AI advisory
Whether to buy it, which one, and who is accountable when it is wrong.
The people best placed to explain AI to you are, almost without exception, selling it.
The demonstrations are uniformly impressive, which is the difficulty. Every vendor claims the same capabilities, the category is barely two years old, and few buyers have seen enough implementations to distinguish a system doing the difficult part from a prompt wrapped around somebody else's model.
We advise on the decision and take no part in what follows. We build no AI, resell no platform, and are paid by you alone.

The questions that reach us
- Should we be doing this at all, for this particular process? Plenty of AI projects are a broken workflow that a model will run faster rather than fix. That answer costs far less before the contract than after it.
- Which vendor? Assessed against your constraints, not the feature matrix the category leader wrote.
- Are we ready? Data, process, and a named person to own it once it is live. This is a finding about you, and we deliver it straight.
- What do we tell the board? Something that survives being read by an auditor.
How we assess a vendor
- We establish whether the difficult part is theirs. The usual answer is a retrieval layer and a prompt over a foundation model, which can be perfectly worth buying — though not at the price proprietary work commands.
- We ask what happens when it is wrong, and who is accountable. An error rate that is fine for drafting a first pass is not fine for anything touching money, and that belongs in the contract rather than the sales call.
- We ask for an evaluation against your data rather than their benchmark. A refusal is itself an answer.
- We read what the agreement says about your data — where it goes, whether it trains a model — as opposed to what the sales engineer said.
- We check what happens on renewal, on acquisition, and on the way out. Including whether you can get your data back in a form anyone can use.
Governance you will actually follow
- Most AI governance material is written for organisations a hundred times the size of the one being asked to adopt it. So it gets adopted on paper and ignored in practice, which is worse than nothing: it creates the appearance of control.
- We write the short version. What this deployment can and cannot do, who signs off a change, what gets logged, and who to call when it produces something wrong.
- Short enough that the people bound by it will read it, which is the only test that matters.
- We are not lawyers. Where the EU AI Act applies we will tell you how the system is likely to be classified and what that implies — then tell you to get counsel.
When we advise against it
- Your own team cannot describe the process you want automated. A model will not resolve that ambiguity; it will reproduce it faster and with more confidence than anyone in the room currently has.
- Nobody will own the system once it is live. An unowned deployment degrades quietly, and the first person to notice is usually a customer.
- The vendor will not let you evaluate against your own data. We have yet to encounter a good reason for that.
- A deterministic system would do the job better and cost less. This is a more common conclusion than the market currently admits, and we have no implementation revenue riding on which way it goes.
What you get
01
A ranked recommendation, with the strongest case we can make against our own pick.
02
What each vendor is actually doing, and what that should cost.
03
A straight read on whether your data, process and ownership are ready — before the invoice.
04
A governance document short enough to be read.
Questions
- What is an AI readiness assessment?
- An evaluation of whether an organisation can successfully adopt an AI system before it commits to one. It examines data quality and access, whether the process to be automated is well enough understood to hand over, who will own the system once it is live, and what the organisation will do when it produces something wrong. The failures we have seen came from these, not from the technology.
- What is an AI governance framework?
- The written rules for how an organisation builds, buys and runs AI systems: what each deployment is permitted to do, who approves a change, what gets logged, how outputs are reviewed, and what happens when something goes wrong. A useful one is proportionate to the deployment — short, specific, and read by the people it binds. Published frameworks tend to be written for very large organisations, then adopted on paper and ignored in practice.
- What is an AI audit?
- A review of an AI system already running: what it does, how often it is wrong, whether the controls on paper are the controls in operation, where data flows, and whether the deployment still matches what was approved. Unlike a pre-purchase assessment, there is real usage to examine — which beats any vendor documentation.
- What is AI due diligence?
- Establishing what an AI product or company is really built on before you commit — whether the defensible work is theirs or a model provider's, what the system does when it fails, what the data rights are, and how the economics behave at scale. Buyers use it before signing; investors and acquirers use it before a deal.
- How do you evaluate an AI vendor?
- By establishing what they are doing rather than what they demonstrate. We ask what happens when the system is wrong and who is accountable, where your data goes and whether it trains a model, and for an evaluation against your data rather than their benchmark. The usual finding is a thin layer over a foundation model, priced as though it were proprietary. Still worth buying sometimes. At a different number.
- Do you build AI systems or resell a platform?
- Neither. We advise on the decision and take no fee, commission or rebate from any vendor, and we hold no reseller agreements. The only software nac builds is its own products. That is the whole reason to hire an independent adviser rather than accept a systems integrator's recommendation for free.
- Can you help with the EU AI Act?
- We will tell you how a specific system is likely to be classified and what controls follow from that, and we build the governance around it. We are not lawyers. Where you need counsel we say so rather than improvise.
Track record
We build and run our own AI products, which is what makes the assessment worth having. We build none for clients. See Creations in the portfolio.
The other services
Technical procurement
Deciding what to buy, before a vendor decides it for you.
Technical due diligence
What you are actually buying, in plain language.
Forward deployed engineering
We help you pick the right ones, and we are not one of them.
Technical leadership due diligence
The technical read on the person you are about to make CTO.
Where to next
Tell us what you are deciding.