Robotic arms working on an automated production line

Services

AI & Automation

We do not run an AI practice that sells AI. That arrangement guarantees the answer before anyone has established the question, and it is the single most reliable predictor of an expensive programme that moves no number. AI shows up inside our other work, applied where it earns its place — and we say so when it doesn’t.

AI readiness and use-case identification

Only 20% of organisations have a mature governance model for AI agents, while 55% describe their own AI use as a chaotic free-for-all. That gap is the actual state of the market in 2026, and it is not primarily a technology gap.

A readiness assessment worth paying for does two things. It establishes where you genuinely stand on data quality, integration, infrastructure and governance — typically two to six weeks of work for a mid-sized organisation. And it builds a single inventory of every AI use case already running in the business, which almost always includes more than leadership expects: internally built models, third-party tools, AI embedded inside SaaS products you already licence, and informal employee usage that nobody has been asked about.

Use-case identification then prioritises against measurable value rather than visibility. The output is deliberately blunt — a ranked list, with the ones that should not proceed marked as such and the reason recorded.

The five questions we apply before any AI investment

  • What is the decision? Name the transaction, not the function. “Customer service” is not a problem; a 38% repeat-contact rate is.
  • What is it costing today? Instrumented, not estimated. If you cannot measure the baseline you cannot prove the benefit.
  • What number has to move? One primary metric, with a target and a date.
  • Why has it not been fixed already? If process redesign, better data or a policy change solves it, AI is the expensive answer to a cheap problem.
  • Who is accountable when it is wrong? A named human, a working override route, and an explanation a regulator would accept.

AI governance and responsible AI

Adoption has outpaced governance almost everywhere. The majority of AI tools in mid-market businesses were deployed without formal risk review, and fewer than half of organisations actively monitor their systems for accuracy or drift.

The governance we build is deliberately minimal — the leanest set of policies that delivers transparency, risk control and defensibility without becoming an obstacle nobody follows. In practice: a named owner for every AI system in production, human oversight defined per use case rather than as a blanket policy, classification against the frameworks that actually apply to you, and a working process for reviewing decisions that cause harm or attract scrutiny.

Governance without ownership is governance in name only — and both UK regulators and the EU AI Act require a demonstrable chain of responsibility, not a document.

For businesses with EU market exposure, the EU AI Act’s high-risk obligations take full effect in August 2026, and it applies to any system placed on the EU market regardless of where the developer is incorporated. In the UK the picture is different in form but not in demand: no single AI-specific law, but Consumer Duty, UK GDPR and ICO guidance already require explainability for customer-facing automated decisions. NIST AI RMF alignment is increasingly expected by enterprise procurement teams whether or not a regulator requires it.

Applied AI and automation

Close-up of a printed circuit board

Where AI does earn its place, it is usually narrower and duller than the version that was originally proposed. Spend classification across fragmented procurement data. Augmented triage across a volume of security findings a human team cannot process. Intelligent document processing where the input is genuinely unstructured. Demand forecasting where the data is clean enough to support it.

These have something in common: structured, consistent data flows and a measurable baseline. That is not a coincidence, and it is the most reliable filter available for deciding what to attempt first.

Agentic systems — those that take autonomous action rather than generating content — change the governance question rather than extending it. The framework has to move from what AI recommends to what AI does, which means treating bots, API keys and service accounts as identities requiring the same controls as people. Consumption pricing deserves equal attention: an undefined use case on a per-transaction platform is an uncapped liability.

AI security and controls assurance

Two distinct exposures, often conflated. The first is AI as an attack surface: prompt injection, model and data poisoning, leakage through systems that were never designed to hold confidential input, and ungoverned non-human identities executing transactions without human authorisation at any step.

The second is assurance: being able to demonstrate, to an auditor, a regulator, an enterprise client or an investor, that your controls work as described. That increasingly appears in procurement questionnaires and due diligence long before any regulator asks. We build the evidence trail as part of delivery, because reconstructing it afterwards costs several times more and convinces fewer people.

Signals this is the conversation you need

  • AI tools are in use across the business and nobody holds a complete inventory
  • A pilot produced a promising result that has not survived contact with production
  • You have EU market exposure and have not classified your systems by risk level
  • Enterprise clients or investors have started asking AI governance questions in diligence
  • Someone has proposed an AI investment and nobody can name the number it moves

AI may well be the answer. But you need to make sure you have the right question first.

Start a Conversation