What is AI governance and how is it different from compliance?+
AI governance is the control layer that decides what an AI system may do, watches it while it operates and leaves evidence of what it did. Compliance is one of its consequences: if the control layer exists and logs, the EU AI Act classification, the technical documentation or an ISO/IEC 42001 management system follow from it. Without a control layer, compliance is a document describing a system nobody is actually controlling.
What is an agent guardian and why are guardrails not enough?+
A guardrail filters what goes into and out of the model. A guardian, as defined by the OWASP Agent Control Standard, is a component external to the agent that decides, on every tool call, whether the action is allowed, denied or modified, and records why. The difference matters once the agent can act on real systems: a guardrail does not stop an agent holding the wrong token from dropping a table; a guardian does.
What does a control assessment include?+
An inventory of the AI systems in use, including those that arrived inside a SaaS product or were set up by a team on its own; a map of who decides what and with which permissions; a review of the thirteen areas of the OWASP LLM security and governance checklist; and a list of gaps prioritised by risk and effort. It is delivered with a fixed scope and price and is the starting point for the control layer as well as for ISO/IEC 42001 or the EU AI Act.
What does the EU AI Act require, and when?+
The AI Act entered into force on 1 August 2024 and applies in phases. Prohibited practices apply since 2 February 2025 and general-purpose model obligations since 2 August 2025. Article 50 transparency applies from 2 August 2026. Regulation (EU) 2026/1744 postponed the high-risk regime to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. That regime requires risk management, event logging, human oversight and technical documentation: exactly what a well-built control layer produces.
Do we need to certify against ISO/IEC 42001?+
It is not mandatory, and KAIX LABS is not a certification body. ISO/IEC 42001 is the reference AI management system standard and maps to the risk management duties of Article 9 of the EU AI Act and to NIS2 for essential entities. What we do is prepare the system and the organisation so that, if you decide to certify, the auditor finds policies that run and evidence that backs them, not documentation written for the occasion.