Cabier AI · Umbrella category
Global AI Assurance
Governance asks who owns AI. Assurance asks whether the institution can prove its policies operate. As systems retain memory, use tools, reach data and take actions, the supervisory question moves from what was approved before deployment to what the estate is doing right now, and who is able to stop it.
Cabier is model-agnostic by design. The institution chooses the models. Cabier assures the estate that results, including the parts of it that were never procured as AI.
Published as reference architecture. Control weights, grading rubrics and the full control set are set per engagement.
Nine disciplines under one umbrella
Each discipline exists because a different person asks the question. The board, the regulator, the CISO, the auditor and the operator are not asking the same thing about the same system.
AI Governance
Who owns AI, and under what policy?
Named accountability per system, an approved policy set and a board record of the risk that was accepted.
AI Assurance
Can the institution prove those policies operate?
Evidence produced continuously by the control itself, not assembled when a supervisor asks.
AI Control
Can the institution constrain what AI is able to do?
Scoped authority per agent, enforced at the point of action rather than described in a policy document.
AI Security
Can it detect and contain an AI-enabled attack?
Prompt injection, jailbreak, privilege escalation and exfiltration treated as cyber events with owners.
AI Resilience
Can it survive model, provider or agent failure?
Fallback models, exit tests and impact tolerance measured with the AI dependency as the failure mode.
AI Regulatory Intelligence
Which rules actually apply, and from when?
Obligation-level mapping from authority to control to evidence, with effective dates and supervisory expectation.
AI Sovereignty
Where do the model, the data and the evidence operate?
Residency and compellability resolved per workload before deployment, not discovered during an examination.
AI Supply Chain
Which third-party models, agents and tools are embedded?
The estate the institution did not choose but already owns through a vendor, mapped to the dependency beneath it.
AI Agent Assurance
What can autonomous systems actually do today?
Authority envelope per agent, an out-of-envelope refusal on record and a named human owner for each.
The architecture
Models and agents sit below. The assurance layer sits above them, and everything it produces resolves into one institutional position.
Global model ecosystem
Ecosystems observed in institutional estates. Naming is not endorsement, and no comparative benchmark is published.
Cabier assurance layers
Assurance Kernel
Seven Trust Gates evaluate every governed invocation.
Trust Graph
One typed map of obligations, controls, systems, models, agents and evidence.
Decision Fabric
Where an intervention is decided, recorded and attributed.
Evidence Vault
The artefact a supervisor, auditor or board reads.
AI Trust Score
Per-system position across fourteen dimensions.
ORS
The institutional resilience position the board is accountable for.
Enterprise
Board, CRO, CISO, CCO, CIO and internal audit read the same position from the same evidence.
Government
Ministries, agencies, supervisors and auditors read it under their own residency conditions.
One kernel, composed per institution
Global horizontal kernel, plus a jurisdiction pack, plus an industry pack, plus the enterprise AI estate. Different obligations, different evidence, the same kernel underneath.
| Jurisdiction | Industry | Pack | What changes |
|---|---|---|---|
| Canada | Banking | OSFI E-23 and B-10 with federal privacy overlay | Model risk rating drives validation depth, and third-party AI is examined at the same time. |
| United States | Insurance | NAIC model bulletin with state-level conduct overlay | Conduct and unfair-discrimination testing sit ahead of model documentation. |
| United Kingdom | Legal | SRA and professional-privilege constraints with SMCR-style accountability | Privilege and confidentiality bound the reach of the agent before any performance question. |
| Singapore | Government | Sovereign deployment with public-sector data classification | Residency and compellability decide the architecture, not the procurement. |
As intelligence becomes more capable and more autonomous, assurance becomes infrastructure. That is the layer Cabier operates.
Start with estate discoveryFlagship analysis
Governance became an operating control
The full argument: why the approval gate stopped working, what a running assurance loop does instead, and what the board should be told rather than scored.
Read the article