An AI-related incident can move quickly from an internal problem to a regulatory one. Data exposed through a third-party model. An employee submitting sensitive information to a public tool. An automated process producing outputs that should not have gone out. A supplier quietly changing how their platform handles your data.
If something has happened and you are not certain what the exposure is, what your obligations are, or what to do next, this service is built for that moment. It is independent, practical, and available at short notice.
We are not here to assign blame. We are here to help you understand what happened, contain what can be contained, and make sensible decisions under pressure.
Fixed price, ex. VAT. Scoped quickly – we understand that timing matters.
A clear three-stage review process designed to understand your environment, speak with the right people, and deliver practical recommendations.
We move quickly. An initial scoping conversation happens within 24 hours of first contact. We gather what is known, structure the review, and work with your team to establish the facts. A written report follows, covering findings, obligations, and recommended next steps.
We can work alongside your legal team, DPO, or existing security function without conflict.
Tell us what has happened. We take it from there.
An incident has already occurred and you need independent support to understand it, contain it, and decide what comes next.
Also appropriate for organisations that have discovered a historical issue – a tool that should not have been in use, data that should not have been submitted – and need to understand the implications before deciding how to respond.
Prevention costs less than response. But when you need response, we are here.
Get in touch. If the situation is urgent, say so and we will prioritise.