Trace, validate and govern every AI decision. Full interaction traceability, human validation and audit trails by architecture.
InnooForge is the enterprise AI governance platform for organisations that cannot afford to lose control — including regulated organisations in Europe. Every AI interaction is traced, validated by a named human and recorded as an audit trail — so your teams can meet EU AI Act, DORA and GDPR obligations, keep enterprise AI on-premise or in European cloud, and demonstrate EU data sovereignty when regulators ask.
Bring one real process — a compliance review, a risk assessment or a contract analysis — and we will show you the traceability, the human validation step and the audit trail it produces.
Regulatory statements on this page are based on the official sources below. Dates and obligations should always be verified against the current text and European Commission guidance.
Consider a Luxembourg fund administrator preparing a quarterly investor compliance review.
Without governance. An analyst pastes fund clauses into a public chatbot to summarise obligations, then copies the result into the review. There is no record of the model used, which documents were submitted, or whether a second person checked the conclusion. If the regulator asks how the assessment was reached three months later, the trail has to be reconstructed — often it cannot be.
With Governed AI. Sources are scoped to the fund's document repository. The permitted model is fixed by policy. The output carries source attribution to specific documents. The compliance officer approves, modifies or rejects the conclusion. The audit trail stores the prompt, the sources, the model version and the approver.
When the question arrives. The evidence exists as a by-product of the work: who asked, what the AI produced, which documents it relied on, and who signed it off. That is the practical difference between using AI and governing it.
To quantify the operational value of that difference, use the AI governance ROI calculator.
AI governance is the set of policies, roles, processes and technical controls that determine how an organisation selects, deploys, monitors and evidences its use of artificial intelligence. In practice it covers accountability, risk tiering, human oversight, logging, documentation and audit. For regulated organisations, AI governance is what makes an AI-assisted decision defensible to a supervisor, an auditor or a court.
AI is already used in processes regulators examine — compliance reviews, risk assessment, contract analysis and quality documentation. Without traceability and human oversight, organisations cannot explain how an output was produced or who approved it. The EU AI Act, DORA and GDPR all assume that evidence exists; governance produces it by design rather than reconstructing it after an incident.
For high-risk AI systems, the Act requires a risk management system, technical documentation, record-keeping and logging, transparency and instructions for use, human oversight, and appropriate accuracy, robustness and cybersecurity. Deployers must use systems correctly, assign oversight to competent people, monitor operation, keep logs and inform affected persons where required. The exact obligations depend on your role and the system's classification — see the EU AI Act compliance guide.
The platform is licensed per organisation rather than per seat, and cost depends on the deployment model (managed EU cloud, private cloud or on-premise) and on the scope of the programme. We publish no rate card: after a scoping call we confirm scope and cost in a written proposal, and most organisations start with a bounded proof of concept. Contact us to discuss your case.
Yes. The platform can be deployed on-premise with Docker, in a private cloud, or as managed SaaS hosted in Luxembourg. On-premise and air-gapped deployments keep prompts, documents, decision logs and audit trails inside your own infrastructure, which matters when data residency or information classification rules prevent the use of public cloud AI services.
The platform is licensed per organisation rather than per seat. Cost depends on the deployment model you choose and on the scope of the programme, and is confirmed in a written proposal after a scoping call — we publish no rate card.
To discuss scope and a proposal, contact us. If you need an independent assessment of your starting position, we can run an AI governance audit as a separate engagement.
The platform implements a six-step governance loop around every AI interaction.
The loop is what makes the difference between an AI assistant and governed AI: the record is created as a by-product of the work, not as a separate administrative task. To see the wider product context, read the InnooForge product overview.
Governance is only credible if the platform itself respects your data rules. The platform is deployed where your information is permitted to live.
| Deployment model | Best suited to | Data residency |
|---|---|---|
| On-premise (Docker) | Organisations with strict residency or classification rules; air-gapped environments | Inside your own infrastructure |
| Private cloud | Teams that need elasticity while retaining control of the tenant | Your European cloud tenant |
| Managed SaaS | Fastest start, with managed installation and onboarding | Hosted in Luxembourg |
The architecture is LLM-agnostic: you connect the models you are permitted to use, including self-hosted open-weight models. On-premise and air-gapped deployments keep prompts, documents, decision logs and audit trails inside your perimeter. Full detail is on the sovereignty and deployment page.
A practical sequence for introducing AI governance without stalling delivery. Steps 1 to 3 can run in parallel with a pilot.
If you need help with step 1 or 2, we can run an AI governance audit as a separate fixed-scope engagement.
Regulatory expectations, industry best practice and product capability are not the same thing. The table below separates them, so you can see exactly what the platform does — and what remains a decision for your organisation.
| Obligation or control | Type | What good evidence looks like | InnooForge |
|---|---|---|---|
| Risk management system — AI Act Art. 9 | Regulatory | A documented, per-system risk file that is reviewed and updated | Governance templates and structured classification records |
| Record-keeping and logging — AI Act Art. 12 | Regulatory | Automatically generated logs of system operation, retained and retrievable | Interaction and decision logs captured at source |
| Transparency and instructions for use — AI Act Art. 13 | Regulatory | Users understand capability, limits and outputs | Source attribution and provenance shown with each output |
| Human oversight — AI Act Art. 14 | Regulatory | Competent persons can monitor, interpret and intervene | Named-approver workflow with approve, reject or modify |
| ICT risk management — DORA Art. 6 & 8 | Regulatory | Documented ICT risk framework and evidence for critical functions | Deployment documentation and exportable audit records |
| Data minimisation — GDPR Art. 5 | Regulatory | Only necessary data is processed, with a defined lawful basis | Scoped source access; documents are not used to train third-party models |
| Records of processing — GDPR Art. 30 | Regulatory | An accurate record of processing activities | Exportable interaction metadata for the record of processing |
| Automated decision-making — GDPR Art. 22 | Regulatory | Meaningful human intervention and the ability to explain an outcome | Human validation gate plus a reproducible decision trail |
| Segregation of duties | Best practice | The person proposing an output is not the sole approver | Role-based approval routing |
| Prompt and instruction governance | Recommendation | Prompts are versioned, reviewed and attributable | Instruction system with version history |
| Retention and retrieval | Capability | A defined retention period with fast retrieval on request | Configurable retention and searchable audit trail |
The platform provides the mechanism and the record. Determining the correct legal basis, classification and retention period remains your organisation's responsibility — our AI compliance checklist helps you work through those decisions.
The table below sets out the capabilities an enterprise AI governance platform should provide, and how the platform delivers each one.
| Capability | Why it matters | How the platform delivers it |
|---|---|---|
| Full interaction traceability | You must be able to explain how an output was produced, not merely that it was produced. | Every interaction records the prompt, the sources used, the model and the output, linked to the requesting user and the decision it supported. |
| Human validation | Accountability cannot rest on an unnamed system. AI Act human-oversight expectations and internal control frameworks both require a competent, identifiable reviewer. | Consequential outputs require explicit approval, rejection or modification by a named human before they are applied. |
| Audit trail and logging | Records must be complete, retained and retrievable, and must survive staff turnover. | Decision logs with timestamps, reviewers and document integrity checks, exportable for internal or external audit. |
| Source attribution | An unsourced answer cannot be relied upon in a regulated process. | Outputs are linked back to the documents they draw on, so a reviewer can verify the basis of a conclusion. |
| Risk tiering and documentation | Obligations differ by risk level; you need a documented classification per system. | Structured governance templates guide classification, documentation and review, so the file exists before it is requested. |
| Agent and tool control | Agents that call tools can act on enterprise systems, where errors have real consequences. | The governance layer constrains which tools and data an AI workflow may reach, and records each action taken. |
| Sovereign deployment | Data residency and information classification rules often prohibit public cloud AI. | On-premise (Docker), private cloud or Luxembourg-hosted SaaS, with an LLM-agnostic architecture. See sovereign AI deployment options. |
An AI governance platform is software that sits between your people, the AI models they use and your enterprise systems. It enforces who may use which model, which sources may be used, which outputs require human approval, and what evidence is retained. It turns AI from an unlogged convenience into an auditable, defensible process.
A governance layer that records every AI interaction (prompt, sources, model version, output), requires named human validation before consequential use, and produces an audit trail that can be examined by internal audit, an external auditor or a supervisory authority.
Most organisations already have AI. What they usually lack is the ability to answer, months later, four questions a regulator will ask: Which model produced this output? Which documents was it based on? Who approved it? What has changed since?
An AI assistant answers a query. A model generates text. A GRC spreadsheet records that a policy exists. None of them capture the interaction itself. An AI governance platform captures the interaction — and makes it reproducible.
For a comparison of the categories, see the AI governance FAQ, which contrasts governed AI with general-purpose assistants.
Three pressures converge on European regulated organisations at the same time.
There is also an asset dimension: in a governed architecture, validated interactions and the institutional knowledge around them remain inside the organisation rather than being dispersed across external tools and personal accounts.
AI Act · DORA · GDPR — compliance by architecture, not retrofit. Designed for regulated environments (GxP, space, healthcare).
Complete audit trail for every AI interaction — who, what, when, and which sources.
Every output linked to its source documents. Know exactly where conclusions come from.
Named approvers for every decision. Audit-ready sign-off at every critical step.
Data minimization, tracked consent, right to erasure, DPO dashboard — built-in, not bolted on.
On-premise or European cloud. Your data never leaves your jurisdiction.
Governance layer designed for high-risk AI compliance. August 2026 deadline covered.
Immutable audit trails, electronic signatures, and document integrity hashes — designed to support requirements such as FDA 21 CFR Part 11 (system validation remains on the customer side).
Cross-reference specs against test plans to support your ISO 13485 and ECSS quality work — as a complement to your requirements-management tools (DOORS, Polarion), not a replacement.
Deterministic pseudonymization, consent tracking, and EU hosting for healthcare data — an architecture compatible with deployment on HDS-certified infrastructure.
Why regulated industries need governed AI, not black boxes
| Feature | ChatGPT / Copilot | InnooForge |
|---|---|---|
| Data sovereignty | ❌ US cloud (Microsoft/OpenAI) | ✅ EU cloud or on-premise |
| Audit trail | ❌ Black box, no logs | ✅ Full traceability |
| Human validation | ❌ Optional / bolt-on | ✅ Required by design |
| Source attribution | ❌ Hallucination risk | ✅ Document-level citation |
| DORA compliance | ❌ Not for regulated industries | ✅ Built-in governance layer |
| AI Act readiness | ❌ Responsibility on you | ✅ Shared compliance architecture |
| Data residency | ❌ US only | ✅ EU, Luxembourg, or on-premise |
| GDPR by design | ❌ Not built-in | ✅ Minimization, consent, DPO dashboard |
| Self-improvement | ❌ Manual prompts | ✅ Prompt Auto-Improvement |
| Institutional IP retention | ❌ Your data trains their models | ✅ Your knowledge stays yours |
Generic AI can be configured for compliance. The platform is compliance by architecture.
What our users say about governed AI
"InnooForge gave us complete audit trails for our AI-assisted compliance reviews. Our CSSF auditors were satisfied with the traceability and documentation."— CFO, Fund Administration Company, Luxembourg
"Finally, an AI solution that understands DORA requirements and keeps our data in Europe. The human-in-the-loop validation is exactly what we needed."— CTO, Asset Management Firm
"We went from 'the algorithm made me do it' to full explainability. Every AI decision now has a clear source and a named validator."— Compliance Officer, ManCo
How regulated industries use governed AI — finance, pharma, biotech, spatial, healthcare
Generate compliance reports with full source attribution and human validation before submission to regulators.
✓ Full audit trail for CSSFAnalyze contracts and legal documents with traceable citations and lawyer sign-off at each step.
✓ Client-ready documentationSupport provision calculations with documented methodology, source data, and explicit validation workflow.
✓ Defensible decision supportAssess and document your AI governance posture with built-in compliance frameworks and audit trails.
✓ Documented governance frameworkAI-assisted SOP drafting and revision with full traceability, audit trails designed for GxP requirements, and human validation at every change-control step.
✓ Designed for GxP environmentsAI-assisted technical documentation with source attribution and engineer sign-off — documentary cross-checks between specs and test plans, as a complement to your requirements-management tools.
✓ Human sign-off at every stepAI-assisted drafting of administrative and quality documents with deterministic pseudonymization, consent tracking, and full audit trail — an architecture compatible with deployment on HDS-certified infrastructure.
✓ GDPR · HDS-compatibleEvidence, obligations and a free assessment — written for regulated European teams.
You don't need to imagine how it might work. We'll show you.
In a focused demo, we'll walk through how Governed AI can capture, govern, validate and retain AI activity against your own compliance and operational requirements — and show you what a controlled AI environment could look like in practice.
Déployable localement ou sur des clouds européens, intégrée à votre écosystème existant.
IA Act · GDPR · Made in Luxembourg
Local (vLLM, LM Studio, Ollama) ou cloud européen (Mistral, Orange)
L'IA gouvernée est le concept. InnooForge en est l'outil. Le concept, c'est le mode de fonctionnement : chaque décision IA tracée, attribuée à un approbateur nommé et conservée comme piste d'audit. L'outil, c'est la plateforme conçue par Ubiclouder au Luxembourg pour l'appliquer — déployée là où vos données sont autorisées à résider.