R&D COPILOT
ROLet’s talk

AI + engineering services

Rules for data and AI, enforced in the system

Governance documents tend to sit in a folder while the actual system does something else. We write the rules alongside the implementation and then enforce them in it. With your team we map each data source: who owns it, who may read it, how long it is kept and which suppliers process it. Then we decide what each model may receive, whether that is full records, redacted fields or nothing at all. Those decisions become configuration, such as retrieval filters, redaction steps, log retention settings and approval gates on actions with real consequences. The result is a set of records your legal, security and data protection colleagues can review, including the technical detail they usually have to chase. Legal interpretation stays with them, and they get an accurate picture of how the system behaves.

Start with your workflow. We agree the first deliverable, data boundaries, scope and budget before work begins.

What we can deliver

What your team receives.

  • Data and AI inventory with owners, access rules and retention periods
  • Model input rule for each source: allowed, redacted or excluded
  • Implemented controls: retrieval filters, redaction, log retention and approval gates
  • Map of suppliers and data transfers
  • Review pack for legal, security and data protection colleagues

Illustrative project example

AI & data governance

An internal assistant is about to be connected to the HR, finance and support systems. Before that happens, the team decides that support tickets can be searched in full, finance figures only by managers and HR files not at all. Names in tickets are masked before they reach an externally hosted model. Logs are kept for 30 days. Each decision is written down and set in the retrieval and logging configuration.

The final design follows your systems, documents and operating requirements.

Keep your team in control.

Data protection

Map approved data sources, access rules, retention and provider use before connecting AI to company information.

EU infrastructure options

Scope EU servers or self-hosting and disclose the processing location of model APIs, logs and backups.

Human approval

Agree where AI may suggest, where it may act and where a person must approve the next step.

Learn before you scope

AI Act · Cyber Resilience Act · EU regulation guides at regulations.md

For NIS2, assess sector, entity size, national transposition and supply-chain requirements. We support technical readiness; legal applicability needs specialist review.

Can we start small?

Yes. Start with one workflow, one team and an agreed outcome. We scope the pilot after learning about your data, systems and constraints.

Can our data stay in the EU?

We can scope EU-hosted or self-hosted options. The proposal identifies where each component processes and stores data, which providers are involved, and any transfer or remote-access implications. EU hosting alone does not establish compliance.

Do you help with the AI Act, NIS2 and CRA?

We help prepare inventories, data flows, security controls, documentation and remediation work for specialist review. Applicability depends on your role, sector, jurisdiction and product. We do not offer a blanket compliance certificate.