Loading…
Loading…
Where we work
On site across central Scotland from our Edinburgh base, and remotely everywhere else with visits by arrangement. Same prices wherever you are, we do not price by postcode.
On site, in person
Remote coverage, visits by arrangement

Services · Tech
Most firms adopted AI faster than they wrote any rules for it. This is the policy, the risk assessment and the controls that stop company data ending up in a public chatbot.£2,500 to £12,000

AI governance is simply having rules for how your business uses artificial intelligence, and controls to make sure the rules are followed. Almost every firm now has staff quietly using AI tools, pasting documents into chatbots to summarise them, drafting emails, analysing spreadsheets, usually with the best intentions and no guidance at all. Governance is the difference between that being a productivity boost and being a slow data leak nobody authorised.
The starting point is usually an honest look at what is already happening, which the industry calls shadow AI: the tools your people already use without telling anyone. Most owners are surprised. From there it is a plain acceptable-use policy people can actually follow, training so they understand why it matters, and technical controls that keep client and commercial data out of public models where it could be stored, learned from, or exposed.
For some businesses it also means formal readiness. New rules are arriving fast, from the EU AI Act to standards like ISO 42001, and if you build AI into products or operate in regulated areas, being able to show you govern it responsibly is becoming a requirement rather than a nicety. We map what actually applies to you and get you ready for it, without drowning you in compliance you do not need.
See it work
Some of these are fine to paste into a free AI tool, some should never be. Which is which?
Sort each one
0/8 rightWrite three subject lines for a spring newsletter about our new range of garden furniture.
Tidy up the wording of this blog post that we have already published on our website.
Draft a polite reply to a customer who is annoyed about a late delivery.
Here is our customer spreadsheet with names, home addresses and dates of birth. Please format it into a table.
The admin login is admin / Summer2024! and the live API key is sk_live_EXAMPLE1234notreal.
Here are our unpublished quarterly results, before we file them. Check that the figures add up.
Summarise these patient notes for me. They include names and medical conditions.
Paste in the full signed contract with our biggest client, including the confidential pricing schedule.
A scripted demonstration. A simple rule of thumb: if it names a real person, or unlocks something, keep it out of a public AI tool.
The first thing it protects is your data, and through it your clients' trust. The most common AI accident is mundane: someone pastes a confidential contract or a customer list into a free tool to save time, and that data is now somewhere you cannot control and may have agreed, in terms nobody read, to let it be used. Clear rules and the right controls stop that quiet leak before it becomes the breach you have to disclose.
The second is that you get the upside safely rather than banning it in fear. The wrong response to shadow AI is a blanket ban, which just pushes it underground; the right one is to channel it. Give people approved tools and clear guidance and you keep the genuine productivity gains, which are real, while removing the risk. Governance is what lets you say yes to AI instead of a nervous no.
And it puts you ahead of the rules rather than behind them. The regulatory picture is moving quickly, and the businesses that wrote sensible AI policies early will find compliance a small step, while those that ignored it face a scramble. Being able to show a customer, an insurer or a regulator that you take AI safety seriously is fast becoming part of being a credible business at all.

Illustrative cases. Tap one to see what happened and what could have been done.
The case
At a professional-services firm, several staff routinely pasted client contracts and financial documents into a free public AI tool to summarise them, unaware the data could be retained and used to train the model. It was a serious confidentiality breach waiting to surface.
What could have been done
Discovering what was actually in use, putting an approved private tool in place, and writing a policy people can follow with a little training would keep the time saving and remove the risk. The leak is easy to close before it surfaces, and very hard to deal with after.
The case
A marketing company assumed 'we don't really use AI yet'. In fact more than a dozen different AI tools were in active use across the team, several handling client data, none approved or checked, an invisible and growing liability.
What could have been done
A shadow-AI discovery brings it all into the open. From there, choosing safe tools and setting simple rules turns an unmanaged liability into a governed capability the leadership can actually stand behind.
Tell us what is going wrong and we will come back with a fixed price in writing, after a short scoping call. No obligation, and no jargon.
£2,500 to £12,000. We agree the exact number before any work starts, so there are no open ended day rates.
Most work of this kind is live within three to four weeks. We give you a date before we begin and tell you early if anything threatens it.
Yes. We are based in Edinburgh and work on site across the Lothians, Fife and Glasgow, and remotely across the United Kingdom.
Same service, same prices, wherever you are. On site across central Scotland and remotely across the rest of the UK.
An honest, plain-English health check of how safe your business actually is, and a clear, prioritised list of what to fix first. The sensible first step before spending a penny on security.
Find out what AI your staff are already using, what business data might be leaking into it, and whether any of it is safe, before it becomes a problem. Plain-English, no hype, no obligation.
Business phone systems that follow your team anywhere. Number porting, call routing, voicemail to email, and call recording where you need it.
Predictive, progressive and preview diallers for outbound teams. Set up, tuned, and kept compliant with Ofcom rules on abandoned calls.
Every call, meeting and voice note turned into searchable text, with summaries and actions extracted automatically. Accurate on strong regional accents.
Stop missing calls. Stop quoting at midnight.