Two of this month's five free Independent AI Audits are still open — included when you start an AI health check.Check eligibility →
Platform

Every AI request passes through one gateway. Six things happen on the way.

Vendor-neutral. Deployed in your own cloud. Everything else is produced from what the gateway already knows.

Where AI is used

Staff toolsChatGPT, Copilot, Claude, Gemini — on managed accounts
AI inside your softwareCRM, finance, HR and service platforms with AI features
Your agentsGenWA Agents and any you have built or bought
Developers & integrationsApplications calling model APIs directly

GenWA Gateway YOUR CLOUD

01
IdentityEvery request tied to a managed account, team and purpose.
02
RulesYour policy, enforced: what is allowed, by whom, for what.
03
Data protectionPersonal and sensitive data removed before it leaves.
04
Model choiceThe approved model for the task, at the lowest adequate cost.
05
MeteringCost per request, per team, per task — with budgets and alerts.
06
LedgerA permanent record of what was asked, answered and decided.

Models & vendors

OpenAIGPT family
AnthropicClaude family
Amazon BedrockNova and hosted models
Microsoft & GoogleAzure OpenAI, Gemini
Private modelsHosted in your environment
Connection point managed by the gatewayDeployed into your AWS or Azure account · Nothing routes through GenWA infrastructure
The gateway

One gateway between your business and every AI lab.

Every request passes through it. Identity, rules, data protection, model choice, metering and a permanent record are applied in the gateway, so they are identical whichever lab answers. Vendors become interchangeable. Control and visibility come from the one place they can.

People Staff on managed accounts Systems AI inside CRM, finance, HR Agents GenWA and your own Developers Applications calling models GENWA GATEWAY IDENTITY · RULES · REDACTION MODEL CHOICE · METERING · LEDGER OpenAI Anthropic Google Microsoft AWS Meta Mistral AI DEPLOYED IN YOUR CLOUD · NOTHING ROUTES THROUGH GENWA · LOGOS ARE THE PROPERTY OF THEIR OWNERS
ControlYour policy enforced on every request, to any model.
VisibilityEvery tool, account, pound and breach, in one register.
IndependenceSwitch models without rewriting a policy or retraining a team.
In use

Built to be read by a finance director, not just an engineer.

watch.genwa.co.uk/prove/rules
Rules · 14 active · 1 suggestedLast change approved by J. Hart, 9 Sep
R-01
Personal data leaves only after redactionapplies to: all requests · action: redact then allow · exceptions: 0
Enforced
R-04
Customer-facing text requires a compliance passapplies to: Comms, Customer operations · sign-off: category-based
Enforced
R-07
Premium models by exception onlydefault: standard tier · override: named roles, logged
Enforced
R-09
Finance team monthly budget £2,500alert at 80% · block non-essential at 100% · owner: FD
Enforced
R-12
Agents may not send external email without approvalaction: hold for named human · timeout: 4h
Enforced
R-15
Block uploads of payroll files to any AI toolproposed by: HR Director · conflicts: none found
Awaiting sign-off
R-16
Suggested: cap premium use in Marketing at 10%proposed by: the gateway, from 30 days of routing data · needs: Marketing Director sign-off
Suggested
A policy is a document. A rule is a control.

Rules are written in plain English by the people who own them, turned into controls by the gateway, and checked for conflicts before they go live.

  • Owners named on every rule
  • Conflicts caught before activation
  • Exceptions counted, never hidden
  • Rules suggested from what the gateway sees, never live without sign-off
watch.genwa.co.uk/prove/audit
Audit logappend-only · hash-chained · example entries
09:41:02 req 8f3a21 cust-ops/a.patel purpose=letter-draft model=standard ALLOW £0.004 09:41:02 req 8f3a21 R-01 redaction: 2 fields (name, account-no) APPLIED 09:41:07 req 8f3a21 R-04 compliance pass: disclosures ok, tone ok PASS sign-off=reviewer 09:43:15 req 8f3a9c finance/m.okafor purpose=analysis model=premium→standard ROUTED R-07 09:44:50 req 8f3b02 hr/upload payroll_sep.xlsx → external tool BLOCK R-15 · notified owner 09:45:31 agent comms-04 action=send-email external HELD R-12 · awaiting approval (owner: S. Reid) 09:52:08 req 8f3b77 eng/s.lee purpose=code model=premium ALLOW override=role:lead £0.061 10:00:00 budget finance £2,105 / £2,500 (84%) ALERT owner=FD
What the AI saw, decided and did — months later.

Every request, rule decision, routing choice and human sign-off is written to a permanent, tamper-evident record in your environment. It is what a regulator, an auditor or a complaint will ask for.

  • No manual logging step
  • Tamper-evident by construction
  • Feeds the evidence pack directly
watch.genwa.co.uk/see/models
Change Control · approved-use list3 releases this month · 1 retirement notice
Task → approved tier · where AI is not to be used
Task Approved tier Data allowed Human check Status
Summarise, draft internal Standard Internal Spot Live
Classify, extract Small / fast Internal, customer (redacted) Sample Live
Customer communications Standard + compliance pass Customer (redacted) Category-based Live
Analysis, reasoning Premium (by role) Internal, financial Always Live
Credit, hiring, medical decisions — — — Not permitted
"Model X 2.1" (released 9 Sep) Under evaluation None yet — Testing
This month’s briefing · for the board

Three new models released; one vendor retirement with 90 days’ notice affecting the classification tier — a tested replacement is staged. No action required by staff. Cost effect of adopting the new standard-tier model: −11% per request at equal quality.

Which model, for what, and when not — decided once, centrally.

New models arrive every week from a handful of companies. Change Control keeps a tracked catalogue, an approved-use list the gateway enforces, and a safe process for switching — so those decisions are made by the business, not by whoever is using the tool.

  • Monthly briefing in plain English
  • Where AI must not be used, written down
  • Tested in our sandbox before any switch
Pace of change

One interface. Any model. Switch without starting again.

A superior model launches on a Tuesday. Your policies, prompts, agents and records are attached to GenWA, not to a vendor. We test the new model in the sandbox, stage the switch under Change Control, and your people notice nothing except the improvement.

How the control wrapper works
Your policyYour prompts and agentsYour record
GenWA control wrapperidentity · rules · redaction · metering · ledger
OpenAIAnthropicGoogleBedrockPrivate

Vendors change underneath. Nothing above the line changes.

08 · The ground keeps moving

New models arrive every few weeks. Old ones are switched off. Someone has to decide.

A handful of companies and governments reshape the AI market month by month. Models are retired with weeks’ notice, change behaviour without a version change, and three vendors hold most of the enterprise market. Today that decision is made by whoever is at the keyboard.

Anthropic model deprecations, 20266

models retired by one leading vendor in six months, on 60 days’ notice.

OpenAI, 20262 wks

notice before four models were removed from ChatGPT.

Menlo Ventures, 2025 · vendor data83→16%

use of the previous model, one month after a new release.

Behaviour changes without a version changeA 2025 update made a leading model “noticeably more sycophantic”; it was rolled back four days later after the vendor’s own tests had looked good (OpenAI, 2025).
Terms change on the vendor’s timetableWeekly usage caps, pricing changes that produce surprise bills, outages with no refund, and government restrictions on specific models.
Capability is uneven and hard to readBenchmarks are gamed and saturating; vendor transparency has fallen. What a model can safely do for your job is specialist work, repeated every time the market moves.
The person deciding is your employee78% of AI users bring their own tools to work (Microsoft, 2024, vendor survey). Which model, for what, on which data, is being decided tool by tool at the desk.
What we do about it

We watch the market, test every relevant release against your jobs in our sandbox, decide where it may and may not be used, set that as the default in the gateway, and manage every change as a controlled event with a way back. Your staff do nothing. How Change Control works

Governance

Governance is a loop, not a document.

01PolicyBoard sets it
02RulesPlain English
03EnforcementGateway applies them
04EvidenceLedger and packs
05ReviewBoard, monthly
BoardSeat: a tapered walnut AI board member with bronze edging, a circular light wheel on top and a glass window revealing the technology inside its crafted case. Concept visual.
Pre-order Powered by GenWA

BoardSeat. A trusted AI in the room.

A physical AI board member you place in the room where you want extra intelligence and governance. It listens and talks, challenges where it adds value, projects the discussion onto the wall and keeps the meeting on track. You choose when it is on, and what it records and leaves out. Your team makes the decisions.

  • Sits locally and is completely configurable: tuned to your business, market and regulators.
  • Designed to speed up decision making, with a design target of ten times faster.
  • Not a black box: a glass window shows what is inside the crafted case.
UK made, governed, trained.
The sandbox

We test it before you use it.

New models arrive most weeks from a handful of companies. Deciding which to use, for what, and when not to, is not a decision your employees should be making. So we make it first, in a controlled sandbox, with a dedicated research team.

01BehaviourDoes it follow instructions, refuse what it should, and stay consistent across runs?
02StabilitySame input, same answer, over days. Drift measured, not assumed.
03CostReal cost per task at equal quality, against the model you use today.
04Data handlingWhere prompts go, what is retained, and whether that meets your policy.

Ask us to test a specific frontier model against your workload. You get a written result and, if it passes, a staged switch with a way back.

sandbox.genwa.co.uk/runs
Sandbox · this month4 releases tested · 1 approved · 1 declined · 2 in progress
Release Behaviour Stability Cost vs current Data Verdict
Standard-tier model, 9 Sep Pass Pass · 0.4% drift −11% Pass Approved
Premium model, 2 Sep Pass Fail · 6% drift +38% Pass Declined
Small model, 11 Sep Testing Day 3 of 7 −54% Pass In progress
Client request · voice model Testing Day 1 of 7 — Review In progress

Example data. Results are written up monthly in the Change Control briefing.

Evidence

Documents your auditor can read, produced from the record.

AI RegisterEVIDENCE PACK · 02 OF 06 · SEPTEMBER 2026
Scope

All AI tools, accounts, agents and integrations observed through the gateway or declared in the audit, with owner, purpose, data classification and control status. Example organisation, 310 staff.

Asset Owner Purpose Data Status
Microsoft 365 Copilot (212 seats) IT Director Drafting, summaries Internal, personal Controlled
ChatGPT Team (48 seats) COO Research, drafting Internal Controlled
Claude (personal accounts, 31 found) — Various Unknown Migrate to managed
CRM "AI assist" feature Head of Sales Email drafting Customer, personal DPIA required
Comms agent (collections letters) Head of Ops Customer communication Customer, financial Controlled · named owner
Finance forecasting script (API) FD Analysis Financial Budget cap set
Recruitment screening tool (vendor) HR Director CV ranking Candidate, personal Automated-decision review
Summary

23 assets registered. 14 controlled; 5 require action within 30 days; 4 pending DPIA. Personal-account use reduced from 31 to 0 on migration to managed identities (target: 30 Oct 2026).

Generated from gateway ledger · hash 4c9e…f21aPage 2 of 6
01
Board reportExposure, spend, value and the decisions that need taking. One page.
02
AI registerEvery tool, account, agent and integration, with owner, purpose and status.
03
Data-flow mapWhat personal and sensitive data goes into which AI, and what comes back.
04
Policy and control matrixEach rule mapped to ISO/IEC 42001, UK GDPR & DUAA, SOC 2 and Cyber Essentials, with gaps named.
05
Model policy, cost and routing reportApproved-use list; spend by team, tool and task; unused seats; savings.
06
Exception and incident logEvery block, hold, override and escalation, with who resolved it and how.
Questions we are asked

Before you book a demo.

Is the gateway a single point of failure?

It runs in your cloud account with the same availability as the rest of your estate, and a fail-open or fail-closed setting you choose per rule.

Does it work with the Copilot or ChatGPT licences we already pay for?

Yes. Managed accounts for those tools are routed through the gateway; usage, cost and rule results appear in Usage Insight.

How does redaction work? Will it break the answers?

Personal and sensitive fields are replaced before the request leaves and restored in the response. Most tasks are unaffected; where a task needs the raw data, a rule permits it for named roles, and that is logged.

Can our own systems call GenWA?

Yes. Your applications and automation tools, including Power Automate flows, can call the gateway directly, so AI inside your own workflows is covered by the same rules and the same record.

What happens when a vendor retires a model?

Change Control gives notice, with a tested replacement staged and a way back. Staff do nothing.

Find out where your AI stands. Then decide.

Under a minute, an upload, or a visit. Something for the board either way.