ENABLE SAFE AI DEVELOPMENT

One partner from
AI confusion to AI control

AI tools reached your team before any rules did. This engagement closes the gap in three steps: train the people, set the rules, and keep a named owner on both. More AI, safely, not less.

  • Three services, one engagement
  • EU AI Act, NIS2, DORA, GDPR, ISO 27001, SOC 2, ISO 42001
  • Start at any step
  • No full-time hire required

Educate, govern, sustain

One path, three services. Most companies run them in this order; where you join depends on where you already are.

The order is the natural path, not a turnstile. Some teams start in the workshop room, others arrive with a policy that needs an owner. The intro call settles where you join.

The gaps this closes

Three gaps open up when AI adoption runs ahead of governance. This is where each one goes.

Shadow AI, surfaced

Personal accounts and unapproved tools get replaced by an approved way to work, so usage you cannot see becomes usage you govern.

Security reviews, answered

Client questionnaires get training records, a written policy, and a named owner, not a scramble the week they land.

Regulation, decoded

The EU AI Act, NIS2, and GDPR turn into concrete next steps for your company, not a reading list.

Step 01 / Educate

AI Security Workshop

Hands-on training built around live attacks on the AI tools your team opens every morning. Awareness first, then the habits that keep client data safe while getting more out of AI.

Explore the workshop

  • Live attack demos on real tools, not slides
  • Safe and effective usage habits people keep
  • Attendance evidence for client security reviews
Step 02 / Govern

AI Policy Consulting

An audit of how your company really uses AI, then a policy written for your tools, clients, and contracts, and embedded into daily work. Not a template with your logo on the cover.

Explore policy consulting

  • Aligned with the EU AI Act, GDPR, NIS2, DORA, ISO 27001, SOC 2, and ISO 42001
  • Approved-tools registry and a fast approval flow
  • Rules embedded into onboarding and code review
Step 03 / Sustain

Fractional Security & Compliance Officer

A combined vCISO and vCCO focused on AI: someone accountable who keeps the policy applied as tools change, and answers client security reviews for you. An owner, not a document.

Explore the fractional officer

  • Policy reviewed as tools and risks change
  • Client questionnaires answered for you, in writing
  • Compliance evidence collected as work happens

What clients say

In their own words: what changed with one partner on the whole path.

Right after the workshop I got a question from one of our lead devs - "Ok now, great workshop - should we change something in our dev work or was it only for our knowledge? Probably tomorrow we will continue working the same way". The best outcome from this workshop was aggregating the knowledge and creating an AI policy for all our dev team to follow. This policy was created specifically for our custom AI usage to be confident from a business perspective and to be protecting our clients from AI threats. After the seminar it took us only 2-3 days to meet and discuss with Stihia experts what AI policy to create and half a day to propagate it to all company members. Great and efficient work. Definitely would recommend.
Stoyan Simov CEO, App Streams

Questions we get asked

Do we have to take all three services?

No. It is a path, not a bundle. The workshop, the policy work, and the fractional officer are scoped separately, and most clients start with one and add the others as the need shows up. The intro call maps what you already have and what is missing.

Where do we start if AI use has already spread?

Usually with the policy audit. It maps how AI is really used, including personal accounts and tools nobody approved, so you have a picture before anyone writes rules. When awareness is the bigger gap, the workshop comes first. We settle the entry point on the intro call.

Can this stop shadow AI?

It replaces it. The audit surfaces which tools people already use, the policy sets an approved list and an approval flow fast enough that nobody routes around it, and the officer vets new tools before they spread. A ban pushes usage underground. A sanctioned path people prefer does not.

Does this cover the EU AI Act and NIS2?

Yes. Policies are aligned with the EU AI Act, NIS2, DORA, GDPR, ISO 27001, SOC 2, and ISO 42001, and the workshop covers the AI-literacy obligation. Which provisions apply depends on how you build and use AI, but your clients and their procurement teams ask these questions regardless.

Will it get us through client security reviews and tenders?

That is much of the point. Questionnaires ask for training records, a written AI policy, and a named person responsible. The three steps produce exactly those, and the fractional officer answers the reviews for you, in writing, with evidence attached.

What does it cost?

The workshop and the policy work are fixed prices, scoped after the intro call. The fractional officer is a monthly retainer. It depends on company size, how many client contracts and reviews you run, and how much of the implementation you want owned for you. You see the price before you commit to anything.

We also build our own AI product. Is that covered?

Not by these three. This path covers how your team uses AI; what you ship to customers is a different attack surface, with its own path: AI Product Security & Compliance. Discovery maps the product, AI red teaming attacks it, and Stihia Sense monitors it in production. Mention the product on the intro call and we scope both sides as one engagement.

Ready to trade AI confusion for AI control?

Start with a half-hour intro call. Tell us where AI has spread and what your clients are asking, and we will tell you honestly where the path should start for you. No obligation past that.