Most organisations cannot answer three basic questions about their own AI: which systems are actually in use, what each one decides, and who signed it off. Regulation has been turning those into questions you have to answer on request — and the answers take longer to assemble than anyone expects.
AGI Software Solutions provides AI governance and compliance services: building an inventory of the AI systems an organisation genuinely runs, classifying each against EU AI Act risk tiers, mapping controls onto ISO/IEC 42001 and the NIST AI Risk Management Framework, and producing the model documentation, evaluation records and human-oversight design an auditor expects to see. Engagements typically run $12k–$25k for a readiness assessment and $30k–$70k for a full governance programme. We are engineers, not lawyers, and we scope that boundary explicitly.
An AI policy nobody can evidence is worse than having none: it sets an expectation you are then measured against. The deliverable that actually helps is an inventory, a risk classification, and a paper trail per system.
Almost every organisation has more AI in use than the register shows, because individual teams adopted tools on their own cards. Discovery is where every programme has to start.
Each system classified against the Act’s tiers, so effort concentrates on the handful that genuinely carry heavy obligations instead of being spread thinly across everything.
Model cards, data lineage, evaluation records, incident logs and human-oversight design — produced as a by-product of how systems get built, not reconstructed under deadline.
Written by people who build these systems, so the controls fit how software actually ships rather than becoming a form that gets filled in afterwards.
AI governance is the work of knowing which AI systems your organisation uses, what each one decides, what could go wrong, who is accountable — and being able to evidence all of it. Under the EU AI Act the obligations scale with risk: most systems carry transparency duties, while systems used in areas such as employment, credit, education, insurance or essential services carry substantially heavier requirements around data quality, documentation, logging and human oversight.
Two standards do most of the practical work. ISO/IEC 42001 gives you a certifiable management system for AI, structured much like ISO 27001. The NIST AI Risk Management Framework gives you a control vocabulary that maps cleanly onto it. Neither replaces legal analysis, but together they turn “be responsible with AI” into a checklist an engineering team can actually run.
Nearly everyone should start on the left, including organisations convinced they already know what they run.
| Readiness assessment | Governance programme | |
|---|---|---|
| Question it answers | “Where do we actually stand?” | “How do we stay there?” |
| Output | Inventory, risk classification, gap list | Policy, controls, documentation, training |
| Duration | 3–5 weeks | 3–6 months |
| Typical cost | $12k–$25k | $30k–$70k |
| Leads to | A prioritised remediation plan | ISO 42001 readiness and audit evidence |
| Start here when | You are not certain what you are running | You know, and now have to prove it |
The same process across every AI Development project, scaled to the size of the problem.
We work out what the system actually has to do, what data exists, and what happens today when it goes wrong.
Architecture, model choice, integration points and failure handling, defined before any of it gets built.
Connecting to the systems that hold your data, with security and permission boundaries handled properly.
The system takes on real work, in the workflows your team already uses rather than beside them.
Tuned against real usage and measured with evals, because how people use a system is never quite how it was designed.
The patterns we see deliver, across startups, SMEs and enterprise teams.
A pass across every AI system in use, classified by risk tier, with obligations and gaps listed per system and a remediation order that reflects real exposure.
The management system, policies and evidence trail needed to enter certification without discovering the gaps during the audit itself.
Assessing the AI inside software you buy, since obligations follow the use of a system rather than who wrote it.
Documentation, evaluation and oversight designed into a project now, which costs a fraction of reconstructing it a year later from commit history.
A streaming voice pipeline with real barge-in, running thousands of live calls a day in 12 languages.
One inbox across web chat, email, WhatsApp and Facebook, with AI replies trained on past resolutions.
Support chatbot, live SEO analyser and a vector recommendation engine, all sharing one retrieval layer.
“We needed a voice agent that could actually qualify leads, not a chatbot pretending to be one. The team shipped a sub-700ms pipeline in 6 weeks. It now handles 5k calls a day.”
“What sold us was their willingness to put AI engineers and product designers on the same call. We got working prototypes by week two and a production rollout in three months.”
“AGI designed a CRM system tailored to our client management process. It is intuitive, reliable, and has centralized all our communication and history in one dashboard. This has greatly improved client retention.”
Often yes. It reaches providers and deployers outside the EU where the system’s output is used within the EU, so a platform operated from India, Australia or the United States can be in scope because of who its results affect. That catches a lot of organisations by surprise, and it is one of the first things a readiness assessment settles.
A readiness assessment — inventory, risk classification and gap list across your AI estate — runs $12k–$25k depending on how many systems and business units are involved. A full programme, taking you from that to documented controls and audit evidence, runs $30k–$70k over three to six months.
Lighter than you fear, but not nothing. Off-the-shelf assistants still raise questions about transparency, what data staff paste into them, and whether people are competent to judge the output. They are also precisely the systems that never make it onto a register, which is what makes the inventory worth doing even at this scale.
It is worth implementing regardless. Certification becomes worth it when customers or tender processes start asking, which is happening earlier in regulated sectors than elsewhere. Our usual advice is to implement first, then decide on certification once you can see how often it is actually requested.
The classification step usually speeds them up. Once it is established that most systems carry light obligations, teams can stop treating every project as though it were high-risk, and the heavy process concentrates on the few that deserve it. Uncertainty is what slows organisations down, not the rules.
No. We build the inventory, the risk classification, the controls, the documentation and the evaluation evidence. Where a question is genuinely a legal judgement, we scope it clearly and you take it to counsel. Anyone offering you AI Act compliance without drawing that line is overselling what they can deliver.
Tell us what the system would need to do and what it is replacing. We will tell you whether it is worth building and roughly what it takes.