Skip to content
Comonad

Home / Services / AI governance

Enterprise AI governance consultancy

Comonad helps UK organisations govern AI that is in production or about to be. We classify each AI system, state what it may and may not do, and write the controls your engineers can implement and your risk team can evidence: evaluation, access control, audit trails, human oversight, and model and vendor risk. Controls are mapped to the EU AI Act, UK regulatory guidance, ISO/IEC 42001 and the NIST AI RMF where they apply.

The governance is written by an architect who builds AI systems, so each control names an owner, a test and the record it produces.

Tell us which AI system needs governing and which frameworks your risk team works to.

Book an introductory call

What is AI governance in practice?

AI governance is the set of decisions and controls that say what an AI system is allowed to do, how you know it is doing that, and who is accountable when it does not. In production that means evaluation, access control, audit trails, human oversight and a tested way to stop the feature.

We work through four stages:

  1. Inventory and classification: a list of AI systems, what each does, who it affects and how it is classified. Output: a classification record per system.
  2. Controls: what each system must and must not do, and how that is enforced. Output: a written control set.
  3. Evidence: how you show each control is working. Output: an evaluation plan and a list of the logs and records each control produces.
  4. Review: whether the running system matches the control set. Output: a review with the gaps listed.

Who it is for

  • Leaders who already have, or are about to ship, an AI feature in a system customers depend on.
  • Risk, legal and compliance teams asked to map the EU AI Act, UK regulatory guidance, ISO/IEC 42001 or the NIST AI RMF onto an actual system.
  • Engineering and security leads who need a written control set they can implement.

Our founder's background is regulated UK energy-market software: almost seven years as co-founder and CTO of Cloud KB. Read his profile.

What an engagement covers

AI system inventory and classification

We record what each model does, who is affected, and what a failure costs. Where the EU AI Act applies, we set out your role for each system (for example provider or deployer) and its risk category, so that the obligations that follow are clear.

Evaluation and reliability

We define how each system is evaluated before and after release, and when it must refuse, escalate or hand over to a person. Human oversight is designed with the people who will do it: who can intervene, how, and with what information in front of them.

Access control, audit trails and retention

We set who may invoke each model and with what data, what is logged, how long records are kept, and how they are reviewed. The aim is a trail that an auditor or incident reviewer can follow without asking the engineering team to reconstruct it.

Model and vendor risk

We document what you send to each model provider, what the provider retains, and how a change of model or provider is assessed and approved. Contract terms and data-processing terms are part of this review; legal interpretation stays with your counsel.

Governing AI agents

Agents act as well as answer, so governance has to cover permissions for tool calls, delegated authority, approval steps for high-impact actions, an audit of every action and a tested way to stop the agent. See how to govern AI agents in production.

Framework mapping

We map each control to the EU AI Act, UK regulatory guidance, ISO/IEC 42001 and the NIST AI RMF, only where they apply to your systems. One control set can serve several frameworks, which avoids running parallel compliance projects.

The control set and a check against the running system

The main output is a written control set that your engineering team can implement, followed by a review of whether the live system matches it. Where it does not, the gaps are listed with owners.

The frameworks, briefly

Last reviewed: 27 September 2026

EU AI Act

The EU AI Act is Regulation (EU) 2024/1689. It applies to UK organisations that place AI systems or general-purpose AI models on the EU market, put AI systems into service in the EU, or provide or deploy AI systems whose output is used in the EU. Prohibited practices have applied since 2 February 2025, general-purpose AI model obligations since 2 August 2025, and most other provisions, including the Article 50 transparency duties, from 2 August 2026. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) set the high-risk dates at 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Does the EU AI Act apply to UK companies?

UK regulatory guidance

The UK has no AI-specific legislation covering AI as a technology. AI is regulated where it is used, through existing law and sector regulators. Relevant sources include the ICO's guidance on AI and data protection, sector guidance such as Ofgem's "Ethical AI use in the energy sector" (updated May 2026), and the Department for Science, Innovation and Technology's AI Risk Management Toolkit (September 2026), written for government teams but usable as a starting point elsewhere.

ISO/IEC 42001

ISO/IEC 42001:2023 is an international management-system standard for AI, published in December 2023. It sets requirements for establishing, implementing, maintaining and continually improving an AI management system: the policies, roles, risk processes and controls an organisation uses to govern its AI. Mapping your controls to ISO/IEC 42001 is not certification. Certification is carried out by accredited certification bodies, which UKAS accredits in the UK. We help you prepare; we do not certify.

NIST AI RMF

The NIST AI Risk Management Framework (AI RMF 1.0, January 2023) is a voluntary framework from the US National Institute of Standards and Technology. It is organised around four functions: Govern, Map, Measure and Manage. NIST has also published a Generative AI Profile (NIST AI 600-1, July 2024). We use the AI RMF as a shared vocabulary for risk treatment and monitoring, often alongside ISO/IEC 42001.

How an engagement works

  1. We start from the system you have, or the one you are about to release.
  2. We build the inventory and classify each system.
  3. We write the control set and the evaluation plan.
  4. We review the running system against the control set.
  5. If you need the controls built, that is scoped separately as AI engineering.

Outputs are documents and decisions your teams can act on: classifications, control lists and evaluation plans. Legal sign-off stays with your counsel.

Who does the work

Engagements are led and delivered by Alex Vakhitov, founder of Comonad Limited. He is an AI and software architect who was co-founder and CTO of Cloud KB, UK energy-market software, from August 2015 to March 2022. Read Alex Vakhitov's profile.

Questions about AI governance

Does the EU AI Act apply to UK companies?

Yes, in many cases. The EU AI Act applies to UK organisations that place AI systems or general-purpose AI models on the EU market, put AI systems into service in the EU, or provide or deploy AI systems whose output is used in the EU (Article 2). Being established outside the EU does not take an organisation out of scope; the activity decides it.

When do the EU AI Act high-risk rules apply?

After the Digital Omnibus on AI (Regulation (EU) 2026/1744), obligations for high-risk AI systems apply from 2 December 2027 for systems listed in Annex III, and from 2 August 2028 for AI in products covered by the EU legislation in Annex I. Prohibited practices, general-purpose AI model obligations and most transparency duties already apply, on earlier dates.

Do you implement the EU AI Act for us?

We map your AI systems to the EU AI Act obligations that apply to them and write the controls you still need, with the evidence each control should produce. We can also review whether the running system matches that control set. Legal sign-off stays with your counsel, and building the controls is a separate AI engineering engagement if you want us to do it.

Can Comonad certify us to ISO/IEC 42001?

No. Certification to ISO/IEC 42001 is carried out by accredited certification bodies; in the UK, UKAS accredits them. We help you prepare: scoping the AI management system, mapping controls to the systems you actually run, and closing gaps before the certification audit. Mapping to ISO/IEC 42001 on its own is not certification.

How do ISO/IEC 42001 and the NIST AI RMF fit together?

ISO/IEC 42001 is a certifiable management-system standard for AI. The NIST AI RMF is a voluntary US framework organised around four functions: Govern, Map, Measure and Manage. They overlap well. We use ISO/IEC 42001 to structure roles, risk treatment and monitoring, and the NIST AI RMF as a shared vocabulary for risk, applying each only where it is relevant.

How do you govern AI agents?

We limit which tools an agent may call and with what authority, record every action in an audit trail, require human approval for defined high-impact actions, evaluate behaviour before and after release, and keep a tested way to stop the agent. Each control has a named owner and produces a record your risk team can review. Our guide covers the control model in detail.

Is AI governance only for regulated industries?

No. Any organisation putting a model in front of customers or staff has a reliability and security problem to manage. Regulation adds documentation and specific obligations, but the need for evaluation, access control and audit trails exists either way. A control set written for a real system is useful whether or not a regulator ever asks to see it.

Can you also build the controls?

Yes, as a follow-on AI engineering engagement. Governance work ends at the written control set and a review of the running system unless we agree implementation separately. Keeping the two apart means the advice can be reviewed independently of the build, and your own team can implement the controls if you prefer.

What do we get at the end of an AI governance engagement?

You receive a classification record for each AI system in scope, a written control set mapped to the frameworks that apply, an evaluation plan, and a review of whether the running system matches the control set, with gaps listed and owners named. These are documents and decisions your engineering, risk and compliance teams can act on directly.

Book an introductory call

Tell us which AI system needs governing and which frameworks your risk team works to.

Book an introductory call