Skip to content
AI governance

Policy, provenance and guardrails, in a form an auditor can follow.

Assurance proves a system is safe once. Governance proves it stays safe and produces the paperwork that says so. That means a written policy, a traceable path from every output back to its source, and controls that run whether or not anyone is watching. Four engagements, $3,900 to $8,900, every price on this page.

We do not certify, and we do not hold SOC 2 or ISO/IEC 42001. We build the evidence the certifying auditor asks for.

2 Aug 2026
EU AI Act Article 50 transparency obligations in force
2 Dec 2026
Article 50(2) marking date, synthetic-content systems already on the market
2 Dec 2027
high-risk application for stand-alone systems
2 Aug 2028
high-risk application for systems inside regulated products

Dates under the EU AI Act as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, published on 24 July 2026 and in force since 27 July 2026. A great deal of indexed guidance still states the pre-Omnibus schedule, so check the date on anything you read, including this page. Verified 2 September 2026.

What governance is made of

Three parts, and the third is the only one that runs by itself.

Policy is what you wrote down. Provenance is whether the output can be traced back to something real. Guardrails are the controls that hold when nobody is looking. A program missing any one of them fails diligence at a predictable point, and it is almost always the second.

01

Policy

A written policy is the artifact an auditor asks for first, and the one most firms discover they have only as a Slack message from March.

  • AI use policy: what staff may put into which system, written per data class rather than as a single prohibition nobody follows.
  • Model cards and system cards: intended use, evaluation results, known failure modes, and the uses that are explicitly out of scope.
  • Risk register: one row per AI system, with a named owner, a written classification, and the reasoning that produced it.
  • Approval path: who signs off a new system, at what threshold, and against which criteria.
  • Exception path: how a team gets a documented exception instead of an undocumented workaround, which is what they will do otherwise.
02

Provenance

Provenance is the question of where every input came from and whether the output can be traced back to it. It is the part that survives being audited.

  • Data lineage: for each corpus in the system, its source, the lawful basis or license it arrived under, and every transformation applied since.
  • Training-data attestation: a written statement of what the system was trained or fine-tuned on, and what it was not.
  • Citation grounding and traceability: every assertion resolvable to the passage that supports it, checkable by someone who did not generate the answer.
  • Content credentials: C2PA manifests on generated media, so provenance travels attached to the file rather than living in a log you control.
  • Retention and deletion: what happens to the document, the embedding, the cache and the log when the source record is deleted.
03

Guardrails

A guardrail is a control that runs whether or not anyone is watching. Anything enforced only by a sentence in a prompt is a preference, not a control.

  • Input filtering: prompt injection, including injection arriving inside a retrieved document, which is the vector most retrieval systems never test.
  • Output filtering: what the system must not emit, enforced after generation rather than requested before it.
  • PII redaction: at ingestion, at retrieval and in logs, because the log is the copy people forget they made.
  • Hallucination measurement: a written groundedness rubric, an evaluation set built from your corpus, and a rate that comes with its method attached.
  • Refusal and escalation design: what the system does at the boundary of what it can support, and which human it hands to.
  • Red-teaming: adversarial testing run by the people who do our offensive security work, not a checklist run by the team that built the thing.

Hallucination measurement is the guardrail buyers ask about most and the one least often implemented as a control. We wrote up the version running on our own platform, including the rubric and the honest limits, in how we hold hallucination under two percent.

Frameworks

Six instruments, and what each one actually asks you to produce.

These overlap more than they conflict. One inventory, one risk register and one set of model cards can satisfy most of what four of these ask for, provided the artifacts are built once with all four in view rather than four times under deadline.

EU AI ActRegulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026
What it asks of youA classification per system with the reasoning recorded, Article 50 transparency disclosure, and technical documentation an authority can request.
What we produceEU AI Act readiness assessment, $4,900. Inventory, written classification per system, and the transparency gaps ranked against the dates.Read the Article 50 briefing
ISO/IEC 42001AI management system standard, certifiable by an accredited body
What it asks of youPolicy, objectives, roles, risk and impact assessment, Annex A controls, internal audit and management review, all with evidence behind them.
What we produceGap assessment, $8,900. Your position control by control, the evidence an external auditor will ask for, and the work needed to produce it.
NIST AI RMFVoluntary, and the vocabulary US enterprise buyers write their questionnaires in
What it asks of youGovern, Map, Measure and Manage applied to systems in production, not to a reference architecture.
What we produceAlignment review, $7,500. NIST supplies the risk method and ISO/IEC 42001 the management system; they are complementary, not a choice.
GDPRApplies wherever EU personal data reaches the pipeline
What it asks of youA lawful basis, a DPIA where processing is high risk, an answer on solely automated decisions, and a transfer mechanism for data leaving the EEA.
What we produceThe AI-specific parts: where personal data enters prompts, embeddings, caches and logs, and which of those you can actually delete from.
DPDP Act 2023India's Digital Personal Data Protection Act
What it asks of youNotice and consent, data principal rights including erasure, and additional duties for entities designated Significant Data Fiduciaries.
What we produceThe mapping between those duties and the pipeline, which matters the moment a corpus, a support workflow or a subprocessor touches Indian personal data.
HIPAAWhere protected health information is in scope
What it asks of youA business associate agreement covering the AI vendor, and de-identification applied to anything used for evaluation or tuning.
What we produceA trace of every place PHI can reach in the pipeline, prompts and evaluation sets and logs included, and where the agreement does not currently cover it.
Booked engagements

Four governance engagements, every price and duration fixed.

A deposit reserves the week on the calendar and the balance is invoiced against delivery. There is no scoping fee in front of any of them. If your problem is not one of these four, we will say so on the first call rather than three invoices in.

  • T2-082 weeks

    Agent governance review

    Kill switches, evidentiary audit trails, human-in-the-loop boundaries and model change control. Every action the agent can take, the blast radius of one compromised step, and where the stop control is missing rather than merely undocumented.

  • T2-062 weeks

    NIST AI RMF alignment review

    Govern, Map, Measure and Manage applied to the systems you actually run, in the vocabulary a US enterprise questionnaire is written in.

  • T2-052 to 3 weeks

    ISO/IEC 42001 gap assessment

    Your current position against the AI management system standard, control by control, with the evidence an external auditor will ask for and the work needed to produce it.

  • T2-091 week

    Attestation readiness scoping

    What SOC 2 or ISO/IEC 42001 will actually take: the scope, the observation window, the control gaps, the internal cost and a realistic date. Buy this before committing to either.

Book an engagement

The full catalog, including the security and evaluation work these sit alongside, is on the assurance page.

Procurement

The seven questions, and what a defensible answer contains.

These are the questions enterprise procurement, security and privacy teams now send, close to verbatim. They arrive as gating conditions rather than preferences, and a missing answer rarely loses a deal loudly; it stalls it in diligence. Answers below describe what a defensible response contains, so you can grade your own before someone else does.

How is the model hosted?
A defensible answer names one of three postures and the contract behind it: a vendor API, a dedicated tenancy in a named cloud region, or self-hosted weights on infrastructure you control. Hosting determines who is able to read the prompt, which is why buyers ask it first. Record the answer per system in the risk register rather than once for the company, because most firms are running more than one posture at the same time and only notice during diligence.
What training opt-outs apply?
Answer per provider and per tier, and cite the executed contract clause with its effective date. Consumer, team and enterprise tiers of the same product frequently carry different terms on whether inputs and outputs may be used for provider training. The evidence a buyer accepts is the clause, not a screenshot of a settings toggle, because a control that lives in a toggle can be changed by anyone with console access and leaves no record when it is.
How are agent identities scoped?
Each agent should hold its own identity and its own credentials, with a written list of actions it may take, rather than inheriting the session of the human who triggered it. The test is blast radius: name what one compromised step can reach, in systems and in records. Our agent governance review, $7,900 over two weeks, produces that authority matrix and names every place the scope is currently unbounded.
Where is data residency?
Answer with a region, a lawful basis and a subprocessor list, per data category, not with one company-wide sentence. Prompts, retrieved documents, embeddings, caches, logs and evaluation sets often sit in different places, and the log is the copy most firms forget to include. Under GDPR and India's DPDP Act 2023 the transfer itself has to be justified, not only the storage location at rest.
What audit trail exists?
A trail that satisfies a regulator records the input, the retrieved context, the model and version, the decision, and any human override, timestamped and retained long enough to answer a complaint. Most systems log only the final output. The internal test is whether you can reconstruct what the system did on a specific date and on what basis, using records that existed before anyone asked the question.
How is the kill switch operated?
Name the person authorized to stop the system, the control they use, how long it takes to take effect, and the date it was last exercised. A stop control that has never been tested is an assumption written in the present tense. Kill switches are one of six conditions enterprise buyers now gate AI purchases on, and the only answer that clears diligence is a procedure with a named owner.
What compliance evidence is produced?
Artifacts, not assurances: an AI system inventory, a written risk classification per system, model and system cards, a risk register with named owners, evaluation results with a method attached, and an ISO/IEC 42001 control mapping. MetaMinds produces that evidence. Certification against ISO/IEC 42001 is issued by an accredited certification body and a SOC 2 report by a licensed CPA firm, never by us.

Sourced from enterprise agent RFP guidance, procurement evidence checklists and CISO buyer checklists published for 2026. Our own posture, including the rows where the answer is no, is on the security page.

Stated plainly

Four things this page does not offer.

A governance vendor that overstates its own standing has answered the only question that mattered. This list costs us deals with buyers who wanted a badge, and it is the reason the ones who read carefully call back.

We cannot certify you against ISO/IEC 42001
Certification is issued by an accredited certification body after an external audit, and we are not one. We do the work before that audit: gap assessment, control design, evidence preparation and readiness review. A firm offering to certify you itself is telling you something useful about the firm.
MetaMinds holds neither SOC 2 nor ISO/IEC 42001
We do not have an attestation report and we do not hold the certificate. A SOC 2 report comes from a licensed CPA firm after a defined observation window, which is exactly why it cannot be self-asserted. Our own posture is published rather than implied.
We do not give legal advice
We describe obligations, gaps and the evidence that closes them. Anything with legal effect belongs with counsel qualified in the relevant jurisdiction, and our reports say so on the page where it matters.
We do not guarantee compliance
No consultancy can. A firm that offers the guarantee has either misread the regulation or is relying on you not reading it.
Start here

Name the system your next questionnaire will ask about.

Thirty minutes with the engineer who would run the review. We will tell you which engagement fits, what it will find, and which parts you can do yourselves without us.

Governance engagements $3,900 to $8,900, fixed price · Typical reply within one business day