01 The position
A policy nobody can enforce is a liability, not a control.
Every company we talk to has an AI usage policy. Almost none can answer the question that follows: show me. Show me a prompt that was blocked. Show me the team that hit its cap. Show me where customer data was sent last Tuesday, and which model saw it.
If the answer lives in a Confluence page and a training slide, you do not have a control — you have a document that will be read aloud during the incident review. Governance that works is a property of the infrastructure, and the gateway is where it goes.
WHAT "WE HAVE A POLICY" LOOKS LIKE WHEN IT IS REAL
Classification drives the route
Public content can reach a vendor API. Internal content stays on self-hosted hardware in your region. Customer and regulated data never leave your infrastructure — with caching disabled and longer retention where policy requires it. Budgets are soft (alert) or hard (stop spending), enforced at the gateway so they apply to the intern's script as much as to production.
02 The controls
03 Frameworks
We build the evidence. Your counsel makes the argument.
We are engineers, not a law firm, and we will not pretend a Terraform module makes you compliant with anything. What we do is produce the technical evidence your legal and compliance people need: the logs, the controls, the architecture diagrams, the retention configuration and the routing rules, documented in a form that maps onto what they are being asked.
In practice that has meant EU AI Act transparency and record-keeping obligations, GDPR data-flow documentation, ISO 27001 control evidence, SOC 2 audit support, and sector rules in finance and healthcare that predate any of this and are not going to bend for it.
USUALLY BOUGHT AS
An add-on to the retainer
Most governance work lands on top of an existing stack — the controls need somewhere to live. Typical implementation is €4k–€12k, then it becomes part of the monthly operation.
ALSO AVAILABLE AS
A standalone review
Two weeks, fixed fee, written findings: what your current AI usage exposes you to, what is enforceable today, and what to fix in what order. No obligation to have us do the fixing.