Private AI governance
AI may perform work.
Authority remains demonstrable.
UNIT2 designs every private AI process layer around data control, explicit authority, human gates and complete traceability. Not as a policy document after the fact, but as an active control layer in every task.
Agent Passports
Every digital process role receives an auditable mandate.
An Agent Passport shows employees, auditors and management the agent identity, approved models and sources, blocked actions and the person who remains accountable.
Pricing & proposal agent
Human owner: Commercial director
Allowed
Calculate cost priceTest marginCreate proposal draftBlocked
Send a price externallyChange payment detailsSet margin below limitControl in the architecture
Six mechanisms that make private autonomy governable.
No absolute safety claims. Concrete technical and organisational controls are designed, tested, logged and reviewed periodically for each process layer.
Minimum access
Agents receive only the data, models and tools demonstrably required for their role.
Human gates
External, financial and high-impact actions wait for the named owner.
Visible uncertainty
Low confidence, missing sources and conflicts are marked and escalated.
Complete audit trail
Input, model version, actor, decision, correction and approval remain traceable.
Stop & rollback
Workflows can be paused immediately, escalated and returned to a controlled fallback.
Independent verification
A separate control layer tests quality and authority before output has consequences.
European context
Sovereignty, auditability and control are business selection criteria.
Europe is driving AI adoption and sovereign, resilient infrastructure. Since 2 August 2026, most AI Act provisions apply and enforcement has started, while some obligations have later timelines. Local deployment, logging, human oversight and controlled data access are therefore not technical side issues, but conditions for durable adoption.
European AI strategyEU AI Act overview
Discuss your governance boundarySystem and process descriptionPurpose, context, participants, models and prohibited use.
Data and deployment modelSources, location, retention, roles and data flows.
Testing and oversight evidenceQuality, robustness, human gates and acceptance criteria.
Operational recordVersions, sources, corrections, incidents and material decisions.
Scale responsibly
Start with one process layer whose boundaries you can draw.
Our intake maps potential value together with knowledge sources, data sensitivity, deployment, decision impact, human control and implementation risk.