Build the policy scaffolding that makes every downstream agent defensible.
"This stage produces the AI Policy, the AI Committee charter, the model inventory, and the vendor register — the four documents a regulator will ask for first. Everything else rests on these."
Draft AI Acceptable Use Policy
Organisation-wide policy covering permitted use cases, prohibited content, incident reporting.
Establish AI Committee charter
Define membership, decision rights, escalation path, meeting cadence for the cross-functional body.
Seed vendor & model register
Catalogue every AI vendor touching your data with risk tier, DPA status, sub-processor chain.
Publish model inventory
Every model in production: owner, purpose, training data summary, last evaluation date, risk tier.
Risk taxonomy & impact classification
Map EU AI Act risk categories (prohibited, high-risk, limited, minimal) onto your use-case portfolio.
Define incident response runbook
Who gets paged when an agent misbehaves, what gets killed, how customers are notified, how we learn.