AI Assurance · Control plane

    Cabier AI Control Plane

    A control architecture, not a model. The institution stays model-agnostic; the plane decides which model may be used for which requirement, under whose authority, with what evidence produced. Every path is human-governed — nothing here executes without an accountable owner.

    Published as reference architecture. Deployment scope, interoperability and residency options are set per engagement.

    Model registry

    Extends the existing AI model inventory rather than duplicating it. Each field exists because a supervisor, an auditor or a resilience test asks for it.

    Model and version

    The unit of supervisory scope; version is what is examined, not the family.

    Accountable owner

    A named human, distinct from the validator.

    Hosting region and residency

    Determines transfer mechanism and sovereign constraints.

    Approval status

    Blocks production use where validation has not closed.

    Security rating

    Adversarial and prompt-injection posture, refreshed on model change.

    Bias and explainability status

    Feeds fairness obligations across FEAT, Art. 10 and fair-lending.

    Cost and latency envelope

    Routing constraint and a resilience input, not a finance metric.

    Last validation and next due

    Drives revalidation cadence and supervisory readiness.

    Evidence chain reference

    Every field resolves to an artefact in the vault.

    Model router

    Requirement in, model out, with the reason recorded and an audit identifier attached. Routing is a control decision before it is an engineering one.

    RequirementRouted toReason
    Personal data of EU residents, high-risk classificationEU-hosted model, no egressChapter V transfer constraint plus Art. 10 data governance.
    Sovereign citizen data, Gulf deploymentIn-country inference endpointNational charter prohibits egress for citizen-service systems.
    Broker-dealer client communicationsRetained, supervised, archived model pathFINRA 3110 supervision and books-and-records retention.
    Internal research summarisation, no personal dataLowest-cost qualified modelNo regulated activity engaged; cost and latency govern.
    Credit decisioningValidated, explainable model onlySR 11-7 plus fair-lending explainability obligations.

    Enterprise tool governance

    Reach

    Which systems an agent may contact, declared before it runs, not discovered afterwards.

    Conditions

    The state the institution must be in for the action to be permitted at all.

    Ceilings

    Value, volume and blast-radius limits that stop the agent rather than warn about it.

    Log

    Every reach, permitted or refused, written to the evidence chain with an audit identifier.

    Multi-model adapter grid

    Frontier commercial

    Contractual right-to-test, sub-processor disclosure, exit path

    Open-weight self-hosted

    Provenance attestation, in-house adversarial testing, patch cadence

    Sovereign or regional

    Residency proof, in-country inference, national charter mapping

    Embedded vendor model

    Discovery first — the model the institution did not know it bought

    The plane is the control layer above whichever models an institution chooses — and above the ones it did not choose but already owns through a vendor.

    Readiness dimensions