AI governance

We published our report on AI governance

Every assessment we deliver starts the same way: inventorying what AI the organisation actually uses. And it almost always ends with the same expression on the other side of the table — the one people make on discovering the usage was already there, only nobody had looked.

After repeating that exercise enough times, the pattern becomes sharp. The risks are the same, the regulatory framework is the same, and so is the sequence of work that actually functions. What changes from one organisation to another is the concrete distance to each control.

So we organised that pattern into a document and published it.

What is inside

The three layers of usage. The declared one —the project approved in committee—, the embedded one —AI features that arrived inside products already in use— and the one adopted by the teams, which is the hardest to see and concentrates the most risk. No policy works if it is written before looking at all three.

The full regulatory framework. ISO standards —42001, 23894, 42005, the 27000 family—, the NIST AI RMF, the European Regulation with its application calendar through 2028, the state of the regional picture, and all the current Uruguayan law that already covers these uses even without a specific AI statute: Law 18.331 and its article 16 on automated decisions, Law 18.381, the National AI Strategy and the regulatory sandboxes.

Seven families of risk, from data leakage to the fragility of LLM-based automation, with a matrix of fifteen risks scored by likelihood and impact.

What to verify before enabling a corporate assistant. The three modes the large providers offer under a single brand carry very different guarantees, and treating them as equivalent is a risk in itself. Also the oversharing problem: an integrated assistant shows each person everything they already have technical access to, whether or not they should.

Thirteen controls mapped to Annex A of ISO/IEC 42001, and a roadmap across three horizons: immediate containment, building the governance, and consolidation.

What it is not

It is not a sales document in disguise. Nor is it legal advice: wherever the regulatory framework moves fast —and in this field it moves very fast— we say so, with the cut-off date in plain sight.

And it is not meant to be read end to end in one sitting. Sections 5 to 8 —risks, controls and roadmap— are the ones most often used as working material in a committee.

How to get it

You can download it from the report page. We ask for your name, organisation and email, and the link arrives immediately as well as by email. We do not add that address to any mailing list and we do not share it with third parties: if we want to write to you again, we will ask first.


If after reading it you want to know how far your own organisation is, our ISO/IEC 42001 maturity assessment inventories actual AI usage and measures the gap in a few weeks.

your business partner

Protecting you today, innovating for tomorrow