HAVOOP

Production sprint

Audit trail, human in the loop, model selection, AI Act and GDPR compliance. Two weeks so your AI holds in production and survives an audit.

Why a production sprint?

When an SMB deploys AI without a frame, two scenarios keep coming back. First: an employee pastes client data into ChatGPT, an involuntary leak, GDPR exposure. Second: the CNIL or Bpifrance audits you, and you improvise under pressure, with no usage inventory, no audit trail, no internal charter.

The EU AI Act came into force in phases over 2025-2027. Maximum penalties: €35M or 7% of worldwide revenue for prohibited practices, €15M or 3% for non-compliance. The vast majority of French SMBs have no visibility on their exposure.

The sprint settles this in two weeks. An operational fitting: what you have, what is risky, what we document, how we design the next step so it holds.

The five production conditions

An agent that works in a demo and an agent still working six months later are two different objects. The second checks five conditions:

  1. Recovery points: the agent can resume after an interruption without redoing everything.
  2. Memory separated from working context.
  3. A written list of what it may do, with thresholds.
  4. Failure handling: what happens when a step fails.
  5. An isolated environment, with limited access to your tools.

We do not ship below 5 out of 5.

Sandboxes eventually give way; in July 2026, OpenAI's model escaped OpenAI's own evaluation environment. What matters is what the agent can reach when containment gives. We specify it for every deployment: which systems, which data, which actions, with a log.

What you receive

  • A complete inventory of AI use in the company (declared and shadow IT).
  • AI Act classification: each use case mapped to the 4 risk levels.
  • A GDPR review of processing involving AI (DPIA if needed).
  • Human-in-the-loop architecture on sensitive decisions.
  • Logging and audit trail design (legal traceability).
  • A model selection report: OpenAI, Anthropic, Mistral, open-source, with EU hosting.
  • An internal AI charter (3 to 5 pages, signable by employees).
  • An operational usage policy (10 to 15 pages).
  • A training pack: slides plus a recorded 30-minute session.

Every deliverable can be put in front of the board, the DPO, or a Bpifrance or CNIL auditor.

The four phases

Audit and inventory

Days 1–2

Workshop with the key users. We map everything touching AI today: tools, data, flows, automated decisions.

Risk analysis

Days 3–5

AI Act, GDPR, data security. For each case, we identify the exposure zones and the priority corrective actions.

Technical design

Days 6–8

Human-in-the-loop architecture, logging, audit trail, model selection. We draw what your AI should be in 6 months.

Final documentation

Days 9–10

Charter, policy, training pack. Restitution to the board (90 min). You leave with everything needed to pass an audit.

Investment

The sprint is billed at a fixed price, calibrated to your organisation's size and complexity.

SMBs under 30 people
A 2-week sprint, scoped tightly on 5 to 10 AI use cases.
From €5,000
SMBs of 30 to 100 people
A 2-week sprint, broader multi-department coverage.
From €8,000
Beyond 100 people
Multi-site or multi-country organisations.
Quoted

Optional quarterly follow-up: €1,500 excl. VAT per quarter, one audit day plus document updates.

Frequent questions

Does the AI Act apply to my SMB even if I haven't developed an AI model?
Yes. The AI Act covers any AI use in a company, not only model developers. If you use ChatGPT to help with HR decisions, or an agent to process client data, you are in scope. Obligations depend on the use case's risk level.
If we only use ChatGPT internally, are we concerned?
Yes. At minimum: an internal usage charter, employee training, and a policy for data shared with the AI. If ChatGPT is used for decisions affecting people (hiring, client scoring, moderation), the obligations are heavier.
What penalty if we do nothing?
For prohibited practices (social scoring, manipulation): up to €35M or 7% of worldwide revenue. For non-compliance with governance obligations: €15M or 3%. For SMBs, the exposure is more often indirect (client litigation, CNIL inspection, reputational impact) than a direct fine.
What happens after the sprint?
You leave with all documents up to date, ready to present. If your AI use evolves (new use case, new provider, new regulation), an optional quarterly follow-up keeps you compliant. Without it, we recommend at least an annual update.
Can you be our AI DPO?
No. The DPO is an internal function, or outsourced to a certified firm. What we do: we prepare the ground for your existing DPO. They receive the inventory, the risk classification and the documentation, and can build on it for their GDPR obligations.

Thirty minutes to assess your exposure