Saltar al contenido

02B — Services

Control for AI systems in production.

Governance that runs, not governance that gets filed. We define who decides what each AI system may do, build the layer that enforces it while it operates, and leave the evidence an auditor, a client or an incident will ask for. ISO/IEC 42001 and the EU AI Act follow from that.

Supported by

NVIDIA Inception
NVIDIA Inception
Cloudflare for Startups
Cloudflare for Startups
AWS Activate
AWS Activate
Anthropic for Startups
Anthropic for Startups
GitHub for Startups
GitHub for Startups

02B — Services

AI Governance

Four ways to engage us. Each one ends in something that runs inside your system and evidence you can show, not in a document ageing in a folder.

  1. GOV.01

    Control assessment

    Inventory of AI systems, a map of who decides what and with which permissions, the thirteen areas of the OWASP governance checklist, and prioritised gaps. Fixed scope and price.

  2. GOV.02

    Control layer for agents

    Policies, a guardian external to the agent, least-privilege tool permissions, human-in-the-loop gates and an autonomy budget. Aligned with the Agent Control Standard.

  3. GOV.03

    Evidence and auditability

    Every decision and every action logged in OCSF, traceability into the SOC, post-deployment monitoring and coverage measured with real attacks.

  4. GOV.04

    Management system and regulation

    ISO/IEC 42001, EU AI Act classification and documentation, GDPR and NIS2 applied to the system. The output of the control layer, not a separate project.

03 — Why now

Five milestones already shaping the control calendar.

AI Act, prohibited practices in force, general-purpose models, liability case law and certifiable standards.

  • 01 · High risk2027.12

    The high-risk regime applies on 2 December 2027.

    Up to €15M or 3% of global turnover in fines. Regulation (EU) 2026/1744 postponed Chapter III, Sections 1 to 3: risk management, technical documentation, human oversight and deployer obligations move from August 2026 to December 2027 (Annex III) and August 2028 (Annex I). The Art. 50 transparency duties do apply from August 2026. The postponement changes the date, not the substance: classifying, documenting and registering is still a multidisciplinary project that is worth starting early.

    EUR-Lex, Regulation 2026/1744
  • 02 · Prohibited practices2025.02

    Article 5 prohibitions are already enforceable.

    In force since 2 February 2025. Subliminal manipulation, social scoring, untargeted facial scraping, emotion recognition at work or in schools, and sensitive biometric categorisation. This sits in the highest fine bracket of the Regulation.

    EUR-Lex, Art. 5
  • 03 · General-purpose models2025.08

    Obligations for general-purpose AI models are already in force.

    Art. 51-56, applicable since 2 August 2025. Technical documentation (Annex XI), downstream information (Annex XII), copyright policy and a training-data summary. Above 10²⁵ FLOPs you are a systemic-risk provider with mandatory red-teaming.

    EUR-Lex, Chapter V
  • 04 · Liability2024.02

    Courts: the company is liable for what its chatbot says.

    Moffatt v. Air Canada: binding precedent. The tribunal rejected the argument that AI is a separate entity from the company. Without audited guardrails and a decision log, every model output puts capital and reputation on the line.

    Civil Resolution Tribunal
  • 05 · Standards2024

    ISO/IEC 42001 is now the reference AI management system standard.

    First international certifiable standard for AI governance. It maps to the risk-management duties of AI Act Art. 9 and to NIS2 obligations for essential entities. Adopting it makes diligence demonstrable to regulators, auditors and B2B buyers.

    ISO/IEC 42001:2023

Free tool

EU AI Act calculator

The EU AI Act is the first European law to regulate AI systems, and it sets different obligations depending on what your company uses AI for. This free calculator applies the decision tree of Regulation (EU) 2024/1689 to your case and returns the applicable risk level, the exact articles and the date from which you have to comply.

04 — Use cases

What we do.

Examples of the type of projects we take on across our two service areas. If your situation looks familiar, we can probably help.

AI Governance, assessment

Control assessment of AI systems in production

Problem
Companies running several AI systems, some of them shipped inside a SaaS product, with no inventory and no clear map of who decides what and with which permissions.
How we do it
Inventory, decision and permission map, review of the thirteen areas of the OWASP governance checklist, and gaps prioritised by risk and effort.

Client types

Scaleups, industrial SMBs, SaaS companies, teams using AI in support, HR or operations.

Similar challenge? Let's talk →

AI Governance, agents

Control layer for agents with access to real systems

Problem
Agents acting on CRM, ERP, email or infrastructure with the developer's token and nobody approving the irreversible actions.
How we do it
Per-action policies, a guardian external to the agent, least-privilege tool permissions, human-in-the-loop gates and a log of every decision.

Client types

Teams operating agents in production, agencies delivering them to clients, regulated businesses.

Similar challenge? Let's talk →

AI Governance, evidence

Auditable evidence, ISO/IEC 42001 and EU AI Act

Problem
AI systems processing personal data, operating in critical contexts, or having to answer to an auditor, a large client or an incident.
How we do it
OCSF logging into the SOC, decision traceability, EU AI Act classification and documentation, and preparation of the ISO/IEC 42001 management system.

Client types

Healthtech, fintech, legaltech, mid-size companies and teams preparing audits.

Similar challenge? Let's talk →

FAQ

What is AI governance and how is it different from compliance?

AI governance is the control layer that decides what an AI system may do, watches it while it operates and leaves evidence of what it did. Compliance is one of its consequences: if the control layer exists and logs, the EU AI Act classification, the technical documentation or an ISO/IEC 42001 management system follow from it. Without a control layer, compliance is a document describing a system nobody is actually controlling.

What is an agent guardian and why are guardrails not enough?

A guardrail filters what goes into and out of the model. A guardian, as defined by the OWASP Agent Control Standard, is a component external to the agent that decides, on every tool call, whether the action is allowed, denied or modified, and records why. The difference matters once the agent can act on real systems: a guardrail does not stop an agent holding the wrong token from dropping a table; a guardian does.

What does a control assessment include?

An inventory of the AI systems in use, including those that arrived inside a SaaS product or were set up by a team on its own; a map of who decides what and with which permissions; a review of the thirteen areas of the OWASP LLM security and governance checklist; and a list of gaps prioritised by risk and effort. It is delivered with a fixed scope and price and is the starting point for the control layer as well as for ISO/IEC 42001 or the EU AI Act.

What does the EU AI Act require, and when?

The AI Act entered into force on 1 August 2024 and applies in phases. Prohibited practices apply since 2 February 2025 and general-purpose model obligations since 2 August 2025. Article 50 transparency applies from 2 August 2026. Regulation (EU) 2026/1744 postponed the high-risk regime to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. That regime requires risk management, event logging, human oversight and technical documentation: exactly what a well-built control layer produces.

Do we need to certify against ISO/IEC 42001?

It is not mandatory, and KAIX LABS is not a certification body. ISO/IEC 42001 is the reference AI management system standard and maps to the risk management duties of Article 9 of the EU AI Act and to NIS2 for essential entities. What we do is prepare the system and the organisation so that, if you decide to certify, the auditor finds policies that run and evidence that backs them, not documentation written for the occasion.

In-house training

Want your team to learn how to do this?

We run tailored in-house technical training. Each course is designed around the client's case: agent control for CTOs and CISOs, governance and compliance of AI systems with ISO/IEC 42001 and the EU AI Act, with the scope the team asks for.

Let's talk about your AI system.

We'll suggest a no-obligation first call to assess your case.

[email protected]WhatsApp · +34 644 43 62 81