Governancethatruns,notgovernancethatiswrittendown.
A policy that lives in a document is a statement of intent. A policy that is evaluated in the request path is a control. This page is about the second kind.

Wherethispagesits
There are two different conversations that both get called AI governance. One is about regulation: which obligations apply, what documentation is required, who signs it. The other is about mechanism: what the system does when a request exceeds what was authorised.
This page is about mechanism. The regulatory material — the frameworks, the residency questions, the procurement pack — lives in the trust centre, because that is what a security or compliance reviewer is looking for and they should not have to read a product page to find it.
Themechanisms
Policy enforcement
Policies are evaluated before execution, against typed objects, with the decision and its inputs recorded. Deny is the default for anything not granted.
Risk classification
Workflows carry a risk level that determines approval thresholds, evidence depth, evaluation frequency and who must review changes.
Agent lifecycle
Draft, review, approved, deployed, under review, deprecated, stopped. Transitions require an owner and leave a record.
Model governance
Registered models with permitted uses, evaluation results, retention terms and a promotion gate between environments.
Approvals
Human decisions routed by object ownership, with the case assembled, an expiry, escalation and recorded reasoning.
Evaluation
Task-specific suites and regression tests run on change, so quality is measured rather than assumed.
Evidence
A reviewable record per decision: inputs, context, model, tools, approvals, outputs and the model version in force.
Change control
Prompt, policy, ontology and model changes are versioned artefacts with authors, reviewers and a rollback path.
Human oversight
Defined oversight roles with the access and the information required to exercise them, rather than a nominal sign-off.
Whathappenswhensomethingchanges
The most common cause of an AI system behaving differently in production is that something changed and nothing measured it.
On compliance language
NeuroCluster supports controls relevant to established AI and information-security frameworks. Whether a given deployment meets a given obligation depends on how it is configured, operated and documented — a deployment-specific assessment is always required, and nothing here is legal advice.
Questions
- Does using NeuroCluster make us compliant?
- No platform can. Compliance is a property of your deployment, your processes and your documentation. What a platform can do is make the required controls implementable and the required evidence a by-product of normal operation rather than a separate reporting exercise.
- Who owns governance in practice?
- Split, and deliberately so. Business owners own mandates and approve actions on objects they are accountable for. Platform and security own the enforcement mechanisms. Risk and compliance own the classification scheme and audit the evidence.
- How is this different from an AI policy document?
- A document tells people what to do. These mechanisms decide what the system does when someone does not. Both are needed; only one of them is testable.
Continue
- Trust centreFrameworks, residency, procurement and diligence material.
- Control planeThe enforcement path policy runs in.
- AgentsMandates, approvals and kill switches.
- SecurityThe controls a security architect will ask about.
- AI governance frameworksHow the mechanisms map to framework expectations.
- Use casesGoverned workflows with their evidence level stated.
Bring us one operational problem.
You do not need a finished brief. Bring the problem — we will work out the next step together.
Or book a call with the team