AI governance

Put AI to work with clear responsibilities.

AI governance defines who may use AI for what, which foundation applies, when a person must decide and what remains traceable. NomOS brings these decisions into the central AI workspace for employees and agents.

Who defines the policies and how NomOS checks them

  1. Define policies within the organisation

    Management, legal, risk and subject-matter owners determine the approved use cases, models, data classes, policies and responsibilities.

  2. Configure policies and approvals in NomOS

    Rooms connect approved knowledge with roles, policies, exceptions and approval paths. People and agents therefore use the same applicable foundation.

  3. Connect systems to the controls

    Gateways, identities and control points determine which paths are actually checked. The declared enforcement level makes that reach visible.

For each workflow, the business policies, NomOS configuration and technical integration need to work together.

Who is responsible for each decision

Management, legal and risk
Decide: scope, risk class, approved models and accountability.
Outcome: an approved framework for AI use.
IT and security
Decide: identities, data flows, integrations and technical enforcement.
Outcome: known and governed access paths.
Governance owner in the business
Decide: valid sources, policies, exceptions, approvals and validity.
Outcome: a room in the impact graph with clear business ownership.
Teams and agents
Work: with the approved foundation and within the allowed steps.
Outcome: traceable proposals, decisions, actions and effects.

Evidence is created while the work happens.

  • Applicable foundation

    Source, version, validity and accountable owner remain attached to the case.

  • Applied policy

    It remains visible which policy allowed, escalated or blocked a step.

  • Human decision

    Approval, adjustment or rejection is recorded with its basis.

  • Action and effect

    Governed execution, correction and observed effect flow back into the impact graph.

Responsibilities that stay with your organisation

  • Legal classification and risk management

    How systems are classified and which risk is acceptable remain the organisation's responsibility.

  • Content of the policies

    NomOS checks defined policies on execution paths integrated for that purpose. Accountable people decide which policies are appropriate in business and legal terms.

  • Bypass paths

    Direct access outside the platform must be restricted through infrastructure, identities and endpoints.

  • AI literacy

    Employees need training and clear responsibility. Software can support that capability but cannot replace it.