The AI Act is not prepared after deployment. It is prepared from the design stage.

KDPO supports the compliance of Data & AI projects from the pre-project stage — where governance and data protection trade-offs are made, before the system goes into production. A practice built on multi-division data governance environments, not on regulatory watch alone.

Support for Data & AI projects — support for business and IT teams from the pre-project stage: scoping compliance issues, identifying trade-off points, support through to deployment

Privacy by design & security by design applied to AI — building in requirements from the design stage, compliance pack from the specification stage, review of access to training data

AI Act compliance — scoping obligations by the system's risk level, technical and governance documentation, prioritised compliance plan

Governance of AI use cases — mapping of use cases, access review, responsible use and access framework, ongoing monitoring indicators

Awareness and training — workshops for business, IT and management teams, adapted to each audience's maturity level

How this pillar connects

AI compliance is not a standalone specialty. It rests on governance (a model is only as sound as the data lineage feeding it), on privacy (training data and outputs carry RGPD obligations), and on cybersecurity (a model is an asset to isolate and monitor). KDPO governs AI as one facet of the data system — not as a detached technical audit.

What you get

  • A qualification of your AI systems by AI Act risk level
  • A prioritised compliance plan, technical and governance documentation
  • A map of AI use cases and access rights to training data
  • Ongoing compliance monitoring indicators

Why now

AI projects are launching today with obligations that are not yet stabilised. Waiting for full regulatory clarity before acting risks having to rebuild afterwards. KDPO scopes what is already required and anticipates what is coming.