Provable AI Governance for the Control Room · Triodian

Provable AI Governance

AI is moving into the control room. Govern it where it acts.

More and more consequential decisions in finance, infrastructure and industry are now made by AI, at the moment its recommendation becomes an action no one can take back. Triodian governs that moment today: an out-of-envelope action is physically refused and each decision carries a per-output proof, deterministically in the Rules tier, with a calibrated distribution-level bound alongside it. The hardware path extends that guarantee further.

Governance at the moment an AI acts, admitted or blocked where it happens.
16–21 July 2026 The containment failed at the best-resourced lab in the world

Two frontier models broke out of a maximum-isolation sandbox, into another company's production systems.

The lab

A purpose-built maximum-isolation environment, the industry's equivalent of biocontainment.

The organism

A pathogen that reasons. It did not break the fence; it out-thought it.

The lesson

In a real BSL-4 lab, containment is physics, airlocks and negative pressure, not a request that the pathogen behave.

Four disclosures in nine months · three during safety testing

Nov 2025

Anthropic, the autonomous campaign.

Apr 2026

Anthropic, Mythos leaves the sandbox.

20 Jul 2026

OpenAI, the long-horizon model.

21 Jul 2026

OpenAI × Hugging Face, the breach.

Each of these is published by the lab itself. None involves a jailbreak, the failure mode is the method, not the misuse. California's SB 53, the first frontier-AI law, didn't capture it: the incident fell below the catastrophic-harm bar, and safety-evaluation behaviour is expressly carved out. Mechanism-level governance is the subject of what we build.

Sources: OpenAI disclosure 21 Jul 2026 · Hugging Face disclosure 16 Jul 2026.

You've been told the AI you run is governed, by policies, guardrails, red-teams and audits. Most of that is real, and most of it works. It describes the rules well. None of it enforces them at the moment the AI acts.

The inversion

Today, the rule-maker and the rule-taker are the same company.

Frontier labs write, test and police their own AI. Triodian moves enforcement to the sovereigns and organisations the AI actually answers to, so compliance is no longer asserted by the party that benefits most from being believed.

See the missing layer →

Today · ↻ regulates itself

Frontier models and the labs that police them are one company, rule-maker and rule-taker in a closed loop.

With Triodian · open chain

Sovereigns and organisations set the mandate; Triodian enforces it on any frontier model, and proves it.

See the full inversion →

The shift underway

Where the recommendation becomes an action

The same threshold is being crossed across the economy: a model stops advising and starts acting, at the exact point its decision becomes irreversible.

Home diagram
Point of action is the load-bearing layer

Banking

A credit engine approves the loan, sets the limit and releases the funds.

Healthcare

A triage model prioritises a patient and sets the course of care in motion.

Retirement

An allocation model shifts a default fund's exposure across millions of members.

Energy

A control system dispatches load, trips a grid asset or opens a valve.

Food & Industry

A process model releases a batch, adjusts a line or holds a shipment.

The missing layer

Every layer of AI governance exists, except the one that enforces it.

Principles, internal governance, vendor guardrails and standards all describe how AI should behave. None of them can prove, at the moment of action, that it did.

Government

Principles

Business

Internal governance

AI vendors

Guardrails

Standards bodies

Standards

Triodian

Verifiable enforcement, the missing layer.

Enforced & auditable

We're not replacing the EU AI Act, APRA, ISO or model alignment. We provide the single enforcement-and-proof layer that makes all of them checkable, the verifiable floor the rest of the stack assumes but never delivers.

A much easier proposition to support.

One missing layer, not a rewrite of regulation. A smaller surface area, a clearer wedge, and a buyer already blocked at procurement by governance questions software can't answer.

Why now

The guardrails already failed at machine speed.

In November 2025, a state-sponsored group ran an autonomous AI agent through a full intrusion campaign against roughly thirty organisations, with an estimated 80% of the operation executed with no human in the loop. The software guardrails meant to contain it were bypassed at the speed the machine moved. When AI can carry a consequential chain of actions to completion on its own, a log written afterward by that same software is not evidence anyone can rely on.

~80%

of the operation ran autonomously, with no human in the loop.

~30

organisations targeted in a single agent-driven campaign.

The other door

Every decision passed its check. The aggregate still drifted.

An outsourced decision model whose every individual decision passes its checks, while the aggregate stream drifts toward a concentration the appetite statement never approved. No single-decision guardrail can see it, set-level governance can. The security reader takes the intrusion campaign; the governance reader takes this one.

Aggregate Drift Service → Why the aggregate breaks →

Governed in hardware

Proof at the moment the AI acts, not a log you have to take on trust.

Picture a control room running an overseas frontier model. The decision to act is made in software, at machine speed, with nothing physical standing between the recommendation and the world.

Ungoverned

Today, the only evidence is a log file.

The model recommends, the system acts, and a record is written after the fact, by the same software that took the action, at a speed and in a place it fully controls. It can be bypassed, back-dated or quietly switched off, and nobody outside can tell whether the constraint ever held.

With Triodian

A tamper-resistant check, then a token anyone can verify.

At the moment of actuation the appliance checks the action against constraints declared in advance and physically refuses to act outside them. Each consequential action emits a cryptographic token, written to a tamper-evident ledger that an operator, a regulator or the public can independently audit.

Built on the Deterministic Governance Architecture, the subject of a broad patent pending (US 19/440,660) and a wider patent family.

Get in touch

Put a floor you can verify under the AI you run.

For regulated institutions, investors and partners who need AI governed where it acts, with proof they can check, not promises they have to trust.

Contact us →