Module · Sovereign AI Governance OS

    Sovereign-routed governance for a multi-model world.

    Most institutions will not depend on a single national AI ecosystem. SAG-OS is the neutral operating layer that governs approved models across jurisdictions, controls what may cross a border, and produces an evidence trail regulators can defend.

    You choose the AI. Cabier orchestrates the trust.

    Module 3 · Cross-Border AI Gateway

    Resolve the four gateway questions before the packet moves.

    This simulator applies a simplified rule set derived from the SAG-OS policy engine. Full test procedures, jurisdiction-specific deltas, and legal-basis templates are released under engagement.

    Select an origin, host and data class, then click Resolve gateway to see a signed decision reference.

    Gate 1

    Can this prompt legally leave the country of origin?

    Gate 2

    Can inference be performed offshore for this data class?

    Gate 3

    Can these model weights be imported into this jurisdiction?

    Gate 4

    Can embeddings cross this border, and under which legal basis?

    Module 1 · AI Model Registry

    Every approved model. Every version. Every deployment.

    A single registry of AI systems approved for a business function — vendor, family, version, fine-tune, evaluation state, jurisdictional approval, accountable owner, effective and end dates. Nothing runs in production without a registry entry.

    VendorFamilyVersionFine-tuneEvaluationApprovalOwnerJurisdictionsEffective dates

    Module 2 · Sovereign AI Policy Engine

    Per-jurisdiction rules, one control plane.

    Country-specific policy packs mapped to the same kernel — no forked codebase, no shadow rulebooks. China is treated as an observed jurisdiction for cross-border cases; SAG-OS does not deploy in-country in the PRC.

    United States

    SR 11-7 · NIST AI RMF · State AI laws · Executive orders

    Canada

    AIDA (proposed) · OSFI E-23 · PIPEDA · AI-for-All strategy

    United Kingdom

    FCA · PRA · ICO · AI regulation white paper

    European Union

    EU AI Act (Art. 5/6/50/53/55) · GDPR · DORA

    UAE

    UAE AI strategy · CBUAE guidance · DIFC / ADGM

    Saudi Arabia

    SDAIA AI Ethics · PDPL · SAMA guidance

    Singapore

    MAS FEAT · Model AI Governance Framework · PDPA

    Japan

    JFSA · METI AI governance guidelines · APPI

    Hong Kong

    HKMA · SFC · PCPD

    Australia

    APRA · OAIC · voluntary AI safety standard

    India

    DPDP Act · MeitY AI advisories · RBI

    South Korea

    AI Basic Act · PIPA · FSC

    Africa (selected)

    SARB · CBN · KDPC · continental AI strategy

    Latin America (selected)

    Brazil ANPD · Mexico INAI · sectoral rules

    Observed: China

    PIPL · CAC generative-AI measures · sovereign export controls

    Module 4 · AI Evidence Vault

    Prompt, output, decision — one signed record.

    The AI Evidence Vault is the public-facing view of the Assurance Kernel's evidence spine, applied specifically to AI systems. Six item classes, one signed audit ID per event.

    Prompt
    Model output
    Decision reference
    Override event
    Human approval
    Escalation & intervention

    Every record is tied to an accountable executive, a jurisdictional envelope, a model registry entry and a Trust Gate outcome — reproducible on demand.

    Vault explorer — published sample

    Search an illustrative set of evidence records: the artefact held, the control it satisfies, the reviewer who asserted it and the system it is bound to.

    EV-24118
    AIS-0114

    Credit-memo faithfulness eval, 480-file holdout set

    Credit adjudication assistant · Evaluation results · reviewed by Independent validation

    MLC-04 · v3
    12 May 2026
    EV-24120
    AIS-0114

    Adjudicator amendment log with sign-off scope

    Credit adjudication assistant · Human oversight records · reviewed by Chief Credit Officer

    AIG-03 · v11
    Continuous
    EV-24133
    AIS-0121

    Alert-rate dispersion analysis by segment

    Transaction monitoring triage · Fairness and bias testing · reviewed by Model risk

    DAT-06 · v2
    3 Jun 2026
    EV-24140
    AIS-0142

    Prompt-injection and tool-abuse test report

    Contract review agent · Red-team findings · reviewed by Offensive security

    AGT-02 · v1
    28 Apr 2026
    EV-24144
    AIS-0142

    Model provider training-data and eval declaration

    Contract review agent · Vendor attestations · reviewed by Third-party risk

    TPR-03 · v2
    5 May 2026
    EV-24151
    AIS-0147

    Citation-fidelity measurement on KYC pack summaries

    Client onboarding summariser · Grounding and factuality · reviewed by Independent validation

    GEN-05 · v4
    21 Jun 2026
    EV-24158
    AIS-0151

    Precision/recall regression against prior release

    Market surveillance anomaly model · Evaluation results · reviewed by Model risk

    MLC-07 · v6
    9 Jun 2026
    EV-24163
    AIS-0130

    Compliance review queue with reviewer assertions

    Supervisory correspondence drafter · Human oversight records · reviewed by Head of Regulatory Affairs

    AIG-03 · v1
    Continuous
    Illustrative, non-client sample. Full evidence specifications, effectiveness grading and the signing chain are released under engagement.

    Sovereign AI Assurance

    Six commitments a sovereign deployment has to meet.

    SAG-OS is the policy engine. Sovereign AI Assurance is what the engine is held to — the commitments a group, a regulator or a sovereign operator can test us against.

    Dual-regulator satisfaction

    One control, evidenced once, accepted by home and host supervisors — with the delta each regime adds recorded explicitly rather than negotiated case by case.

    Sovereign deployment options

    Multi-tenant, dedicated VPC or on-premise sovereign enclave. No mandatory US data storage; residency is a deployment parameter, not a caveat.

    Cross-border evidence without data transfer

    Assurance artefacts and attestations cross the border; the underlying records do not. Each crossing carries a signed legal basis.

    Jurisdiction-specific AI control libraries

    Per-jurisdiction control sets with test procedures, evidence artefacts and deltas — published as a sample, held in full within engagement.

    AI supply-chain and model provenance

    Provenance, licensing and third-party posture recorded for every model, dataset and inference provider in the estate, including those inside vendor stacks.

    Continuous multi-model assurance

    Drift, quality, incident and policy-violation telemetry across every model in the estate, continuously — not an annual attestation.

    Guardrails

    What SAG-OS will not do.

    Neutral by design
    SAG-OS does not depend on, or endorse, any single national AI ecosystem. It governs whichever the sovereign or institution has approved.
    No in-China deployment
    China is an observed jurisdiction for cross-border cases involving multinational institutions. Cabier does not deploy in-country in the PRC.
    No model training
    Cabier does not train, host, resell or fine-tune the models governed by SAG-OS.
    Human-signed
    Every material policy state, cross-border decision and registry change is signed by a named accountable executive.
    Regulator-safe
    No promissory language, no autonomous execution claims, no comparative model benchmarks. Evidence-first.