Control and Visibility
- A live register of every AI tool in use across the business
- A clear approval route before teams adopt a new one
- Shadow AI brought into the open, not driven onto personal devices
Client emails, contracts and customer records get pasted into ChatGPT every day, usually on personal accounts, with no policy and no record of it. The problem is not that your staff use AI. It is that nobody governs how. We show you what is really happening, then put simple governance in place.
Experience spanning technology, telecoms, energy, professional services and government, across international teams.
The tools are already in use. The questions are which ones, what company and customer data goes into them, whether anything is scoring or deciding, and who answers when a client or regulator asks. In most organisations, nobody can say.
What your people are already doing with itThe same gaps show up in nearly every organisation. Once they are closed, the difference in control, and in what you can put in front of a customer, is felt within weeks.
Select any stage to see what it includes. You start free and only go further when it makes commercial sense for the business.
No cost, no obligation, and no pitch on the call. The report is yours either way.
You end with a document you could hand to a customer’s procurement team without flinching.
Controls that survive contact with a working business, not a policy nobody opens.
Ban AI and people simply move onto their phones. This is the half that keeps them fast and safe.
Most organisations then continue with Ongoing AI Risk & Governance Support, a rolling retainer that keeps the register current, handles customer AI questionnaires when they land, and keeps teams trained as tools and rules change. Scope is agreed after your free AI Risk Assessment. No day rates, and no locked in contracts.
The delay is real, but it is narrower than the headlines suggested. The prohibitions, the AI literacy duty and the transparency rules are all live now. What moved is the heaviest documentation regime, and it moved to a fixed date rather than an open one. Organisations that use the window are the ones who answer a customer’s AI questionnaire without flinching. Discrimination and data protection law applies throughout, whatever any AI rule says.
Sources: EU AI Act (Regulation (EU) 2024/1689), Articles 4, 5 and 50; the Digital Omnibus on AI (Regulation (EU) 2026/1744), signed 8 July 2026, published in the Official Journal 24 July 2026 and in force from 27 July 2026, which deferred Annex III high risk obligations to 2 December 2027 and Annex I to 2 August 2028; the Texas Responsible Artificial Intelligence Governance Act, in force 1 January 2026; NIST AI Risk Management Framework 1.0; ISO/IEC 42001:2023. The EU AI Act can reach organisations outside the EU where the output of an AI system is used there. Positions are correct at the date of publication and confirmed at the point of engagement. We are not a law firm and this is not legal advice.
Online training is easy to ignore, and a policy emailed round on a Friday is ignored by Monday. A core part of every engagement is delivered live with your people, on site where you are within reach and remotely where you are not, led by Sohaib Chohan, founder of Telo AI.
I have sat on both sides of this: selling into organisations and watching how work actually gets done inside them. I know what someone does at five o’clock with a document that has to go out, and I know why they open ChatGPT to do it. That is what this is built around. A framework written for a regulator does not survive contact with a working team. I am not a lawyer and I will tell you when a question needs one.
Published research and buyer behaviour show the same pattern. The gap is not the technology, it is the controls around it. That is the gap we close.
Microsoft research found most workers have used unapproved AI tools for work, over half of them weekly, while almost all executives believe they have full visibility.
The EU AI Act’s prohibitions and AI literacy duty have applied since February 2025, and its transparency rules since August 2026. It can reach organisations outside the EU where the output of an AI system is used there. Meanwhile the US has become a patchwork of state law rather than one regime.
AI due diligence is now a scored category in enterprise supplier questionnaires, and ISO/IEC 42001, the first international standard for AI management systems, is moving from differentiator to baseline expectation. When procurement asks how you control data in AI tools, the supplier with an answer keeps the contract.
Sources, 2026: Microsoft shadow AI research; the EU AI Act (Regulation (EU) 2024/1689), under which the Article 5 prohibitions and the Article 4 AI literacy duty have applied since 2 February 2025 and the Article 50 transparency obligations since 2 August 2026; the Digital Omnibus on AI (Regulation (EU) 2026/1744), in force 27 July 2026, which deferred Annex III high risk obligations to 2 December 2027 and Annex I to 2 August 2028; the Texas Responsible Artificial Intelligence Governance Act, in force 1 January 2026; NIST AI Risk Management Framework 1.0; ISO/IEC 42001:2023, published December 2023.
Illustrative scenario for guidance only, not a client result. Modelled from published research on shadow AI and typical operations, and deliberately conservative. Figures vary by organisation. Your free AI Risk Assessment gives you the equivalent picture for your own business.
Focused engagements you can bring in at any point, alongside a programme or on their own.
Find out exactly which AI tools your people use, what company and customer data goes into them, and how to bring it under control without killing the speed.
A clear twelve month plan for where AI takes the organisation, sequenced by value and risk, so leadership knows what comes next in each function.
Get straight on data protection, automated decision rules and the EU AI Act where it may reach you, with a plain English review and a plan to close the gaps.
A close look at where AI touches decisions about people, and whether someone is genuinely reviewing it, so your process stays defensible under discrimination law.
Prepare for the AI management standard buyers increasingly ask about in tenders, with a gap analysis and a clear route to certification.
A tested library of prompts and playbooks for the tasks your teams repeat most, so good results repeat across every function rather than living with one person.
When you are ready to move beyond chat, we scope the automations and AI agents that pay back fastest across your systems and workflows, with oversight designed in from the start. Build is delivered by our approved technical partner.
No, and we say so on every call. We are not lawyers and nothing we produce is legal advice. Our work is operational: what your people are actually doing, what data is actually moving, and what controls would actually hold. Where a question genuinely needs a solicitor or local counsel, we tell you and help you brief them.
It can, depending on your circumstances. The Act can reach organisations established outside the EU where the output of an AI system is used there, and it turns on what role you play in the systems you use. The assessment establishes that rather than assuming it. For many organisations the more pressing issues are local data protection law, customer contracts and discrimination law.
Part of it did. The Digital Omnibus became law in July 2026 and moved the high risk obligations from August 2026 to December 2027, and to August 2028 for AI built into regulated products. What did not move: the prohibitions and AI literacy duty live since February 2025, and the transparency rules that applied from August 2026. The delay covers the heaviest documentation regime, not the whole Act.
The opposite. Controls that stop people using AI have failed, because they move onto their phones and you lose visibility completely. The aim is a sanctioned route that is genuinely better than the unsanctioned one, so people use it because it works rather than because they were told to. Output does not drop. That is the whole point of pairing risk work with adoption.
We could, and it would sit in a folder unread. A policy that does not match what your people actually do is worse than having none, because it evidences that you knew and did nothing about it. The free assessment and the audit are what make a policy worth writing.
Thirty minutes, and a willingness to answer honestly rather than tell us what the policy says. There is no pitch on the call and the report is yours whether or not anything follows. If there is a case for paid work, we will make it in the report. If there is not, we will say so.
The work is sector agnostic, because the failure pattern is the same everywhere: tools nobody approved, data nobody tracked, decisions nobody documented. We work with organisations internationally, on site where you are within reach and remotely where you are not. Where your obligations are genuinely local, we scope that in rather than pretending one framework covers the world.
A free 30 minute AI Risk Assessment for your organisation. Nothing to prepare, no pitch on the call, and a written report in your inbox within 24 hours.