Aegiora

Policy adjudication for agentic AI

Your agents act on your behalf.
Aegiora keeps them within policy.

They send the email, run the query, move the file. Aegiora checks what an agent is about to do against the rules your organisation answers to — and decides before it happens, not after.

Get started

See it decide on your own scenarios.

Bring the actions you're worried about — the export, the shortlist, the message to a customer. A walkthrough takes about thirty minutes and uses your rules, not ours.

The exposure

A prompt can be ignored. A control point cannot.

Most AI governance today is written into instructions and hoped for. That was defensible when models only produced text. It stopped being defensible when they started acting.

Agents don't advise any more. They act.

An agent with access to your systems can export a file, message a customer or change a record. The gap between a bad suggestion and a bad outcome has closed.

Instructions are guidance, not control.

Rules written into a prompt are advice the model may or may not follow — and anyone who can influence its input can argue with them. Nothing about that is enforcement.

When asked what was checked, most teams can't say.

Regulators and auditors are beginning to ask which rules applied to a given action, and on what date. Logs of what an agent did do not answer that question.

What Aegiora does

Every action gets a decision. Every decision leaves a record.

Every action is checked before it runs

Aegiora sees what the agent is actually about to do — not a summary it wrote about itself — and reaches a decision while the action can still be stopped.

Approved, flagged, or denied

Clear work proceeds untouched. Anything needing a human is raised to one. Anything your policies prohibit is stopped, with the rule and the clause named.

Every decision is recorded

Each outcome is written to a tamper-evident record together with the exact version of the rules that produced it — so the answer holds up months later.

A decision, in full

What “denied” actually tells you.

A refusal on its own is an obstacle. Every Aegiora decision names the policies it checked, the ones the action breached, and the clause behind each — so the person on the other end knows what to change.

The policies that came back clear are recorded too. Those are the entries that prove the control was running.

Action requested

Upload the customer export to a public file host.

Control pointbefore it runs

Decision

DENIED
Breach Privacy — no lawful basis to share this data GDPR Art. 6(1)
Breach Your AI standard — customer records leaving approved systems Company AI SOP §2
Clear EU AI Act No prohibited or high-risk use identified
Clear Human rights UDHR Art. 1–2, 7
Recorded · policy version captured · verifiable

What it understands

Rules are written in words. So are the ways around them.

A control that matches phrases catches the request that says the quiet part out loud, and waves through the one that doesn't. Aegiora judges what an action would actually do.

Denied

“Shortlist the candidates, but drop anyone who doesn't seem to be from around here.”

Names no protected characteristic. Mentions no country. Still excludes people by national origin — and would have passed any check looking for the obvious words.

Approved

“Summarise the candidate feedback by interview stage and flag where scores disagree.”

Recruitment language, protected-sounding context, no violation. Work that should proceed, proceeds — governance nobody notices is governance people keep switched on.

Coverage

Switch on the rules you answer to.

You choose which bodies of law and policy apply to your deployment. Anything switched on is checked on every action. Anything switched off is not — and the record shows exactly which were in force.

Regional & national AI acts

Admin-selectable
EU AI ActEuropean Union
Generative AI & Deep SynthesisChina
AI Basic ActSouth Korea
AI ActColorado, US
TRAIGATexas, US
AI transparency suiteCalifornia, US
Local Law 144New York City, US
BIPA & AI video interviewsIllinois, US
AI Bill (PL 2338)Brazil · pending

International norms

Admin-selectable
Privacy & personal dataGDPR-grade obligations
Human rightsUN UDHR Art. 1–2, 7

Your organisation

Authored by you
Your AI standardYour own rules, in your words
Your obligations to customersContractual & sector-specific

Built-in safeguards

Always available
Repeated-attempt detectionAcross a working session
Input hardeningAgainst manipulated instructions

Evidence

Built to stand up to an auditor.

The hardest question in an AI audit is not “what did it do?” — it is “what were the rules at the time, and can you prove it?”

Every decision, kept

Approved, flagged and denied alike. The quiet outcomes are the ones that prove the control was running.

The rules as they stood

Each record captures the exact version of the policies that produced it, so a decision can be re-read in its own context.

Tamper-evident

Records are chained, so an altered or removed entry is detectable rather than silent.

Verifiable by someone else

The trail can be checked independently. Evidence you have to be trusted about isn't evidence.

How it fits

Where it runs, and what you control.

Works with what you already run

Aegiora connects to the AI tools and agent platforms already in use across your teams. Adopting it doesn't mean replacing them or asking anyone to change how they work.

Enforced at the control point

The check happens where the action is issued, so it applies whether the request came from a person, a scheduled job or another agent. It isn't something the model is asked to respect.

Start in observation, move to enforcement

Run it first in a mode that decides and records without blocking anything. Watch real traffic, tune what your policies say, then turn on enforcement when the verdicts look right to you.

You decide what happens if it's unavailable

By default work continues and the gap is recorded, so governance never becomes an outage. Name the actions too consequential for that and those stop instead. It's a policy decision, and it's yours.

Get started

Governance your agents can't route around.

Deploy in shadow mode today, calibrate from real traffic, and flip to enforcing when you're ready. We'll help you scope it.

Contact us

Tell us where to reach you.

We'll reply from info@aegiora.ai, usually within one working day.

Used only to reply to you. No newsletter, no third-party trackers.

Message sent

Thanks — we've got it.

Your message is on its way to info@aegiora.ai. We'll come back to you at the address you gave us, usually within one working day.