Governed and sovereign AI

Governed AI for regulated industries

Control your AI before you scale it.

What governed AI is

A control plane between AI and your systems.

A control plane sits in the request path between AI and the systems AI uses. The AI can be a person in a chat assistant or an autonomous agent calling tools. In both cases a gateway enforces policy. You operate the gateway, not the model provider.

Users and agents authenticate to the gateway, never directly to the model.
Every request passes a policy check and leaves an audit record tied to a named person.
Data stays inside your own cloud account, in EU regions.
Credentials are short-lived and follow your identity provider, so offboarding is automatic.
Definitions

Governed AI, defined.

The question a regulator asks is not whether you use AI. It is whether you control it.

What is governed AI?

Governed AI is an architecture and operating model in which every AI interaction passes identity, policy, access, approval, and audit controls before the AI can reach data or take action.

What is an AI control plane?

An AI control plane is a gateway in the request path between AI and the systems it uses. Users and agents authenticate to it, every call is policy-checked and logged to a named person, and it runs in your own EU cloud account. You operate it, not the model provider.

Why now

The obligations already apply.

Regulated firms do not get to wait for AI rules to settle. Several are in force today, and they all ask the same thing: show who did what, with which data, and prove it.

EU AI Act

Article 50 transparency duties are in force since 2 August 2026. High-risk obligations follow: Annex III systems from 2 December 2027, Annex I from 2 August 2028. Building the controls now means later use cases inherit them instead of retrofitting.

Primary source (EUR-Lex)

DORA

AI vendors and cloud services count as ICT third parties. Financial entities must govern that third-party risk and keep a register of their contractual arrangements with ICT providers. This is the strongest hook for banking.

Primary source (EUR-Lex)

GDPR

Personal and investor data needs minimization and purpose limits, and transfers outside the EEA must satisfy Chapter V. EU-only inference reduces transfer risk and keeps that data inside the boundary.

Primary source (EUR-Lex)

AML and KYC

Monitoring obligations demand traceable, auditable processes. An AI step in that chain has to leave the same evidence as any other control.

The six requirements

What a governed setup has to satisfy.

These are the tests every use case runs against. Meet them once, in one foundation, and each new use case is born compliant instead of retrofitted later.

Transparency

People always know when they are talking to AI. Disclosure is enforced for everyone, not left to each team.

Human oversight

AI assists and suggests. People decide. Approval gates sit in front of anything that changes state.

Traceability

Every AI action is logged and attributable to a named person. The record survives outside the tool.

Least privilege

Each use case gets only the data and tools it needs. Access follows identity provider groups, nothing wider.

Cost accountability

Spend is capped and attributed per team and per person, with a hard stop at the cap.

Data sovereignty

Regulated data stays inside your cloud boundary, in the EU. No traffic to third parties.

The autonomy ladder

Earn autonomy with evidence.

A use case moves up one rung only after its controls are proven in production. Autonomy is earned with evidence, not granted by default.

  1. 01

    Assisted

    AI drafts and suggests. A person reviews and acts on every output.

  2. 02

    Semi-autonomous

    AI completes low-risk steps within tight bounds. A person approves before anything commits.

  3. 03

    Supervised autonomous

    AI runs a workflow end to end. A person monitors and can stop it at any point.

  4. 04

    Fully autonomous

    AI acts without a person in the loop. Reserved for reversible, well-proven paths.

From requirement to evidence

Every control answers an obligation.

Governance only counts if you can point at the record. This is how each requirement maps to a regulation and to a control that produces evidence.

RequirementRegulatory anchorControl that produces evidence
TransparencyAI Act Art 50Disclosure and house rules enforced across the organization through the gateway.
Human oversightAI Act Arts 14 and 26, GDPR Art 22An autonomy tier per use case. Assistants suggest, people approve.
TraceabilityAI Act Art 12, DORA, AML recordsA per-request audit record with the caller's identity, streamed to your logging and SIEM.
Least privilegeGDPR Arts 5 and 32, DORAIdentity provider groups drive model and tool permissions per use case.
Cost accountabilityManagement accountabilitySpend caps per organization, team, and person, with a hard stop.
Data sovereigntyGDPR Chapter V, EBA outsourcingInference runs in EU regions inside your account. No data leaves the boundary.
Who this is for

Built for teams that have to prove it.

The pattern transfers across any environment where an AI action needs an owner, a log, and a boundary it cannot cross.

Banks and financial firms

Licensed, supervised, and accountable for who used which data, for what, and at what cost. Governed AI turns that into evidence a regulator can read.

Research institutes

Sensitive datasets, funding conditions, and export rules that make data residency and access control non-negotiable.

High-security environments

Teams where every action needs an owner and a log, and where a tool that cannot prove what it did is a tool that cannot be used.

Selected outcomes

Proof it works.

We design governed AI foundations for European regulation. What that produces, in practice:

Model inference stays inside the firm's own EU cloud account. No regulated data leaves the boundary.
Every AI request leaves an audit record tied to a named employee, ready for the regulator.
Access is scoped per use case from the firm's existing identity provider. Least privilege by default.
One governed foundation that new use cases inherit, so each is compliant from the start.
AI-assisted development stays within existing review, audit, and deployment controls, with no ungoverned path to data or production.

The outcomes above are kept non-identifiable. Named references and case detail are available on request, under NDA.

Assessment

See where you stand.

An assessment reviews how you control AI today, across nine areas from the control plane to governed delivery. How we think is public, so you can read the whole picture before we talk.

See what we assess

How it works

A structured review, then a plan you can act on.

An assessment works with your Risk, Security, Platform, and Architecture people. It produces documents you can use, not a summary you file away.

What you get

  • A prioritized shortlist of use cases that are safe to start with
  • An autonomy tier and risk assessment for each candidate
  • The control model your first use case must satisfy
  • A requirement to control to evidence map for your regulator
  • Ownership split across Risk, Security, Platform, and Architecture
  • A 90-day plan for a first governed pilot
Format

Remote or on site, whichever suits your teams. You work directly with the person running the assessment, not a rotating team.

Request an assessment