✓ AI Act Ready ✓ DORA Ready ✓ GDPR Compliant Forged in Luxembourg OWASP Security Review Passed

Governed AI for organisations that
cannot afford to lose control

Trace, validate and govern every AI decision. Full interaction traceability, human validation and audit trails by architecture.

InnooForge is the enterprise AI governance platform for organisations that cannot afford to lose control — including regulated organisations in Europe. Every AI interaction is traced, validated by a named human and recorded as an audit trail — so your teams can meet EU AI Act, DORA and GDPR obligations, keep enterprise AI on-premise or in European cloud, and demonstrate EU data sovereignty when regulators ask.

By architecture
Traceability, not bolt-on
Human
Named approver per decision
AI Act · DORA · GDPR
Evidence-oriented design
EU
On-premise or European cloud
InnooForge Knowledge Loop Dashboard

See the governance loop on your own documents

Bring one real process — a compliance review, a risk assessment or a contract analysis — and we will show you the traceability, the human validation step and the audit trail it produces.

Sources and further reading

Regulatory statements on this page are based on the official sources below. Dates and obligations should always be verified against the current text and European Commission guidance.

About this page

Author: Governance team, Ubiclouder S.à r.l., Luxembourg.

Last reviewed: 12 September 2026, against the official European Commission and EUR-Lex sources listed above.

Corrections and questions: [email protected] · +352 27997851

This page is provided for information and does not constitute legal advice. Obligations under the EU AI Act, DORA and GDPR depend on your role, use case and jurisdiction. Always confirm requirements with your legal and compliance advisers and the current regulatory text.

A worked example: quarterly compliance review

Consider a Luxembourg fund administrator preparing a quarterly investor compliance review.

Without governance. An analyst pastes fund clauses into a public chatbot to summarise obligations, then copies the result into the review. There is no record of the model used, which documents were submitted, or whether a second person checked the conclusion. If the regulator asks how the assessment was reached three months later, the trail has to be reconstructed — often it cannot be.

With Governed AI. Sources are scoped to the fund's document repository. The permitted model is fixed by policy. The output carries source attribution to specific documents. The compliance officer approves, modifies or rejects the conclusion. The audit trail stores the prompt, the sources, the model version and the approver.

When the question arrives. The evidence exists as a by-product of the work: who asked, what the AI produced, which documents it relied on, and who signed it off. That is the practical difference between using AI and governing it.

To quantify the operational value of that difference, use the AI governance ROI calculator.

Frequently asked questions

What is AI governance?

AI governance is the set of policies, roles, processes and technical controls that determine how an organisation selects, deploys, monitors and evidences its use of artificial intelligence. In practice it covers accountability, risk tiering, human oversight, logging, documentation and audit. For regulated organisations, AI governance is what makes an AI-assisted decision defensible to a supervisor, an auditor or a court.

Why does enterprise AI governance matter?

AI is already used in processes regulators examine — compliance reviews, risk assessment, contract analysis and quality documentation. Without traceability and human oversight, organisations cannot explain how an output was produced or who approved it. The EU AI Act, DORA and GDPR all assume that evidence exists; governance produces it by design rather than reconstructing it after an incident.

What does the EU AI Act require?

For high-risk AI systems, the Act requires a risk management system, technical documentation, record-keeping and logging, transparency and instructions for use, human oversight, and appropriate accuracy, robustness and cybersecurity. Deployers must use systems correctly, assign oversight to competent people, monitor operation, keep logs and inform affected persons where required. The exact obligations depend on your role and the system's classification — see the EU AI Act compliance guide.

How much does AI governance software cost?

The platform is licensed per organisation rather than per seat, and cost depends on the deployment model (managed EU cloud, private cloud or on-premise) and on the scope of the programme. We publish no rate card: after a scoping call we confirm scope and cost in a written proposal, and most organisations start with a bounded proof of concept. Contact us to discuss your case.

Can the platform be deployed on-premise?

Yes. The platform can be deployed on-premise with Docker, in a private cloud, or as managed SaaS hosted in Luxembourg. On-premise and air-gapped deployments keep prompts, documents, decision logs and audit trails inside your own infrastructure, which matters when data residency or information classification rules prevent the use of public cloud AI services.

How licensing and engagement work

The platform is licensed per organisation rather than per seat. Cost depends on the deployment model you choose and on the scope of the programme, and is confirmed in a written proposal after a scoping call — we publish no rate card.

  • Managed European cloud — operated for you in Luxembourg or the EU, with governance templates, dashboards and support included.
  • Private cloud — installed in your own cloud tenancy or region, keeping data residency under your control.
  • On-premise — deployed inside your own infrastructure, with air-gapped operation possible, for the strictest classification or residency rules.
  • Proof of concept — a bounded engagement on your own processes with success criteria agreed up front. Most organisations start here.

To discuss scope and a proposal, contact us. If you need an independent assessment of your starting position, we can run an AI governance audit as a separate engagement.

How it works

The platform implements a six-step governance loop around every AI interaction.

  1. Scope. You define the perimeter: which documents and systems the AI may reach, and which users may reach them.
  2. Request. A user starts a task. The permitted model and the permitted sources are fixed by policy rather than chosen ad hoc.
  3. Generate. The AI produces an output and records the sources it used.
  4. Validate. A named human approves, modifies or rejects the output before it is applied.
  5. Capture. The interaction, its sources, the model version and the approver are written to the audit trail.
  6. Retain and reuse. Validated knowledge stays inside the organisation and informs later decisions.

The loop is what makes the difference between an AI assistant and governed AI: the record is created as a by-product of the work, not as a separate administrative task. To see the wider product context, read the InnooForge product overview.

Deployment and data residency

Governance is only credible if the platform itself respects your data rules. The platform is deployed where your information is permitted to live.

Deployment modelBest suited toData residency
On-premise (Docker) Organisations with strict residency or classification rules; air-gapped environments Inside your own infrastructure
Private cloud Teams that need elasticity while retaining control of the tenant Your European cloud tenant
Managed SaaS Fastest start, with managed installation and onboarding Hosted in Luxembourg

The architecture is LLM-agnostic: you connect the models you are permitted to use, including self-hosted open-weight models. On-premise and air-gapped deployments keep prompts, documents, decision logs and audit trails inside your perimeter. Full detail is on the sovereignty and deployment page.

Implementation roadmap

A practical sequence for introducing AI governance without stalling delivery. Steps 1 to 3 can run in parallel with a pilot.

  1. Establish your baseline. Work through the AI compliance checklist to identify where AI is already used and what evidence is missing.
  2. Define the perimeter and classify systems. Decide which use cases are in scope and how each is classified under your AI Act, DORA and GDPR obligations.
  3. Deploy. On-premise, private cloud or managed SaaS, depending on your residency constraints.
  4. Configure templates and approval roles. Set the governance templates for your domains and define who may approve what.
  5. Pilot one high-value process. Choose a process that regulators already examine, such as a compliance review or a risk assessment.
  6. Review the evidence and extend. Take the audit trail of the pilot to internal audit and compliance, then extend to further processes.

If you need help with step 1 or 2, we can run an AI governance audit as a separate fixed-scope engagement.

Mapping AI governance obligations to platform evidence

Regulatory expectations, industry best practice and product capability are not the same thing. The table below separates them, so you can see exactly what the platform does — and what remains a decision for your organisation.

Regulatory requirement Best practice / framework Our recommendation Product capability
Obligation or controlTypeWhat good evidence looks likeInnooForge
Risk management system — AI Act Art. 9 Regulatory A documented, per-system risk file that is reviewed and updated Governance templates and structured classification records
Record-keeping and logging — AI Act Art. 12 Regulatory Automatically generated logs of system operation, retained and retrievable Interaction and decision logs captured at source
Transparency and instructions for use — AI Act Art. 13 Regulatory Users understand capability, limits and outputs Source attribution and provenance shown with each output
Human oversight — AI Act Art. 14 Regulatory Competent persons can monitor, interpret and intervene Named-approver workflow with approve, reject or modify
ICT risk management — DORA Art. 6 & 8 Regulatory Documented ICT risk framework and evidence for critical functions Deployment documentation and exportable audit records
Data minimisation — GDPR Art. 5 Regulatory Only necessary data is processed, with a defined lawful basis Scoped source access; documents are not used to train third-party models
Records of processing — GDPR Art. 30 Regulatory An accurate record of processing activities Exportable interaction metadata for the record of processing
Automated decision-making — GDPR Art. 22 Regulatory Meaningful human intervention and the ability to explain an outcome Human validation gate plus a reproducible decision trail
Segregation of duties Best practice The person proposing an output is not the sole approver Role-based approval routing
Prompt and instruction governance Recommendation Prompts are versioned, reviewed and attributable Instruction system with version history
Retention and retrieval Capability A defined retention period with fast retrieval on request Configurable retention and searchable audit trail

The platform provides the mechanism and the record. Determining the correct legal basis, classification and retention period remains your organisation's responsibility — our AI compliance checklist helps you work through those decisions.

What an AI governance platform must do

The table below sets out the capabilities an enterprise AI governance platform should provide, and how the platform delivers each one.

CapabilityWhy it mattersHow the platform delivers it
Full interaction traceability You must be able to explain how an output was produced, not merely that it was produced. Every interaction records the prompt, the sources used, the model and the output, linked to the requesting user and the decision it supported.
Human validation Accountability cannot rest on an unnamed system. AI Act human-oversight expectations and internal control frameworks both require a competent, identifiable reviewer. Consequential outputs require explicit approval, rejection or modification by a named human before they are applied.
Audit trail and logging Records must be complete, retained and retrievable, and must survive staff turnover. Decision logs with timestamps, reviewers and document integrity checks, exportable for internal or external audit.
Source attribution An unsourced answer cannot be relied upon in a regulated process. Outputs are linked back to the documents they draw on, so a reviewer can verify the basis of a conclusion.
Risk tiering and documentation Obligations differ by risk level; you need a documented classification per system. Structured governance templates guide classification, documentation and review, so the file exists before it is requested.
Agent and tool control Agents that call tools can act on enterprise systems, where errors have real consequences. The governance layer constrains which tools and data an AI workflow may reach, and records each action taken.
Sovereign deployment Data residency and information classification rules often prohibit public cloud AI. On-premise (Docker), private cloud or Luxembourg-hosted SaaS, with an LLM-agnostic architecture. See sovereign AI deployment options.

What is an AI governance platform?

An AI governance platform is software that sits between your people, the AI models they use and your enterprise systems. It enforces who may use which model, which sources may be used, which outputs require human approval, and what evidence is retained. It turns AI from an unlogged convenience into an auditable, defensible process.

An AI governance platform is not a chatbot, a model or a spreadsheet

Definition: AI governance platform

A governance layer that records every AI interaction (prompt, sources, model version, output), requires named human validation before consequential use, and produces an audit trail that can be examined by internal audit, an external auditor or a supervisory authority.

Most organisations already have AI. What they usually lack is the ability to answer, months later, four questions a regulator will ask: Which model produced this output? Which documents was it based on? Who approved it? What has changed since?

An AI assistant answers a query. A model generates text. A GRC spreadsheet records that a policy exists. None of them capture the interaction itself. An AI governance platform captures the interaction — and makes it reproducible.

For a comparison of the categories, see the AI governance FAQ, which contrasts governed AI with general-purpose assistants.

Why enterprise AI governance matters now

Three pressures converge on European regulated organisations at the same time.

  • Regulatory obligations. The EU AI Act introduces transparency, logging, documentation and human-oversight requirements for high-risk systems. DORA requires financial entities to manage ICT risk and maintain evidence for critical systems. GDPR requires a lawful basis, data minimisation and records of processing. Each regime assumes that evidence exists.
  • Shadow AI. When governance is absent, staff adopt consumer AI tools outside IT oversight. The organisation then holds neither an inventory of AI use nor a record of what data was submitted.
  • Reconstruction is expensive. Attempting to rebuild an AI decision trail after an audit request is slow, incomplete and often impossible. Governance by architecture avoids that cost by capturing the record at the moment of the decision.

There is also an asset dimension: in a governed architecture, validated interactions and the institutional knowledge around them remain inside the organisation rather than being dispersed across external tools and personal accounts.

Built for Compliance

AI Act · DORA · GDPR — compliance by architecture, not retrofit. Designed for regulated environments (GxP, space, healthcare).

Full Decision Traceability

Complete audit trail for every AI interaction — who, what, when, and which sources.

Source Attribution

Every output linked to its source documents. Know exactly where conclusions come from.

Human Validation Required

Named approvers for every decision. Audit-ready sign-off at every critical step.

GDPR by Design

Data minimization, tracked consent, right to erasure, DPO dashboard — built-in, not bolted on.

EU Data Sovereignty

On-premise or European cloud. Your data never leaves your jurisdiction.

AI Act & DORA Ready

Governance layer designed for high-risk AI compliance. August 2026 deadline covered.

Audit Trails & Document Integrity

Immutable audit trails, electronic signatures, and document integrity hashes — designed to support requirements such as FDA 21 CFR Part 11 (system validation remains on the customer side).

Documentary Cross-Checking

Cross-reference specs against test plans to support your ISO 13485 and ECSS quality work — as a complement to your requirements-management tools (DOORS, Polarion), not a replacement.

Healthcare Data Sovereignty

Deterministic pseudonymization, consent tracking, and EU hosting for healthcare data — an architecture compatible with deployment on HDS-certified infrastructure.

Compliance dashboard

InnooForge vs. Generic AI Tools

Why regulated industries need governed AI, not black boxes

Feature ChatGPT / Copilot InnooForge
Data sovereignty ❌ US cloud (Microsoft/OpenAI) ✅ EU cloud or on-premise
Audit trail ❌ Black box, no logs ✅ Full traceability
Human validation ❌ Optional / bolt-on ✅ Required by design
Source attribution ❌ Hallucination risk ✅ Document-level citation
DORA compliance ❌ Not for regulated industries ✅ Built-in governance layer
AI Act readiness ❌ Responsibility on you ✅ Shared compliance architecture
Data residency ❌ US only ✅ EU, Luxembourg, or on-premise
GDPR by design ❌ Not built-in ✅ Minimization, consent, DPO dashboard
Self-improvement ❌ Manual prompts ✅ Prompt Auto-Improvement
Institutional IP retention ❌ Your data trains their models ✅ Your knowledge stays yours

Generic AI can be configured for compliance. The platform is compliance by architecture.

Trusted by Regulated Industries

What our users say about governed AI

"InnooForge gave us complete audit trails for our AI-assisted compliance reviews. Our CSSF auditors were satisfied with the traceability and documentation."
— CFO, Fund Administration Company, Luxembourg
"Finally, an AI solution that understands DORA requirements and keeps our data in Europe. The human-in-the-loop validation is exactly what we needed."
— CTO, Asset Management Firm
"We went from 'the algorithm made me do it' to full explainability. Every AI decision now has a clear source and a named validator."
— Compliance Officer, ManCo

Built for Your Industry

How regulated industries use governed AI — finance, pharma, biotech, spatial, healthcare

ManCo

AI-Assisted Compliance Reviews

Generate compliance reports with full source attribution and human validation before submission to regulators.

✓ Full audit trail for CSSF
Law Firms

Contract Analysis with Validation

Analyze contracts and legal documents with traceable citations and lawyer sign-off at each step.

✓ Client-ready documentation
Fund Admin

Provision Calculations

Support provision calculations with documented methodology, source data, and explicit validation workflow.

✓ Defensible decision support
Compliance

DORA / AI Act Readiness

Assess and document your AI governance posture with built-in compliance frameworks and audit trails.

✓ Documented governance framework
Pharma & Biotech

GxP Document Control with AI

AI-assisted SOP drafting and revision with full traceability, audit trails designed for GxP requirements, and human validation at every change-control step.

✓ Designed for GxP environments
Spatial

Governed Technical Documentation

AI-assisted technical documentation with source attribution and engineer sign-off — documentary cross-checks between specs and test plans, as a complement to your requirements-management tools.

✓ Human sign-off at every step
Hospitals

Administrative & Quality Documentation

AI-assisted drafting of administrative and quality documents with deterministic pseudonymization, consent tracking, and full audit trail — an architecture compatible with deployment on HDS-certified infrastructure.

✓ GDPR · HDS-compatible

Go deeper on AI governance

Evidence, obligations and a free assessment — written for regulated European teams.

See what governed AI looks like in your organisation

You don't need to imagine how it might work. We'll show you.

In a focused demo, we'll walk through how Governed AI can capture, govern, validate and retain AI activity against your own compliance and operational requirements — and show you what a controlled AI environment could look like in practice.

Une plateforme souveraine et conforme, pensée pour les exigences réglementaires européennes.

Déployable localement ou sur des clouds européens, intégrée à votre écosystème existant.

Conformité

IA Act · GDPR · Made in Luxembourg

LLM agnostique et hébergement Européen

Local (vLLM, LM Studio, Ollama) ou cloud européen (Mistral, Orange)

Intégration

Nextcloud · Collabora Online · Microsoft · Salesforce

L'IA gouvernée est le concept. InnooForge en est l'outil. Le concept, c'est le mode de fonctionnement : chaque décision IA tracée, attribuée à un approbateur nommé et conservée comme piste d'audit. L'outil, c'est la plateforme conçue par Ubiclouder au Luxembourg pour l'appliquer — déployée là où vos données sont autorisées à résider.

Request a Demo