Every AI request passes through one gateway. Six things happen on the way.
Vendor-neutral. Deployed in your own cloud. Everything else is produced from what the gateway already knows.
Where AI is used
GenWA Gateway YOUR CLOUD
Models & vendors
One gateway between your business and every AI lab.
Every request passes through it. Identity, rules, data protection, model choice, metering and a permanent record are applied in the gateway, so they are identical whichever lab answers. Vendors become interchangeable. Control and visibility come from the one place they can.
Built to be read by a finance director, not just an engineer.
Rules are written in plain English by the people who own them, turned into controls by the gateway, and checked for conflicts before they go live.
- Owners named on every rule
- Conflicts caught before activation
- Exceptions counted, never hidden
- Rules suggested from what the gateway sees, never live without sign-off
Every request, rule decision, routing choice and human sign-off is written to a permanent, tamper-evident record in your environment. It is what a regulator, an auditor or a complaint will ask for.
- No manual logging step
- Tamper-evident by construction
- Feeds the evidence pack directly
Task → approved tier · where AI is not to be used
| Task | Approved tier | Data allowed | Human check | Status |
|---|---|---|---|---|
| Summarise, draft internal | Standard | Internal | Spot | Live |
| Classify, extract | Small / fast | Internal, customer (redacted) | Sample | Live |
| Customer communications | Standard + compliance pass | Customer (redacted) | Category-based | Live |
| Analysis, reasoning | Premium (by role) | Internal, financial | Always | Live |
| Credit, hiring, medical decisions | — | — | — | Not permitted |
| "Model X 2.1" (released 9 Sep) | Under evaluation | None yet | — | Testing |
This month’s briefing · for the board
Three new models released; one vendor retirement with 90 days’ notice affecting the classification tier — a tested replacement is staged. No action required by staff. Cost effect of adopting the new standard-tier model: −11% per request at equal quality.
New models arrive every week from a handful of companies. Change Control keeps a tracked catalogue, an approved-use list the gateway enforces, and a safe process for switching — so those decisions are made by the business, not by whoever is using the tool.
- Monthly briefing in plain English
- Where AI must not be used, written down
- Tested in our sandbox before any switch
One interface. Any model. Switch without starting again.
A superior model launches on a Tuesday. Your policies, prompts, agents and records are attached to GenWA, not to a vendor. We test the new model in the sandbox, stage the switch under Change Control, and your people notice nothing except the improvement.
How the control wrapper worksVendors change underneath. Nothing above the line changes.
New models arrive every few weeks. Old ones are switched off. Someone has to decide.
A handful of companies and governments reshape the AI market month by month. Models are retired with weeks’ notice, change behaviour without a version change, and three vendors hold most of the enterprise market. Today that decision is made by whoever is at the keyboard.
models retired by one leading vendor in six months, on 60 days’ notice.
notice before four models were removed from ChatGPT.
use of the previous model, one month after a new release.
We watch the market, test every relevant release against your jobs in our sandbox, decide where it may and may not be used, set that as the default in the gateway, and manage every change as a controlled event with a way back. Your staff do nothing. How Change Control works
Governance is a loop, not a document.
BoardSeat. A trusted AI in the room.
A physical AI board member you place in the room where you want extra intelligence and governance. It listens and talks, challenges where it adds value, projects the discussion onto the wall and keeps the meeting on track. You choose when it is on, and what it records and leaves out. Your team makes the decisions.
- Sits locally and is completely configurable: tuned to your business, market and regulators.
- Designed to speed up decision making, with a design target of ten times faster.
- Not a black box: a glass window shows what is inside the crafted case.
The rules of your industry, built in as controls.
Every rule set is mapped to controls the Gateway enforces and the evidence pack reports. Your policy adds to it; it never starts from a blank page.
- UK GDPR and the Data Protection Act 2018
- Data (Use and Access) Act 2025
- ICO guidance on agentic AI and automated decisions
- CMA guidance on AI and consumers
- PECR (marketing and cookies)
- Equality Act 2010
- Employment law and ACAS guidance
- Consumer Rights Act 2015
- Companies Act reporting duties
- Bribery Act 2010 and Modern Slavery Act
- Cyber Essentials and NCSC guidance
- ISO/IEC 27001 and 42001
- PCI DSS (where cards are taken)
- FCA Consumer Duty
- CONC, DISP and SM&CR
- PRA SS1/23 model risk (AI and vendor models)
- Money Laundering Regulations 2017
- CQC AI expectations
- NHS DSPT and Caldicott principles
- MHRA ambient voice and software guidance
- SRA Standards and Regulations and the AI warning notice
- FRC guidance on AI in audit
- ICAEW, ACCA and CIOT guidance on AI
- Client confidentiality and privilege
- Ofcom (online safety, communications)
- Ofgem (energy)
- ASA CAP Code (advertising)
Control sets are mapped to published rules and guidance; they support compliance, they do not constitute legal advice. Coverage is extended each quarter. [Coverage to be confirmed by John.]
We test it before you use it.
New models arrive most weeks from a handful of companies. Deciding which to use, for what, and when not to, is not a decision your employees should be making. So we make it first, in a controlled sandbox, with a dedicated research team.
Ask us to test a specific frontier model against your workload. You get a written result and, if it passes, a staged switch with a way back.
| Release | Behaviour | Stability | Cost vs current | Data | Verdict |
|---|---|---|---|---|---|
| Standard-tier model, 9 Sep | Pass | Pass · 0.4% drift | −11% | Pass | Approved |
| Premium model, 2 Sep | Pass | Fail · 6% drift | +38% | Pass | Declined |
| Small model, 11 Sep | Testing | Day 3 of 7 | −54% | Pass | In progress |
| Client request · voice model | Testing | Day 1 of 7 | — | Review | In progress |
Example data. Results are written up monthly in the Change Control briefing.
Documents your auditor can read, produced from the record.
Scope
All AI tools, accounts, agents and integrations observed through the gateway or declared in the audit, with owner, purpose, data classification and control status. Example organisation, 310 staff.
| Asset | Owner | Purpose | Data | Status |
|---|---|---|---|---|
| Microsoft 365 Copilot (212 seats) | IT Director | Drafting, summaries | Internal, personal | Controlled |
| ChatGPT Team (48 seats) | COO | Research, drafting | Internal | Controlled |
| Claude (personal accounts, 31 found) | — | Various | Unknown | Migrate to managed |
| CRM "AI assist" feature | Head of Sales | Email drafting | Customer, personal | DPIA required |
| Comms agent (collections letters) | Head of Ops | Customer communication | Customer, financial | Controlled · named owner |
| Finance forecasting script (API) | FD | Analysis | Financial | Budget cap set |
| Recruitment screening tool (vendor) | HR Director | CV ranking | Candidate, personal | Automated-decision review |
Summary
23 assets registered. 14 controlled; 5 require action within 30 days; 4 pending DPIA. Personal-account use reduced from 31 to 0 on migration to managed identities (target: 30 Oct 2026).
Before you book a demo.
Is the gateway a single point of failure?
It runs in your cloud account with the same availability as the rest of your estate, and a fail-open or fail-closed setting you choose per rule.
Does it work with the Copilot or ChatGPT licences we already pay for?
Yes. Managed accounts for those tools are routed through the gateway; usage, cost and rule results appear in Usage Insight.
How does redaction work? Will it break the answers?
Personal and sensitive fields are replaced before the request leaves and restored in the response. Most tasks are unaffected; where a task needs the raw data, a rule permits it for named roles, and that is logged.
Can our own systems call GenWA?
Yes. Your applications and automation tools, including Power Automate flows, can call the gateway directly, so AI inside your own workflows is covered by the same rules and the same record.
What happens when a vendor retires a model?
Change Control gives notice, with a tested replacement staged and a way back. Staff do nothing.
Find out where your AI stands. Then decide.
Under a minute, an upload, or a visit. Something for the board either way.