Source Dossier · Triodian

For journalists · source dossier

A working folder you can fact-check.

Not a newsroom, and not a press release. Primary sources, operational definitions of every quotable term, and a plain statement of what we are and are not claiming, so a story about us can be accurate.

Stage, stated plainly

Triodian is an early-stage company with a strong thesis and, as yet, no independently produced validation. Everything below is sourced to a primary document or labelled as first-party. Where a term is quotable but hard to falsify, we define it operationally and link the evidence.

What the company is

In plain language.

Triodian builds a governance layer that sits at the point an AI recommendation becomes an action, checks it against a policy the deploying institution authored, and produces a record an outside party can verify. Two enforcement configurations rest on established method and are deployable today; one signal is under open experiment, and is labelled that way wherever it appears. The company is early-stage: the thesis is strong, independent validation is not yet produced.

Fast facts

Base: Brisbane, Australia

Data residency: Australian residency available; deployment inside the customer boundary

Regulatory relevance: APRA CPS 234, CPS 230; EU AI Act; NIST AI RMF; ISO/IEC 42001

Stage: pre-launch; one production engine in an unrelated domain (pinpole)

Primary-source library

The documents, not our description of them.

Patents →

US 19/440,660 (USPTO Track One, filed 6 Jan 2026) and the CIP family, numbers and status.

Architecture spec →

The Deterministic Governance Architecture, the six-stage enforcement datapath.

UGP specification →

The open Universal Governance Protocol and its conformance suites.

Evidence Centre →

The claim-status register and the harness result set, first-party, graded.

The harness →

Eight named tests, pre-registered floors, pass/fail criteria.

Methods (this page) ↓

Operational definitions of every quotable term, each with its adversary.

Methods

Every quotable term, defined operationally.

Each definition names the adversary it addresses and links to its row in the claim-status register. The eight rules are surfaced in full on the Provable AI page rather than rewritten here.

"Govern it where it acts" / point of actuation

The moment an AI recommendation crosses into an action that can't be taken back. Adversary: a decision that is irreversible before any human sees it. Register →

Miss-rate

A distribution-free ceiling, certified at a stated confidence on a named corpus, on how often a violation gets through a detector. Adversary: a tuned threshold that looks good only on the data it was fit to. Method →

Aggregate drift

A set-level move of a decision stream out of a declared appetite, invisible to any single-decision check. Adversary: local compliance masking global drift. Method →

Complete mediation

The property that every meaningful action path passes through the governed boundary. Adversary: an alternate route around the boundary. Method →

Six-stage non-bypassable enforcement

A fixed-order hardware datapath where stages 2–6 cannot be reordered or suppressed by software; stage 1 is the probabilistic input the rest narrows. Adversary: privileged software owning the enforcement host. Method →

Mode A / Mode B

Mode A governs what an action means (semantic); Mode B makes a forbidden output structurally impossible. Adversary: form-compliant, intent-violating output (A); an unemittable command being emitted (B). Method →

The eight rules

The eight conditions of verifiable responsible operation at the action boundary, defined in full, with their deliberate exclusions, on the Provable AI page.

For fact-checking

The claim-status register

The same register the Evidence Centre carries: one row per claim, its status, its adversary, and what independent proof would look like. Nothing on it is graded above what we can support.

Open the register →

What we are not claiming

  • No independent audit, certification, or third-party benchmark yet.
  • No production customers of the governed appliance.
  • The hardware tier does not ship today; it is graded later.
  • The semantic signal is under experiment, not proven.

People & credentials

Real, linkable, precisely characterised.

Foundation chair, characterise exactly

Professor Toby Walsh (UNSW) has agreed to serve as independent chair, taking up the role on the Foundation's establishment. He leads the guardian, not the company, and must not be presented as endorsing any unvalidated technical claim.

The full team, with roles and prior programmes, is on the About page. When citing a person, distinguish their status: advisor/board (a governance relationship), cited (their published work is referenced), and quoted (they have given a statement for attribution). Do not collapse these.

Category of risk

The class of problem, not any single incident, and no claim of involvement.

The risk Triodian addresses is consequential AI actions taken without a tamper-evident record, faster than human oversight can intervene. Independent reporting on autonomous-agent incidents and the regulatory response (EU AI Act Article 6; NIST AI RMF; ISO/IEC standards) describe the category. We cite these as context for the class of risk, never as events we predicted, prevented, or were involved in.

Any incident we mention elsewhere on the site is cited as reported by others, for illustration of the category only.

Corrections

We keep a corrections log.

If we state something inaccurately, we fix it here and say what changed. The log is empty today, its presence is the commitment.

Corrections log · no entries yet

Media contact

A named contact, with a response commitment.

Damian Hickey · damian.hickey@triodian.com

Media enquiries receive a substantive reply, not a call-booking link, within two business days. Embargo terms are agreed in advance for any pre-briefed material.

Contact →