Skip to content

Guztia AI Infra Ops

Guztia /Services /AI Governance

SVC-03 · Policy layer

AI Governance

Most AI governance is a document nobody can enforce. This is the other kind — budgets that actually stop spending, routing rules that keep regulated data on the right hardware, an audit trail that survives contact with an auditor, and approval gates on the outputs that warrant them.

01 The position

A policy nobody can enforce is a liability, not a control.

Every company we talk to has an AI usage policy. Almost none can answer the question that follows: show me. Show me a prompt that was blocked. Show me the team that hit its cap. Show me where customer data was sent last Tuesday, and which model saw it.

If the answer lives in a Confluence page and a training slide, you do not have a control — you have a document that will be read aloud during the incident review. Governance that works is a property of the infrastructure, and the gateway is where it goes.

WHAT "WE HAVE A POLICY" LOOKS LIKE WHEN IT IS REAL

Classification drives the route

Public content can reach a vendor API. Internal content stays on self-hosted hardware in your region. Customer and regulated data never leave your infrastructure — with caching disabled and longer retention where policy requires it. Budgets are soft (alert) or hard (stop spending), enforced at the gateway so they apply to the intern's script as much as to production.

02 The controls

Budget enforcement
Per team, per project, per key, per person. Soft caps alert; hard caps stop spending. Enforced at the gateway, which means it applies to the intern's script as much as to the production service.
Data-class routing
Classify once, then route by class. Public content can reach a vendor API; customer records cannot leave your hardware; regulated data goes to a specific model in a specific region with caching disabled. The rule is in infrastructure, so there is nothing to remember and nothing to forget.
Residency
EU prompts answered on EU hardware. Mainland China prompts answered inside the mainland, which is a solved problem here rather than a new one. Documented per route, with the reason attached, in a form that survives a DPIA.
Audit trail
Every call traced with identity, model, timestamp, token counts, cost and — where policy requires it — the content. Retained to your schedule, exported to object storage or a SIEM, immutable where that matters. This is the artefact that answers "show me".
Human in the loop
Approval gates on outputs that reach customers, move money, change records or carry regulatory weight. Queue, reviewer, decision, reason, timestamp — all of it recorded. We have built exactly this before and it is less work than teams expect.
Access lifecycle
Model access tied to SSO identity, so it is granted and revoked with everything else. When someone leaves on Friday, their model access leaves on Friday. Static keys on laptops are the thing we are removing.
Egress control
Network policy that makes "no data leaves" a firewall rule rather than a promise. If a service is not supposed to reach the public internet, it cannot.
Post-quantum transport
Where the threat model includes harvest-now-decrypt-later, we add a PQC layer to model API transport through our partner QuReady. Relevant for long-lived confidential data; overkill for most. We will say which you are.

03 Frameworks

We build the evidence. Your counsel makes the argument.

We are engineers, not a law firm, and we will not pretend a Terraform module makes you compliant with anything. What we do is produce the technical evidence your legal and compliance people need: the logs, the controls, the architecture diagrams, the retention configuration and the routing rules, documented in a form that maps onto what they are being asked.

In practice that has meant EU AI Act transparency and record-keeping obligations, GDPR data-flow documentation, ISO 27001 control evidence, SOC 2 audit support, and sector rules in finance and healthcare that predate any of this and are not going to bend for it.

USUALLY BOUGHT AS

An add-on to the retainer

Most governance work lands on top of an existing stack — the controls need somewhere to live. Typical implementation is €4k–€12k, then it becomes part of the monthly operation.

ALSO AVAILABLE AS

A standalone review

Two weeks, fixed fee, written findings: what your current AI usage exposes you to, what is enforceable today, and what to fix in what order. No obligation to have us do the fixing.

Own the stack before the bill owns you.

Thirty minutes. Bring your current AI invoice. We look at what your teams send to model APIs, what it costs today, and what a self-hosted stack would cost instead. No deck, no discovery phase.