Governance is the line item that unblocks the rest of your AI budget.
Your buyer now gates the purchase on kill switches and audit trails. The EU AI Office has held enforcement powers since 2 August 2026. Both of them want the same thing, which is evidence. We produce it in one to three weeks, at a published price, and we are precise about what we can and cannot attest to.
Eight engagements, $2,500 to $8,900, every price on this page. No scoping fee in front of any of them.
Analyst figures, published by Gartner and Forrester. They are market context, not our results. Numbers describing our own work appear elsewhere on this site with a source attached to each one.
Three separate people started asking for the same evidence in 2026.
The regulator, the enterprise buyer and your own CFO converged on one question this year: show me what this system does, on what basis, and who can stop it. None of them will accept a demo as the answer.
- 01
The regulator has powers now, not a timetable
EU AI Act Article 50 transparency obligations have been in force since 2 August 2026. From that same date the AI Office and member-state authorities can request technical documentation, evaluate general-purpose AI models, require corrective measures and issue fines. Systems already on the market before 2 August 2026 have until 2 December 2026 for Article 50(2).
- 02
The buyer has a checklist now
Enterprise procurement asks for six things by name: kill switches, evidentiary audit trails, human-in-the-loop boundaries, model change control, outcome-based SLAs, and an ISO/IEC 42001 or SOC 2 attestation. They arrive as gating conditions, not preferences. Missing one does not lose the deal loudly; it stalls it in diligence.
- 03
The CFO wants evidence before the spend
A quarter of planned enterprise AI spend for 2026 is being deferred into 2027, because CFOs want ROI evidence and security teams flag governance gaps. Forrester expects 60% of the Fortune 100 to appoint a head of AI governance during 2026, so the person whose job is to ask now exists and has a title.
Six conditions, and the engagement that answers each.
These are the six things enterprise buyers now name in AI procurement. They are not a maturity model to grow into; each one is a yes or no question asked before signature. Below each condition is the question as it is actually asked, and the work that produces an answer.
- 01
Kill switches
Show me how a human stops this system mid-task, and who is allowed to.
Agent governance review (T2-08). We map every action the agent can take, the blast radius of one compromised step, and where the stop control is missing rather than merely undocumented.
- 02
Evidentiary audit trails
Reconstruct for me what the system did on 14 March, and on what basis.
Agent governance review (T2-08) and EU AI Act readiness assessment (T2-01). We check whether the trail records the input, the retrieved context, the decision and the human override, or only the final output.
- 03
Human-in-the-loop boundaries
Which decisions can this system take alone, and who signed off on that line?
Agent governance review (T2-08). The boundary comes back written down as an authority matrix, rather than living in the head of the engineer who built it.
- 04
Model change control
Your provider updated the model last night. What is your process?
Agent governance review (T2-08) and ISO/IEC 42001 gap assessment (T2-05). Version pinning, a change log with an owner, and a regression gate that runs before a swap reaches production.
- 05
Outcome-based SLAs
Put a number on accuracy and put that number in the contract.
Hallucination and grounding audit (T2-03). You cannot sign an SLA against a metric nobody has measured. We build the evaluation set from your own corpus, measure groundedness against it, and hand back the baseline the SLA has to be written around.
- 06
ISO/IEC 42001 or SOC 2 attestation
Send me the certificate, or tell me your date.
ISO/IEC 42001 gap assessment (T2-05), NIST AI RMF alignment review (T2-06) and attestation readiness scoping (T2-09). We produce the control design and the evidence. The certificate is issued by an accredited certification body and the SOC 2 report by a licensed CPA firm, never by us.
The four frameworks we work against
One control set, read four ways. The EU AI Act carries the legal obligation, ISO/IEC 42001 supplies the management system, NIST AI RMF supplies the risk method, and data protection law sits under all three. Most vendors present the middle two as a choice. They are complementary, and published crosswalks exist.
Eight assessments. Every price published, every duration fixed.
Fixed scope and a slot on a calendar. A deposit reserves the week and the balance is invoiced against delivery. If your problem is not one of these, we will say so on the first call rather than three invoices in.
- T2-011 week
EU AI Act readiness assessment
An inventory of the AI systems in scope, a written classification for each with the reasoning recorded, and the transparency gaps ranked by exposure against the 2 December 2026 date.
Read the Article 50 briefing first
$4,900$900 depositBook EU AI Act readiness assessment, $4,900 - T2-022 weeks
AI security assessment
Prompt injection, including injection arriving through retrieved documents. Data exfiltration paths. Agent authority and what one compromised step can reach.
$6,500$1,200 depositBook AI security assessment, $6,500 - T2-032 weeks
Hallucination and grounding audit
An evaluation set built from your own corpus, groundedness measured against it, and the failure modes returned with a rate attached instead of an impression.
$5,900$1,000 depositBook Hallucination and grounding audit, $5,900 - T2-043 days
Vendor AI assessment
We assess a supplier you are about to buy from, and tell you which of their answers should worry you. Prepaid because three days leaves no room for an invoice cycle.
$2,500Paid in fullBook Vendor AI assessment, $2,500 - T2-052 to 3 weeks
ISO/IEC 42001 gap assessment
Your current position against the AI management system standard, control by control, with the evidence an external auditor will ask for and the work needed to produce it.
$8,900$1,500 depositBook ISO/IEC 42001 gap assessment, $8,900 - T2-062 weeks
NIST AI RMF alignment review
Govern, Map, Measure, Manage applied to the systems you actually run. NIST supplies the risk method and ISO/IEC 42001 supplies the management system; they are complementary, not a choice.
$7,500$1,400 depositBook NIST AI RMF alignment review, $7,500 - T2-082 weeks
Agent governance review
Kill switches, audit trails, human-in-the-loop boundaries and model change control. Four of the six conditions above, answered in the vocabulary your buyer used when they asked.
$7,900$1,400 depositBook Agent governance review, $7,900 - T2-091 week
Attestation readiness scoping
What SOC 2 or ISO/IEC 42001 will actually take: the scope, the observation window, the control gaps, the internal cost and the realistic date. Buy this before committing to either.
$3,900$900 depositBook Attestation readiness scoping, $3,900
Not sure which one? Describe the system in two sentences and we will name the right assessment, including when the answer is none of them.
What we hold, and what we do not.
An assurance firm that overstates its own credentials has answered the only question that mattered. The list on the right costs us deals with buyers who wanted a badge, and it is the reason the ones who read carefully call back.
What we hold
- OWASP Top 10 and MITRE ATT&CK as working method
- EC-Council CEH
- ISO/IEC 27001 trained
- VAPT across 50+ government web assets
- Critical CVE exposure reduced 65% across that estate
Offensive security is in-house rather than subcontracted, which is why the security review that stalls most AI projects is where we start instead of where we finish.
What we do not hold
- SOC 2 Type II: not yet held
- We do not have an attestation report. A SOC 2 report is issued by a licensed CPA firm after a defined observation window and it names the auditor, which is exactly why it cannot be self-asserted. We publish our actual posture instead.
- ISO/IEC 42001: we cannot certify you, or ourselves
- Certification requires an external audit by an accredited certification body. We are not one. We sell gap assessment, readiness, control design and evidence preparation for the auditor who does issue it. Any firm offering to certify you against ISO/IEC 42001 itself is telling you something useful about the firm.
- We do not give legal advice
- We describe obligations, gaps and the evidence that closes them. Anything with legal effect should be reviewed by counsel qualified in the relevant jurisdiction, and our reports say so on the page where it matters.
- We do not guarantee compliance
- No consultancy can, and a firm that offers the guarantee has either misread the regulation or is relying on you not reading it.
The full posture, including where data lives and what we will sign, is on our security page.
Four commitments that apply to every engagement on this page.
Published price, fixed scope, fixed duration
Every engagement above lists its price, its deposit and its length. There is no scoping fee and no discovery retainer in front of it.
A deposit reserves the slot
The deposit holds the week on the calendar. The balance is invoiced against delivery, not before it.
Written for two readers
Findings go to your engineers with enough detail to act on, and to your board with enough context to decide on. One engagement, both documents.
The section most reports leave out
Every deliverable ends with an explicit list of the things you do not need us for, wherever that is true. It costs us follow-on revenue and it is the reason these convert.
Name the system a buyer or a regulator will ask about first.
Thirty minutes with the engineer who would run the assessment. We will tell you which engagement fits, what it will find, and where you can do the work yourself.
Assurance engagements $2,500 to $8,900, fixed price · Typical reply within one business day