The AI Act is not prepared after deployment. It is prepared from the design stage.
KDPO supports the compliance of Data & AI projects from the pre-project stage — where governance and data protection trade-offs are made, before the system goes into production. A practice built on multi-division data governance environments, not on regulatory watch alone.
Support for Data & AI projects — support for business and IT teams from the pre-project stage: scoping compliance issues, identifying trade-off points, support through to deployment
Privacy by design & security by design applied to AI — building in requirements from the design stage, compliance pack from the specification stage, review of access to training data
AI Act compliance — scoping obligations by the system's risk level, technical and governance documentation, prioritised compliance plan
Governance of AI use cases — mapping of use cases, access review, responsible use and access framework, ongoing monitoring indicators
Awareness and training — workshops for business, IT and management teams, adapted to each audience's maturity level
How this pillar connects
AI compliance is not a standalone specialty. It rests on governance (a model is only as sound as the data lineage feeding it), on privacy (training data and outputs carry RGPD obligations), and on cybersecurity (a model is an asset to isolate and monitor). KDPO governs AI as one facet of the data system — not as a detached technical audit.
What you get
- A qualification of your AI systems by AI Act risk level
- A prioritised compliance plan, technical and governance documentation
- A map of AI use cases and access rights to training data
- Ongoing compliance monitoring indicators
Why now
AI projects are launching today with obligations that are not yet stabilised. Waiting for full regulatory clarity before acting risks having to rebuild afterwards. KDPO scopes what is already required and anticipates what is coming.