AI Governance & EU AI Act

Overview

Who it is for. Compliance leads, CISOs, general counsel, CIOs and boards of organisations that provide or deploy AI in the EU, and their suppliers.

The problem. AI spreads through teams faster than governance. According to a Cloud Security Alliance research note from March 2026, over half of organisations lack a systematic AI inventory. The timeline has also changed. The AI Act's prohibitions and AI literacy duty have applied since 2 February 2025, obligations for general-purpose AI models since 2 August 2025 and the Article 50 transparency duties since 2 August 2026. Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026, moved high-risk obligations to 2 December 2027 for stand-alone Annex III systems and to 2 August 2028 for AI in products covered by Annex I. The delay is not a repeal. In Poland the act on AI systems has been in force since 11 August 2026, with KRiBSI as the market surveillance authority.

What we do. We inventory AI systems, including vendor-embedded and unsanctioned AI, map your role for each, classify risk with engineers and your legal counsel in the same room, and build the controls: documentation, logging, human oversight, transparency labelling and incident handling. The management system follows ISO/IEC 42001, which on its own gives no presumption of conformity with the AI Act.

What you get. Evidence linked to the systems actually deployed, and a plan set against dates that are law. This is information, not legal advice.

How we work

At Keter AI, every engagement moves through the same four layers, in the order of our mark: strategy, architecture, delivery, governance. Each layer ends in something you can inspect and keep: a decision, a design, a working system, a set of controls. The depth changes with the service; the order does not.

Strategy

01

We start from the business problem: which decisions and workflows AI should improve, what that is worth and what must be true first.

Architecture

02

We design the system around your constraints: data boundaries, model strategy, integrations, evaluation and where it will run.

Delivery

03

We build with real data and real users, in short increments, until the system passes its evaluation set and is ready for production.

Governance

04

We leave controls that last: named owners, monitoring, an audit trail, documentation and a clear view of AI Act duties.

Deliverables

Governance fails when it lives in documents that nobody connects to the deployed system. Every output below is tied to real systems and real owners, and is built with engineering input. What we provide is information and implementation support, not legal advice; we work alongside your legal counsel.

01

AI system inventory

A register of AI systems in use, including vendor-embedded and unsanctioned AI, with owner, purpose, data and your role for each.

01

AI system inventory

A register of AI systems in use, including vendor-embedded and unsanctioned AI, with owner, purpose, data and your role for each.

02

Risk classification records

Each system assessed against the AI Act's prohibited, high-risk and transparency categories, with the reasoning recorded.

02

Risk classification records

Each system assessed against the AI Act's prohibited, high-risk and transparency categories, with the reasoning recorded.

03

Gap analysis and action plan

Gaps against provider and deployer duties, turned into a prioritised plan set against the dates that are binding law.

03

Gap analysis and action plan

Gaps against provider and deployer duties, turned into a prioritised plan set against the dates that are binding law.

04

AI management system

Policy, roles, risk process and review cycle following ISO/IEC 42001, sized to the organisation rather than copied.

04

AI management system

Policy, roles, risk process and review cycle following ISO/IEC 42001, sized to the organisation rather than copied.

05

Controls and documentation

Logging, human oversight, transparency labelling and technical documentation, designed with the engineers who run the system.

05

Controls and documentation

Logging, human oversight, transparency labelling and technical documentation, designed with the engineers who run the system.

06

Incident and vendor process

An incident register and reporting workflow, plus a review process for AI vendors and the models they rely on.

06

Incident and vendor process

An incident register and reporting workflow, plus a review process for AI vendors and the models they rely on.

Technologies we work with

Docker

Containers

Portable, reproducible packaging, so the same AI workload can move between EU cloud, private cloud and on-prem.

AWS

Cloud platform

Managed AI services and EU regions, including the AWS European Sovereign Cloud for workloads with stricter sovereignty needs.

AWS

Cloud platform

Managed AI services and EU regions, including the AWS European Sovereign Cloud for workloads with stricter sovereignty needs.

Microsoft Azure

Enterprise cloud

Azure AI services for enterprise estates, and Azure Local disconnected operations where systems have to run offline.

Cursor

AI code editor

Agentic coding in the editor. We add the repository rules, review gates and metrics that make it safe at team scale.

Cursor

AI code editor

Agentic coding in the editor. We add the repository rules, review gates and metrics that make it safe at team scale.

GitHub

Code and CI

Repositories, pull-request review and CI pipelines: the place where agent-written changes are tested and approved.

Google Cloud

Data and AI cloud

Data, analytics and Gemini models, used where the client's estate and data classification allow a managed platform.

Google Cloud

Data and AI cloud

Data, analytics and Gemini models, used where the client's estate and data classification allow a managed platform.

Hugging Face

Open-weight model hub

Hub for open-weight models and datasets. We evaluate, adapt and serve selected models inside private environments.

Kubernetes

Orchestration

The base layer for private model serving: GPU scheduling, scaling of inference and portable deployments.

Kubernetes

Orchestration

The base layer for private model serving: GPU scheduling, scaling of inference and portable deployments.

Book a readiness call.

Bring one process, product or function where AI should help. We will suggest the most practical next step.

Book a readiness call.

Bring one process, product or function where AI should help. We will suggest the most practical next step.