What you'd show the regulator, before they ask.
Every AI-assisted decision your business makes needs a rule behind it, a log to prove it was followed, and a named human who owns it. Right now, most of that exists nowhere.
of UK organisations lack basic AI access controls.
IBM, 2025in 2026, the first publicly documented breach reached production systems via an AI agent.
GenWA incident researchof organisations have had an agent exceed its intended permissions.
Cloud Security Alliance, 2026- Policies that exist as documents, not as anything actually enforced
- No answer ready for what data an agent touched, what it decided, or who signed off
- Sector rules — UK GDPR and DUAA, SS1/23 and Consumer Duty, the SRA notice, CQC boundaries — treated as a compliance memo rather than a working control
- Personal liability for a decision an AI system made, with nothing you can point to
- Every regulatory framework that applies to a workflow configured as an enforceable rule, not a policy PDF
- A ledger of what every agent did, when, on what data, and under whose authority
- Evidence packs ready for a regulator, insurer or tender panel on demand
- A named human mapped to every agentic workflow before it runs, not after something goes wrong
Most compliance and legal leads start with Guard — the rules, enforcement and evidence layer — then extend it to whichever sector overlays apply.
Find out where your AI stands. Then decide.
Under a minute, an upload, or a visit. Something for the board either way.