Start Here

AI Control Architecture is an open-source, vendor-agnostic model for governing, securing, assuring, and containing enterprise AI. It gives your organisation a shared way to answer one question about any AI you run — is this under control? — and to prove it.

The idea in one minute

The next major AI failure in the enterprise won't come from a model becoming evil. It will come from giving a probabilistic system deterministic authority — over data, decisions, or actions — without a control architecture.

An AI touches the enterprise in exactly three ways: what it can See, what it can Decide, and what it can Do. AI Control Architecture bounds each of those, grades how strongly every boundary actually holds — Declared → Evidenced → Verified → Enforced — and insists that a named human owns every consequential outcome. Controls scale with risk across five tiers, so a low-risk copilot and an action-capable agent never carry the same burden.

The result is a claim you can make, and defend, for any AI you operate:

We know what it can see, decide, and do. We have graded how strongly each boundary holds. A named human owns every outcome. We can observe it, stop it, and recover.

The executive briefing

A 13-slide, board-to-CISO walkthrough of the whole model. View it here or download it below.

View fullscreen Download PDF All resources →

Start using it

  • New to the idea?Why This Exists
  • Want the argument in full?The Core Thesis
  • Ready to try it now?Quickstart — one AI use case, end to end
  • Want everything to download?Resources — the executive pack and the practitioner course

Everything here is open

The specification is licensed CC BY 4.0, the reference tools are open source, and the model is deliberately vendor-agnostic. It is stewarded by Neo Control, which offers the reference implementation — but you never need Neo, or any vendor, to adopt it.