Global AI Assurance · Layer 01
AI Estate Discovery
You cannot assure what you do not know exists. Most institutions hold an AI register that describes what was procured, and an AI estate that describes what is running. Discovery closes the distance between the two before any control question is asked.
The whole surface a sweep returns, approved or not. Sample estate, 1157 objects on this lens.
Foundation models
Direct API and hosted endpoints across five providers.
Agents
Anything that can take an action, not merely answer a question.
Applications with AI features
Feature flags turned on inside software already under licence.
Tool servers
Interfaces that let a model reach an institutional system.
Datasets used for inference
Retrieval corpora carry the same data obligations as source systems.
APIs exposed to models
Reach is the control surface. Every exposed API widens it.
Vendors supplying AI
Includes sub-processors disclosed only on request.
Embedded AI in licensed software
Owned by the institution without ever having been procured as AI.
Shadow AI
Discovered through egress and expense signals rather than a register.
Autonomous systems
Systems able to act without a human in the path of the action.
Figures are illustrative of a sample estate. Real sweeps run against the institution's own systems and produce a per-object record in the Trust Graph.
How the sweep finds it
Discovery does not rely on anyone volunteering the truth. It correlates signals the estate already emits.
What discovery hands over
Every object typed
Models, agents, tools, datasets, vendors and autonomous systems entered into the Trust Graph as first-class objects.
Every gap named
Unowned and unapproved objects routed to a person, with a date, rather than to a report.
Every dependency visible
The provider and infrastructure beneath each object, which is where concentration risk starts.