Skip to content
Discuss your AI plans 

AI governance and compliance

Before anything is bought or built, we write down what data AI may use, who signs off on its outputs and what it may never do.

What a Charter settles.

Four decisions, agreed once, in language your team can read.

01

What stays with a person and what can be automated.

02

How each use is risk-classified.

Following the risk tiers the EU AI Act sets out.

03

Who signs off and when a person stays in the loop.

04

How data is handled and where it lives.

How a Charter is written.

Listen

We sit with your leadership, your compliance team and the people doing the work. The risks named are yours, not a template’s.

Draft

We write the four decisions in plain language, then put the draft in front of the people they bind.

  • Before Every output is signed off by the model. After Every output is signed off by a named person.
  • Before Data lives wherever the vendor puts it. After Data lives where we agreed it lives.

Who marks it up

  • Leadership Owns the decisions the Charter makes and signs it.
  • Compliance Checks it against the obligations you already carry.
  • The people doing the work Tell us where a rule would get in the way of the work.

Nothing is adopted until every mark is resolved.

Adopt

Your leadership agrees it, then we brief everyone it touches and revisit it as the rules or the tools change.

The four risk tiers.

The EU AI Act sorts AI uses into four tiers of risk. The Charter classifies yours against them, so the rules that apply are known before anything is bought or built.

We align your uses to the tiers and close the gaps against the requirements that apply. If you want to see where your own uses land before we talk, there is a free EU AI Act applicability check at AI Governance Check that works through the Article 2 roles and the risk tiers.

The approved tools list.

One part of what the Charter fixes is which AI tools your company may use and which it may not, with the reason written against each. The list below is an example of the shape it takes. Yours is settled with your compliance team and revisited when the terms or the tools change.

Approved

A business tier with an agreement behind it and an admin who can see who is using it.

  • ChatGPT Enterprise Business tier with a data processing agreement and prompts that are not used to train the model.
  • Microsoft 365 Copilot Runs inside your own tenant and inherits the permissions your files already carry.
  • Claude for Work Enterprise tier with single sign-on and an admin log of who used it.
  • A model you host yourself Nothing leaves your own infrastructure.

Not approved

No agreement behind it, or no way to say where the data goes.

  • Free and personal accounts No agreement behind them and inputs that may be used to improve the model.
  • Tools with no admin controls No way to add or remove people and no record of who used what.
  • Browser extensions with broad page access An extension that can read every page can read client data you never meant to send.
  • Anything not yet reviewed New tools go through the review before they are bought, not after.

The list is settled while the Charter is written, then adopted with the rest of it.

It runs beneath the whole engagement.

An AI Charter is an optional addition to the standard AI Audit, with its scope agreed separately. Once your leadership adopts it, it governs the AI work across the business, including anything we build with you.

AI Audit from £10,000 AI Charter optional, +£3,000 both excluding VAT

Where a governance need is larger than a Charter, we scope that on its own terms.

The Charter Adopted once by your leadership, then it holds under all three.

Our success stories

All case studies 
“Their team quickly understood the unique challenges of our business … and delivered a thorough, evidence-based strategy.”
Simon Patton CEO, EMQN CIC case study 
“Professional, yet friendly, Reuben & Ibrahim made sure to fully understand our situation and business objectives before providing advice and proposing solutions rooted in the most recent AI and prompt-engineering research.”
Matt Jaworski Co-Founder, Adopter case study 

Your compliance team is welcome at the first call. Discuss your AI plans 

FAQ

Is the AI Charter included?

No. It is an optional £3,000 addition to the standard £10,000 audit, both excluding VAT, with its scope agreed separately.

Is this a policy PDF?

No. A Charter is four decisions with names against them, short enough that people actually read it.

Does the EU AI Act apply to UK companies?

If you sell into the EU or process EU citizens’ data, parts of it will. The Charter classifies your uses against its tiers either way, so you are not retrofitting later.

We already have an IT security policy.

Good: the Charter sits beside it. Security policy says how systems are protected; the Charter says what AI may and may not do.

Who maintains it after adoption?

Your team owns it. It is written in language your own people can keep current. It is revisited when the rules or the tools change. Where you want us involved in those reviews, we agree that as part of the engagement.

Can you certify us under the EU AI Act?

No. OpenKit is not an EU AI Act notified body. We align your uses to the Act’s tiers and close the gaps against the requirements that apply.

Can you bring our compliance team into the room?

Yes, bring them to the first call. It goes faster with them in from the start.

Not ready to talk? The free AI readiness check scores where you stand in about five minutes.

What could your business do with AI?

Find out with experts who become part of your team. We uncover opportunities, get ideas working, and help your people build on the results.

We reply within one working day.