Skip to content
McCullochRegulatory Compliance
All practices

Artificial Intelligence

Practical, defensible AI governance across the EU, UK, and US, from a first map of where AI is used through risk classification, controls, and documentation, to independent assurance and EU AI Act readiness.

EU AI ActISO/IEC 42001NIST AI RMFLife SciencesTechnology & AI

Governing framework

  • EU AI Act

    Reg (EU) 2024/1689 · risk-tiered · GPAI duties

    Phasing in
  • ISO/IEC 42001

    AI management system · certifiable

    In effect
  • NIST AI RMF

    Govern · Map · Measure · Manage

    Voluntary
  • UK & EU GDPR

    DPIAs · Art. 22 automated decisions

    In effect
Aligned toISO/IEC 23894OECD AI PrinciplesFDA GMLPColorado AI ActISO/IEC 42001NIST AI RMF

What we do

Adopting AI is the easy part. Proving it is governed is the job.

Boards, regulators, and customers increasingly ask the same question: can you show that your AI is lawful, safe, and well governed?

We turn a fast moving, fragmented set of rules into controls your teams can actually run. From a first inventory of where AI is used, through risk classification and proportionate controls, to documentation and independent assurance, we cover the full path end to end.

Our work is grounded in regulatory compliance and risk. We give you a clear view of which obligations apply to each system, what good looks like, and the shortest credible path to meeting it.

The AI governance lifecycle

One governance system, end to end.

Inventory, classification, risk assessment, controls, and assurance, scaled to the risk of each system and the stage you are at.

01 / Map

Inventory & roles

  • AI use-case register
  • Provider or deployer role
  • Triage for new use cases

Govern (NIST)

02 / Classify

Risk classification

  • AI Act risk tiers
  • Prohibited-use screen
  • GPAI obligations

EU AI Act

03 / Assess

Risk & impact

  • Safety & fundamental rights
  • Bias, robustness, security
  • DPIA / FRIA

ISO/IEC 23894

04 / Control

Controls & oversight

  • Data governance
  • Human oversight
  • Technical documentation

AI Act Annex IV

05 / Assure

Audit & monitor

  • Independent AI audit
  • Post-market monitoring
  • Incident reporting

ISO/IEC 42001

Three approaches, one standard of rigour

EU, US & UK, mapped to the controlling regime.

The rules diverge sharply across markets, from a comprehensive statute in the EU to a framework-and-sector model in the US and a principles-based approach in the UK. We navigate each on its own terms and keep your programme coherent across all three.

AI Act · 2024/1689

European Union

The EU AI Act is the first comprehensive AI law, applying a risk-tiered set of obligations to providers and deployers, with separate duties for General-Purpose AI. Obligations phase in over several years.

Role & risk classificationArt. 6 · Annex III

Determine provider or deployer status and classify each system across the prohibited, high-risk, limited, and minimal-risk tiers.

High-risk conformityArt. 8-15

Risk-management system, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness, and cybersecurity.

General-Purpose AIArt. 53-55

Documentation, a training-data and copyright policy, and systemic-risk duties for general-purpose and frontier models.

Conformity & registrationArt. 43 · 49

Conformity-assessment route, EU declaration of conformity, CE marking where applicable, and EU database registration.

Transparency & oversightArt. 50

User-facing disclosure for chatbots and AI-generated content, and human-oversight design.

Post-market & incidentsArt. 72 · 73

Post-market monitoring plan and serious-incident reporting once systems are in use.

Who we help

Builders, adopters, and regulated innovators.

Whether you build AI, deploy someone else’s, or put it to work in a regulated setting, we meet you where you are.

01

AI builders

Developers and providers shipping AI features or models who need a defensible compliance position.

02

AI adopters

Organisations deploying third-party or generative AI who must govern use, vendors, and risk.

03

Regulated innovators

Life-sciences and health-tech teams putting AI into clinical, device, or quality-critical settings.

Practical · Proportionate · Defensible

Responsible AI as an advantage, not a brake.

Done well, AI governance shortens security and procurement reviews, reassures boards and investors, and lets you move faster because the guardrails are clear. We combine hands-on regulatory experience with a compliance-first mindset, so your position holds up when it is tested.

Mapped

Every control traced to its rule

AI Act article, ISO clause, or NIST function: advice with a source, never opinion alone.

Proportionate

Sized to your risk

Light-touch where risk is low, rigorous where it is high. No box-ticking for its own sake.

Defensible

Built for the question you will be asked

Documentation and assurance that hold up with a regulator, a customer, or your board.

Specialists in this area

Putting AI to work, or proving the AI you already run is governed?

Tell us where you are, and we will map the shortest credible path to a compliant, defensible position.