Home / Governed AI
Governed AI

Governed AI: what it means, and how to check it.

An AI agent is governed when every consequential action passes four checks. This page explains each one in plain English. Then it shows you how to verify our work yourself.

The four guarantees

Routine work runs on its own. These four checks apply to the actions that matter: money, access, data and changes to systems.

01

A policy gate before the action

A deterministic gate reads the proposed action and decides: allow, escalate or deny. The rules are code you can read, not a prompt a model can talk its way around.

02

A rollback path after it

Every change keeps a way back. Decisions and records are superseded with a pointer to what replaced them, never overwritten.

03

A record a reviewer can check

Each decision goes on an append-only ledger. Every entry carries the hash of the one before it, so editing any entry breaks the chain at that point.

04

A person who approves

Unusual actions wait for a person. Risky ones are blocked before anything moves. The person's decision goes on the ledger too.

The independent checker

No work counts as done on the worker's own word. A separate checker gates every material step. It runs the test, reads the file or probes the system itself, then records what it found.

A claim without that evidence does not count. The same rule applies to people and to agents.

Owned compute

Agents run on hardware you control, with local inference. Disconnected operation is a supported deployment profile. Sensitive data never leaves the environment.

Cost stays predictable, because there is no per-token cloud bill that grows with every agent.

The evidence ledger, in public

Our internal ledger stays private, but a slice of it is public. White paper v2.3 is bound to ledger entries 3399 to 3428 by a dated addendum.

The public spend governor keeps its ledger the same way: each entry carries the hash of the one before it. Its demo edits one recorded entry on a copy and shows the verifier catching the edit:

# runs offline; exits 0 on pass and prints the index where the chain breaks
git clone https://github.com/cerebrocybersolutions/cortex-governor
cd cortex-governor
python3 demo_scenario.py

White paper v2.3

The architecture behind everything on this page, released 4 October 2026. Every file is hash-stamped, so you can confirm that what you downloaded is what we published.

Cerebro: Operator-Owned AI Infrastructure as a Governance Discipline
Version 2.3 · 4 October 2026 · CC BY-ND 4.0

To check the files, clone the repository and run two commands:

git clone https://github.com/cerebrocybersolutions/cerebro-whitepaper
cd cerebro-whitepaper
shasum -a 256 -c SHA256SUMS
python3 verify_hash_stamp.py VERIFICATION.md

A clean run prints hash stamp clean. An edited or swapped file exits 1 and names the file.

The paper is licensed CC BY-ND 4.0. The checker script is Apache 2.0.

See it run

Questions

What is governed AI?

An AI system where every consequential action passes four checks. A policy gate before it runs. A rollback path after it. A tamper-evident record a reviewer can check. A person who approves anything unusual.

Can governed AI run without an internet connection?

Yes. Local inference on hardware you control is the default, and disconnected operation is a supported deployment profile.

How do I check your claims?

Clone the white paper repository and run its two checks, then run the tamper demo in cortex-governor. None of it needs an account or a call with us.

Who builds this?

Cerebro Cyber Solutions, a service-disabled veteran-owned small business. We run our own company on the same platform, as customer zero.