25+operating companies covered
8board decisions surfaced
3-tierclassification framework
01 · The situationThe situation
A publicly listed scientific instruments group of 25+ operating companies, run on a deliberately decentralised model in which each subsidiary managing director holds full commercial autonomy. Microsoft 365 Copilot deployments were accelerating company by company, with no shared basis for deciding which tools were acceptable, what data could go into them, or who carried the risk. The EU AI Act was already in force — penalties reaching €35m or 7% of global turnover, AI literacy training mandatory — and the board wanted a position before an incident forced one.
02 · What we builtWhat we built
- A three-tier classification framework that sorts tools by where data is processed rather than which model is running — consumer cloud, business AI under enterprise agreement, and local or self-hosted
- A 14-section group policy with four appendices: an approved-tool register of around 20 tools with per-tool privacy configuration steps, an AI-enabled business software register, and a third-party AI notification letter
- A banned list with documented rationale, spanning agentic tools with root-level system access, cloud services in jurisdictions incompatible with the group’s data obligations, and consumer apps never designed for business use — OpenClaw, DeepSeek, Baidu ERNIE, Alibaba Qwen, ByteDance Doubao, Clearview AI and unrestricted Stable Diffusion among them
- Mandatory conditions for Microsoft 365 Copilot and GitHub Copilot covering intellectual property, NDA-bound customer data, HR and special-category data, and pre-deployment permission hygiene
- An EU AI Act compliance path: AI system inventory, risk classification, documentation for high-risk systems, and AI literacy training
- A governance structure that assigns oversight, inventory and training to subsidiaries and reserves an annual Group AI Committee for policy, regulatory monitoring and shared practice
- A board decision pack setting out eight open questions — oversight frequency, Copilot stance, NDA defaults, liability allocation, training standards, tool approval, HR AI and enforcement — each with the drafted position, the alternatives and the trade-off
03 · The outcomeThe outcome
A board-adopted AI framework, now the group standard across 25+ operating companies. Rather than presenting a finished policy for rubber-stamping, the eight genuine judgement calls were separated out and put to the board with their trade-offs, so directors set the dial on group oversight versus subsidiary autonomy themselves. The framework leaves the decentralised model intact: group sets minimum standards and a mandatory banned list, subsidiaries keep tool selection, licensing and implementation. The policy is maintained on a quarterly cycle to track regulatory movement and a tool landscape that changes faster than any annual review can follow.
Facing something similar?
Tell us what you are dealing with. We will tell you honestly whether AI helps.
Talk to us →← All case studies