What happens in an AI regulatory readiness workshop?

A half-day leadership session that lists the AI in use, maps where it carries risk, and leaves you with a one-page policy, team rules and an action plan.

What the workshop is for

Most AI risk in a business comes from everyday use: tools nobody approved, client data pasted into them and output nobody checked. Regulation such as the EU AI Act matters too, but the first job is to see what is really happening. A regulatory readiness workshop brings the leadership team together for half a day to get that picture and agree what to do about it.

Go Wisely runs this as the Regulatory Readiness Audit. It can be a working session with the leadership team or a lighter audit carried out for you, depending on how much time your leaders can give.

What the half day covers

  • AI inventory: Which AI tools are in use, where and by whom, including AI features inside software you already pay for. Most businesses find more than they expected.

  • Risk mapping: Where that use carries exposure, including under the EU AI Act rules that already apply, such as the transparency duties and banned practices.

  • Governance position: A one-page AI policy in plain English that you can adopt, adapt or pass to your legal advisers.

  • Team guardrails: Practical rules for daily use. Each one says what to do, who owns it and what gets checked before AI output is used.

  • Action plan: What to do and in what order, sized for your business and not for a corporation.

Who should be in the room

Keep the group small. The owner or managing director should attend, with whoever looks after operations, people and IT. If you have someone responsible for data protection or compliance, include them. Four to six people is usually enough to make decisions on the day.

How to prepare

You do not need a finished inventory beforehand, but a little groundwork makes the session go further.

  • Ask around: A short, no-blame question to staff about which AI tools they use will surface most of what is out there. See what shadow AI is and how to spot it.

  • Check your EU links: Note any customers, staff or operations in the EU, and any work whose output is used there. This decides how far the EU AI Act reaches you, as explained in whether the EU AI Act applies to UK businesses.

  • Bring existing documents: Any IT, data protection or acceptable use policies you already have.

What it does not do

Go Wisely is not a law firm, and the workshop does not give legal advice or a compliance certificate. It gives your leadership team and your legal advisers a clear, shared starting point, so any legal review is quicker and more focused.

Where it takes place and what follows

The workshop runs in person at your offices or by video call. Go Wisely is based in Essex and works with businesses in London, the East of England and across the UK.

A policy only works if people use it. Many businesses follow the workshop with a two-hour or half-day training session that takes the team through its own guardrails, using their tools and examples from their work. Ongoing support is available if you want someone to keep the policy current as the rules change.

Want to talk this through?