AI TRUST
Your company already uses AI. What is missing is the proof that you control it.
With DM11's AI Trust, you get the governance, the measured risks, and the secured AI applications you need to accelerate innovation without creating your next major liability.
What AI governance puts in place
You reach the rule before it reaches you
The EU AI Act is already in force in Europe, Brazil's AI legal framework is advancing, and the ANPD has named artificial intelligence one of its four enforcement priorities for 2026 and 2027. Get structured now and you meet every deadline with the documentation already written.
The AI already in circulation becomes visible
Your employees are feeding internal data into generative AI tools. An inventory of AI uses, sanctioned and unsanctioned, shows where personal data, trade secrets and intellectual property are leaving, and the usage policy sets what may go into a prompt.
Decisions made by AI can be explained
With human oversight defined, clear boundaries for autonomous agents and bias assessment across models, your company can answer for every automated decision in front of the customer, the regulator and the board.
WHAT WE DO
AI governance: six fronts, one program
AI use inventory, risk assessment, regulatory compliance, model audits, AI pentesting and readiness for ISO/IEC 42001. A complete program, led by a team with 17 years of GRC and cybersecurity practice.
We build your AI Management System (AIMS) aligned with ISO/IEC 42001, the first certifiable international standard for AI governance. Roles, policies, approval workflows, and human oversight, all defined and auditable.
- AI governance maturity assessment
- AI usage policies and responsibility matrix
- AI committee and use-case approval workflows
- ISO/IEC 42001 certification readiness
We inventory every AI use across your company, sanctioned or not, and classify each one by regulatory, security, privacy, and reputational risk. You get a prioritized risk map, built on the same proven method behind oitenta20®.
- Inventory of AI systems and use cases, including unapproved use (shadow AI)
- Risk classification aligned with ISO/IEC 23894 and the NIST AI RMF
- Prioritized risk map with a treatment plan
- Board-ready reporting indicators
We prepare your company for the regulatory landscape taking shape: the EU AI Act if you operate in or sell to Europe, Brazil's emerging AI legal framework, and the right to review of automated decisions under article 20 of the LGPD, which the ANPD has placed among its enforcement priorities.
- Gap assessment against the EU AI Act and Brazil's Bill 2338/2023 (AI legal framework)
- System classification by regulatory risk category
- Required technical documentation and impact assessments
- LGPD applied to AI: legal bases and automated decision-making
AI systems open attack routes that did not exist before: malicious instructions hidden in the text that reaches the model, poisoning of the training data, copying of the model through repeated queries, and leakage of sensitive information through the answer itself. We apply offensive and defensive methodology to your models, your data pipelines, and your generative applications, from training through production use.
- Pentesting of AI applications and language models (malicious instructions in the prompt, and bypassing the model's guardrails)
- Simulated attacks on AI systems (AI Red Teaming), following MITRE ATLAS and the OWASP Top 10 for LLM
- Security across the whole model pipeline, from training data to release, with an inventory of the components used
- Detection of training-data poisoning and of model copying through queries
- Incident response for AI systems
Models that make decisions about people must answer for those decisions. We audit your AI models for bias, explainability, and robustness, and we produce the evidence that regulators, customers, and the board demand.
- Assessment of bias and of fair treatment of the affected groups, across models and training data
- Explainability of automated decisions (LGPD art. 20)
- Alignment with OECD AI Principles and UNESCO AI Ethics
- Audit reports for regulators, customers, and the board
Your board needs to make decisions about AI, and your workforce needs to use AI without creating risk. We develop both levels: strategic risk perspective for leadership, secure practice for teams.
- Executive workshop: AI risks and opportunities for the business
- Responsible AI use policy, communicated and trained
- Role-based awareness tracks (legal, IT, business)
- AI incident simulation exercises
Need to scope more than one service? Browse the full catalogue
REFERENCE FRAMEWORKS AND STANDARDS
- ISO/IEC 42001
- ISO/IEC 23894
- NIST AI RMF
- EU AI Act
- Bill 2338/2023
- OWASP Top 10 for LLM
- MITRE ATLAS
- OECD AI Principles
- UNESCO AI Ethics
- LGPD, article 20 (automated decisions)
Prepare your company to govern and demonstrate responsible AI use
Start with an AI Risk Assessment and learn in weeks what a regulator, or an incident, would teach you the hard way.
