Nobody is winning enterprise AI yet
Pilots have produced tools, not advantage. The gap is operational: what to build, who has the judgement to run it, and who owns it in production. Five lines of work close that gap; start where the pain is.
Where each line sits
Four delivery stages; ORCA is the platform several of them run on. The market read behind this page: Nobody is winning enterprise AI yet
Advisory
Most AI strategy is vibes: confident, decisive, and unexplainable six months later. We do the other kind. Decisions made on evidence, an architecture that survives audit, and a plan that names what you will not build.
Talk about advisory| Where it fits | Before commitment. When there is pressure to act and no agreed view of what is worth doing. |
| What you get | A readiness assessment, a target architecture, a sequenced plan with the dependencies named, and governance designed in framework terms: an ISMS aligned to ISO/IEC 27001, and your EU AI Act position mapped, provider or deployer, before you inherit the obligations. |
| What it is not | A strategy deck that ends at the recommendation. Every engagement names who does the next thing and when. |
| Typical shape | Four to eight weeks, small senior team, working alongside your people rather than interviewing them. |
Training and enablement
Everyone is an agent operator now, trained or not. The gap is not tool access, it is judgement: what to delegate, what to verify, what to refuse. We build that judgement in your team, on your systems, on work that was going to be done anyway.
Talk about training and enablement| Where it fits | When the capability has to live in your organisation, not in a supplier relationship. Article 4 of the EU AI Act makes AI literacy a legal obligation for anyone operating AI systems; we build the judgement, not just the compliance tick. |
| What you get | Cohort programmes for practitioners, working sessions for the people who approve and defend this work, and coaching embedded in live delivery. |
| What it is not | A course. Teaching happens against your systems and your data, on work that was going to be done anyway. |
| Typical shape | Runs alongside a delivery engagement so the learning has something real to attach to. |
Managed services
Models drift, data changes, and the engineer who built it moves on. Production AI is an operations discipline, not a launch event. We run what has been built to defined service levels: drift watched, incidents owned, reporting you read yourself.
Talk about managed services| Where it fits | Once a system is in production and the question changes from can we build it to who is on call. |
| What you get | Model performance monitoring, drift detection, and evaluation reruns before any model version change: when a provider deprecates a model, your evaluation set decides the replacement, not the changelog. Incident response, capacity planning, and reporting you read yourself. In AI Act terms, this is Article 72 post-market monitoring, run as a discipline rather than filed as a plan. |
| What it is not | A monthly PDF. You see the same operational picture we do, continuously. |
| Typical shape | Service levels agreed in advance and written into the contract, with defined response times by severity. |
Outsourced operations
Some functions you want outcomes from, not headcount for. We operate the function end to end: scope, service levels and escalation agreed up front, the operating record visible to you the whole time.
Talk about outsourced operations| Where it fits | When you need the outcome and do not want to build the team to produce it. |
| What you get | A defined function operated to agreed scope, service levels and escalation, with the operating record visible to you throughout. |
| What it is not | A staff-augmentation contract measured in bodies. We are measured on the outcome. |
| Typical shape | Longer term by nature, with review points and an exit procedure documented from the start. |
Service levels and escalation
Written into the contract rather than described in a proposal. Targets are agreed per engagement; the structure below is the shape every managed and outsourced agreement takes.
How severity is judged
By impact on your operation, not by how hard the fix looks to us. A cosmetic defect that blocks a regulatory submission is a P1.
Severity is agreed at raise time, and either side can escalate a disagreement about it without waiting for the underlying issue to be resolved.
If we miss an agreed target, it is reported to you in that period's review whether or not you noticed. We do not wait to be asked.
| Severity | Definition | Response |
|---|---|---|
| P1 | Service unavailable, or output is materially wrong and in use | Immediate, continuous until mitigated |
| P2 | Degraded, or a control is not operating as designed | Same working day |
| P3 | Defect with a workaround, no control impact | Next working day |
| P4 | Question, request, or planned change | Scheduled |
| First | The engineer on call, who owns it until it is handed over deliberately |
| Then | The named engagement lead, who can commit resources without asking |
| Then | A director, reachable by you directly. There is no gatekeeping layer. |
| Always | A written post-incident record for anything at P1 or P2, shared whether or not you request it |
What we do not do
Scope boundaries stated up front. A firm that claims everything is a firm that has thought carefully about nothing.
We do not sell staff by the day
We are measured on outcomes and service levels. If what you need is bodies against a rate card, another firm will serve you better and we will say so early.
We do not build frontier models
We build the systems, controls and operations around models that already exist. If your problem genuinely requires training a foundation model, that is a different kind of firm.
We do not take work we cannot staff properly
Capacity is finite and we would rather decline than spread a team thin across an engagement that deserves better.
We do not use your data to improve anything outside your engagement
What we learn about your systems stays with your systems. Method generalises; your data does not travel.
ORCA
Our governed AI platform. Offered as a service, and the substrate a lot of our delivery runs on.
ORCA handles the parts of an AI system that are tedious to build and expensive to get wrong: provenance, access control, personal data handling, approval flow and audit. It is the platform we built for our own practice, and we run our own business on it.
It is one offering among the five, not the reason the others exist. Plenty of engagements never touch it.
What ORCA doesYou are never locked into it. If an engagement uses ORCA and you later want out, the exit procedure is the same one we document for everything else.
- OpenAI
- Anthropic
- Google Gemini
- Meta
- Mistral AI
- xAI
- DeepSeek
- Cohere
- Qwen
- Ollama
- Hugging Face
- NVIDIA
the model layer we work across · routing, evaluation and fallback Marks are the property of their owners, shown to describe our own stack. No endorsement, sponsorship or partnership implied.
Tell us what you are accountable for.
The useful first conversation is usually about the thing that worries you, not about our capabilities. If it turns out we are the wrong firm for it, we will say so.
One reply from a person who has read what you sent.