Skip to content
NOVA

Intelligent Systems

Control before consequence.

AI is starting to act inside real business systems. We build the controls that decide what an action is allowed to do before it runs, involve people where the risk requires it, and keep the record of what was decided.

Built / Verified

Working implementation with internal verification.

The problem

AI systems are moving from making recommendations to taking actions. They call systems, move data, initiate transactions, and change states in software that organisations depend on. The distance between a model deciding something and the world changing because of it is collapsing.

Most governance was built for a slower world. Policies are written in documents, reviewed in committees, and checked after the fact through audit and incident review. That works when a human sits between intention and consequence. It does not work when an autonomous system acts in milliseconds, thousands of times a day, across systems no single reviewer sees.

The result is a gap organisations can describe but cannot close: they can tell you what their AI is permitted to do, and they cannot tell you what it actually did, at the moment it did it, with proof.

What we are doing

  1. Move the decision to the moment of action

    Governance is evaluated when an action is attempted, not summarised afterwards. The question changes from "what happened last quarter" to "is this specific action permitted, right now".

  2. Make the acting system identifiable

    An autonomous system gets an identity, a scope, and boundaries, the same way a person or a service would.

  3. Keep people in the path where risk requires it

    Higher-risk activity routes to human approval as part of the flow. Oversight is a step in the system, not a report produced after the outcome.

  4. Preserve evidence as it happens

    What was attempted, what was decided, and on what basis is retained at the time of the decision, so accountability does not depend on reconstruction.

Technology in play

  • AI Governance
  • Autonomous Systems
  • Cybersecurity
  • Runtime Control
  • Human Oversight
  • Evidence

Proof of work

What we can evidence today, with the limits of that evidence stated alongside it.

  1. The core governance platform and its enforcement model have been built and verified internally.

    Verification is internal. We do not publish the runtime path, decision logic, or service design.

  2. Runtime decisions are organised around four outcomes: proceed, proceed with constraints, route for human approval, or stop.

    This describes the shape of the decision, not the rules that produce it.

  3. Human approval and evidence retention are designed in as first-class paths, not added as reporting.

    Applies to higher-risk activity as classified by the operating organisation.

Status last verified 15 August 2026

The decision, in shape

Four outcomes, and what each one means for the system that attempted the action.

A governed action, one step at a time

When an autonomous system attempts something, the question is whether that specific action is permitted right now. A quarterly review cannot answer it. Select an outcome to see how the decision reads.

  1. Signal
  2. Decision
  3. Trust
  4. Evidence

Proceed

The action is within defined boundaries.

The system continues without interruption, and the decision is recorded with the context that produced it.

Illustrative. Decision logic is not shown.

Designed responsibly

  • Safety over convenience

    When the system cannot establish that an action is within boundaries, the safe outcome takes precedence over the fast one.

  • Separation between actor and authority

    The system taking an action is never the system that decides whether it is allowed to.

  • Evidence integrity

    Decision records are designed to be resistant to quiet alteration, because governance evidence is only worth what its integrity is worth.

Why it matters

Organisations are being asked to adopt autonomy at a pace that outruns their ability to supervise it. The usual answers are to slow down or to accept the risk quietly. Neither is durable.

Preventive control changes the trade-off. It lets an organisation grant real autonomy inside boundaries it has defined, with a record of how those boundaries were applied. Governance stops being the reason a deployment is delayed and becomes the reason it can proceed.