noēsiss

Strategic AI consulting · EU AI Act · GDPR

Every clean balance sheet can hide something.

Run the lens across the numbers. The problems you can't see are the ones that cost you: fines, failed audits, automation that never ships. Noēsiss either finds them first, or deploys systems that never need to be found.

Move the lens across the statement

Statement of financial position€ · audited

Assets

Cash & equivalents€ 2,140,000

Liabilities & Equity

Trade payables€ 2,880,000
Provisions€ 410,000
Shareholders' equity€ 12,700,000

Off balance sheet

Regulatory radar

We watch the laws so you don't have to. Hover a milestone.

CriticalAI Act · Feb 2025

Prohibited AI banned

Unacceptable-risk systems like social scoring and untargeted face-scraping are banned EU-wide. Using one is an immediate breach.

The price of getting it wrong

The fines are not theoretical.

AI Act · GDPR

Two regulations now set the ceiling for almost every European company that touches data or AI. The penalties are deliberately large enough to hurt, and they are levied on global turnover, not local profit.

EU AI Act

€35M or 7%

of global annual turnover, whichever is higher

Top tier: using a banned ('unacceptable-risk') AI system.

AI Act · high-risk

€15M or 3%

of global annual turnover, whichever is higher

HR, credit scoring, biometrics, critical infrastructure.

GDPR

€20M or 4%

of global annual turnover, whichever is higher

Unlawful processing, no valid legal basis, weak security.

How exposed you already are

  • A 200-person company using an AI CV-screenerHigh-risk under the AI Act: needs conformity assessment plus a DPIA, or faces up to €15M.
  • A retailer running a customer-service chatbotMust disclose it's an AI (Art. 50) and document its data use, or risk GDPR action.
  • Any firm buying an AI tool from a vendorYou stay liable as the deployer. 'The vendor handles it' is not a defence.

Most companies are already exposed and don't know where. That's the gap we close.

See how we fix it →

Services

Four disciplines. One lens.

Every engagement draws on the same four disciplines, whichever one brings you to us, and ends with a system your own team runs.

  1. 01

    EU AI Act compliance

    We classify where each of your systems falls and produce the documentation regulators expect, so you ship AI your customers can trust.

    • Risk classification (Prohibited → High → Limited → Minimal)
    • Conformity assessment & technical documentation
    • Human-oversight and logging design
    • GPAI obligations & FRIA
  2. 02

    GDPR alignment

    Compliance as a design constraint, not a paperwork tax. We make data protection part of the architecture.

    • DPIA (Art. 35) & prior consultation (Art. 36)
    • Lawful-basis & special-category review
    • Data-flow mapping for AI processing
    • Vendor & sub-processor assessment
  3. 03

    AI automations & systems

    Tailor-made for each business. From pilot to production, we design, build, integrate and hand over, with monitoring in place and your team trained to run it.

    • Process automation & systems integration
    • Custom AI workflows, tailored to your business
    • Model fine-tuning where it pays
    • Team enablement & handover
  4. 04

    AI strategy

    We turn uncertainty into a prioritised roadmap with honest ROI, human judgement kept firmly in the loop.

    • Executive AI workshops
    • Use-case identification & readiness
    • Business-case modelling
    • Custom roadmap & tech-stack advisory

Noēsiss Security

Every system has two views.

The one its owners see, and the one an attacker sees. Noēsiss Security works from the second: penetration testing, AI security, EU AI Act and GDPR readiness, run as one practice, with evidence you can reproduce.

  • Penetration testing
  • AI security
  • EU AI Act
  • GDPR
The same system02 / The attacker's view

Three ways in.

  1. 01 / AUTH ≠ ACCESS

    The unlocked boundary

    PENETRATION TESTING

  2. 02 / INPUT → AUTHORITY

    The obedient assistant

    AI SECURITY

  3. 03 / DELETED ≠ GONE

    The forgotten copy

    GDPR & DATA PROTECTION

00/03weak points in view

Illustrative system, fictional findings. Nothing is scanned.

Enter the security experience

Its own world: three signals to investigate, one connected practice.

Let's bring your system into focus.

A focused 30-minute call, the discovery where you leave with a clearer sense of where AI pays off for you, and where it doesn't.

mesh 85 spokes, 6 contours