The governance and audit layer for AI workflows in regulated industries
PHÖNIX reviews, builds and evidences the use of AI in your company. Not in a binder, not in a policy document, but where your people actually work with AI: in the workflow.
AI governance you can prove.
At PHÖNIX, data sovereignty is not a promise but an architectural decision. Where the case requires it, models run locally on your premises. Where cloud services are involved, the data paths are described, limited and logged. You are not asked to sign a leap of faith. You receive evidence you can verify: which data flows where, who has access, what is stored.
One example: a language model that summarises contracts can run on a machine inside your own network. The contracts never leave the building. And exactly that can be demonstrated instead of merely promised.
Three services, one principle: verifiable instead of asserted.
AI Operating System
Outcome: orderly, evidenced AI use instead of one-off solutions.
For companies that want to introduce AI or need to bring unmanaged growth into order.
More on the AI Operating SystemAI Audit
Outcome: a findings report with priorities on your current AI use.
For companies whose AI is already working and who want to know whether it will hold up.
More on the AI AuditAI Governance
Outcome: rules and evidence that run along in daily work instead of sitting in a binder.
For companies that the EU AI Act affects now or will affect soon.
More on AI GovernanceVerifiable instead of asserted.
How an engagement runs.
Initial consultation
You describe the situation, we define the scope. Free of charge.
Assessment
A non-disclosure agreement (NDA) precedes any look into your operations. We then map where and how AI works in your company.
Findings
You receive the results with priorities and discuss them with us in a meeting. The timeframe from start to findings is stated in the proposal before you commission anything.
Implementation
On request, we rework the items from the findings together with you. You decide scope and order.
What PHÖNIX is not.
- Not a certification body: you receive a robust findings report, not a seal.
- No accreditation: PHÖNIX does not act as an officially designated body.
- No tool sales: tools are selected for your case, not sold to you.
- No consulting without examining the real workflow: slide wisdom without a look at your operations is not on offer here.
Built and audited by a person with a name.
Matthias Downey is the founder of PHÖNIX. His path begins in the real estate industry, a field where every number must be verifiable. Today he builds and reviews AI deployments in regulated industries: systems that do not just work but hold up when someone asks questions.
Frequently asked questions.
Does the EU AI Act apply to our company?
Very likely yes, to varying degrees. The transparency obligations under Art. 50 of the AI Act (Regulation (EU) 2024/1689) have applied since 2 August 2026; the obligations for high-risk systems follow on 2 December 2027 (Digital Omnibus, agreement of 6 May 2026). Which role your company holds and what follows from it becomes clear by looking at your actual AI use. An overview of terms and deadlines is on our knowledge page.
Does our data stay in-house?
That is an architecture question, and it is answered before the start, not afterwards. Depending on the case, models run locally on your premises, or cloud paths are described, limited and logged. You see in advance which data flows where. A non-disclosure agreement precedes any look into your documents.
How do we start?
With an email. You receive a proposed date for an initial consultation, followed by the non-disclosure agreement and the assessment. You take on no obligation before scope and approach are agreed in writing.
More answers are on the knowledge page.