Alice Labs helps organizations build AI governance frameworks that enable responsible, compliant AI adoption. We deliver practical policies, EU AI Act compliance, risk assessment, and monitoring—not bureaucratic overhead. Governance that accelerates AI innovation within clear guardrails.
Have a project in mind?
Get a response within 24 hours — no obligation.
An experienced team with broad AI and tech backgrounds from leading companies
Linus
Co-founder & AI Consultant
Alice
CEO & Co-founder
Jens
AI Consultant
Eric
Co-founder & AI Consultant
Lisa
Project Lead & Implementation
Production-grade AI delivery, EU-native, senior team
Ready to talk?
Tell us about your goals and we'll suggest the fastest path forward.
Verified outcomes from completed AI implementations
Ljusgårda (Supernormal Greens)
Public Sector
Media Company
Ready to see similar results?
Book a free discovery call - we'll map your highest-impact AI opportunities.
AI governance is the system of policies, processes, and controls that ensures an organization deploys AI responsibly, securely, and in compliance with applicable regulations. It's the bridge between AI ambition and organizational trust—enabling teams to innovate with confidence.
A comprehensive AI governance framework covers: AI usage policies, risk assessment and classification (aligned with the EU AI Act), data governance and privacy, vendor and model evaluation, access controls, monitoring and audit trails, incident response, and continuous compliance. The key is making governance practical—enabling faster AI adoption, not blocking it.
At Alice Labs, we build governance frameworks that are pragmatic, not bureaucratic. Our approach: classify risks, create clear policies, implement monitoring, and train teams—so your organization can scale AI responsibly. We work with enterprises, public sector, and growth-stage companies across Europe.
Practical governance that your teams will actually use
Clear, practical usage guidelines by role and function
EU AI Act risk mapping for all your AI use cases
Evaluated and approved AI platforms and vendors
GDPR-compliant data handling and privacy controls
Dashboards, audit trails, and incident response
Role-specific governance training for all teams
Gap analysis against EU AI Act and industry regulations
Complete framework with processes and templates
1-2 weeks
Map all AI use cases. Classify by EU AI Act risk level. Identify compliance gaps.
2-4 weeks
Create practical policies. Define approved tools. Implement access controls and logging.
1-2 weeks
Role-specific training. Launch governance framework. Establish review cadence.
Ongoing
Continuous compliance monitoring. Quarterly reviews. Adapt to new regulations and use cases.
Most "AI governance" consulting stops at the EU AI Act. Real regulated industries operate under overlapping US and EU regimes. Below is how Alice Labs maps services to the specific frameworks US and European regulators actually enforce — with direct citations to the source documents.
US Federal Reserve, OCC, FDIC, EU EBA
AI in credit scoring, fraud detection, AML and trading is treated as a model under long-standing US bank supervisory guidance. Alice Labs builds your model risk management program to satisfy Federal Reserve SR 11-7 and OCC Bulletin 2011-12 in parallel with EU AI Act Annex III (credit scoring is high-risk).
From Federal Reserve SR 11-7
"The use of models invariably presents model risk, which is the potential for adverse consequences from decisions based on incorrect or misused model outputs and reports. Banks should objectively assess model risk and the associated costs and benefits using a sound model-validation process."
US NAIC, NYDFS, Colorado DOI, EU EIOPA
Underwriting, claims, pricing and marketing AI are explicitly in scope of the 2023 NAIC Model Bulletin and Colorado's algorithmic discrimination testing rule (SB21-169). Alice Labs builds insurer AI programs (AIS — AI Systems) with documented governance, bias testing, disparate-impact analysis and consumer-disclosure controls.
From NAIC Model Bulletin on Use of AI (2023)
"Decisions impacting consumers that are made or supported by advanced analytical and computational technologies, including AI, must comply with all applicable insurance laws and regulations, including those that address unfair trade practices and unfair discrimination."
US HHS / OCR / ONC, EU MDR
Clinical-decision support, ambient documentation and patient-triage AI sit at the intersection of HIPAA, the ONC HTI-1 algorithm transparency rule (effective 2025), HHS Section 1557 non-discrimination and EU AI Act Annex III. Alice Labs builds hospital/payer AI programs that satisfy all three regimes in parallel.
From ONC HTI-1 Final Rule (45 CFR 170.315(b)(11))
"Certified Health IT Modules that supply Decision Support Interventions must be capable of providing source attribute information for Predictive DSIs, including intervention purpose, intended user, intended decision, training data and fairness information."
US FDA CDRH, EU MDR / IVDR
AI/ML Software-as-a-Medical-Device must demonstrate Good Machine Learning Practice and ship with a Predetermined Change Control Plan if it is to learn after deployment. Alice Labs builds the technical documentation, lifecycle controls and post-market monitoring that the FDA Center for Devices and Radiological Health expects, mapped one-to-one to EU MDR Annex II/III.
From FDA PCCP Guidance (final, 2024)
"A PCCP describes planned modifications to an AI/ML-enabled device, including the methodology to develop, validate and implement those modifications in a manner that ensures the device remains safe and effective across the lifecycle without requiring additional marketing submissions."
The same Alice Labs offer often satisfies multiple regulators simultaneously. Use this matrix to see which engagement covers which framework.
| Alice Labs Service | EU Framework | US Framework | Typical Duration |
|---|---|---|---|
| EU AI Act Compliance Program | EU AI Act (Reg. 2024/1689), ISO/IEC 42001 | NIST AI RMF 1.0, NIST AI 600-1 | 8–12 weeks |
| Banking Model Risk Program | EBA model validation, EU AI Act Annex III | Fed SR 11-7, OCC Bulletin 2011-12, FDIC FIL-22-2017 | 12–20 weeks |
| Insurance AIS Program | EIOPA AI Principles, EU AI Act Annex III | NAIC Model Bulletin, NYDFS CL-7, Colorado SB21-169 | 10–16 weeks |
| Clinical AI Governance | EU AI Act Annex III, MDR/IVDR, GDPR Art. 22 | HIPAA, ONC HTI-1, HHS §1557 | 10–14 weeks |
| SaMD AI/ML Governance | MDR 2017/745, IVDR 2017/746, ISO 13485 | FDA PCCP, GMLP, 510(k) / De Novo | 12–24 weeks |
| ISO/IEC 42001 Readiness | ISO/IEC 42001:2023, ISO/IEC 23894 | NIST AI RMF crosswalk | 10–14 weeks |
Sources: European Commission AI Act, NIST AI RMF, ISO/IEC 42001:2023.
Eight productized engagements with fixed-fee ranges. Most clients start with the Assessment, then layer in one or two implementation packages. All fees are indicative and exclude VAT.
EUR 15–25k
1–2 weeks
Inventory + EU AI Act risk classification + remediation roadmap.
EUR 60–180k
8–12 weeks
Article 11 docs, Article 14 oversight, Article 72 monitoring, Annex IV file.
EUR 45–95k
10–14 weeks
AIMS implementation aligned to ISO/IEC 42001:2023.
USD 55–140k
10–14 weeks
Govern / Map / Measure / Manage + NIST AI 600-1 GenAI profile.
EUR 75–200k
12–20 weeks
Model risk program for credit, fraud, AML and trading AI.
EUR 85–250k
12–24 weeks
FDA PCCP + HIPAA + EU MDR alignment for clinical and SaMD AI.
EUR 12–22k
2–3 weeks
Board-ready Acceptable Use Policy + GenAI guidelines + incident playbook.
EUR 8–15k
Half-day
Executive briefing for board, audit committee and C-suite.
We aren't the right fit for every buyer. Here is an honest comparison against the most common alternatives so you can self-qualify before you book a call.
| Selection Criterion | Alice Labs | Big Four (Deloitte, EY, KPMG, PwC) | Global SI (Accenture, Capgemini, IBM) | MBB (McKinsey, BCG, Bain) |
|---|---|---|---|---|
| EU AI Act + NIST AI RMF in one engagement | Yes — productized | Partial — separate practices | Partial | Strategy only |
| Senior partners on the work | Always (founder-led) | Sell senior, deliver junior | Offshore-heavy | Partners on slides only |
| Fixed-fee engagement | Yes — every offer | Rare | Rare | No — T&M |
| ISO/IEC 42001 readiness in 14 weeks | Yes | Yes (longer) | Yes (longer) | No |
| Hands-on technical implementation | Yes — builds + governs | Subcontracted | Yes | No — advisory only |
| FDA SaMD / PCCP experience | Yes — productized | Life sciences practice | Limited | No |
| Typical engagement size | EUR 15k – 250k | EUR 300k – 3M | EUR 500k – 5M | EUR 1M – 8M |
| Time to first deliverable | 2 weeks | 6–10 weeks | 8–12 weeks | 4–8 weeks |
Deep-dives on the regulations, frameworks and operating models behind every Alice Labs governance engagement — from the EU AI Act timeline to NIST AI RMF and ISO/IEC 42001.
Let's discuss your AI journey
Our team will help you prioritize use cases and build a concrete roadmap.
"We decided early on to embrace AI technology and needed a partner who could explore opportunities, propose solutions, lead change management, and build them. With Alice, we got everything in one place and have implemented multiple solutions that increased efficiency so significantly that an entire team could be reallocated."
Andreas Wilhelmsson
CEO & Co-founder
Supernormal Greens / Ljusgårda
"Alice Labs' AI training gave us all a real aha-moment, whether we were completely new to the field or experienced! The training contained a perfect balance between theory and practice. We have definitely become more efficient at work!"
Åsa Nordin
IT Manager
Trollhättan Energi
"The collaboration with Alice Labs has been easy, educational, and incredibly supportive. We engaged them to improve our processes and create more efficiency in the team, and the result truly exceeded expectations. Through their guidance, we've gained better structure, faster workflows, and more time for what actually creates results."
Frida
Partner Manager
Bruce Studios
"Fast, professional, and wonderful people. Find out for yourself <3"
Johannes Hansen
Founder
Johannes Hansen AB
AI governance is the framework of policies, processes and controls that ensures AI systems are used responsibly, lawfully and safely. It covers EU AI Act compliance, ISO 42001 alignment, model risk management, bias and fairness testing, incident response and board-level oversight — increasingly required for any production AI in regulated industries.
Everything you need to know about AI governance and compliance
AI governance is the framework of policies, processes, and controls that ensures an organization uses AI responsibly, securely, and in compliance with regulations. It covers: AI usage policies, risk assessment and classification, data handling and privacy, model selection and evaluation, monitoring and audit trails, incident response, and regulatory compliance (including the EU AI Act). Good governance enables faster AI adoption—not slower.
An AI governance strategy is a structured plan for how an organization will manage AI risks, ensure compliance, and enable responsible innovation. It typically includes: a governance framework with roles and responsibilities, AI risk classification methodology, approved tools and platforms list, data governance policies, compliance mapping to relevant regulations, monitoring and reporting mechanisms, and an incident response plan.
The EU AI Act is the world's first comprehensive AI regulation, classifying AI systems by risk level: Unacceptable (banned), High-risk (strict requirements), Limited risk (transparency obligations), and Minimal risk (no requirements). Most business AI applications fall into limited or minimal risk, but some HR, credit, and safety applications may be high-risk. We help you classify your AI systems, understand obligations, and implement compliance efficiently.
We follow a four-phase approach: 1) Inventory—map all AI use cases and classify by risk level. 2) Policy—create clear, practical policies for AI usage, data handling, and vendor management. 3) Controls—implement technical and organizational controls (logging, access, monitoring). 4) Operationalize—train teams, establish review processes, and build continuous compliance monitoring. The goal is a framework that enables innovation within clear guardrails.
No—done right, governance accelerates AI adoption. Without governance, every AI project faces ad-hoc security reviews, legal uncertainty, and stakeholder resistance. With a clear framework, teams know what's allowed, how to evaluate tools, and what approvals are needed. Our clients typically see faster project approval and broader organizational buy-in after implementing governance.
A practical AI policy covers: approved AI tools and platforms, acceptable use guidelines by role/function, data classification and handling rules, vendor and model evaluation criteria, privacy and confidentiality requirements, output review and quality standards, incident reporting procedures, and escalation paths. We write policies that people actually follow—clear, practical, and role-specific.
GDPR compliance is built into every engagement: we map personal data flows, implement data minimization, ensure lawful basis for processing, configure data processing agreements with AI vendors, implement right-to-erasure capabilities, and maintain processing records. For high-sensitivity data, we use EU-hosted or on-premise AI models.
We use a structured risk assessment combining EU AI Act risk categories with business impact analysis. Each AI use case is evaluated on: data sensitivity, decision autonomy, affected population, reversibility of decisions, regulatory classification, and organizational readiness. The result is a prioritized risk register with clear mitigation actions.
Yes. We conduct comprehensive AI audits covering: inventory of all AI tools and use cases, risk classification per the EU AI Act, compliance gap analysis, data governance assessment, security and access control review, vendor and model evaluation, and policy effectiveness assessment. Deliverables include a detailed audit report and prioritized remediation roadmap.
Start with a governance assessment (1-2 weeks) where we inventory your AI use cases, classify risks, and identify gaps. From there, we build a prioritized roadmap: quick wins (policies, approved tools list) first, then structural changes (monitoring, controls, training). Most organizations can have a functional governance framework within 4-8 weeks.
Have more questions? Let's talk.
No commitment - just a conversation about what AI can do for your business.
Book a governance assessment to identify gaps and priorities. Enforcement is live. Fines up to €35M. We get you compliant in 8–12 weeks.
Combine multiple services for maximum impact – we help you find the right mix