Most AI initiatives fail not on technology but on what you pick and in which order — and on bolting AI onto old processes instead of rethinking the process itself. Our approach is deliberately lean: a fast assessment, the 2–3 most valuable processes first, clear stage-gates and measurable KPIs — tailored to size, maturity, budget and time.
Free · no sign-up · runs in your browser · neutral orientation
Throw in documents, key facts and the goal — or a kickoff conversation. We capture size, maturity, systems and constraints (budget, time, risk).
Every use case is scored by value × feasibility × risk and grouped into waves — quick wins first, chosen so the first step lays the reusable foundation for scaling (not a dead-end pilot).
Wave 1 with 2–3 initiatives. Clear stage-gates: pilot (useful in ≥ 80 % of cases) → validation → scale-up.
Each initiative gets KPIs with a baseline and target. We only roll out once value is proven.
EU AI Act classification, GDPR and training are built in. Success is 70 % about people — sponsor, champions, clear communication. And people use AI markedly more when they stay in control (the human decides, the AI suggests).
From 2 August 2026 the AI Act’s core obligations apply. Whether a system is high-risk and how it is operated compliantly is the operator’s call — the architecture provides the foundation. What ZenSation brings to it:
Open-source core, documented memory operations — traceable, not a black box.
Every store and recall operation is loggable and auditable.
The human decides, the system suggests — control stays with you.
Self-hosting, data minimisation and access control are configurable; data never leaves your house.
Important: classifying and conformity-assessing a specific system remains the operator’s responsibility. ZenSation provides the architectural foundation — not a certificate.
The fact underneath: personal data never leaves your house. ZenSation runs self-hosted in your own or EU infrastructure — no external processor, no third-country transfer. Every store and recall operation is traceable, and data minimisation and access control are configurable. What other vendors secure by contract is here excluded by architecture. For the erasure duty under Art. 17 the guarantee is published and re-computable: deletion counts as complete only once a query over the erased scope returns zero rows in every derived store — evidence a third party can re-run, rather than a receipt asserting that deletion happened (DOI 10.5281/zenodo.21964563). The standard variant already provides this foundation — for specific requirements we set everything up exactly to your needs.
No. Models and memory run in your infrastructure (on-premise or an EU cloud of your choice), with no transfer to third parties. This removes the most sensitive data-protection question — data leaving the building — architecturally, from the outset.
Yes, up to authority level. Because the architecture is modular, it can be defined precisely against regulatory and organisational requirements — from the standard variant to specific public-sector demands. We set up deep specialisations exactly as the given framework requires.
Co-determination is considered from the start. Full traceability, configurable access control and clear purpose limitation make it straightforward to meet works-council or staff-council requirements — no covert monitoring. This is not a statement of intent: the underlying guarantees are published as a citable specification — four governance invariants for organisational agent memory, co-determination among them as a structural property rather than a configuration option (DOI 10.5281/zenodo.21964563). We agree the concrete arrangement with your council.
The standard variant already provides the GDPR foundation — self-hosted, auditable, data-minimising. For deeper or public-sector requirements we configure every layer as needed, without breaking the architecture, because modularity is the foundation.
Yes. As an open-source library (Apache 2.0), ZenSation runs in almost any stack — your own database (PostgreSQL/SQLite), your own LLM, your own infrastructure. No cloud lock-in, no vendor lock-in.
The architecture supports core AI Act obligations: transparency through open source, traceability and logging of every operation, human oversight, and data governance through self-hosting. We name the conflict that comes up most often rather than glossing over it: erasure duties (GDPR Art. 17) and record-keeping duties (AI Act Art. 12) pull against each other. The published specification resolves this by separating the record of events from the recoverability of content — that an access and an erasure occurred stays tamper-evidently provable, without the erased content remaining reconstructable (DOI 10.5281/zenodo.21964563). Classifying and conformity-assessing a specific system remains the operator’s responsibility — the architecture provides the foundation for it.
Try it — a few key facts are enough (or use an example). The simulation derives scope, modules, a prioritised roadmap with waves, gates and KPIs, plus a vendor-independent cost estimate. Meant as neutral orientation, not a quote.
Runs right in your browser, no sign-up.
Our method is grounded in ZenBrain technology and peer-reviewed research.