Governancethatruns,notgovernancethatiswrittendown.

A policy that lives in a document is a statement of intent. A policy that is evaluated in the request path is a control. This page is about the second kind.

Illustration of an approval card between a request and its reviewers, guarded by a policy check.

Wherethispagesits

There are two different conversations that both get called AI governance. One is about regulation: which obligations apply, what documentation is required, who signs it. The other is about mechanism: what the system does when a request exceeds what was authorised.

This page is about mechanism. The regulatory material — the frameworks, the residency questions, the procurement pack — lives in the trust centre, because that is what a security or compliance reviewer is looking for and they should not have to read a product page to find it.

Themechanisms

  • Policy enforcement

    Policies are evaluated before execution, against typed objects, with the decision and its inputs recorded. Deny is the default for anything not granted.

  • Risk classification

    Workflows carry a risk level that determines approval thresholds, evidence depth, evaluation frequency and who must review changes.

  • Agent lifecycle

    Draft, review, approved, deployed, under review, deprecated, stopped. Transitions require an owner and leave a record.

  • Model governance

    Registered models with permitted uses, evaluation results, retention terms and a promotion gate between environments.

  • Approvals

    Human decisions routed by object ownership, with the case assembled, an expiry, escalation and recorded reasoning.

  • Evaluation

    Task-specific suites and regression tests run on change, so quality is measured rather than assumed.

  • Evidence

    A reviewable record per decision: inputs, context, model, tools, approvals, outputs and the model version in force.

  • Change control

    Prompt, policy, ontology and model changes are versioned artefacts with authors, reviewers and a rollback path.

  • Human oversight

    Defined oversight roles with the access and the information required to exercise them, rather than a nominal sign-off.

Whathappenswhensomethingchanges

The most common cause of an AI system behaving differently in production is that something changed and nothing measured it.

What happens when something changes
01ProposedA change to a prompt, policy, model, mapping or mandate is raised as a versioned artefact.
02EvaluatedThe relevant suites run against the change. Results are attached, including regressions.
03ReviewedA reviewer appropriate to the risk class approves, with reasoning recorded.
04PromotedThe change moves environment by environment. Each promotion is a gate, not a deploy.
05ObservedPost-change behaviour is monitored against the pre-change baseline.
06ReversibleRollback is a tested path, and the evidence shows what was in force when.

On compliance language

NeuroCluster supports controls relevant to established AI and information-security frameworks. Whether a given deployment meets a given obligation depends on how it is configured, operated and documented — a deployment-specific assessment is always required, and nothing here is legal advice.

Questions

Does using NeuroCluster make us compliant?
No platform can. Compliance is a property of your deployment, your processes and your documentation. What a platform can do is make the required controls implementable and the required evidence a by-product of normal operation rather than a separate reporting exercise.
Who owns governance in practice?
Split, and deliberately so. Business owners own mandates and approve actions on objects they are accountable for. Platform and security own the enforcement mechanisms. Risk and compliance own the classification scheme and audit the evidence.
How is this different from an AI policy document?
A document tells people what to do. These mechanisms decide what the system does when someone does not. Both are needed; only one of them is testable.

Bring us one operational problem.

You do not need a finished brief. Bring the problem — we will work out the next step together.

Or book a call with the team