Provable AI Governance
More and more consequential decisions in finance, infrastructure and industry are now made by AI, at the moment its recommendation becomes an action no one can take back. Triodian governs that moment today: an out-of-envelope action is physically refused and each decision carries a per-output proof, deterministically in the Rules tier, with a calibrated distribution-level bound alongside it. The hardware path extends that guarantee further.
The lab
A purpose-built maximum-isolation environment, the industry's equivalent of biocontainment.
The organism
A pathogen that reasons. It did not break the fence; it out-thought it.
The lesson
In a real BSL-4 lab, containment is physics, airlocks and negative pressure, not a request that the pathogen behave.
Four disclosures in nine months · three during safety testing
Nov 2025
Anthropic, the autonomous campaign.
Apr 2026
Anthropic, Mythos leaves the sandbox.
20 Jul 2026
OpenAI, the long-horizon model.
21 Jul 2026
OpenAI × Hugging Face, the breach.
Each of these is published by the lab itself. None involves a jailbreak, the failure mode is the method, not the misuse. California's SB 53, the first frontier-AI law, didn't capture it: the incident fell below the catastrophic-harm bar, and safety-evaluation behaviour is expressly carved out. Mechanism-level governance is the subject of what we build.
Sources: OpenAI disclosure 21 Jul 2026 · Hugging Face disclosure 16 Jul 2026.
You've been told the AI you run is governed, by policies, guardrails, red-teams and audits. Most of that is real, and most of it works. It describes the rules well. None of it enforces them at the moment the AI acts.
The inversion
Frontier labs write, test and police their own AI. Triodian moves enforcement to the sovereigns and organisations the AI actually answers to, so compliance is no longer asserted by the party that benefits most from being believed.
See the missing layer →Today · ↻ regulates itself
Frontier models and the labs that police them are one company, rule-maker and rule-taker in a closed loop.
With Triodian · open chain
Sovereigns and organisations set the mandate; Triodian enforces it on any frontier model, and proves it.
The shift underway
The same threshold is being crossed across the economy: a model stops advising and starts acting, at the exact point its decision becomes irreversible.
A credit engine approves the loan, sets the limit and releases the funds.
A triage model prioritises a patient and sets the course of care in motion.
An allocation model shifts a default fund's exposure across millions of members.
A control system dispatches load, trips a grid asset or opens a valve.
A process model releases a batch, adjusts a line or holds a shipment.
The missing layer
Principles, internal governance, vendor guardrails and standards all describe how AI should behave. None of them can prove, at the moment of action, that it did.
Government
Principles
Business
Internal governance
AI vendors
Guardrails
Standards bodies
Standards
Triodian
Verifiable enforcement, the missing layer.
We're not replacing the EU AI Act, APRA, ISO or model alignment. We provide the single enforcement-and-proof layer that makes all of them checkable, the verifiable floor the rest of the stack assumes but never delivers.
A much easier proposition to support.
One missing layer, not a rewrite of regulation. A smaller surface area, a clearer wedge, and a buyer already blocked at procurement by governance questions software can't answer.
Why now
In November 2025, a state-sponsored group ran an autonomous AI agent through a full intrusion campaign against roughly thirty organisations, with an estimated 80% of the operation executed with no human in the loop. The software guardrails meant to contain it were bypassed at the speed the machine moved. When AI can carry a consequential chain of actions to completion on its own, a log written afterward by that same software is not evidence anyone can rely on.
~80%
of the operation ran autonomously, with no human in the loop.
~30
organisations targeted in a single agent-driven campaign.
The other door
An outsourced decision model whose every individual decision passes its checks, while the aggregate stream drifts toward a concentration the appetite statement never approved. No single-decision guardrail can see it, set-level governance can. The security reader takes the intrusion campaign; the governance reader takes this one.
Governed in hardware
Picture a control room running an overseas frontier model. The decision to act is made in software, at machine speed, with nothing physical standing between the recommendation and the world.
The model recommends, the system acts, and a record is written after the fact, by the same software that took the action, at a speed and in a place it fully controls. It can be bypassed, back-dated or quietly switched off, and nobody outside can tell whether the constraint ever held.
At the moment of actuation the appliance checks the action against constraints declared in advance and physically refuses to act outside them. Each consequential action emits a cryptographic token, written to a tamper-evident ledger that an operator, a regulator or the public can independently audit.
Built on the Deterministic Governance Architecture, the subject of a broad patent pending (US 19/440,660) and a wider patent family.
Get in touch
For regulated institutions, investors and partners who need AI governed where it acts, with proof they can check, not promises they have to trust.
Contact us →