Advisory · AI Governance · Consulting · Training · Recruitment

Your strategic partner for technology transformation.

A boutique consultancy uniting an expert network of senior practitioners, embedded fractional leadership, full-spectrum consulting, executive training and precision recruitment — for organisations delivering complex change under regulatory pressure.

25+
Years senior delivery
12
Sectors served
3
Geographies
48hr
Brief response
Where regulation, technology
and execution intersect.
Expert NetworkAI GovernanceEU AI Act + Digital OmnibusCybersecurityData & AnalyticsDigital TransformationRegulatory ComplianceISO 42001NIST AI RMFDORAGDPRNIS2NYC Local Law 144Colorado AI ActTexas TRAIGACalifornia SB 53Singapore Model AI GovernanceSR 11-7 · PRA SS1/23Fractional LeadershipPrecision Recruitment Expert NetworkAI GovernanceEU AI Act + Digital OmnibusCybersecurityData & AnalyticsDigital TransformationRegulatory ComplianceISO 42001NIST AI RMFDORAGDPRNIS2NYC Local Law 144Colorado AI ActTexas TRAIGACalifornia SB 53Singapore Model AI GovernanceSR 11-7 · PRA SS1/23Fractional LeadershipPrecision Recruitment
01 / Services

Three pillars, one operating model.

A curated expert network, embedded fractional leadership, and rigorous recruitment — delivered as a single integrated offering, calibrated to the scale and tempo of your challenge.

Three pillars, one conversation away.

48-hour response · no obligation
02 / The defining governance challenge of 2026

AI & Data·Governance.

The pace of AI adoption has outrun the controls that govern it. Regulators have caught up — and they are now coordinating. The EU AI Act (as amended by the May 2026 Digital Omnibus), ISO 42001, NIST AI RMF, NYC Local Law 144, Colorado AI Act, Texas TRAIGA, California SB 53, DORA, NIS2, GDPR, the UK pro-innovation framework, Singapore's Model AI Governance, and sectoral model-risk regimes (SR 11-7, PRA SS1/23) now place unprecedented obligations on boards, model owners and data custodians. Incube helps organisations move from ad-hoc AI experimentation to governed, auditable, enterprise-grade deployment — without slowing innovation.

At stake — non-compliance penalties
Up to €35M or 7% of global turnover
EU AI Act enforcement is extraterritorial. Provider or deployer — if your AI affects EU residents, you're in scope. The May 2026 Digital Omnibus deferred high-risk obligations to December 2027 (use-based) and August 2028 (product-regulated) — extending the runway, not the obligation. Standards and conformity evidence still need to be in place before then.
Whitepaper · download

The 2026 regulatory calendar for AI Governance.

A consolidated view of all 22 key dates across the EU AI Act (as amended by the May 2026 Digital Omnibus), DORA, GDPR, NIS2, the Cyber Resilience Act, ISO 42001, NIST AI RMF and US state-level laws (TRAIGA, California SB 53, Colorado). Sorted chronologically, sourced and ready for the risk register.

  • 22Regulatory milestones
  • 5Jurisdictions covered
  • 4Pages · PDF
Sent on submission · no marketing list, no spam
Incube.
CONFIDENTIAL / INSIGHT
WHITEPAPER · MAY 2026
AI Governance · Regulatory Briefing
The 2026 regulatory calendar for AI Governance.
A consolidated view of EU AI Act enforcement dates, DORA, GDPR, NIS2, CRA and US state-level laws.
Annex III · High-risk AI

Is your AI in scope?

Nine high-risk categories. If your product touches any of these — as provider or deployer — the full obligations apply.

i

Recruitment & HR decisions

CV screening, candidate ranking, interview scoring, sourcing.

ii

Workplace AI

Performance evaluation, monitoring, promotion, termination.

iii

Education & assessment

Admissions, exam grading, learner placement and progression.

iv

Credit & financial services

Scoring, access to essential financial services, eligibility.

v

Insurance pricing

Life and health risk assessment, premium pricing decisions.

vi

Public benefits

Eligibility decisions for state benefits and essential services.

vii

Biometric & emotion AI

Identification, categorisation, emotion and affect recognition.

viii

Critical infrastructure

Safety components in transport, utilities, communications.

ix

Law enforcement & borders

Migration, asylum, border control, justice administration.

Our compliance journey

Five steps from unknown to auditable.

A phased path, deliverable in 12–20 weeks depending on portfolio complexity. Expert network embedded throughout.

i01

Assess

AI inventory across business. Map every system, every supplier.

ii02

Classify

Risk-classify each system against Annex III. Provider or deployer.

iii03

Document

Article 11 technical files, datasheets, intended-purpose records.

iv04

Implement

Risk management, human oversight, transparency, post-market plan.

v05

Monitor

Conformity assessment, EU database, ongoing drift & incident control.

What we deliver

Advisory through to executed conformity — not just opinions.

Four governance pillars, each with named deliverables. Network specialists embedded for the duration.

— 01

Regulatory frameworks & readiness

Cross-regime alignment — EU AI Act, ISO 42001, NIST AI RMF, US state-level laws (TRAIGA, California SB 53, Colorado), UK pro-innovation framework, Singapore Model AI Governance and sectoral model-risk regimes — mapped to your risk profile and the revised timeline.

  • AI inventory & risk classificationCatalogue every system, classify against Annex III (use-based) and Annex I (product-regulated), document scope, surface dependencies.
  • Article 11 technical documentation packDatasheet, intended purpose, design specs, performance metrics — to the level a notified body or regulator can audit.
  • Article 9 risk management systemContinuous monitoring, mitigation, post-market surveillance under the revised enforcement dates.
  • Conformity assessment supportSelf-assessment or notified body liaison, EU database registration, Article 50(2) transparency for synthetic content.
  • ISO 42001 alignmentAI management system design, audit readiness, certification path — paired with ISO 27001 for security baseline.
  • Multi-regime mappingSingle control set evidenced against EU AI Act, NIST AI RMF, ISO 42001, DORA, GDPR — eliminate parallel compliance work.
— 02

Responsible AI

Bias auditing, explainability, human oversight, and fairness testing baked into the model lifecycle — covering both EU and US obligations.

  • Article 14 human oversight designControls, override paths, training and competence frameworks.
  • Article 13 transparency & disclosureUser-facing communications, deployer instructions. Synthetic content marking under Article 50(2) (Dec 2026).
  • Bias auditing & fairness testingPre-deployment evaluation, ongoing monitoring, demographic parity. Special-category-data carve-out under new Article 4a.
  • Explainability frameworksModel cards, decision logs, contestability mechanisms.
  • NYC Local Law 144 readinessBias audit for HR/employment AI used in the US.
  • New prohibitions readinessControls and safety measures against AI-generated non-consensual intimate imagery and CSAM (enforceable Dec 2026).
— 03

Model risk management

Model inventory, validation, monitoring, drift detection and control frameworks aligned to SR 11-7 and PRA SS1/23.

  • Model risk policy & frameworkThree-lines-of-defence operating model, RACI, escalation.
  • Independent model validationPre-deployment review, performance, soundness, conceptual integrity.
  • Drift & performance monitoringProduction telemetry, alerting, retraining triggers.
  • Vendor / third-party AI attestationSupplier due diligence, contractual controls, evidence gathering.
  • Board reporting & KRIsQuarterly AI risk dashboards for audit committee and ExCo.
— 04

Data governance

Lineage, quality, privacy, consent, stewardship and lifecycle controls — from data foundation up to AI use case. Aligned across the EU digital stack: GDPR, NIS2, Data Act, Cyber Resilience Act.

  • Article 10 data governanceTraining, validation and test data quality, representativeness.
  • GDPR Article 22 & DPIA supportAutomated decision-making controls, lawful basis review.
  • Data lineage & provenanceSource tracking, consent records, retention controls.
  • Privacy-enhancing techniquesSynthetic data, differential privacy, secure enclaves.
  • NIS2 & Data Act alignmentCritical-entity controls, data-sharing obligations, cross-regulation evidence.
  • Stewardship operating modelData owners, custodians, quality SLAs.
Whitepaper · download

Fifteen frameworks in scope for AI.

A framework-by-framework reference. EU AI Act, GDPR, DORA, NIS2, EU Data Act, ISO 42001, NIST AI RMF, NYC Local Law 144, Colorado AI Act, Texas TRAIGA, California SB 53, UK pro-innovation framework, Singapore MGF, SR 11-7 and PRA SS1/23 — each with jurisdiction, status, next milestone and what it means in practice. Mapped to a single control set, so one body of evidence carries across regulators.

  • 15Frameworks mapped
  • 5Jurisdictions covered
  • 6Pages · PDF
Sent on submission · no marketing list, no spam
Incube.
CONFIDENTIAL / INSIGHT
WHITEPAPER · MAY 2026
AI Governance · Frameworks Reference
Fifteen frameworks in scope for AI.
A framework-by-framework reference across EU, US, UK, international and sector-specific regimes.

Have December 2027 on your risk register?

The May 2026 Digital Omnibus moved the high-risk deadlines, but the standards work, conformity evidence and operating-model build still need 12–18 months of runway. Tell us your sector, scope and current state. We come back within 48 hours with a tailored brief, a shortlisted bench, and a phased path to compliance.

Run the scope check
03 / 60-second scope check

Find out if your AI is high-risk under the Act.

Five questions. No data collected. Indicative only — not legal advice. For a definitive scoping, request a brief.

Question 1 of 5
Is your AI system used, marketed, or producing outputs that affect people in the EU?
The Act applies extraterritorially. If outputs reach EU residents, your company's headquarters location doesn't matter.
04 / Consulting

Full-spectrum advisory and execution.

Five practice areas, drawn from the same expert network. Outcome-led, regulator-aware, embedded for the duration. Engaged as discrete advisory, multi-workstream programmes, or as fractional capability alongside your team.

— 01

Cybersecurity

Zero-trust architecture, application & API security, cloud and database defence, SOC and SecOps maturity.

Zero TrustWAF / DDoSApp / APISOCSecOps
— 02

Data & Analytics

Modern data platforms, migration programmes, AI-led intelligence and self-service analytics — insight to advantage.

PlatformsMigrationAI / MLBIPrivacy
— 03

Digital Transformation

Cloud adoption, platform re-architecture, legacy decommissioning and emerging-tech integration that scales under compliance pressure.

CloudLegacyArchitecturePlatformDevSecOps
— 04

Regulatory Compliance

EU AI Act, DORA, Operational Resilience, GRC, AML and KYC. Scope, gap-assess, remediate and evidence — for the regulator, not just the auditor.

EU AI ActDORAOp ResAML / KYCGRC
— 05

Programme, Portfolio & PMO

Shape, govern and deliver strategic initiatives at enterprise scale. Portfolio prioritisation, programme assurance, PMO setup, benefits realisation.

PortfolioAssurancePMOAgileBenefits

Have a consulting mandate worth scoping?

Curated team, named deliverables, embedded for the duration
05 / Training

Executive training, built to shift outcomes.

Seven programmes designed for senior teams. Cohort-based, scenario-led, and delivered by the same practitioners who run the consulting work. Every module is grounded in current regulatory reality and live engagement experience.

07Programmes
Delivered in person, hybrid, or remote
Cohorts of 12–24
Flagship
Boards · ExCo · ML & Risk

AI Governance

EU AI Act, ISO 42001, NIST AI RMF in practice. From inventory through to conformity. Includes a live tabletop exercise on a real Annex III scenario.

3-day intensive · or 6-week cohort
Engineering · Product

Vibe Coding

Working effectively with AI coding agents. Prompt patterns, agentic workflows, code review, security and IP hygiene.

2-day workshop
All staff · Security teams

Cybersecurity

Zero-trust foundations, threat awareness, secure-by-design and incident response. Role-based modules from C-suite to engineering.

Tiered · 1–5 days
Compliance · Risk · Audit

GRC

Governance, risk and compliance operating models. Deep specialism in DORA, EU AI Act and operational resilience.

4-day cohort
Senior leaders · High-potential

Leadership

Strategy under uncertainty, stakeholder management, decision craft under pressure in regulated, technology-led environments.

5-day · 12-week cohort
Transformation teams · ExCo

Culture Change

Designing and landing culture change in technology transformation. Frameworks, diagnostics, intervention design, measurement.

3-day workshop · coaching
All audiences

Soft Skills

Communication, influence, executive presence, difficult conversations, negotiation — for technical and non-technical audiences.

1–3 day modules

Learning paths by role.

Pre-mapped curricula combining modules across programmes. Customisable for the specific seniority and remit of the cohort.

Board & ExCo
Strategic oversight
AI GovernanceGRCLeadershipCybersecurity (exec)
Engineering leadership
CTO, VPE, Architects
Vibe CodingAI GovernanceCybersecuritySoft Skills
Compliance & risk teams
CRO, CCO, Internal Audit
GRCAI GovernanceSoft Skills
Transformation programmes
Programme directors, CoS
Culture ChangeLeadershipSoft SkillsGRC
Emerging leaders
High-potential cohort
LeadershipSoft SkillsVibe CodingCulture Change

Designing a cohort for your team?

Enquire about training →
7 programmes · in person, hybrid or remote · cohorts of 12–24
06 / The Incube network

A curated collective of senior practitioners.

Not a database. Not a marketplace. A deliberately small, continuously cultivated network of operators who have led at the highest levels — and now choose to engage on problems worthy of their time.

— i

Rigorously vetted

Every member carries a verifiable track record of senior delivery at Tier-1 scale.

— ii

Precision-matched

We match to mandate — not the other way round. No irrelevant introductions.

— iii

Cross-disciplinary

Technology, regulation, data, cyber, AI and ESG — spanning every senior domain.

— iv

Continuously cultivated

Knowledge-exchange programmes keep the network sharp and relevant.

— v

Embedded, not introduced

Practitioners stay with the mandate. Continuity of context, accountability for outcome.

— vi

48-hour shortlist

Submit a brief, receive a curated shortlist within 48 hours. Not a generic CV dump.

07 / Senior roles, engaged on your terms

Executive expertise, without the full-time cost.

Six distinct ways to embed senior leadership into your organisation — from hands-on operators to independent board-level oversight.

— i

Fractional COO

Drive operational excellence and lead cross-functional execution as an embedded senior operator.

— ii

Fractional CIO

Shape and lead technology strategy, oversee modernisation and align digital investment.

— iii

Chief of Staff

Manage strategic priorities, align teams, accelerate decisions at executive level.

— iv

Adviser

Strategic counsel to founders and boards navigating technology, growth or regulation.

— v

Non-Executive Director

Independent board-level oversight bringing technology, risk and transformation expertise.

— vi

Interim Leadership

Senior cover for gaps — programme directors, transformation leads, regulatory specialists.

Senior leadership, without the headcount?

From 1 day per week to multi-day embedded · scoped to the mandate
08 / Talent acquisition · UK + India delivery

Precision recruitment, at scale.

A full-spectrum technology and regulated-industry recruitment practice — delivered through Incube India (Incube Professional Services India Private Limited), our wholly-owned subsidiary. Senior search expertise out of London, dedicated delivery engine out of India, accelerated by our proprietary AI agent Samixa. Niche mandates filled in days, not months.

The bottleneck
The funnel — not the talent.
Most searches stall in the time it takes to identify, shortlist, screen and onboard the right candidate — hoping the offer lands, the screening clears, and they actually show up. For stringent project timelines or replacement roles, that funnel is the biggest single risk to delivery. Our methodology compresses it without compromising quality.
Two-arm delivery model

Senior search in London, scale in India.

Strategic search expertise paired with a dedicated delivery engine — and our AI agent in the middle.

— INCUBE UK · LONDON

Search direction & client interface

Senior recruiters with Tier-1 financial services and regulated-industry track records. Brief intake, search strategy, market positioning, offer negotiation, candidate experience.

  • Boutique advisory · single point of accountability
  • Senior client relationship ownership
  • UK and EU candidate sourcing
Samixa
— INCUBE INDIA

Sourcing engine & delivery

Our wholly-owned subsidiary running the sourcing engine. Continuous sourcing across CV databases, LinkedIn, GitHub, niche communities. Screening, scheduling, market intelligence — 24/7 coverage across time zones.

  • Multi-platform sourcing & screening
  • Candidate engagement at scale
  • Global outreach across APAC, GCC, EMEA
How we run a search

Four steps from brief to placement.

01

Source

Brief intake. Search strategy designed per requirement — internal pool, job boards, referrals, direct outreach, LinkedIn, niche communities, university partnerships. Samixa accelerates outreach at scale.

02

Screen

Structured conversational screening — adapted to each candidate's background rather than scripted Q&A. Skills validation, role fit, motivation, availability and salary expectations.

03

Shortlist

A curated, ranked shortlist with rationale — not a CV dump. Hiring-manager briefing pack with structured interview guides focused on the gaps and strengths of each candidate.

04

Place

Offer support, reference and screening coordination, onboarding handover, and post-placement check-ins. Continuity through to day 90 — not "submit and forget."

Briefing · request the skills coverage

The full skills coverage reference.

A comprehensive view of roles and technologies we recruit for — business and leadership (CIO, CDO, CISO, CTO, COO, CPO, VP, Partner), programme delivery, risk and compliance, financial crime, cybersecurity, ESG; full stack development, cloud platforms, data engineering, data & analytics, AI / ML. Available on request as a PDF briefing.

  • 12+Role categories
  • 30+Tech stacks
  • 4Pages · PDF
Sent on submission · no marketing list, no spam
Incube.
CONFIDENTIAL / INSIGHT
BRIEFING · MAY 2026
Recruitment · Skills Coverage
The full skills coverage reference.
Roles and technologies Incube recruits for, across leadership, delivery, risk, cybersecurity, data and AI.
The technology behind the practice

Meet Samixa — our proprietary AI hiring agent.

Samixa is the agentic AI layer that powers our delivery engine: sourcing, screening, scheduling and shortlisting at machine speed — under human direction. It's why we can move quickly without losing the quality of a senior search.

A role to fill, or a team to build?

48-hour response · curated shortlist · no commission until placement
09 / In active development · Agentic AI

Meet Samixa. Recruitment, reimagined.

Samixa
The hiring agent of record.

Samixa is the proprietary agentic AI layer behind Incube's recruitment practice. An AI recruitment companion that autonomously sources candidates, screens applications, schedules interviews and surfaces ranked shortlists — across ATS, calendar, email and LinkedIn — so human recruiters spend their time only where it counts: the final decision.

Built for the entire hiring ecosystem: candidate experience, recruiter efficiency, hiring-manager quality and compliance — all in one agent. Bias-audited and EU AI Act / NYC Local Law 144 compliant from the foundation. Not a chatbot scripted on top of an ATS.

60–80%
Recruiter time saved
24/7
Global coverage
10x
Faster shortlisting
S
Samixa · Live interview
Active session · encrypted
Hi Priya — thanks for applying for the Senior Data Engineer role. I'd love to learn more about your experience. Do you have a few minutes?
Sure — happy to chat now.
You mentioned building a real-time pipeline in Spark last year. Could you walk me through the failure modes you designed around, and how you chose between Kafka and Kinesis?
We prioritised replayability, so Kafka made sense. For failures, we built idempotent consumers with…
Dynamic · Bias-audited · GDPR & AI Act compliant
Capabilities & roadmap

Twelve capabilities that change how hiring works — for recruiters, candidates, hiring managers and compliance.

Samixa goes beyond chatbot scripts. The agent decides what to do next based on pipeline state, acting across systems without waiting for human input at each step.

— 01

End-to-end autonomy

Sources, screens, engages, schedules, follows up and re-engages cold candidates — across platforms — without human triggers at each step.

— 02

Conversational screening

Questions adapt in real time to candidate answers — probing deeper on unusual backgrounds rather than following rigid scripts.

— 03

Skills-based evaluation

Evaluates demonstrated skills, project work and contextual experience — not just keyword matching or university pedigree.

— 04

Candidate-side advocacy

Tells candidates where they stand, why they may not fit, and where they'd be better suited — building trust and reducing ghosting.

— 05

Bias auditing

Continuously audits screening decisions for demographic bias and generates explainability reports — ready for NYC Local Law 144 and EU AI Act.

— 06

Quality-of-hire scoring

Goes beyond "qualified" to "will succeed and stay" — learning from post-hire performance with employer consent over time.

— 07

Proactive pipeline

Continuously nurtures a warm talent pool — re-engaging silver medalists, tracking passive candidates, ready the moment a role opens.

— 08

Cross-platform sourcing

Actively sources from LinkedIn, GitHub, Behance, academic publications or niche communities — and crafts personalised outreach.

— 09

Hiring manager coaching

Briefs managers with structured, candidate-specific interview guides — focused on gaps and strengths, not generic questions.

— 10

Market intelligence

Tells employers when compensation, job description or requirements are off-market — and recommends specific adjustments.

— 11

Feedback & complaints

A dedicated channel for candidate and employer feedback — ensuring every escalation feeds back into model-level improvement.

— 12

24/7 global compliance

Concurrent, compliant interviewing across geographies — adhering to existing and evolving data, employment and AI regulations.

Early-access partners welcome. We're piloting Samixa with select clients. Talk to us about shaping the roadmap — and being first in line.
Request early access →
10 / Who leads Incube

Founded and led by a senior operator.

Sridhar Somasundar

Founder & Managing Partner

Twenty-five years delivering technology change at Tier-1 financial institutions — HSBC, NatWest, Barclays Capital, Deutsche Bank — and global consultancies.

Specialist in Financial Crime programme delivery, data governance, AI/ML product development and regulatory transformation. Programmes spanning the UK, India and the GCC corridor.

  • Oxford Saïd — AI Governance programme
  • CEO, Talboost.ai (recruitment technology)
  • COO, Helix.earth (climate-tech)
  • Advisor, We Hold A Hand (mental health nonprofit)

A boutique by design, not by default.

Incube exists because senior practitioners deserve a route to substantive work, and complex organisations deserve more than a generic body shop. The boutique structure is deliberate — small enough that every engagement matters, deep enough that no problem is outside the network's reach.

We work where regulation, technology and execution intersect. That's where the hardest mandates sit — and where the strongest practitioners are needed.

The AI Governance work in particular has been the focus of 2026. We've built a deep bench specifically for the EU AI Act enforcement runway — December 2027 for use-based high-risk systems, August 2028 for product-regulated — and the broader regulatory wave behind it. Every engagement is led personally; network practitioners come to the work, not the other way round.

Want to start a conversation?

Get in touch ↓
11 / Get in touch

Tell us the shape of the mandate.

We come back within 48 hours with a tailored response — not a brochure.

For corporates

Submit a brief.

Tell us the capability, the engagement shape and when you need to start. Whether it's AI Governance, a fractional CXO, or a niche specialist — we respond with a curated shortlist or scoped proposal within 48 hours.

Training

Cohort programmes.

From AI Governance to Vibe Coding to Leadership. Tell us audience, outcome and timing. We come back with a draft curriculum and proposal.

Enquire about training →
For consultants

Join the network.

Senior practitioners with Tier-1 delivery track records — we'd welcome your profile. Every submission is personally reviewed before any introduction.