Controls built in, not bolted on.
How North Axiom governs the AI it builds, deploys and advises on.
Regulation has arrived
The EU AI Act is now in force in stages, with substantial penalties. The UK takes a principles-based approach through existing regulators. Both expect demonstrable control.
Of global turnover, the maximum EU AI Act penalty for prohibited practices.
DLA Piper, EU AI Act obligationsWhen the European Commission’s enforcement powers over general-purpose AI providers apply.
DLA Piper, EU AI Act obligationsOf firms report an AI-related incident.
McKinsey, The State of AI in 2025Eight controls
Applied to every system we build or operate.
AI governance
Named accountability, an approval route and a register of systems in use.
Human oversight
Explicit decision rights, approval thresholds and escalation paths.
Data
Lawful basis, minimisation, provenance and retention.
Security
Access control, secrets management, logging and monitoring.
Privacy
Personal data kept out of models and prompts unless there is a lawful basis.
Evaluation
Testing before release, and continuous monitoring after it.
Third parties
Model and vendor assessment, and contractual control of data use.
Regulatory alignment
EU AI Act, UK GDPR and sector rules. Fill in: confirm which regimes apply to North Axiom itself
The UK position
Principles-based rather than a single statute.
No comprehensive UK AI statute
AI is managed under existing rules on governance, resilience and data.
Financial services
Three quarters of UK financial services firms already use AI, and most have a named accountable person for it.
Discuss AI governance
Ask us how we would govern AI in your environment.
Information on this website is provided for general information only and does not constitute investment, legal, tax or accounting advice.
AI-generated and AI-assisted outputs require controls and appropriate human review. Accuracy, completeness and suitability are not guaranteed.
