Check your exposure Deadlines Services About FAQ Book a call
AI transformation and oversight · European mid-market

Find out what AI your company is actually running.

An independent three-week review: what you run, what's worth keeping, and which EU rules already apply to it.

Takes about a minute. No email required. Or book a 30-minute call.

An illustration of a protective shield over a network of connected systems.
3 weeksKickoff to written findings
Fixed priceScope agreed before we start
Build and stopWe ship what works, retire what doesn't
EU-basedEstonian company, working EU-wide
Does any of this sound familiar

Nobody planned to lose track of their AI.

Pick the system closest to yours. Written twice — once for the board, once for engineering.

EU AI Act

The delay didn't cover everything.

High-risk duties moved to 2027 and much of the market read that as a pause. The obligations reaching ordinary mid-sized companies didn't move at all.

Since Feb 2025
AI literacy — staff using AI must be trained to understand it
In force
2 August 2026
Transparency — disclosing AI interaction and marking synthetic content
In force
2 December 2026
Those duties extend to systems already in service; further prohibited practices apply
4 months
2 December 2027
High-risk duties for standalone systems — hiring, credit, education, essential services
Scheduled
2 August 2028
High-risk duties for AI embedded in regulated products
Scheduled

We work out which apply to your systems. Where a formal legal opinion is needed, we introduce qualified counsel by name.

Services

Review, build, supervise. Each one stands alone.

Each stage leaves you something you own and can act on without us. Advice you can't walk away from isn't advice, it's a dependency.

Start here

AI review

Three weeks. We map every AI system in the organisation, judge which are worth scaling and which should stop, and hand over a prioritised plan.

  • Full inventory, including the tools nobody registered
  • A verdict per system: scale it, fix it, or stop it
  • What applies per system, with the reasoning
  • 90-day plan with named owners
€9,500Fixed price, fixed scope
Then, if you want it

Build and implementation

We finish the cases worth building, with the oversight around them. On the systems you already have.

  • The two or three priority cases, taken to production
  • Approval steps and disclosure built in, not bolted on
  • Durable records of decisions and sign-off
  • Policy, staff training and vendor review
Scoped from reviewHalf the review fee credited
Ongoing

Continuous supervision

Systems drift, vendors revise terms, teams add tools. Monthly review of what runs against what was agreed.

  • Monthly exception and change review
  • New systems assessed as they appear
  • Evidence pack kept current
From €2,000 / month30 days' notice
Week one

Discovery

Interviews across departments, tool and contract review, mapping where data travels.

Week two

Analysis

What applies to each system, where oversight is missing, what your vendors are doing.

Week three

Findings

Written report, prioritised remediation, a plan naming who does what by when.

Week four

Handover

Ninety minutes with leadership, and a separate session for the people using the tools.

Open now — first two companies

Founding client rate: €2,500

For the first two companies: €2,500 instead of €9,500, focused on two departments over ten working days. In return, honest feedback and a written reference if the work was worth it.

Nothing about the findings changes. A report that is easier to sell is a report nobody should buy.

Ask about the founding rate

Half the review fee is credited against implementation starting within 60 days. The other half stays with the review, which is priced to stand alone — a review that pays for itself only when you build is a review you should distrust.

What changes

The difference three weeks makes.

Not a document for a drawer. The practical difference, in things you can check yourself.

A leadership team reviewing findings around a table.
Week four: ninety minutes with the people who have to act on it.
Before
After
Three pilots have been nearly ready for a year, and nobody will call it.
The ones worth finishing are in production. The rest were stopped, on purpose.
Nobody knows how many AI tools are in use, or who introduced them.
One list, with an owner beside each entry and the data it touches.
"Does the AI Act apply to us?" gets a different answer from everyone you ask.
A written determination per system, with the reasoning attached.
A client or auditor asks how you govern AI, and someone improvises.
An evidence pack you can send, without a week of scrambling first.
When the model gets something wrong, "who catches it" is a pause.
Named approval points, with thresholds and a record of who decided.
And who does what

We tell you which parts aren't ours.

Every plan splits three ways. If we billed for all of it, the review would stop being honest.

We do this

Governance and oversight

  • Policy and approval thresholds
  • Human oversight design
  • Record and logging structure
  • Disclosure and content marking
  • Staff training and evidence
  • Vendor assessment
Your team does this

Operational changes

  • Applying the policy day to day
  • Owning each system on the register
  • Running the approval steps we design
  • Flagging new tools before they spread
Your vendor does this

Inside their product

  • Changes within their software
  • Their own conformity documentation
  • Contract terms on data and training
  • We write the questions you put to them
The practice

We don't have anything to sell you afterwards.

Most AI advice comes from someone holding a product — a partnership, a margin, a licence to move. The recommendation and the revenue point the same way.

If the right answer is to switch a system off, drop a vendor, or leave a process manual, that's what the report will say.

It's why we publish fixed prices, and why every plan says plainly which parts are ours.

A quiet working office.
Before you ask

The questions we get on every first call.

Are you a law firm?

No, and we say so before anyone asks. We establish which obligations apply to which systems and what to do about them. For a formal legal opinion we introduce a qualified lawyer by name.

Can you certify that we're compliant?

Nobody can, and be wary of anyone who says otherwise. What you can have is a reasoned position on every system and evidence that you acted on it — which is what auditors and enterprise customers actually ask for.

We already have a lawyer and a data protection person. What's different here?

They work on the legal position. We work on the systems, so that position is true in practice. Most companies have someone who can read the regulation and nobody who can map it onto the tools staff actually use. That gap is the job.

We're only 40 people. Is this really for us?

The duties already in force have no size exemption, and smaller companies tend to have more unmanaged use, not less — nobody's job is to notice. If your exposure is smaller than you feared, the report says that too.

What if the review finds we're badly exposed?

Then you found out from us rather than from a candidate, a customer or a regulator. Findings are sequenced by what's urgent and what's cheap, and nothing in the report leaves your organisation.

Have you done this before?

Supvisor is a new practice and won't pretend otherwise — hence the founding rate and the absence of logos. What isn't new is the work: building AI systems that run in production, and knowing where they go wrong when nobody is watching. If you want a long client list, we're the wrong firm this year.

Do you actually build anything, or only review?

We build. The review decides what's worth building; most of what follows is taking those cases to production, with approval steps and records built in. We are paid for the work, not for how much AI you end up running — which is why the review is as willing to say stop as build.

How much of our time does it take?

Five to eight interviews of about 45 minutes, your tool and contract records, and one workshop per department. Beyond that, the three weeks are ours.

Get in touch

Start with a conversation.

Thirty minutes, no preparation needed. Tell us what you're running and we'll tell you plainly whether there's a problem worth paying to solve.

Book a call

Or email contact@supvisor.ai

No logos on this page yet

We'd rather say that plainly than fill the page with badges we haven't earned. The first two engagements run at the founding rate.

Passing this to a colleague?

Most decisions here need more than one person.

Supvisor — AI review A three-week review: an inventory of every AI system we operate, a verdict on which are worth scaling and which should stop, which EU AI Act duties apply, and a 90-day plan. Timing matters — transparency duties applied from 2 August 2026 and extend to systems already running on 2 December 2026. Implementation afterwards is optional. €9,500, or €2,500 as one of their first two clients. supvisor.ai · contact@supvisor.ai
Copied