Control before consequence.
AI is starting to act inside real business systems. We build the controls that decide what an action is allowed to do before it runs, involve people where the risk requires it, and keep the record of what was decided.
Working implementation with internal verification.
The problem
AI systems are moving from making recommendations to taking actions. They call systems, move data, initiate transactions, and change states in software that organisations depend on. The distance between a model deciding something and the world changing because of it is collapsing.
Most governance was built for a slower world. Policies are written in documents, reviewed in committees, and checked after the fact through audit and incident review. That works when a human sits between intention and consequence. It does not work when an autonomous system acts in milliseconds, thousands of times a day, across systems no single reviewer sees.
The result is a gap organisations can describe but cannot close: they can tell you what their AI is permitted to do, and they cannot tell you what it actually did, at the moment it did it, with proof.
What we are doing
Move the decision to the moment of action
Governance is evaluated when an action is attempted, not summarised afterwards. The question changes from "what happened last quarter" to "is this specific action permitted, right now".
Make the acting system identifiable
An autonomous system gets an identity, a scope, and boundaries, the same way a person or a service would.
Keep people in the path where risk requires it
Higher-risk activity routes to human approval as part of the flow. Oversight is a step in the system, not a report produced after the outcome.
Preserve evidence as it happens
What was attempted, what was decided, and on what basis is retained at the time of the decision, so accountability does not depend on reconstruction.
Technology in play
Proof of work
What we can evidence today, with the limits of that evidence stated alongside it.
The core governance platform and its enforcement model have been built and verified internally.
Verification is internal. We do not publish the runtime path, decision logic, or service design.
Runtime decisions are organised around four outcomes: proceed, proceed with constraints, route for human approval, or stop.
This describes the shape of the decision, not the rules that produce it.
Human approval and evidence retention are designed in as first-class paths, not added as reporting.
Applies to higher-risk activity as classified by the operating organisation.
The decision, in shape
Four outcomes, and what each one means for the system that attempted the action.
A governed action, one step at a time
When an autonomous system attempts something, the question is whether that specific action is permitted right now. A quarterly review cannot answer it. Select an outcome to see how the decision reads.
The action is within defined boundaries.
The system continues without interruption, and the decision is recorded with the context that produced it.
Designed responsibly
Safety over convenience
When the system cannot establish that an action is within boundaries, the safe outcome takes precedence over the fast one.
Separation between actor and authority
The system taking an action is never the system that decides whether it is allowed to.
Evidence integrity
Decision records are designed to be resistant to quiet alteration, because governance evidence is only worth what its integrity is worth.
Why it matters
Organisations are being asked to adopt autonomy at a pace that outruns their ability to supervise it. The usual answers are to slow down or to accept the risk quietly. Neither is durable.
Preventive control changes the trade-off. It lets an organisation grant real autonomy inside boundaries it has defined, with a record of how those boundaries were applied. Governance stops being the reason a deployment is delayed and becomes the reason it can proceed.
Explore NOVA
- Information SystemsSources, confidence, and agreement stated in the result itself.
- Financial InfrastructureIdentity, movement, risk, and the ledger designed as one system.
- Work & Human SystemsLearning, hiring, and employment held in a single continuous record.
- Health SystemsReception, records, devices, and follow-up moving as one flow.
- Public SystemsNational-scale systems that integrate without displacing institutional authority.