Governing AI you did not build
The EU AI Act, model risk, and the models already running in your product and your operations. Wizard gives you a register of what is in use, who owns it, and what it is allowed to do.
Request a demo or assess your compliance maturity. No email needed to start the assessment.
Nobody knows the full list
Most organisations governing AI do not have an AI problem yet. They have an inventory problem. Models arrive through vendors, features and individual teams, and no single list exists.
The AI Act asks you to classify systems by risk, know whether you are provider or deployer for each, and maintain documentation proportionate to that. All three assume you know what is in use.
Meanwhile the obligations attach to systems that change without a release note, because the vendor updated a model behind an API.
Frameworks exist, systems do not
The guidance is abundant and the tooling is not.
There is no shortage of AI Act commentary. There is very little that helps you hold a register of systems, classifications and owners that stays current.
AI governance is treated as separate.
It is the same discipline as everything else: know what you have, decide who owns it, document why, keep it current. Building a separate AI system repeats work already done for security and privacy.
Classification is not a one-off.
A system's risk classification changes when its use changes. Something classified as limited risk becomes high risk when a team applies it to a hiring decision.
A register that survives contact with reality
An inventory of AI systems.
Owner, purpose, classification and provider or deployer status for every system in use, including the ones that arrived through a vendor.
Risk assessments attached to systems.
Linked to the systems they cover, with review cycles, so a change of use triggers a reassessment rather than sitting unnoticed.
The same structure as your other obligations.
AI governance extends the system you already run for security and data protection instead of starting a parallel one.
Evidence that accumulates.
Decisions, classifications and approvals recorded as they happen, so documentation is a by-product of governing rather than a project.
Where Wizard fits, and where it does not
Against doing nothing yet.
Defensible if the AI Act does not apply to you and no client is asking. Most organisations in this position discover otherwise through a customer rather than a regulator.
Against a spreadsheet.
Genuinely fine for a handful of systems with one owner. It fails at the point where systems are added by people who do not know the register exists.
Against a dedicated AI governance tool.
A small number exist and some are good. The question is whether AI is your only new obligation, or one of several, and whether you want a fourth system alongside the three you already maintain.
What Wizard is not.
It does not classify your systems for you, and it is not legal advice on the AI Act. It holds the classification you decide and keeps it current.
Built by people who have been audited, and who have audited others
Wizard was designed by people who spent years building these systems inside regulated organisations before they built software for them. What follows is their professional background. These were consultancy and audit engagements, not Wizard implementations, and we mention them because the design decisions in this product came directly from that work.
Eoghan Kenny, Co-Founder and CEO
Over twenty years in governance, risk and compliance. His recent focus is AI: running compliance evaluations, drafting AI governance policies and operationalising them, and helping organisations get to grips with the EU AI Act. That work spans clients including Alto Health, OneTouch Health and Unobravo, and Horizon projects for Thesl.
Derek Mizak, Co-Founder and CTO
Over thirty years across cybersecurity, audit and systems architecture, and a certification body auditor for Certification Europe (now Amtivo). He holds an MSc in Digital Investigation and Forensic Computing from UCD, is a certified penetration tester, and leads 3Be's internal AI research and development.
Dominic O'Toole, Co-Founder and CPO
Over twenty years building enterprise software, including at IBM and Fidelity.
None of this makes Wizard the right fit for every organisation. It does mean the people who designed it have implemented, maintained and audited the systems it manages.
Common questions
Does the EU AI Act apply to us?
That depends on what your systems do and whether you are a provider or a deployer of them. We are not the right people to give you a legal answer on that. What we can help with is knowing what you have, so the question can be answered at all.
Does Wizard classify our AI systems for us?
No, and it should not. Classification under the AI Act depends on how a system is used, which is a judgement your organisation makes. Wizard holds the classification you decide, in a register of AI systems with owners and linked risk assessments, and keeps it current as use changes. The register and the links are configured, not automatically populated.
We only use AI through vendors. Does this still apply?
Usually yes, as a deployer. Obligations attach to use as well as to building, and vendor-supplied models are the ones most likely to be missing from an inventory because nobody remembers adding them.
How does this relate to ISO 27001 or GDPR work we already do?
It is the same discipline applied to a new obligation. Ownership, risk, documentation and review. Running it in the same system is the point.
Where is our data held?
Microsoft Azure, with enterprise-grade access controls. Our sub-processor list and data processing agreement are published on the site.
What does it cost?
Standard plans start at 600 euro per month billed annually for up to 30 active users. Consultant accounts are free and do not count toward the limit.
What we have written about AI governance
- AI Governance Challenges: Why Most Organisations Get It Wrong
- How to Perform an AI Risk Assessment in Practice
- Provider vs Deployer in the EU AI Act
- AI Compliance Risks: What Organisations Often Miss
- How to Use AI in GRC (Without Losing Control)
See what a working AI register looks like
Request a demo and we will walk through how this works for the systems you already have. If you would rather see where you stand first, the Health Check takes five minutes. Request a demo or start the Health Check.