PILLAR · GOVERNANCE

AI Governance

AI without governance is a regulatory and reputational risk. We set up policies, oversight, and risk control that scale with your AI footprint — built for the European regulatory context, not retrofitted from US frameworks.

30 days
to a full AI risk register
100%
EU AI Act-aligned policy set
0
compliance surprises at audit
EU AI Act timeline
2024 — 2027
  • Aug 2024
    EU AI Act enters into force
  • Feb 2025
    Prohibited AI practices ban
  • Aug 2025
    GPAI obligations + governance bodies
  • Aug 2026
    High-risk AI system rules apply
  • Aug 2027
    Annex II products full coverage

Are you ready for the next deadline?

Why governance now

AI without governance is a regulatory and reputational risk you can't see — until you do.

The EU AI Act is now in force. Bulgarian and EU enterprises that deployed generative AI, AI agents, or model-driven decisions need policy, oversight, and risk control that hold up under audit. Tooling is the easy part — governance is what separates a compliant AI footprint from a board-level liability.

€35M / 7%
Maximum EU AI Act fine — whichever is higher of revenue or fixed cap
Aug 2026
High-risk AI system rules become enforceable
73%
Of EU enterprises with deployed AI have no formal AI policy yet
What we deliver

A complete AI governance program — not a policy PDF

We don't sell templates. We embed with your team, map your AI footprint, classify by risk, and stand up the policies, controls, and oversight cadence you need.

EU AI Act mapping & classification

Full inventory of every AI system — internal, vendor, embedded — classified by risk tier (prohibited, high, limited, minimal).

AI policy templates

AI usage policy, vendor policy, generative-AI policy, model-risk policy. Bilingual (EN/BG), Bulgaria + EU-aligned, ready to deploy.

AI risk register & model lineage

Single source of truth for every model, prompt, dataset, and decision — auditable, queryable, and continuously updated.

Prompt injection & data residency review

Practical security audits aligned to OWASP LLM Top 10 plus EU data-residency and GDPR overlap analysis.

Board-level AI oversight

Quarterly review cadence with KPI dashboards, incident reports, and forward-looking risk assessment for your executive team.

Fractional AI Governance partner

We operate as your outsourced Head of AI Governance — owning policy, register, vendor assessment, and the board cadence on a fractional basis.

EU AI Act primer

Why this matters — and what it costs to ignore

The EU AI Act (Regulation 2024/1689) is the world's first comprehensive AI law. It applies a risk-based framework: the more impactful the AI system, the stricter the obligations. Bulgarian companies are in scope the moment they place AI on the EU market, deploy AI in their operations, or use AI to make decisions affecting EU citizens — including off-the-shelf tools like ChatGPT used in production.

Compliance is not optional. National authorities (CPLD in Bulgaria) gain enforcement powers from August 2026 for high-risk systems. Companies caught without proper governance face enforcement actions, market access restrictions, and reputational damage that compounds quickly in B2B sales cycles where compliance reviews are now standard procurement gates.

Penalties for non-compliance

EU AI Act · Art. 99
€35M / 7%
Use of prohibited AI practices
Higher of fixed cap or global annual turnover
€15M / 3%
High-risk AI obligation breaches
Includes failure to maintain risk register, oversight, or transparency
€7.5M / 1.5%
Supplying incorrect or misleading info to authorities
Includes incomplete documentation during audit
Prohibited
In force since Feb 2025

Banned outright — social scoring, real-time biometric ID in public spaces, manipulative AI, emotion recognition in workplaces and schools.

High-risk
Enforced from Aug 2026

AI in HR, credit scoring, education, critical infrastructure, law enforcement, medical devices. Requires risk management, data governance, transparency, human oversight, post-market monitoring, and CE-marking-style conformity assessment.

Limited risk
Enforced from Aug 2026

Chatbots, deepfakes, emotion recognition outside workplaces. Transparency obligations — users must know they're interacting with AI; AI-generated content must be labelled.

Minimal risk
No specific obligations

Spam filters, AI in video games, recommendation engines without sensitive impact. Voluntary codes of conduct only.

Most Bulgarian companies have at least one high-risk or limited-risk system in their AI footprint and don't know it yet. We translate the regulation into something operational: a risk register, policies your team will actually follow, and a quarterly review cadence that keeps your board informed and audit-ready.

How we work

From audit to ongoing oversight

First measurable artefacts within 30 days. Full board-level cadence operational within 60. Then we run the program — or hand it back to your team.

01
Week 1–2

AI inventory & risk classification

We map every AI system — internal builds, vendor tools, embedded features — and classify each by EU AI Act risk tier.

  • Comprehensive AI inventory
  • Risk classification report
  • Gap analysis vs EU AI Act
02
Week 3–4

Policy set & risk register

We deliver the policies, the AI risk register, and vendor assessments — drafted for your business, reviewed with legal and engineering.

  • AI usage + vendor + GenAI policies
  • AI risk register with controls
  • Top-10 vendor assessments
03
Week 5–8

Oversight cadence & training

We set up the quarterly board cadence, train executives and managers, and run the first review with your leadership team.

  • Board AI dashboard
  • Executive AI training
  • First quarterly AI review
04
Ongoing

Fractional governance partner (optional)

We operate as your outsourced Head of AI Governance — running quarterly reviews, updating the risk register, assessing new vendors, owning audits.

  • Quarterly board reviews
  • Continuous risk register updates
  • Audit & incident response support
Outcomes

What you get out the other side

Concrete artefacts and a working oversight motion — not a 200-page report you'll never reread.

100%
EU AI Act-aligned
Policies, controls, and classification mapped to the regulation
30 days
To full AI risk register
Single source of truth for every model and decision
0
Audit surprises
Documented controls, evidence on demand
FAQ

AI governance — common questions

What is AI governance?
AI governance is the set of policies, processes, and oversight that ensure AI systems are deployed safely, legally, and effectively. It covers usage policies, model risk management, vendor assessment, data residency, board-level oversight, and audit readiness — particularly under the EU AI Act and GDPR.
How does the EU AI Act apply to my Bulgarian company?
The EU AI Act applies to any Bulgarian company that develops, deploys, or distributes AI systems in the EU — including using third-party tools like ChatGPT in production. Obligations scale with risk class. We map your AI footprint, classify systems, set up policies, and prepare for audits.
Do I need an AI policy if my team only uses ChatGPT?
Yes. Even consumer-grade AI use creates risk: data leakage to third parties, untracked decisions, inconsistent quality, and shadow AI. A simple usage policy plus light governance (vendor assessment, data classification, training) is the right starting point.
What's the difference between AI governance and AI security?
AI security focuses on technical defenses — prompt injection, model exfiltration, data poisoning. AI governance is broader: policy, oversight, risk management, vendor selection, audit, and the human/organizational side. They overlap, but you need both.
How do I set up board-level AI oversight?
Define a quarterly AI review cadence with three artefacts: a risk register update, a KPI dashboard (deployments, incidents, costs), and a forward-looking risk + opportunity report. We set this up turn-key and can run the cadence as your fractional governance partner.
How long does an AI governance implementation take?
First measurable artefacts (policy set, risk register, classification report) within 30 days. Full board-level cadence operational within 60. Ongoing fractional governance available month-to-month.
What does AI governance cost?
Initial setup engagements typically start in the four-figure euro range and scale with company size and AI footprint. Fractional ongoing governance is priced monthly. We offer a free 30-minute review to assess your situation before quoting.
Can encorp.ai be our outsourced AI governance partner?
Yes. Our fractional engagement makes us the de-facto Head of AI Governance for your company — owning policy, register, vendor assessment, and the quarterly board cadence. Especially fit for Bulgarian and EU enterprises that aren't yet at full-time hire scale.

Get your AI risk under control in 30 days.

Book a free 30-minute AI governance review. We'll map your AI footprint, identify your top 3 risks, and recommend a starting point — no commitment.

No sales pressure · Free 30-min consultation · Bilingual delivery (EN/BG)