Financial Institutions · Triodian

Financial institutions

For the institutions where AI now sits behind the capital.

The same failure recurs wherever consequential decisions are automated and capital sits behind them: an AI optimising locally while exposure compounds globally, every individual decision compliant, the aggregate drifting somewhere no one chose. Triodian governs the book, not just the decision, and gives you evidence you can verify.

One governed substrate beneath banking, energy, healthcare and industry.

Every position clears mandate. Your risk report rolls up green. It probably should, each decision was compliant when it was made. That is exactly why the thing that's drifting doesn't show up in it.

Why now

Machine speed is how compliant decisions become a book-level exposure.

In November 2025, a state-sponsored group ran an autonomous AI agent through a full intrusion campaign against roughly thirty organisations - with an estimated 80% of the operation executed with no human in the loop. The same capability that made that possible is now inside the engines allocating, pricing and underwriting capital: an AI can carry thousands of individually-compliant decisions to completion faster than any quarterly review can reconstruct what they add up to. By the time the aggregate is visible, the exposure is already on the book.

~80%

of the operation ran autonomously, with no human in the loop.

~30

organisations targeted in a single agent-driven campaign.

Where this applies

The same failure, across regulated capital

Super & pension funds · asset managers

Investment-signal or allocation models that drift toward concentrated, correlated positions while each trade clears mandate, relevant to trustee diligence and CPS 230 operational-risk obligations over AI-driven processes.

Banks & lenders

Credit and pricing engines that build correlated exposure or conduct risk across a portfolio while every individual loan stays comfortably inside policy.

Insurers & reinsurers

Underwriting AI that thins tail-risk margin and stacks correlated peril book-wide, assembling a solvency exposure entirely out of individually compliant policies.

Private equity & institutional acquirers

Any target whose value rests on an AI running a consequential path, where the aggregate behaviour is the asset you are buying, and the risk you inherit at completion.

Getting to the data

When can you actually instrument the decision stream?

The first practical objection is access. There are three routes to it, in descending order of ease, and we are candid that the hardest case is not solved by software.

Strongest

You already hold the position

An owner asking an investee to instrument a risk it already carries. This is the natural home of the capability, the incentive and the access already sit on the same side.

A condition of the capital

Where you are the incoming capital

Governance becomes a condition of the deal, not a demand a target can refuse, most valuable where deep diligence into AI behaviour was previously uneconomic to attempt.

The honest hard case

A target that does not want to be examined

Answered only by the hardware appliance: the target runs its own decisions through a verifiable instrument, keeps its data, and produces the attestation. We do not pretend software solves this, this route is gated and optional.

What it changes

A risk you can see, govern and price

01

Diligence that reaches the aggregate

Evidence about what an AI’s decisions mean in combination, the layer ordinary diligence cannot reconstruct.

02

Oversight that doesn’t decay with its people

Enforcement holds whether or not the team’s skill to supervise the machine stays intact, the last line of defence isn’t a competence you can’t measure.

03

A governed asset post-completion

Compounding tail risk becomes detected and enforced rather than invisible, lowering the risk carried on the balance sheet you’ve acquired.

04

Provenance boards and regulators can check

A tamper-evident record of what was governed converts “we trust the operator’s guardrails” into something an outside party can verify after the fact.

Regulatory context

We make these checkable, we don’t replace them.

The obligations are already written. What’s missing is a way to prove, to a regulator or a board, that an AI-driven process actually held to them. The appliance produces exactly that evidence, it sits beneath these frameworks rather than competing with them.

EU AI Act

High-risk system obligations on governance, record-keeping and human oversight.

High-risk provisions in force Aug 2026

APRA CPS 230

Operational-risk obligations over critical, AI-driven processes and controls.

Operational risk management

ISO/IEC 42001

The management-system standard for governing AI across its lifecycle.

AI management systems

NIST AI RMF

The risk-management framework institutions map their AI controls against.

AI risk management framework

How the appliance protects the position

It governs the book, not just the decision

The appliance compares what the AI’s cumulative behaviour actually means against what the institution’s stated risk appetite means, so the drift is flagged as it forms, enforced at the point of decision, and bound to a record an outside party can check.

A position without it

An invisible, compounding tail risk

Drift accumulates inside compliant decisions, undetected by the controls the institution relies on, and carried in full on the balance sheet.

A position running the appliance

Detected, governed, auditable

The same risk becomes one that is flagged as it forms, enforced at the point of decision, and backed by a record an outside party can check, lowering the risk you carry once invested.

Govern the AI that sits behind your capital.

Discuss a use case →
The same substrate, read by a carrier Insurance & Underwriting →