Supero foundations

Explainable. Responsible. Transparent. By design.

Supero's methods were built on the same principles the EU AI Act now formalises. AI is held to the same bar as every other part of our work, applied case by case, with human oversight and clear documentation.

The EU AI Act arrives in stages, with prohibited practices and AI literacy live since 2 February 2025, general-purpose AI and governance rules live since 2 August 2025, and transparency and high-risk obligations phasing in through 2028. We treat the Act as ratification of how we already work, not a constraint to manage. Final legal approval for any live client deployment sits with the client's own legal team. See the regulatory clock below.

Last updated: 24 July 2026

ExplainableEvery output traceable to its evidence
ResponsibleHuman oversight on material decisions
TransparentPurpose, data, and limits documented
EU AI Act alignedBy design, not by retrofit
Client legal approvalRequired before live deployment

Every Supero engagement is designed to be explainable to a board, responsible in how it treats people and data, and transparent in what it claims and what it does not. AI sits on top of that standard. It does not lower it. This page sets out how those principles show up in our work, why our methods are natively aligned with the EU AI Act, and where client-side legal approval remains essential.

For the leadership argument behind this policy, including how value-drift shows up in the revenue engine and what the board should be asking, read our flagship perspective The White-Collar Horse by Cumai Aboul Housn and Alex Abbott.

What AI is used for

AI is applied across a focused set of use cases where it materially improves the quality of revenue diagnostics, GTM design, or execution. Not every engagement uses AI. It is used where it is useful, and not where it is not.

Each use case is evaluated on its own merits against the type of activity, users affected, data involved, and deployment context before any AI component is introduced.

How Explainable, Responsible, Transparent shows up in our work

These are not five rules layered on top of our methods. They are the foundations our methods were built on. They apply to internal work, client-facing systems, and anything we design for production use.

1. Risk-based design

Each AI use case is reviewed against its type of activity, the people affected, the data involved, and the deployment context. The level of governance applied scales with the level of risk. This mirrors the risk-based structure of the EU AI Act.

2. Human oversight

AI supports judgement. Humans remain accountable for material business decisions. Review, escalation, and override paths are built into any workflow that touches forecasts, pipeline decisions, customer communications, or commercial commitments.

3. Transparency

Where AI interacts with people or generates content in a relevant context, appropriate disclosure and review measures are considered. Users and stakeholders should be able to tell when they are engaging with an AI system, and reviewers should be able to understand what the system is doing and why.

4. Documentation

Important AI-enabled workflows are documented at a practical level: purpose, data sources, model or tool used, known limitations, and controls. This supports client review, audit readiness, and informed use by operators.

5. Data responsibility

AI systems use only approved data and approved tools. Privacy, confidentiality, and data protection considerations sit alongside AI governance, not separate from it. See our Privacy Policy for how we handle personal data.

Why our approach is natively AI Act aligned

Our methods were built on the same principles the EU AI Act now codifies. The Conversation Operating System, our diagnostic instruments, and the Financial Impact Model are all designed around traceability, human accountability, and quantified confidence. The Act is a regulatory expression of how we already work.

The EU AI Act (Regulation (EU) 2024/1689) establishes a risk-based framework for AI systems, with stronger obligations applying to certain categories of use. The Act entered into force on 1 August 2024 and applies in stages, with obligations already live for prohibited practices, AI literacy, and general-purpose AI, and further obligations phasing in through 2028.

The Act sorts AI systems into four broad risk categories: prohibited practices, high-risk systems, limited-risk systems (which carry transparency obligations under Article 50), and minimal-risk systems. Most AI-supported GTM activities (pipeline analysis, account research, content drafting, meeting summarisation, coaching support) are likely to fall outside the prohibited and high-risk categories. We apply the same explainable, responsible, transparent standard to every use case regardless of category.

Supero reviews AI use cases case by case and flags any scenario that may require deeper legal, compliance, privacy, or employment review before implementation. Where a use case could carry elevated risk, for example AI involved in employment decisions, access to services, or significant customer-facing automation, we make that explicit and recommend the client's legal team is engaged early.

The regulatory clock

The Act arrives in stages. This is what has already applied, what applies next, and what is still ahead. Dates reflect the European Commission's official implementation timeline as amended by the Digital Omnibus package adopted in June 2026, which delayed the standalone high-risk regime by roughly sixteen months.

2 February 2025In force
Prohibited practices and AI literacy. Article 5 bans on unacceptable-risk AI (including social scoring, manipulative techniques causing material harm, workplace and educational emotion inference, and untargeted scraping of facial imagery). Article 4 requires providers and deployers to ensure staff and other people handling AI on their behalf have sufficient AI literacy. Fines for Article 5 breaches reach up to €35m or 7% of global turnover.
2 August 2025In force
General-purpose AI and governance. Obligations on providers of general-purpose AI models (including systemic-risk models), plus the governance framework: national competent authorities, the AI Office, the AI Board, and the penalty regime. Providers of GPAI models placed on the market before this date have until 2 August 2027 to reach full compliance.
2 December 2027Ahead
Standalone high-risk systems. Full obligations for Annex III high-risk systems: risk management (Article 9), data governance (Article 10), technical documentation, logging, transparency to deployers, human oversight (Article 14), accuracy, robustness and cybersecurity, plus post-market monitoring, incident reporting and conformity assessment. Covers areas such as employment and worker management, education, credit scoring, essential services, biometrics, and law enforcement. Delayed from 2 August 2026 by the Digital Omnibus.
2 August 2028Ahead
High-risk systems embedded in regulated products. Annex I obligations for AI that is a safety component of, or is itself, a product covered by existing EU product-safety law (for example medical devices, machinery, in-vitro diagnostics, automotive). Delayed from 2 August 2027 by the Digital Omnibus.

Grandfathering: AI systems and general-purpose AI models placed on the market before the relevant milestone are broadly covered by the Act only where a significant design change is made, or, for general-purpose AI, on the extended timeline set out in Article 111. This is a summary for orientation, not legal advice.

Read against this timeline, the Supero foundations, explainable, responsible, transparent, are not a response to any single date. They are the operating standard we already work to, whichever category a use case ultimately falls into, and whichever milestone is closest.

Our position: Supero's foundations meet the EU AI Act's standard by design. They sit alongside, not in place of, the client's own legal review.

Client legal review remains essential

We can help design AI-enabled GTM systems in a way that aligns with the principles and structure of the EU AI Act. We cannot, and do not, provide legal advice.

Final legal and regulatory approval for any live implementation must be provided by the client's own legal team. This is because compliance depends on the exact use case, data, contracts, jurisdictions, deployment model, and internal policies, none of which Supero is positioned to make binding decisions on.

Supero's policy supports responsible design and implementation. It does not replace legal advice, regulatory approval, or the client's own risk management processes.

Frequently asked questions

What is Supero's AI policy?

Supero's foundations were built on three principles: explainable, responsible, transparent. AI is held to the same bar as every other part of our work, applied case by case to strengthen revenue diagnostics and GTM design, with human oversight and clear documentation. Our methods are natively aligned with the EU AI Act because the Act formalises the standard we already work to. Final legal approval for any live client deployment sits with the client's own legal team.

Does Supero use AI in every engagement?

No. AI is applied only where it improves the outcome for the client. Many Supero engagements are led by human expertise alone, drawing on our Conversation Operating System and revenue diagnostic methodology. AI is introduced when it adds commercial value and can be governed responsibly.

Is Supero's AI approach aligned with the EU AI Act?

Yes, by design. Our methods were built on explainability, human accountability, and quantified confidence from the start, which are the same principles the EU AI Act now codifies. We treat the Act as ratification of how we already work rather than a constraint to retrofit.

Does Supero guarantee legal compliance for client AI deployments?

No. Supero does not provide legal advice and does not guarantee regulatory compliance. Compliance depends on the exact use case, data, contracts, jurisdictions, and deployment model. Supero supports responsible design and implementation; final legal and regulatory approval must come from the client's own legal and compliance team.

Who approves the legal position of an AI-powered GTM system?

The client's own legal team. Supero can help design an AI-enabled system in a way that aligns with the principles and structure of the EU AI Act, but the accountable legal approval for any live deployment rests with the client.

What types of AI use cases does Supero support?

Typical use cases include revenue diagnostics and pattern detection, sales and pipeline analysis, meeting and call summarisation, account research and planning, sales coaching support, draft generation for outreach or content, and GTM workflow design and automation support. Each use case is reviewed on its own merits.

Does Supero build autonomous AI systems?

Supero designs AI-enabled systems to support human decision-making, not to replace it. Where automation is introduced, humans remain accountable for material business decisions and appropriate oversight, review, and escalation steps are built into the workflow.

Supero foundations at a glance

  • Explainable: every output traceable to its evidence
  • Responsible: human oversight on material decisions
  • Transparent: purpose, data, and limits documented
  • AI used case by case, where it improves the outcome
  • EU AI Act aligned by design, not by retrofit
  • Client legal review required before live deployment

Want to talk about AI in your revenue engine?

We'll walk through the specific use case, the data involved, and whether AI is the right lever before anything gets built.

Book a conversation