Regulation became
infrastructure.
We build yours.

A specialist consultancy that turns the EU AI Act, GDPR and CCPA/CPRA into a running control environment — inventoried, classified, evidenced, and tested in production.

Abstract illustration of AI governance infrastructure: a control grid, neural pathways, a classical column and scales of justice in warm oxblood and cream tones

The obligation ledger

0 obligations are already in force. The next binds in 0 days. 0 dates below have moved. The obligations behind them did not.

Verified 9 August 2026
Re-checked quarterly

    The situation

    The Digital Omnibus deferred the high-risk obligations to December 2027 and Colorado repealed its AI Act before it ever took effect. The common reading is that the pressure came off.

    It did not. Nothing in the substance was withdrawn. Risk management, data governance, technical documentation, logging, human oversight and post-market monitoring are all still there, worded as they were. What moved was the date on which a regulator may ask to see them.

    What actually changed is that there is now runway to build a program properly rather than assemble one under deadline. Most companies will spend that runway doing nothing, and will arrive at the new dates with the same problem and less time.

    Method

    • 01

      Inventory

      Every model, vendor feature and automated decision path in one register, with owner, purpose, data categories and the jurisdictions it touches. Nothing downstream is reliable without it.

    • 02

      Classify

      Role and risk tier determined per system against the actual statutory tests, recorded with the reasoning, and locked once a determination has been referred.

    • 03

      Control

      A control set mapped to the obligations that apply, expressed as things people do and systems enforce — not a document set that describes an intention.

    • 04

      Evidence

      Each control produces dated, attributable evidence as a by-product of operating. Assessments, model cards, logs and oversight records are artifacts, not exercises.

    • 05

      Sustain

      Intake screening, a scheduled obligation calendar, committee records and an audit trail, so the program survives the people who built it.

    Policy is not step one. A policy written before the control set exists is a guess about scope, and it gets rewritten within six months.

    Engagements

    Fixed fee. Published, so the wrong engagement is ruled out before a call.

    3–4 weeks

    AI & Data Estate Diagnostic

    A complete register of systems, roles and risk tiers, with the gaps ranked by exposure.

    from $22,000

    4–6 weeks

    Article 50 Transparency Conformance

    Disclosure, labelling and marking taken to production across every user-facing surface.

    from $35,000

    6–10 weeks

    CCPA Risk Assessment Program

    A repeatable assessment method, the legacy backlog cleared, and an attestable register.

    from $45,000

    6–8 weeks

    ADMT Readiness

    Notice, opt-out and explanation paths designed into the decision systems that need them.

    from $40,000

    10–16 weeks

    ISO/IEC 42001 Readiness

    A management system built to pass certification audit and to carry the EU AI Act evidence.

    from $60,000

    ongoing

    Fractional AI Governance Lead

    Named accountability in the room — committee, intake, regulator correspondence, reporting.

    from $9,500/mo

    Why Numé

    Specialists, not generalists

    AI governance and data protection are the whole practice. We do not staff this work from an adjacent capability and learn the regime on your budget.

    Artifacts, not advice

    Every engagement ends in things a regulator, an auditor or an acquirer can read: registers, assessments, control evidence, dated determinations.

    We tell you where our remit ends

    Where a question is legal rather than operational, we say so and refer it. That boundary is stated in writing at the start of every engagement.

    Scope of practice

    Numé is a regulatory compliance consultancy. We are not a law firm, we do not provide legal advice, and no lawyer-client relationship arises from working with us.

    Analysis produced by a consultancy carries no legal privilege. Anything we write may be discoverable. Where you need a candid assessment of exposure — the kind that is only useful if it can be written down plainly — commission it through your own counsel, who can hold it under privilege, and use us to build and evidence the controls underneath it.

    In a typical engagement four to eight determinations are referred to counsel rather than settled by us. We record each referral, the reasoning and the answer received, and we take no referral fee from any firm.

    Read the full statement

    Start with the diagnostic.

    Three to four weeks, fixed fee, and a register of every system with its role, tier and gaps ranked by exposure. If the conclusion is that you do not need us yet, that is written down too.

    Book a 30-minute call

    Principal

    Dr. John N. Adu

    Ph.D. · LL.M. · MBA
    English and French
    San Francisco

    Academic legal qualifications. Not admitted to practise law in any jurisdiction, and Numé does not provide legal services.