AI POLICY CONSULTING

AI speed for your team.
Protected client data.

We audit how your company really uses AI, write an internal AI policy built for your tools, your clients, and your contracts, and embed the rules into daily work, not a PDF nobody reads.

  • Built on an audit of your real AI usage
  • EU AI Act, NIS2, GDPR, ISO 27001 & 42001, SOC 2
  • English or Bulgarian
  • Implemented, not just written
AI policy draft with annotations on a table

A policy nobody reads changes nothing

Three ways companies usually get an AI policy. Three ways it fails.

Templates fail client reviews

Security questionnaires ask how the rules apply to your tools and your client data. A template downloaded from the internet has no answer to give them.

Unclear rules slow AI down

When no one knows what is allowed, people either stop using AI or start hiding it. You lose the speed or you lose the control, and sometimes both at once.

Paper without enforcement is not evidence

Clients and regulators increasingly want proof that controls operate: approvals, briefings, review logs. A signed PDF on its own produces none of it.

Audit, policy, implementation

Three stages, one outcome: rules that match reality and hold in daily work.

Stage 01 Map reality

Audit

We map how your company actually uses AI today, before a single rule is written. Guesswork gets replaced with a clear picture of what is really happening.

  • Inventory of AI tools, accounts, and subscriptions in use
  • Shadow AI: personal accounts and unapproved tools
  • Client contracts: confidentiality, IP, and data clauses AI use has to respect
  • Existing policies and processes the new rules must fit
Stage 02 Write

Policy

We draft a policy built for your company: your tools, your clients, your contracts. Not a template with your logo on the cover.

  • Aligned with the EU AI Act, GDPR, NIS2, DORA, ISO 27001, SOC 2, and ISO 42001
  • An approved-tools registry and a fast approval flow for new tools
  • Clear rules: what never goes into a prompt, when AI output needs a human review
  • Client-policy handling: whose rules win and how conflicts get escalated
Stage 03 Embed

Implementation

Rules only matter where the work happens. We integrate the policy into your processes and stay until it holds on its own.

  • Rules embedded into onboarding, project kickoffs, and code review
  • Tool configuration guidance: retention and training switches off
  • Employee briefing so the team knows what is allowed and why
  • A review schedule so the policy keeps pace with the tools

Aligned with what your clients and regulators ask about

The policy maps to these so security reviews and tenders get direct answers. We write them in plain language, not legalese.

EU regulation

  • EU AI Act: documented usage rules and the AI-literacy duty for your team
  • GDPR: personal data stays out of tools without the right terms
  • NIS2: risk-management measures covering AI tooling, if you are in scope
  • DORA: ICT requirements from financial-sector clients that land in your contracts

Frameworks & standards

  • ISO 27001: AI rules slotted into your ISMS controls
  • ISO 42001: the policy as anchor of an AI management system
  • SOC 2: written controls and the evidence trail auditors expect
  • NIST AI RMF: a governance mapping US clients may ask for

Not every framework applies to every company. The audit identifies which ones actually touch your business.

From intro call to a working policy

Four steps. The first costs you just half an hour.

Step 01

Intro call

Thirty minutes. Which AI tools are in play, what your clients are asking of you, and whether a policy is the right next step at all.

Step 02

Usage audit

We map tools, accounts, workflows, and client contracts, then summarize findings and gaps before any drafting starts.

Step 03

Drafting & review

We write the policy, your leadership reviews in short iterations, and we adjust until the rules match how you actually deliver.

Step 04

Implementation & handover

We embed the rules into your processes, brief the team, and leave you the policy with its review schedule.

What clients say about the result

In their own words: what changed once the rules were real.

Right after the workshop I got a question from one of our lead devs - "Ok now, great workshop - should we change something in our dev work or was it only for our knowledge? Probably tomorrow we will continue working the same way". The best outcome from this workshop was aggregating the knowledge and creating an AI policy for all our dev team to follow. This policy was created specifically for our custom AI usage to be confident from a business perspective and to be protecting our clients from AI threats. After the seminar it took us only 2-3 days to meet and discuss with Stihia experts what AI policy to create and half a day to propagate it to all company members. Great and efficient work. Definitely would recommend.
Stoyan Simov CEO, App Streams

A policy is the middle of the job

Education makes the rules stick. A named owner keeps them alive.

Educate

AI Security Workshop

Hands-on training that turns policy from text into habit, and keeps the team current as the risks change.

Learn more

Sustain

Fractional Security & Compliance Officer

A named owner who keeps the policy applied, reviews new tools, and answers client security reviews for you.

Learn more

Full package

Enable Safe AI Development

The whole path (educate, govern, sustain) in one engagement, for teams moving to AI-first delivery.

Learn more

Questions we get asked

We already have an information security policy. Do we need a separate AI policy?

Usually yes, as a dedicated document or an addendum. AI tools raise questions a generic security policy never answers: which tools are approved, what can go into a prompt, who may ship AI output to a client. We fit the AI policy alongside your existing documents, not instead of them.

Will this slow our developers down or block them from using AI?

The opposite. The rules exist so people can use AI without guessing. A clear approved-tools registry and a fast approval flow mean more AI, safely, not less.

How is this different from downloading a template?

A template does not know your tools, your contracts, or your clients. Most of the value is in the audit and the implementation, not the text, which is exactly where a template has nothing to offer.

Do we even fall under the EU AI Act?

Depending on how you build and use AI, parts apply, for example the AI-literacy obligation and transparency duties. Regardless of strict applicability, your clients and their procurement teams are already asking these questions. A written policy answers them in one place instead of case by case.

What if a client has their own AI policy?

Common in outsourcing. Your policy defines how the team discovers, follows, and escalates conflicts between client rules and your own. We bake that into the employee responsibilities section, so a clash never gets quietly ignored.

How long does an engagement take?

Typically a few weeks from kickoff to a signed policy, depending on review cycles. The audit runs about one to two weeks; drafting and implementation follow. We agree timing on the intro call so nothing drifts.

What language is the policy written in?

We provide English and Bulgarian natively, often both in the same engagement. Other languages are available on request. We also align the policy with the local laws of the country you operate in.

Does this help with client security questionnaires and tenders?

Yes. A written policy is the first thing they ask for; together with training records and a named owner, a security review gets answers instead of scrambling. That is where the fractional officer and the workshop come in.

What does it cost?

Fixed price, scoped after the intro call. It depends on company size, the number of client contracts to map, and how much of the implementation you want us to run. You see the price before you commit to anything.

Ready for rules your team can build with?

Start with a half-hour call. Tell us which AI tools your team uses and what your clients ask of you, and we will tell you honestly whether policy work is the right first step.