Classification first
Most of the cost sits in one early decision: which of your systems are in scope, and at what risk tier. Teams that skip a rigorous classification pass either over-engineer everything or discover a high-risk use case late, when it is expensive.
Classification is not a legal exercise alone. It requires an accurate map of what each system actually decides in production, which is often different from what the documentation claims.
Four obligations that become engineering
Record keeping becomes structured, tamper-evident logging of inputs, decisions and actions with retention that survives an audit. Human oversight becomes an interrupt path with real authority, plus proof it was available. Transparency becomes user-facing disclosure at the point of the decision. Accuracy and robustness monitoring becomes live evaluation with alerting, not a pre-launch report.
Each of these is a ticket, not a paragraph. Scoped properly, they are also reusable across every system you run.
Sequencing that does not stall the roadmap
The pattern that works: instrument first so you can see what your systems do, classify against real behaviour, then close gaps in order of blast radius. Instrumentation is useful whether or not the deadline moves, which makes it the safest first spend.
We run this sequence with organisations in the EU, the UK and the Gulf, and we build the instrumentation rather than specifying it for someone else to build.
“Human oversight is not a person with an inbox. It is a system that can be stopped, and a record showing it could have been.”
Continue
- The gap between intelligence and action6 min
- What 'autonomy with evidence' looks like in practice7 min
- How to evaluate an AI system you intend to let act5 min
- AI governance in London: what boards are actually asking for5 min
- How to choose an ethical tech consultancy without buying theatre6 min
- How we work inside a transformation programme5 min
- Running one AI governance model across the Gulf and Europe6 min