Wave 5 · Assurance Operating System

    The AI Oversight Fabric.

    Institutions no longer choose one AI. They run estates — Western frontier labs, open-weight models, sovereign stacks, and Chinese ecosystems observed at the edge. Cabier is the independent oversight, governance and assurance layer above that estate, wired into the same evidence vault that already scores resilience, cybersecurity and tokenisation.

    Dax Philbert, LLM

    Founder, Cabier Consulting · 24 July 2026 · ~11 min read

    Executive summary

    The AI conversation inside regulated institutions has quietly shifted from procurement to portfolio. Boards no longer ask which model to pick; they ask how to oversee a portfolio of models — some Western frontier, some open-weight, some sovereign, some observed only from the perimeter — without losing the accountability that regulators, counterparties and their own risk committees now demand. Cabier's answer is architectural. One oversight fabric, one policy engine, one trust score, one assurance kernel — all feeding a single institutional resilience score.

    Model planeData & toolsAgents & workflowsSovereign policy engineAI Trust ScoreAssurance KernelORS
    Stylised architecture. Cabier does not deploy or endorse specific models; it operates the oversight, policy and assurance layer above them.

    Two systems, one estate

    The United States and China are solving different problems. The West is optimising for frontier capability, alignment research and consumer-scale distribution. China is optimising for state-scale deployment, industrial integration and cost. A multinational bank, insurer or asset manager does not have the luxury of choosing one system over the other. Its estate touches both — through vendors, cloud regions, subsidiaries, and increasingly through customer expectations that a global counterparty will interoperate with either side of the divide.

    That reality is what the Oversight Fabric was built for. Neutrality is not a political posture; it is an operational requirement. An institution that cannot see, score and govern both halves of its AI estate cannot honestly report the estate to a board.

    The AI Oversight Fabric

    The fabric is a three-plane architecture. The model plane registers every deployed and observed model — Western frontier labs, open-weight releases, sovereign stacks, and named Chinese ecosystems appearing only as observed vendors with no endorsement. The data and tools plane registers the training and retrieval surfaces, the agent tools and the workflow scaffolding that turn a model into a system. The agent plane registers the autonomous processes the institution allows to act on those systems — with human-in-the-loop, kill-switch and blast-radius controls.

    Every plane feeds the same evidence vault. Every entity carries a lineage record. Nothing enters production without a Trust Gate.

    Sovereign AI Governance OS

    Above the fabric sits the Sovereign AI Governance OS — a policy engine that encodes the obligations of the jurisdictions the institution operates in. EU AI Act, US SR 11-7 and OMB M-24-10, UK AI regulation, Canada AIDA and OSFI E-23, Japan METI/FSA guidance, Singapore MAS FEAT, and the frameworks emerging from the Gulf. Where PRC frameworks — PIPL, the CAC generative-AI measures — apply to extraterritorial data flows, they are encoded as observed obligations, not deployment surfaces.

    The engine's output is not a checklist. It is a per-jurisdiction routing decision that determines which models may serve which use cases, with which data, under which disclosure regime, and with what human accountability attached.

    The AI Trust Score

    Every entity on the fabric earns an AI Trust Score across ten dimensions: security, reliability, hallucination and grounding, alignment, data provenance, third-party risk, explainability, human oversight, incident history, and jurisdictional posture. The score is not a marketing number. It is the artefact Cabier can defend to a supervisor, an auditor or a board committee — with lineage, evidence and a versioned rubric behind every band.

    Trust scores flow into the institution's Operational Resilience Score alongside cyber, resilience, tokenisation and conduct signals. That single-figure roll-up is what makes the fabric legible to a non-technical board without flattening the detail underneath.

    Continuous Financial Infrastructure Assurance

    AI oversight is only half of the assurance operating system. The other half is CFIA — Continuous Financial Infrastructure Assurance — applied to the payment rails, tokenised settlement substrates and cross-border messaging systems the institution's book already depends on. The two halves share one kernel, one evidence vault, one policy engine and one score. An institution that runs AI on infrastructure it cannot assure is exposed twice. An institution that assures both is telling one coherent story to its regulators.

    The China question, honestly framed

    Cabier does not deploy in the People's Republic of China and does not benchmark Chinese models against Western ones. The Chinese frontier ecosystem — DeepSeek, Qwen, Kimi, Pangu, Hunyuan and their successors — appears on the model plane only as an observed vendor set, with no logos and no endorsement. What Cabier does offer is oversight to the regulated multinationals and sovereign operators whose estates already touch those ecosystems, whether directly, through vendor stacks, or through consumer-facing products in markets where their customers use them.

    The moat is neutrality. Boards and supervisors have made it clear that they will not buy oversight from any party that also sells the model.

    What the board should be asking

    Three questions clear the noise. First, does the institution have a single registry that names every model, data source and agent in production — including the ones sitting inside vendor stacks? Second, is there a single policy engine that reconciles the obligations of every jurisdiction the institution serves, and does it route AI use accordingly? Third, is there a single score that a board committee can read in five minutes, backed by evidence a supervisor can interrogate for five days? If the answer to any of the three is no, the institution does not yet have AI oversight; it has AI usage.

    FAQs

    Is Cabier an AI company?

    No. Cabier is the independent oversight, governance and assurance layer for institutions that operate multi-model AI estates. Clients own the AI. Cabier operates the trust.

    Does Cabier govern Chinese frontier models?

    Cabier provides oversight to institutions whose estates include Chinese frontier ecosystems as observed vendors on the model plane. There is no in-PRC deployment; China sits as an observed jurisdiction on the sovereign policy engine.

    How does the AI Trust Score relate to ORS?

    The AI Trust Score grades individual model, data and agent surfaces across ten dimensions. Those grades roll up as an input to the institution's Operational Resilience Score (ORS), alongside cyber, resilience, tokenisation and conduct signals.

    Where does CFIA fit?

    Continuous Financial Infrastructure Assurance (CFIA) applies the Assurance Kernel to the financial plumbing itself — payment rails, tokenised settlement substrates and the shared infrastructure institutions depend on. AI oversight and CFIA share one kernel, one evidence vault and one score.

    Is this a replacement for internal model governance?

    No. It sits above it. Cabier is the independent, cross-institution overlay that gives boards, supervisors and counterparties a comparable view of AI trust posture without displacing SR 11-7, EU AI Act or local model-risk workflows.

    References and citations

    Primary sources. Positions change; verify at source before relying on any figure or determination.

    1. 1NIST AI Risk Management Framework (AI RMF 1.0) and the Generative AI Profile (NIST AI 600-1)Control taxonomy underlying the oversight-layer mapping.Source
    2. 2European Union, Regulation (EU) 2024/1689 (AI Act)Obligations for providers and deployers, including general-purpose AI models.Source
    3. 3Board of Governors of the Federal Reserve System / OCC, Supervisory Guidance on Model Risk Management (SR 11-7 / OCC 2011-12)Validation, challenge and independent-review expectations applied to AI systems.Source
    4. 4ISO/IEC 42001:2023 — Artificial intelligence management systemManagement-system reference for the assurance loop.Source
    5. 5European Union, Regulation (EU) 2022/2554 (DORA) and related regulatory technical standardsThird-party and resilience obligations applied to model and inference providers.Source
    Editorial independence. Cabier has no commercial relationship to any named frontier model, lab or cloud platform referenced or to the underwriters of the securities discussed in this article. Analysis is editorially independent. Cabier does not provide investment, legal or tax advice; nothing in this article is a recommendation to buy, sell or hold any security. Figures are drawn from public filings and named secondary sources current at the date of publication.

    Named sources

    • Public regulatory sources through July 2026EU AI Act Official Journal text; US NIST AI RMF and OMB M-24-10; UK DSIT AI regulation white paper; Canada AIDA legislative status and OSFI E-23 guideline; Japan METI/FSA AI guidelines; Singapore MAS FEAT and Model AI Governance Framework; PRC CAC Generative AI Measures and PIPL. Named vendors appear only as observed entities with no comparative benchmarking.