Your team is already using AI in a dozen places. Greyrox is the one place where every tool and agent is found, given its own identity, permissioned per action, logged as it works, and priced — so you can say yes to the next workflow instead of quietly hoping.
Built for teams of 10–250 · Typically live in 2–3 weeks · No engineers required
Gottmer — children's publishing, Netherlands. Editorial and production workflows governed from the first run, delivered on our own platform, with no third-party engine underneath.
Your team gets hours back, clients get faster answers, and you stop falling behind competitors already doing this. Governance is what makes it safe to keep going — but it isn't why you start.
Routine drafting, summarising, and data entry get handled automatically — freeing your team for the work only they can do.
Responses and deliverables move in a fraction of the time, without adding headcount to keep up with demand.
The same quality bar on the first task of the day and the fiftieth — less depends on who's busy or who's tired.
Connect the AI tools already changing your industry, without hiring engineers to wire them together yourself.
These figures reflect broader workplace AI research, not Greyrox's own measured customer results.
AI spend arrives as one line on a card statement, and nobody can say which team spent it. Greyrox prices each workflow as it runs, so the bill is attributable before it lands.
Spend broken out per workflow and per run, not aggregated into a single unexplainable total.
Where a task is templated and the risk is low, Greyrox recommends a cheaper model — only if the alternative is still EU-hosted.
A high-risk workflow is never switched to a cheaper model to save money. Cost optimisation stops where the risk tier begins.
Figures shown are illustrative.
Most companies are already using AI somewhere — in email, in a browser extension, in a tool a client asked for. "Shadow AI" is the part nobody signed off on: a personal ChatGPT account used for client work, a free trial that quietly became a daily habit. Nobody's being reckless. It's just how tools spread when there's no single place to see them all.
Greyrox continuously scans for AI activity across your systems — sanctioned or not — and surfaces anything unreviewed the moment it appears.
Staff adopt AI tools faster than IT can track them. There's no single list of what's connected to what.
One tool flags data leaks, another checks model bias, a third does access logs. None of them talk to each other.
Most AI governance advice is written for enterprises with dedicated compliance staff. You have neither the time nor the headcount.
The point isn't a bigger inventory — it's a safe way to add the next workflow. Every one, new or already running, goes through the same three checks before it's trusted with a live system.
A pass across your accounting or expense feed, plus whatever CRM, ERP or collaboration tools you connect, shows what's already in use — so a new workflow isn't the first thing on the list.
Each workflow is tied to its real EU AI Act tier and its own open actions, with permissions and an audit trail applied as it goes.
Every workflow — your team's idea or ours — goes through the same policy check before it can touch a live system. Approved actions run, anything sensitive pauses for a person, and the guardrails don't loosen on the tenth workflow just because the first nine went fine.
Every workflow request gets checked against your policies before it touches a live system, whether it reads a spreadsheet or sends an email to a client. Actions inside policy run immediately. Anything that reads sensitive data, writes to a system of record, or sends something outside the company pauses for a named person to approve — every time, not just the first time.
Discovery works the same way in reverse: connect your accounting feed or another system, and Greyrox flags AI vendor line items and existing usage automatically, without reading mailbox or document contents.
The agents do the work. Greyrox sits in between — logging what they touched, and holding anything sensitive for a person to approve first.
However many AI tools you connect, they all pass through the same layer — so every action, from any agent, gets the same identity check, permission, and log entry.
An agent cleared to draft emails isn't automatically cleared to send them.
No canvas required to start. Type what you want in plain English and watch the steps take shape as you refine it — then send it for review, or hand-build it yourself node by node if you'd rather.
← swipe to see the full workflow →
Every draft — chat-built or hand-built — goes through policy review before it goes live. A cost or convenience fix can never quietly skip that step.
The tier is what the workflow is: it follows from what the workflow touches and it barely changes. The open actions are the work state — that's the number that moves as you close things out. Greyrox keeps them apart, and keeps them attached to the workflow all the way into production.
No specific obligations. Logged and permissioned anyway, because that's how you keep it that way.
Sends content directly to a person outside the company, so the Article 50 transparency obligations apply — in force since 2 August 2026. Its send step is held for a person to approve until a named sender is set.
Recruitment screening is explicitly listed as high-risk. Chapter III obligations apply from 2 December 2027, deferred from August 2026 by that summer's Omnibus amendment — the substance didn't change, only the date. Which obligations land on you depends on whether you built the system or deploy a vendor's.
The AI Act's Digital Omnibus amendment — Regulation (EU) 2026/1744 — entered into force on 27 July 2026. It pushed high-risk obligations under Annex III to 2 December 2027 and Annex I to 2 August 2028, while Article 5 prohibitions, Article 4 AI-literacy duties and Article 50 transparency were left exactly where they were. A great deal of published guidance — and a great many vendor decks — still cite the old August 2026 deadline.
Which obligations land on you depends on whether you built the system or deploy a vendor's. Greyrox works that out per workflow, so you're not guessing, and so the answer survives being asked by an auditor.
Every integration inherits the same permissioning, audit log and risk status — no matter which vendor it comes from.
Greyrox is a Dutch company, built and run from Amsterdam, for European companies that want the productivity without the exposure. We build the platform ourselves — our customers run on our own codebase, not on somebody else's engine with our name on it.
Where your data lives, who processes it, and how long we keep it →
Greyrox B.V.
IJsbaanpad 2
1076 CV Amsterdam
The Netherlands
Next to the Olympic Stadium, five minutes' walk from Amsterdam Zuid station.
Open in Maps →Thirty minutes. We'll show you the handoff on real screens, answer where your data sits, and tell you plainly if we're not the right fit.