ai-governence-banner

 An AI Governance Consultancy for UK Businesses

AI should be the tool, not the objective. If your business is using AI, planning to, or being asked hard questions about it by customers, boards or regulators, you need senior people who can tell you where you stand and what to do next. That is what we do.

We are an AI governance consultancy supporting and advising UK businesses.You work directly with the principals responsible for your engagement. No offshoring, no frameworks handed over without context.

Advising business owners and leaders across the UK, Australia, New Zealand, Canada, Sweden and the Philippines. Members of the IAPP.

The Consultancy UK Businesses Actually Need

Most AI consultancies fall into one of two camps. The large generalist firms sell transformation programmes and staff them with delivery teams. The technical boutiques build models and integrate systems. Neither is set up to answer the question most UK businesses are actually asking, which is: is what we're doing with AI defensible, and where are we exposed?

That question is a governance question, not a transformation question or a build question. It sits across regulation, privacy, procurement, risk and internal accountability. Answering it well takes senior people who have done it before, not a methodology and a team of analysts.

Governance is not a checklist, but a strategy. Ours starts with the business you actually run, the AI you have or are about to bring in, and the regulators and customers you have to answer to.

What Working With Us Looks Like

We start with your situation, not a framework

Every engagement begins with a conversation about what you are doing with AI, what you are worried about, and what you have already put in place. We do not just hand you a template but suit the solution to your needs.

Scope is set to the decision you need to make

 Some clients need a short piece of work to answer a specific question. Others need a standing advisory relationship. We shape the engagement around the decision, not the other way round.

We hand over something usable

You leave the engagement with clear positions, documented decisions, and the people in your business who need to own it knowing what they own. Not a slide deck that sits on a drive.

What We're Brought In To Do

Four services sit under the consultancy. Most engagements draw on more than one.

AI governance advisory

Standing or project-based advisory on how your business governs AI. Framework design, oversight structures, board reporting, policy architecture. For businesses that need senior input on the shape of their AI programme rather than a single deliverable.

Read more about AI governance advisory

Fractional Chief AI Officer / Data Protection Officer

Senior AI and privacy leadership on a fractional basis. For businesses that need a named accountable person for AI or data protection but do not need or want to hire full time at that level.

Read more about the fractional service

AI governance and privacy review

A structured review of where your business stands on AI and data. Covers the AI you are using, the AI embedded in tools you have not chosen deliberately, the data flowing through it, and the gaps between what you are doing and what you should be able to defend.

Read more about the review

Document and policy review

Review and drafting of the documents your AI programme runs on. AI policies, acceptable use policies, Data Protection Impact Assessments (DPIAs), supplier contracts, board papers, customer-facing statements. Written to hold up to a regulator, a customer or a board.

Read more about document and policy review

Meet the Consultants

Hyplon is Marnie McLeod and Roger McCluskey. Between us we have well over two decades of experience across AI governance, data protection and regulated industries in the UK and internationally. We are both members of IAPP. We advise boards, general counsel, and CTOs on AI decisions that carry real consequence.

You work with us directly. That is not a positioning line, it is how the business is set up.

How UK Regulation Shapes What We Do

The UK's approach to AI is regulator-led rather than statute-led. There is no single UK AI Act. Existing regulators, including the ICO for data protection, the FCA for financial services and the MHRA for medical devices, apply their existing powers to AI within their remit. That means what a UK business has to do about AI depends on the sector it operates in and the data it handles.

UK GDPR still applies to any AI system that processes personal data. The ICO has published specific guidance on AI and data protection, and enforcement action on AI has already happened.

The EU AI Act reaches UK businesses that place AI systems on the EU market or whose AI output is used in the EU. Trading into the EU means EU AI Act exposure, regardless of where the business is based.

ISO 42001 is the international standard for AI management systems. It is a framework businesses can use internally, and one they can certify against. Which route makes sense depends on why you are doing it.

We keep this section short deliberately. The full picture sits on our AI Governance page.

Frequently Asked Questions

Let’s Talk

lets-talk
Marnie

Send us a message or book a free 20 minute call. You'll leave with a clear read on where your business is exposed, what's working, and where a consultancy would help. No pitch and no obligation.