L'essentiel en bref
Nehos is an AI agency based in Brussels' Schuman district, serving EU institutions, associations, and Belgian FinTech.
We build EU AI Act-compliant AI systems with full technical documentation, conformity assessments, and post-market monitoring.
Trilingual delivery: French, English, and Dutch for Brussels' mixed-language professional environment.
EU-sovereign hosting on OVH Europe — no US cloud, full GDPR Article 28 DPA provided.
From AI strategy audit to production deployment: 8 to 14 weeks depending on use case complexity.
AI Agency in Brussels — EU AI Act Ready, Trilingual
Nehos builds EU AI Act-compliant AI systems for Brussels institutions, sector federations, NGOs and Belgian FinTech. FR/EN/NL delivery. EU-sovereign infrastructure.
Adapté à toute taille de structure
Questions fréquentes
#AI Agency in Brussels — EU AI Act Ready, Trilingual
Nehos AI agency in Brussels: EU AI Act compliance, agentic AI for institutions, NGOs & FinTech. Trilingual FR/EN/NL delivery, EU-sovereign hosting.
#The city that writes the rulebook is a harder place to sell AI
Nowhere else does a vendor pitch land in front of people who have read the primary legislation. In Brussels, the person across the table may have sat in the working party that drafted the article you are quoting. That changes the conversation entirely: generic assurances about "responsible AI" collapse within ten minutes, and the useful discussion starts where it should — risk classification, logging obligations, human oversight arrangements, and who signs the declaration of conformity.
The regulatory calendar is unusually concrete here too. Regulation (EU) 2024/1689, the AI Act, entered into force on 1 August 2024. Its prohibitions and the AI literacy duty of Article 4 have applied since 2 February 2025. Obligations for general-purpose AI models, the governance architecture and the penalty regime followed on 2 August 2025. The core high-risk regime applies from 2 August 2026, with a longer runway to August 2027 for AI embedded in products already covered by Union harmonisation legislation. Member States had to designate national competent authorities during 2025. For anyone building a two-year AI roadmap from Brussels, those dates are not background reading — they are the gating factors that determine when a system is allowed to go live, and they need to sit in the project plan next to the sprint dates.
The buying process reflects that seriousness. Whether you are an EU agency procuring through a framework contract advertised on TED, a sector federation answerable to a member assembly, an NGO accountable to institutional funders, or a Belgian financial firm supervised by the NBB and the FSMA, an AI project is judged on its dossier as much as on its demonstration. Someone will ask where the data sits, which sub-processors touch it, how a decision can be reconstructed eighteen months later, and what happens when the model is wrong. An agency that cannot answer those questions in writing does not get past the second meeting — and in our experience the second meeting is where most AI vendors in this city quietly disappear.
The second half of the Brussels market is financial, and it operates under a different but overlapping stack. Belgian institutions supervised by the National Bank of Belgium and the FSMA have been subject to DORA — Regulation (EU) 2022/2554 — since 17 January 2025, which imposes ICT risk management, incident classification and reporting, resilience testing and a maintained register of information on third-party ICT providers. NIS2 sits alongside it for essential and important entities, transposed in Belgium ahead of most Member States and supervised by the Centre for Cybersecurity Belgium. An AI supplier entering this environment is itself a third-party ICT provider and will be assessed as one. That is why our contracting, exit provisions and sub-processor transparency get scrutinised in the same review as our model architecture, and why we prepare for that scrutiny rather than being surprised by it. Around this supervisory core sits an unusually dense payments and post-trade cluster — Euroclear in Brussels, Swift in La Hulpe, Mastercard's European operations in Waterloo, and the Febelfin membership — which means the local talent pool understands settlement, reconciliation and financial messaging deeply, and expects a vendor to speak that language too.
Finally, Brussels is genuinely trilingual in working practice: French and Dutch as the official languages of the Brussels-Capital Region, English as the de facto operating language of the European quarter, and German present in Council documents. An AI system that performs well in English and degrades in Dutch is not a minor quality issue in this market — it is a service gap with legal consequences for organisations that owe obligations to both Belgian language communities. Our office sits in the Securex building on Cours Saint Michel in Etterbeek, close enough to Schuman and Mérode that workshops happen in person rather than on a call.
#What Brussels organisations actually ask us to build
Regulatory intelligence a legal team will sign off on. Federations, public affairs consultancies and corporate EU offices track dozens of files at once across EUR-Lex, the Parliament's Legislative Observatory, the Council's public register, comitology documents, the Commission's consultation portal and the Official Journal. We build retrieval pipelines over those sources with one non-negotiable rule: no statement without a link to the document it came from. The hard engineering is not summarisation — it is version-delta detection, so an analyst sees precisely which recital or paragraph moved between two committee readings, rather than a fresh summary that hides the change.
AI literacy and governance programmes under Article 4. The literacy obligation is the most under-served requirement we encounter. It applies to providers and deployers alike, and it is not satisfied by circulating a slide deck. We start with an honest inventory of what is already running in the organisation, including the assistant tools staff adopted on their own without telling anyone, then build role-specific training, an internal usage policy that people can actually follow, and a maintained AI register that answers the first question any auditor asks: what systems do you operate, and who is accountable for each.
High-risk qualification for Belgian financial services. Annex III captures more of the financial sector than most firms initially assume — creditworthiness evaluation for natural persons, and risk assessment and pricing in life and health insurance among them. Qualification is the decision that shapes everything downstream: technical documentation under Article 11 and Annex IV, conformity assessment under Article 43, registration duties, post-market monitoring under Article 72. We do that analysis before architecture, alongside your compliance function, because a system designed without logging and traceability cannot be retrofitted into a high-risk system without substantial rework.
Knowledge assistants over a document estate. Think tanks, research institutes and NGOs in this city sit on twenty years of reports, position papers, evaluations and grant documentation, in several languages, mostly as PDFs with inconsistent structure. The value is not a chatbot; it is making an institutional memory searchable by meaning rather than filename. We treat access rights as a first-class design constraint: the assistant inherits the permissions of the person asking, so an embargoed draft never surfaces in an answer to someone who should not see it.
Member and citizen-facing services in three languages. Where an AI system interacts directly with people, Article 50 transparency duties apply — users must know they are dealing with a machine. We design these services with a deliberate escalation path to a human, because the reputational cost of an AI assistant confidently misstating your organisation's position on a live file is far higher than the cost of a slightly slower reply.
Deployer readiness for organisations buying AI rather than building it. Most Brussels organisations will be deployers, not providers, and the obligations are different: operating the system according to the supplier's instructions, assigning competent human oversight with the authority to override, keeping the logs the regulation requires, and informing affected people where relevant. Public bodies and certain deployers additionally face a fundamental rights impact assessment. We are frequently engaged to assess a third-party AI tool a client has already bought, establish what obligations transfer to them as deployer, and negotiate the documentation gap with the original vendor — work that has nothing to do with building software and everything to do with keeping an organisation out of trouble.
The data work nobody puts in the proposal. Realistically, most of the effort in these projects goes into extraction from badly structured documents, deduplication, entity resolution across language variants of the same institution or company name, and building the evaluation set that tells you whether the system is improving. Production infrastructure runs in the EU, with a GDPR Article 28 processing agreement and an EU-only sub-processor list, because for a supervised or publicly funded organisation that is a precondition rather than a preference.
#How an engagement runs
We start with a framing workshop on site, with your business owners, your DPO and — if you are supervised — someone from compliance in the room from the first session rather than at the review at the end. The output is a scored shortlist of use cases: expected value, data readiness, and regulatory exposure under the AI Act and GDPR, assessed together. Roughly half the ideas that arrive at that workshop do not survive it, which is the point.
The second phase is data readiness. We look at what actually exists rather than what the documentation says exists, and we build the evaluation set before we build the system. Without an agreed set of questions and correct answers, "it works well" is an opinion; with one, quality becomes a number that moves between sprints and can be shown to a steering committee.
Build runs in short cycles with working software reviewed on site. Compliance artefacts are produced in parallel — technical documentation, the logging design, the human oversight procedure, the monitoring plan — not assembled in a panic before go-live. Standard scopes reach production in eight to twelve weeks. After launch, monitoring covers both technical availability and answer quality, because a system that is up and wrong is worse than one that is briefly down. Your team is trained to operate it, and the codebase and documentation are yours.
#Where these projects go wrong
The proof of concept that proves nothing. A demo on a curated sample tells you the technology works, which was never in doubt. It tells you nothing about your real documents, your permissions model, or your edge cases. We prefer a narrow slice built to production standards over a broad prototype that cannot be promoted.
Buying a model instead of designing a process. The model is a component. The value comes from where it sits in a workflow, who checks its output, what happens when it abstains, and how the correction loop works. Organisations that skip this end up with an impressive tool nobody uses.
Treating compliance as a document produced at the end. Traceability, logging and human oversight are architectural properties. If they are not designed in from the start, the compliance dossier written afterwards describes a system that does not exist.
Assuming multilingual means translated. Running a French pipeline and translating the output produces Dutch that is technically correct and professionally wrong — terminology in Belgian administrative and financial contexts does not survive machine translation intact. Language belongs in the architecture and in the evaluation set, per language.
Underestimating change management. In organisations where analytical judgement is the profession, an assistant that appears to do that judgement is met with justified scepticism. The successful deployments are the ones positioned as removing the reading load so the expertise has more room, and that framing has to come from the client's own leadership, not from us.
#Four questions worth putting to any AI agency in this city
Ask where production data is processed, and ask for the sub-processor list in writing rather than a reassurance. Plenty of stacks that are described as European route inference through a US-controlled endpoint at some point in the chain, and you will not discover that from a sales deck.
Ask how the supplier will demonstrate that a specific output was produced by a specific version of the system on a specific date. If the answer involves retrieving logs that were never designed to be retrieved, you have a compliance problem that will surface at the worst possible moment.
Ask what the evaluation set looks like and who owns it. A supplier who cannot show you how quality is measured is asking you to accept their judgement about their own work — and when the engagement ends, you inherit a system nobody can assess.
Ask what happens on exit. You should be able to leave with the code, the prompts, the evaluation data, the documentation and a migration path for the data. Anything less is a dependency, and a supervised organisation will be asked about it during a resilience review.
#What you can expect to measure
Across our AI engagements the average is 340% ROI over twelve months, with a 40% reduction in operating costs on the processes we automate and a 55% productivity gain on high-value tasks. Standard scopes reach production in 8 to 12 weeks, with 99.5% availability observed in operation. These are measured against KPIs agreed with you during framing, on your own baseline — not commercial projections, and not transferable between clients without checking that the comparison holds.
#Why Nehos in Brussels
- On the ground — Securex building, Cours Saint Michel 30A, 1040 Brussels. Framing workshops, sprint reviews and steering committees held in person, minutes from the European quarter.
- 47 specialists in AI, data and cloud, including people who have followed the AI Act since the trilogue stage and can discuss it at article level with your legal team.
- 200+ projects in production since 2014 — an operating record, not a research portfolio.
- European sovereign hosting — production data stays in the EU under GDPR, with the documentation an FSMA review or an AI Act assessment will ask for.
- Trilingual delivery — French, English and Dutch, in the product and in the documentation.
- Free audit — 30 minutes to qualify your use case, name the regulatory constraints that apply, and give you an honest view of expected return.
#Complementary services in Brussels
- our national AI agency service
- the Nehos Brussels office
- AI agents for Brussels institutions and federations
- GEO/AEO citability for EU affairs teams
- Next.js platforms for institutions and Belgian FinTech
- our client success stories
- our guide to EU AI Act compliance
Related areas we cover: artificial intelligence agency Brussels, EU AI Act compliance agency, AI agency Belgium, fintech AI Brussels, agentic AI EU institutions.
The FAQ below answers the questions our Brussels clients ask most often on this topic.
Get in touch with our Brussels team for an initial conversation with no strings attached: we assess the potential of your project together and give you a costed estimate of the expected ROI.