LOG 03 · COMPLIANCE.ONE
The compliance lawyers went AI-first, with regulated EU data.
Client · Compliance.One · legal and compliance regtech · lawyer-led, no in-house engineers
Engagement · Lead, build and go-to-market · March to June 2026
We sell trust, so the test was simple: we went AI-first and still can handle regulated client data exactly the way we tell everyone else to.

David Klement · Compliance.One
The brief
Compliance.One is a lawyer-backed compliance platform for German and EU SMEs, covering GDPR, the AI Act, whistleblowing, NIS2 and DORA. They wanted to grow by going AI-first across the whole business. But they are a compliance firm: they advise others on data protection and handle PII and privileged client data every day. For them a data slip is not a bug, it is an existential hit to the one thing they sell, which is trust. The question was never whether to use AI. It was how to go AI-first without breaking their own compliance promise, and without becoming a tech company to do it.
The build
We made them AI-first across every function, with data risk handled by design and without hiring a single engineer.
- A governed AI layer, bought not built: a managed, compliance-oriented AI gateway with PII and GDPR protection built in, so the data risk sits with a specialist. A compliance firm has no business hand-rolling its own AI guardrails.
- AI-built product: software shipped with spec-driven development on Claude and Cursor, with automated technical and commercial documentation.
- AI-run go-to-market: outreach, design and sales decks produced through an AI workflow.
- Zero friction for the lawyers: they consume AI through a simple web UI, with no engineering skills and no new tooling to learn.
Engineers hired to take the whole firm AI-first.
From start to AI-first across product, delivery and sales.
Of AI use routed through one governed, compliant layer.
The result
- AI-first across product, delivery and sales in about four months.
- Compliant by design: every interaction routes through a governed layer, so data protection is enforced, not improvised.
- No engineering org required: a non-technical firm transformed without becoming a tech company.
- They walk their own talk: a firm that sells AI Act and GDPR compliance now proves the thesis on itself.
Debrief
The conventional fear is that safe AI means building an engineering team and your own guardrails. It does not. A domain-expert firm went AI-first by integrating a governed third-party layer, buy the compliance layer rather than build it, not by becoming an engineering shop.
That path generalises to the huge market of non-technical professional-services firms, in law, accounting and consulting, that want AI but fear the risk and cannot hire engineers. There is no stronger proof it is safe than the compliance lawyers adopting it first.
Want a result like this on your books?
The free assessment is how this engagement would start today: five minutes of questions and an instant pre-flight score, then a call with a founder.
Next: LOG 04 · From knowledge sprawl to a unified knowledge base, compliant by design.