We have already paid two consultancies for an AI strategy and nothing shipped.
Fair, and it is the norm rather than the exception — NANDA measured roughly 60% of tools investigated, 20% piloted, 5% implemented. The structural difference is what the engagement is contracted to produce: if the deliverable is a roadmap, you get a roadmap. Contract instead for a measured baseline, a portfolio with written kill criteria, and one use case through an acceptance gate whose threshold the process owner signed in advance. A useful test for any advisor is to ask for the last three use cases they recommended against building, and why. Here is our honest answer to our own test: Palamed has four delivered projects, not a hundred, so we cannot recite a decade of anonymised kills and we are not going to invent them. What you can hold us to is written into the engagement instead — a kill criterion and a decommission condition on every case before build, the rejected list handed over with the reason recorded, half the pilot-phase fee at risk against the signed threshold, and a week-five recommendation to build nothing if nothing clears twelve-month payback.
Our data is not ready. We have been told we need a data platform programme first.
This is how two years disappear. Enterprise-wide maturity is not a prerequisite for a specific use case; readiness of the critical data elements that case consumes is, and in practice that is often 5 to 15 fields with a named owner, documented lineage and an agreed quality SLA. We block the cases that genuinely cannot proceed and price the narrow remediation for the rest. Where the assessment shows the binding constraint is upstream master data rather than the model, the recommendation is to fix the fields and buy nothing — and that recommendation is on the table from week one, not after the invoice.
The AI Act was delayed, and Bulgaria has not even designated a market surveillance authority.
Both true, and neither is a reason to stop. The Omnibus moved standalone Annex III to 2 December 2027 and Annex I to 2 August 2028, but Article 5 prohibitions and Article 4 AI literacy have applied since 2 February 2025 and GPAI obligations since 2 August 2025. In Bulgaria the Ministry of Electronic Governance leads, Council of Ministers Decision No. 398 of 18 June 2025 designated seven fundamental-rights bodies, and as of August 2026 there is still no sanctions regime and no designated market surveillance authority. Obligations attach on the Regulation timetable regardless — and in practice your German and Nordic customers ask in a procurement questionnaire long before a regulator does.
Our engineers say they can build this internally.
Sometimes right, and the statistic usually quoted here is weaker than it looks. NANDA measured roughly 33% deployment success for internal builds against 67% for external partnerships, but that is survey data with an obvious confound: the organisations that hire outside help also have budget, an executive sponsor and a scoped problem, and those are the things that ship software. Build internally when three conditions are already true — someone owns the evaluation harness by name, the process owner can actually change the workflow, and there is a named maintenance owner for year two. Where any of the three is missing, buy the layer underneath and build only the thin differentiating part. Either way the decision should come from pricing build, buy and partner over 36 months with the same line items, human review and model migration included.
How do you prove ROI when the benefit is just people working faster?
By measuring before, not after — and this is the honest hard question, which is exactly why NANDA found budget flowing to sales and marketing, where attribution is easy, while back-office cases with faster payback went unfunded. A time study or a process-mining extract sets the baseline; a holdout group that does not get the tool separates your delta from seasonality. Value is then stated as cost per successful task against that baseline, and the ROI line counts only benefits a CFO will accept: reduced external spend, reduced overtime, or volume growth absorbed without hiring. If a case cannot be measured that way, we score it lower and say so.
We are regulated. One hallucination in a customer-facing answer and we have a problem.
Then the system should not be answering your customers unsupervised, and the design should say so on the first page. Most of what gets called hallucination in a RAG system is retrieval failure — the right passage was never in the context — which is measurable as recall@k and fixable. Beyond that: groundedness enforced as a release gate rather than a dashboard, citation-required output formats, confidence-based routing to human review, and a documented Article 14 human oversight arrangement naming a competent person rather than a role. The regulated deployment is a drafting or triage assistant under mandatory review, not an autonomous responder — and that version still carries most of the value, because the expensive part of the work was the reading, not the typing.
Why you rather than a Big Four firm?
Use whoever will put a falsifiable number in the contract. Ask any bidder for the article numbers governing your specific system, the post-Omnibus date each one applies from, and the acceptance threshold they would sign. Ask where the baseline comes from — process mining and a time study, or a manager estimate — and who builds the evaluation set. Those answers separate advisory from packaging at any firm size, and they are cheap for you to check. The difference here is smaller and more specific: the person who writes the strategy is the person who ships the first use case, and there is no pitch team handing you to juniors afterwards.
You are a small, founder-led firm. What happens if you are unavailable?
A fair question and the honest answer has limits in it. Palamed is founder-led, with named specialists brought in for the specific phase rather than a bench, and we cap this to two advisory engagements of this size at a time so the calendar is real. The protection is not headcount, it is the artifacts: every phase ends in something that reads without us — the Baseline Ledger, the AI register, the scored portfolio with the weights and the rejected list, the golden dataset and the regression suite in your repository, thresholds in writing. Any competent successor can pick that up. The limits we will not talk you out of: we do not staff a 24/7 on-call rota, and if you need forty consultants in a room next month we are the wrong call.