In short
Nobody wants to teach this one. There is little payoff in it for the consultant and the legislation is genuinely dull.
That is exactly why it gets skipped, and it is one of the most important things a leadership team can get right before AI use spreads any further through the organisation.
Let me be straight about scope. I am not a qualified compliance officer and I will never pretend to be one in front of your team. What I do is risk assess your organisation, inventory those risks against the workflows your people actually use, work with you on a safe AI usage policy, cover Token Economics, meaning what these tools really cost to run once a team uses them properly, and give you factual, current information on UK GDPR and data protection.
That extends to the EU AI Act, which a lot of UK businesses have written off because of the first two letters. Major provisions come into force on 2 August, and plenty of firms who assumed it was somebody else's problem are going to find they are in scope.
We finish on hallucination, bias, citation failures and sycophancy, where the model simply agrees with whatever you put in front of it, and what governance realistically looks like at your size. That might mean NIST alignment. It might mean ISO 42001. It might mean neither.
My network includes the specialists needed to take this further. They get brought in when the work genuinely calls for it, never by default.
Your team is already using tools you have not sanctioned. That is a data breach waiting to happen.
The EU AI Act makes staff training mandatory. The UK will follow. Most organisations are not ready.
The EU AI Act's highest fines, up to €35m or 7% of global turnover, are reserved for prohibited AI practices. Everyday misuse sits far below that ceiling, but it is the same law, and knowing where your firm stands on it is the whole point of an assessment.
The ICO can fine up to £17.5m or 4% of global turnover for the most serious UK GDPR breaches. For most firms the real damage is smaller and closer to home: the client who leaves, the insurer who asks questions, the reputation that took years to build.
What it is
AI Risk & Compliance covers the whole picture in one engagement: the EU AI Act, UK GDPR, AI risk, bias and hallucinations, how to spot them and how to manage them. Everything we build aligns with the core principles of ISO 42001, the international standard for AI management systems, and the NIST AI Risk Management Framework, the American framework that has quietly become the global common language for AI risk.
It starts with a proper assessment. In almost every business we visit, AI use is bigger than the leadership thinks. The marketing manager has a ChatGPT habit. A fee earner found a summarising tool. Someone switched on Copilot because it appeared in the ribbon one morning. None of it was signed off, none of it is written down anywhere, and every bit of it carries your firm's name and your clients' data. The gap between what leadership believes and what is actually happening is the single biggest AI risk in most organisations. This work closes it.
First, some honesty
Plenty of consultants will happily tell you they can make you "compliant". Be careful with that word. ISO 42001 certification can only be issued by an accredited third-party auditor working to ISO/IEC 42006. The NIST framework is voluntary and has no certification mechanism at all: an organisation can be aligned with it, but nobody on earth can certify you against it.
So here is our position, in writing: Safer Haven aligns your organisation to the core principles of these frameworks. We do not issue certifications or compliance sign-off, because we are not a certification body. If your firm needs that formal final step, we introduce you to a qualified associate who takes you the rest of the way, with all the groundwork already done and paid for once, not twice.
Why it matters
An AI-related data breach does not stop at the ICO. For the most serious UK GDPR breaches, the ICO can fine up to £17.5m or 4% of global turnover. If the same incident touches the EU AI Act, a second regime applies on top: its highest fines reach €35m or 7% of global turnover for prohibited practices. Two regulators, two fine structures, one mistake.
Those are the ceilings, and most firms will never go near them. The real damage is usually smaller and closer to home: the client who quietly moves their files elsewhere, the insurer who asks questions at renewal you cannot answer, the reputation that took 20 years to build and one screenshot to dent. Compliance work is not really about avoiding the headline fine. It is about being able to answer the client-data question without flinching.
The programme
A practical programme covering the regulatory landscape, data protection obligations, and the real-world fines organisations face when they get AI wrong. It covers what the law actually requires, where the enforcement happens, and how to build systems that protect both your organisation and your people.
AI systems generate convincing lies. This session covers how hallucinations happen, where bias enters the system, and what fake citations look like in practice, along with the systems and processes you can put in place to catch these before they damage client relationships or expose your organisation to liability.
What GDPR actually requires when you use AI. ICO scope, enforcement, and the fines that have already landed on organisations that got this wrong. The practical question: if you are using consumer tools like ChatGPT, where is your data going, what happens to it, and does it break any laws? For enterprise tools, how to maintain data sovereignty and keep your information under your control.
Your proprietary workflows, client information and strategic thinking can all end up in an AI model's training data if you are not careful. This covers what you should and should not share with any AI tool, and how to structure your use so you keep what matters to you.
Scope, enforcement, and the fines. The specific articles UK companies need to be aware of now, and why this matters even if you are not in the EU.
DPA, DPIA, AUP, risk assessment and tool inventory: the documentation and processes that prove you have done your due diligence.
A clear picture of what governance and oversight should look like in your organisation, how alignment to ISO 42001 or NIST AI RMF standards is smart, and how we can support you beyond the training day.
The session ends with Q&A.
How it works
We do this with the stakeholders who know the business best. The practice manager who knows every process. The senior administrator everyone actually goes to with questions. The IT lead who knows what is installed. They know how work really gets done, which is often quite different from how the org chart says it gets done.
We sit with your key people and walk through how work actually flows: where data enters, who touches it, which tools are involved and where AI has quietly crept in. People tell us things in these sessions they had never thought to mention to anyone.
Every tool, every use, every data flow goes into a single inventory. Sanctioned and unsanctioned alike. This becomes a living document your firm owns, not a report that gathers dust in a drawer.
Each entry is mapped against the rules your firm answers to: UK GDPR, your sector regulator's expectations, and the EU AI Act's risk categories, including the Article 4 duty on staff AI literacy. You see exactly which obligations each use touches.
Then we build what the findings call for: an AI policy written in your firm's voice, an AI register with named accountability, approval routes so "can I use this?" has a fast clear answer, and a review cycle that keeps pace as the rules and the tools change.
Regulated sectors
For law firms and conveyancers, the work maps against SRA obligations and COLP accountability. For FCA-regulated firms, it leads with the questions compliance is already asking: which tools touch client data, what has gone into them, and what record exists if anyone asks. For everyone, the ICO and UK GDPR set the floor.
Free practitioner briefings
Written for the person doing the work, not for a technology audience. No charge and nothing to fill in.
The outcome
You know exactly where you stand, the policies and guardrails are in place, and when a client asks how their data is handled when your team uses AI, you have the answer in writing.
Where this fits
New to AI? Start with AI Enablement and get your team using the tools well before you formalise the rules around them.
Policy on paper is not enough if your people do not trust the tools. See The Human Risk of AI for the human side: confidence, over-trust and burnout.
Free · No sign-up · Instant
Compliance is easier to justify to a board when you can show the maths. The calculator works out the exposure you avoid alongside the hours your team gets back, using your figures rather than ours.
Open the ROI calculatorNothing is stored or sent anywhere. The numbers stay on your screen.
Pricing
Priced on the work, never per head. The free intro call tells us which route fits your firm.
The assessment, the regulatory mapping and the findings in plain English, with a prioritised action list your firm owns.
Support from A to Z: your acceptable use policy, data processing agreements with your AI vendors, data protection impact assessments when new tools arrive, and liaising with your IT team on the correct licence tiers. Availability is capped so response times hold up.
Take more than one pillar and the price per programme comes down.
Compliance pairs naturally with AI Enablement: the rules and the skills, built together. Adding the third covers what AI is doing to the people using it.
One pillar A single Full Programme.
Two pillars £1,345 per programme.
The Full Training Programme £1,250 per programme. Enablement, Risk & Compliance, and The Human Risk of AI.
Bundle pricing applies to Full Programmes. Workshops and the monthly compliance retainer are priced separately.
Before you book a call
Five minutes of honesty now saves us both a wasted hour later.
Free · 5 minutes · Instant result
Eighteen questions across risk, people, governance and cybersecurity. Answer honestly and you get an instant AI readiness score, the specific gaps most likely to cost you, and clear next steps built around your answers.
Start the free risk checkNo obligation. Seen only by us, never shared.
Thirty minutes, free, and you will know exactly where your gaps are and what closing them involves.
Book a free intro call