EU AI Act Governance Starter Kit: Get Compliant Without the Legal Maze
Pre-built policies, templates, and procedures to comply with the EU AI Act. Designed for SMEs who need governance that works — not 200-page documents nobody reads.
The EU AI Act is Here — But Compliance Doesn't Have to Be Painful
The problem with most compliance approaches
- Legal firms charge €20k+ for generic policies you can't actually use
- Templates online are either too vague or written for enterprises
- You're stuck between "do nothing and hope" or "hire a compliance team"
- Nobody explains it in plain language — just legal jargon
- You don't know if you're high-risk, limited-risk, or minimal-risk
What you get instead
- Templates written for SMEs — practical, not academic
- Plain language policies your team can actually follow
- Self-assessment tool to classify your AI use cases
- Implementation timeline (what to do first, second, third)
- Audit-ready documentation from day one
What's in the Kit
1. Data Classification Policy
4-level system (Critical, Confidential, Internal, Public) defining what data can be used in AI tools, what requires anonymization, and what's off-limits. Includes quick-reference checklist for employees.
2. Approved AI Tools List
Vendor due diligence checklist covering DPAs, data storage location, training opt-outs, encryption, and subprocessors. Plus template for tracking approved vs. prohibited tools.
3. Human-in-the-Loop Framework
Decision matrix for when AI can act autonomously vs. when human approval is required. Includes escalation procedures, override protocols, and accountability assignment.
4. Logging & Audit Procedures
What to log, how long to keep it, and what constitutes an auditable decision. Includes sample log templates and retention schedules compliant with GDPR.
5. AI Literacy Training Plan
Onboarding curriculum for employees: what AI is, what it isn't, how to use it responsibly, and what to escalate. Includes quiz templates and certification tracking.
6. EU AI Act Self-Assessment
Risk classification tool to determine if your AI use cases are prohibited, high-risk, limited-risk, or minimal-risk. Maps directly to compliance requirements for each category.
7. Implementation Timeline
Week-by-week rollout plan: policy approval, training schedule, tool certification, audit setup. Designed for teams of 5-50 people — realistic timelines, not fantasy deadlines.
Customization Session
90-minute workshop with Coen to adapt templates to your business, identify gaps, and answer questions. Your policies are ready to sign, not half-finished drafts.
Sample: Data Classification Quick Reference
What Can You Put Into AI Tools?
This is what your team gets — simple, visual, actionable.
| Data Type | Example | AI Usage? |
|---|---|---|
| Customer names | John Doe, ABC Inc | ❌ NO |
| Personnel data | Salaries, sick days | ❌ NO |
| SOPs (anonymized) | "Invoicing process" | ⚠️ DPA only |
| Excel formulas | SUM, VLOOKUP | ✅ YES |
| Marketing copy | Website drafts | ✅ YES |
| Public research | Wikipedia, papers | ✅ YES |
Rule of thumb: If you're not sure, assume 🔴 CRITICAL and ask your data protection contact. Better safe than fined.
Who This Is For
✅ You're a good fit if:
- You're using AI tools (ChatGPT, Copilot, etc.) and need governance
- You're planning to deploy AI agents or automation
- You need to show compliance to clients or auditors
- You want policies that your team will actually follow
- You have 5-50 employees (SME sweet spot)
❌ You're NOT a good fit if:
- You're not using AI yet (get the Diagnostic first)
- You need enterprise-scale governance (500+ employees)
- You're deploying high-risk AI systems (medical, biometric, etc.) — you need specialized legal counsel
- You want someone else to "handle compliance" for you — this is a DIY kit with expert guidance
Pricing & Packages
Templates Only
€2,500
For businesses that can adapt templates themselves
- ✓ All 7 policy templates (Word/Google Docs)
- ✓ EU AI Act self-assessment tool
- ✓ Implementation timeline template
- ✓ Quick-reference checklists
- ✓ 30 days email support
Best for: Teams with HR/legal resources who just need a starting point
Customized Kit
€3,800
Templates adapted to your business
- ✓ Everything in Templates Only, plus:
- ✓ 90-minute customization workshop
- ✓ Policies pre-filled with your company details
- ✓ Risk assessment for your specific AI use cases
- ✓ Approved tools list customized to your stack
- ✓ 60 days support + implementation Q&A
Best for: Most SMEs — you get policies ready to sign
Full Implementation
€5,000
We help you roll it out to your team
- ✓ Everything in Customized Kit, plus:
- ✓ Training sessions for your team (up to 3 sessions)
- ✓ Vendor DPA review (up to 5 tools)
- ✓ Audit log setup & compliance dashboard
- ✓ Quarterly compliance check-ins (6 months)
- ✓ Priority support
Best for: Businesses with limited internal compliance resources
Add-on: Annual compliance review + policy updates for €1,200/year. Keeps you current as the EU AI Act evolves.
Common Questions
Is this legally binding / will it hold up in an audit?
The templates are based on EU AI Act requirements and GDPR best practices. However, we're not a law firm — if you're deploying high-risk AI systems (medical devices, biometric surveillance, etc.), you need specialized legal counsel. For typical SME use cases (ChatGPT, Copilot, basic automation), these policies are solid.
How long does implementation take?
Customized Kit: 2-3 weeks from workshop to signed policies. Full Implementation: 6-8 weeks including team training and rollout. We give you realistic timelines, not promises we can't keep.
What if regulations change?
The EU AI Act is still evolving. With the annual review add-on (€1,200/year), we update your policies as regulations clarify. Without it, you get 1 year of minor updates included, then you're on your own.
Can I use this if I'm outside the EU?
If you process EU citizen data or operate in EU markets, yes — you need EU AI Act compliance regardless of where you're based. If you have zero EU exposure, these policies are still solid governance, but overkill for your legal requirements.
Do you offer this in Dutch or German?
Yes. All templates are available in EN, NL, and DE. Workshop can be conducted in any of those languages.
What if I just want one policy, not the whole kit?
We don't sell individual templates — compliance doesn't work that way. The policies are interdependent (e.g., data classification drives approved tools, which drives human-in-loop rules). Piecemeal compliance is fake compliance.
Get compliant without the legal drama
Policies that work. Templates you can use. Guidance from people who actually build AI systems.
Book Your Customization Workshop 📄 Not ready yet? Download the free Playbook first