Company AI Control Review
A written AI control plan in one week.
For an established Irish business where staff already use AI and someone needs a clear answer about what information may go where, which tools are suitable and what to do first.
The starting point
Bring the real concern.
Start with a free 15-minute call. If the review fits, the paid work begins with one 60-minute workshop involving the person responsible for the decision and, where useful, the company’s IT provider or MSP.
- Current AI use
Which tools staff use, whether accounts are managed and what guidance exists today.
- The information involved
The documents, records and systems the workflow needs, described without sending confidential material for the fit call.
- One repeated workflow
The work people want AI to help with and the person who must remain accountable for the result.
- Existing technology
The Microsoft 365, Google Workspace, cloud, model-provider or other services already available to the business.
The deliverable
Your Company AI Control Plan.
Delivered within five business days after the workshop and receipt of the agreed materials.
- Current AI-use and data-flow map
A plain account of the people, tools, company information and high-level route through the chosen workflow.
- Data-location questions answered
Where source documents, prompts, retrieved context, model requests and logs are processed or retained.
- Control decisions
The permissions, logging, retention and human-approval requirements that matter for this workflow.
- Recommended route
Use an existing enterprise product, commission a customer-controlled implementation or take no project forward.
- One bounded pilot scope
The first workflow, dependencies and implementation boundary, with a separate estimate if a build is justified.
- 30-minute readout
Walk through the recommendation, answer questions and agree what happens next.
Where does the data go?
Make the boundary explicit.
Customer-selected EEA hosting can be used where the chosen architecture and provider support it. An external model may still receive selected information, so location is only one part of the decision.
- Enterprise service
The provider hosts the interface, storage and model under its enterprise terms and controls. The review checks whether its regions, retention and access model fit the workflow.
- Customer data, external model
Documents and retrieval stay in the customer-controlled environment. Deliberately selected prompts or context still go to an approved external model provider.
- Customer data and model
The interface, storage, retrieval, model inference and workflow components operate inside the defined customer-controlled boundary.
The plan names relevant providers, processors, regions, retention questions and international-transfer safeguards. It does not claim that EEA residency alone establishes GDPR compliance.
Scope boundary
A review, not an open project.
- Included
One workshop, supplied policies and system summaries, one workflow, a written plan and one readout.
- No credentials or live access
The fixed review does not require Airlark to enter company systems or inspect production data.
- Not a legal or security audit
The review identifies decisions and dependencies. It is not legal advice, a GDPR compliance audit, penetration testing or security certification.
- No implementation
Configuration, software changes and custom development are separately scoped and optional.
- No open-ended solution design
The fixed scope ends with one recommended route and one bounded pilot. Further discovery or design is separately agreed.
The decision
Three valid outcomes.
- Use a product you already have
Copilot or another enterprise service may provide the required controls more safely and economically than a custom system.
- Scope one implementation
When the workflow needs a different boundary or integration, the plan defines a small first build that the business can own.
- Do not start a project
A clearer policy, a process change or no further work can be the responsible recommendation.