Why governance is not a model question
Most AI failures are not the model's fault. They are the fault of unverified sources, missing permissions, silent retries, and unlogged outputs. Attnora treats governance as an operations discipline, not a model card.
- Canonical source registry with provenance and freshness.
- Retrieval with citations and per-document permissions.
- Project and session memory scoped to roles.
- User roles and tool permissions enforced at runtime.
- Evaluation and human review for consequential outputs.
- Model routing and deployment with audit logs.
- Cost, cache, and loop monitoring with kill-switches.
How it relates to EU AI Act readiness
Attnora is not a law firm. We help you produce the technical artefacts a regulator will ask for: source provenance, evaluation reports, human-review records, and audit logs. Most of these are already byproducts of the four services.
How a pilot starts
We map your current AI surface, score it against the seven controls above, and ship a prioritised gap-closure plan in two weeks.
Frequently asked questions
Do you write AI policies?
No. We produce the technical controls and the audit artefacts that a policy needs. The policy itself is for your legal and compliance team.
Is this a model risk management framework?
It is the operational layer below MRM. Attnora gives you the controls; your MRM framework decides which controls are required for which risk tier.
How do you evaluate agent quality?
Per-agent evaluation suites that score retrieval accuracy, citation coverage, tool-call correctness, and end-to-end task success on a held-out set.
Can logs be exported for an audit?
Yes. Every prompt, retrieval, tool call, and output is logged with timestamps and citations. Logs are exportable as CSV or JSON.
Related services
Next step
Score your AI surface against the seven controls.
Tell us which AI systems are in production. We will respond with a control-score report within one business day.
Request a governance review