Nine places where AI policy has to hold
Every use case below uses the same controls and produces the same evidence. Pick the one your security review is stuck on, and start there.
Govern production AI agents
An agent that can act is an actor in your organisation. It needs an owner, a risk rating, a permitted set of tools and a record of what it did.
Protect sensitive data
Personal data, credentials and confidential records reach models through prompts, retrieved context and tool responses. Minimisation has to happen in the request path, not in a policy document.
Control models and providers
Approval decisions are made per model and per region, then quietly bypassed the next time a team hardcodes a model name. Logical model names put the decision back in policy.
Govern MCP tools
MCP turned every internal system into something a model can call. The question stops being what the model says and becomes what it is permitted to do.
Enforce organisation-wide AI policies
An AI policy that lives in a wiki gets read once. The same policy, expressed as locked, recommended and optional controls, applies itself to every project on creation.
Build a live vendor and processor register
Your Article 30 records and vendor inventory are usually a spreadsheet describing last year. The control plane already knows which processors receive data today.
Prepare evidence for audits and reviews
Auditors and enterprise buyers ask the same question: show me that the control was active on this date, for this system. Answering it should take an export, not a project.
Control AI spend and usage
Runaway spend is a governance failure with an invoice attached. Budgets and rate limits belong next to the other controls, enforced on the same request.
Extend governance to coding assistants
The largest source of unmanaged AI traffic in most organisations is not an application. It is an IDE assistant and a browser tab, both reading source and customer data.
Consultancies, ISO 42001 implementers and AI Act advisors connect their assessments to obstruo enforcement, so their recommendations end up as active controls instead of a report.
Your AI. Your data. Your control.
Bring the use case that is blocking your security review. We will show the controls and the evidence it produces.