customer data goes into them, and how to bring it under control without killing the speed.

AI Strategy & Roadmap

A clear twelve month plan for where AI takes the organisation, sequenced by value and risk, so leadership knows what comes next in each function.

AI Compliance & Risk

Get straight on data protection, automated decision rules and the EU AI Act where it may reach you, with a plain English review and a plan to close the gaps.

Bias & Fairness Review

A close look at where AI touches decisions about people, and whether someone is genuinely reviewing it, so your process stays defensible under discrimination law.

ISO/IEC 42001 Readiness

Prepare for the AI management standard buyers increasingly ask about in tenders, with a gap analysis and a clear route to certification.

Prompt Libraries & Playbooks

A tested library of prompts and playbooks for the tasks your teams repeat most, so good results repeat across every function rather than living with one person.

AI Agents & Automation

When you are ready to move beyond chat, we scope the automations and AI agents that pay back fastest across your systems and workflows, with oversight designed in from the start. Build is delivered by our approved technical partner.

Straight Answers

What Leaders Ask First

No, and we say so on every call. We are not lawyers and nothing we produce is legal advice. Our work is operational: what your people are actually doing, what data is actually moving, and what controls would actually hold. Where a question genuinely needs a solicitor or local counsel, we tell you and help you brief them.

It can, depending on your circumstances. The Act can reach organisations established outside the EU where the output of an AI system is used there, and it turns on what role you play in the systems you use. The assessment establishes that rather than assuming it. For many organisations the more pressing issues are local data protection law, customer contracts and discrimination law.

Part of it did. The Digital Omnibus became law in July 2026 and moved the high risk obligations from August 2026 to December 2027, and to August 2028 for AI built into regulated products. What did not move: the prohibitions and AI literacy duty live since February 2025, and the transparency rules that applied from August 2026. The delay covers the heaviest documentation regime, not the whole Act.

The opposite. Controls that stop people using AI have failed, because they move onto their phones and you lose visibility completely. The aim is a sanctioned route that is genuinely better than the unsanctioned one, so people use it because it works rather than because they were told to. Output does not drop. That is the whole point of pairing risk work with adoption.

We could, and it would sit in a folder unread. A policy that does not match what your people actually do is worse than having none, because it evidences that you knew and did nothing about it. The free assessment and the audit are what make a policy worth writing.

Thirty minutes, and a willingness to answer honestly rather than tell us what the policy says. There is no pitch on the call and the report is yours whether or not anything follows. If there is a case for paid work, we will make it in the report. If there is not, we will say so.

The work is sector agnostic, because the failure pattern is the same everywhere: tools nobody approved, data nobody tracked, decisions nobody documented. We work with organisations internationally, on site where you are within reach and remotely where you are not. Where your obligations are genuinely local, we scope that in rather than pretending one framework covers the world.

Start Here

Find Out Where Your Company Data Is Really Going

A free 30 minute AI Risk Assessment for your organisation. Nothing to prepare, no pitch on the call, and a written report in your inbox within 24 hours.

30 minute callNothing to prepareReport in 24 hoursNo pitch on the callNo obligation
Free AI Risk Assessment →
Get My Free AI Risk Assessment →