Three questions most firms cannot answer
Most mid-market firms do not have an AI problem. They have an AI pilot problem: every pilot that works becomes something the business is suddenly responsible for, but never designed properly.
What is actually running?
Which AI systems and agents are live right now, sanctioned and shadow? Copilot trials, chatbots, citizen-built agents in Copilot Studio, and the tools nobody formally approved.
What data do they touch?
What information reaches which models, where does it go, and where is it stored? Most firms cannot map this, and it is the first thing an auditor asks for.
Could we prove it is governed?
If a regulator or auditor asked you to evidence that any of it is controlled, could you? None of this shows up until something goes wrong. By then it is not a config tweak, it is an incident.
Find the risk. Build the foundation. Keep it governed.
Three packages, one journey. Each step is a decision gate, not a fork: the assessment scopes the build, and the build becomes the baseline the retainer maintains.
Which package is the right entry point?
| AI & Agent Readiness Assessment | Governed AI Landing Zone | Ongoing AI Governance | |
|---|---|---|---|
| What it does | Finds and classifies AI and agent risk | Builds the governed foundation | Keeps the estate compliant |
| Format | Fixed-scope diagnostic | Fixed-scope build | Monthly retainer |
| Timeline | 2-3 weeks | Agreed at scoping | Ongoing, 12-month term |
| Price | Fixed, from £9,500 | Fixed, from £35,000 | From £3,500/month |
| Best for | "What are we running, and is it safe?" | "Get us production-ready, safely" | "Keep us compliant as we scale" |
Not sure where you sit? Most firms start with the assessment: it is priced as an easy yes, and everything after it is built from evidence rather than assumptions. A discount applies to the Landing Zone when it follows an assessment.
"The value was never in the pilot. It's in everything below it. The boring stuff is what makes the interesting stuff safe."
How governed is your AI, right now?
Twelve questions, two minutes, an instant indicative score across the five layers that matter: identity, data, guardrails, monitoring, and access control. No sign-up, no sales call required.
Illustrative preview. Your score is calculated from your answers.
Frequently asked questions
What regulated firms ask us most often about governing AI and agents.
We only run a few Copilot pilots. Is this really for us?
That is exactly the stage it is for. Every pilot that works becomes something the business is responsible for but never designed properly. The Readiness Assessment finds what is already running, approved or not, and tells you whether you have a gap before an auditor or an incident does. If the answer is "not much, and it is under control", the assessment says so and you are done.
Does the EU AI Act even apply to us as a UK firm?
Possibly. The Act reaches beyond the EU, so UK firms serving EU clients can be in scope. Transparency duties apply from August 2026 and the high-risk duties follow in December 2027. Whether it applies to you is a legal question for your compliance team. Our job is to map each AI system against the risk categories, so that conversation happens with evidence rather than guesswork.
We already have an Azure landing zone. Do we need another one for AI?
Not a separate one. The Governed AI Landing Zone extends the same written, enforced rules to your AI agents: an identity for each one, controls on what data they can touch, allow-lists for models and regions, and a full activity log. If your existing foundation is sound, we build on it. If you never had one, this establishes it properly.
Can we skip the assessment and go straight to the build?
If you already have a validated view of your AI estate and its gaps, yes, we start from that evidence. If not, we run a compressed discovery first. Building a governed foundation on assumptions is how the wrong controls get enforced. The assessment exists so the build fixes what is actually broken.
What do you need from us to get started?
For the assessment: read-only access granted under NDA, a list of the AI tools you already know about, and a couple of hours each from an engineering contact and a compliance contact. We share a full checklist once the engagement is agreed. Prompt access is what keeps the timeline to two to three weeks.