Europe
NOW OS maps your organization's work to individual actions, scores each against your own rules, and recommends one of four modes — Automate, Augment, Assist, or Human-Only. Your named people decide, and every decision carries a name, a date, and a rationale. That is the decision architecture works councils and regulators ask about first — and it is how the product works, not a European edition of it.
Two audiences, stated separately
Our UK remote offices lead conversations with UK organisations. They do not answer EU-27 questions — EU representation, EU data residency, and EU AI Act conformity are separate commitments, and we will claim each only when it is real.
United Kingdom — engage now
Nexus of Work has UK remote offices in Manchester and Tyneside. Conversations with UK organisations happen on UK hours with UK-based people — not across a transatlantic time difference.
EU-27 — a readiness conversation, stated plainly
Today we have no EU entity, no appointed EU representative, no EU data residency, and no European customers. EU AI Act obligations for high-risk workplace systems in our category (Annex III) apply from 2 December 2027 — a runway we are building along, and we publish what exists against it rather than ahead of it.
For workers’ representatives
A system that maps work to individual actions will be examined under co-determination and consultation rights — Germany’s Betriebsrat, the Dutch ondernemingsraad, the French CSE. It should be. Here is our answer, written down before any contract is signed.
NOW OS maps the structure of work — what the actions are, what rules govern them, and which of four modes is recommended for each. It scores actions against rules. The decision record then captures who decided each allocation, when, and on what rationale. Your works agreement and your access rules govern who sees what; we build to make that governable, and we expect the question in every European deal.
The decision record itself captures the people doing the deciding — managers signing allocation decisions by name. That record is exactly what makes governance verifiable, and it is also employee data about the deciders. We say that plainly, because your works council will see it in the first demo — and because a record worth trusting is worth negotiating over.
NOW OS recommends Human-Only with the same scoring, evidence, and rules as the other three modes. Some work should stay with people; when the scoring says so, that is the recommendation — and your people can decide that way about any action regardless of what we recommend.
The EU AI Act expects workers and their representatives to be informed before a high-risk workplace system is put into use. The per-action decision record is a document an employer can actually put in front of worker representatives — a concrete artifact, not a policy summary. Country-specific collateral (German works-agreement clauses, French CSE briefing) is in development; we will publish it when it exists, not before.
Data, hosting, and GDPR posture
Today NOW OS runs on Amazon Web Services in the United States (US East, N. Virginia). We do not offer EU or UK data residency, and we will not imply otherwise. An EU region is a roadmap item tied to a first European customer commitment — a build, not an announcement.
The part residency would not fix: as a US-controlled company, Nexus of Work is subject to US access statutes — the CLOUD Act among them — wherever the servers sit. An EEA region operated by a US company changes transfer mechanics; it does not change that fact. Your privacy team will raise this. We would rather raise it first.
On automated decisions (GDPR Article 22): NOW OS is built so that named humans genuinely decide — real authority to decide otherwise, an actual assessment, a documented rationale. The record shows who decided, when, and why: the evidence a privacy team asks for. Whether the review is genuine in practice depends on how you staff and empower your deciders — the record makes that verifiable; it does not make it automatic.
Transfers: any EU or UK personal data processed on US infrastructure needs a lawful transfer mechanism — for the UK, typically the ICO’s IDTA or the UK Addendum — assessed with your counsel case by case. We will not rest that story on any single framework’s current status.
We support customer data-protection impact assessments, and — for public bodies — fundamental-rights impact assessments, with the per-action evidence they need.
Trust inventory
We are a beta-stage company, so we publish the list. Updated quarterly; dated below.
| Item | Status today | Notes |
|---|---|---|
| Tamper-evident decision record | Shipping | Every allocation decision signed with a name, date, and rationale; in use in our U.S. beta. |
| Per-action provenance and scoring evidence | Shipping | Each recommendation carries its rule basis and evidence trail. |
| Reference deployment | One, in beta | A major U.S. public university system; one governed process end-to-end. Labeled beta because it is one. |
| SOC 2 report | Not yet held | Planned as commercial deployments mature; status updates here. |
| ISO 27001 certificate | Not yet held | Same basis as above. |
| Independent penetration test | Not yet published | Will be commissioned and summarized here before first European production deployment. |
| EU / UK data residency | Not offered | Roadmap item tied to a first European customer commitment. |
| EU representative (GDPR / AI Act) | Not appointed | To be appointed when GDPR Article 27 requires it — a trigger we assess with counsel, including for inquiries that reach us through this site. |
| European customers or references | None yet | We will not imply otherwise anywhere on this site. |
Maintained by Nexus of Work · Last reviewed 1 September 2026 · Regulatory dates on this page should be confirmed with your counsel; we update this page as the regime evolves.
Proof, labeled
Alpha-Reveille, our first product, is in beta with one major U.S. public university system — governed allocation decisions made by named people, on a real process, with the tamper-evident record in daily use. What it does not yet demonstrate: a European deployment, a works-council-negotiated rollout, or scale beyond one process. We label the difference because the record of what is proven matters more to us than the size of the claim — and because European public-sector and university buyers ask the same governance questions, of a vendor they will judge on European terms.
Start the conversation
Talk to our UK team about governed AI adoption — universities and public sector first. The conversation happens on UK hours.
The readiness conversation vendors usually postpone: timelines toward December 2027, the evidence your worker representatives will need, and what has to exist before a deal can.