Invisible usage
Nobody knows exactly which team uses which model with which data. You cannot run a risk assessment on a surface you have never inventoried.
Make enterprise AI usage visible, tier it by risk and produce an audit record for every decision. Your employees already use Claude, Copilot, n8n and OpenAI; AIZEC makes that usage governable without banning it.
Enterprise SSO (OIDC) · Mandatory TOTP MFA · Row-level tenant isolation
AI tools do not enter your organisation through procurement. They enter through a browser tab. Banning them does not stop usage; it only makes it invisible.
Nobody knows exactly which team uses which model with which data. You cannot run a risk assessment on a surface you have never inventoried.
Customer records, price lists and technical documents get pasted into third-party models with no contract in place. By the time a breach surfaces, there is no evidence to reconstruct.
The same automation is rebuilt separately in four business units. There is neither reuse nor institutional memory of what actually worked.
When a regulator or internal audit asks "who made this decision, and on what basis?", you end up reconstructing evidence from email threads.
Governance is not about imposing rules. When the approved path becomes the easiest path, shadow AI declines on its own.
The EU AI Act applies in phases, and it does not only cover companies established in the EU. It can reach providers whose output is used there. The duty to produce evidence begins the day you start using a system, not the day you finish building it.
Regulation (EU) 2024/1689 formally entered into force, starting the phased application timeline.
Unacceptable-risk practices (social scoring, manipulative techniques and others) became prohibited; the AI literacy obligation began.
Obligations for general-purpose AI models and the national authority / penalty regime started to apply.
Most of the Regulation becomes applicable, including high-risk systems listed under Annex III.
The transition period ends for high-risk AI systems covered by Annex I product safety legislation.
Six modules feed each other: every tool visible in the inventory reaches triage, every triage lands on a risk tier, every tier applies a control set, and every decision is written to an immutable audit record.
Surface real AI usage through employee self-service and gateway telemetry.
A working queue with a one-page intake form, a defined SLA and automatic reminders.
Every use-case lands on one of three autonomy tiers and inherits the matching control set.
Collect traffic and policy-violation events from the gateway owned by your security team.
Every decision (classification, approval, revocation, role change) is recorded with actor and rationale.
Coverage, time-to-decision, gateway ratio and business impact metrics on a real-time dashboard.
The modules are interlocked rather than standalone: a tool that is not in the inventory cannot enter triage, and a use-case that has not been triaged is not counted as approved traffic at the gateway.
Debating every request from scratch is the most expensive part of governance. Three tiers settle what a team must do while the form is still open.
If the agent has read-only access, the output concerns only the requester, and no internal data is touched, nothing stands in the way.
If the agent touches internal data or the output reaches another person, CoE review and a DLP check apply.
If the agent writes to a production system or produces decisions about customers or employees, testing, audit trail, a kill switch and legal approval are mandatory.
Tier criteria are configurable per tenant. Automating red-tier decisions over time draws on both the sector benchmarks published by firms such as Gartner and McKinsey and the business impact data accumulating in the platform.
A central AI Center of Excellence sets the standard; a designated spoke representative applies it inside each business unit. AIZEC turns that model from an org chart into a working system.
AIZEC is not an abstract framework but a workflow with defined SLAs and recording duties. The following are platform defaults.
Outcome metrics such as inventory coverage, time-to-decision and gateway traffic are specific to your tenant and reported on your own dashboard.
Everyone looks at the same data, but only sees what they need to. A spoke representative cannot query another unit's inventory, and an employee cannot read past their own records.
As the owner of enterprise AI policy, run the full inventory, queue and decision log from one place.
Oversee gateway traffic, policy violations and red-tier agents from a single console.
Stop collecting regulatory evidence at the end of a project; accumulate it as decisions are made.
See where AI investment creates value and where risk is accumulating, in a monthly report.
See your team's real AI usage, steer it to approved alternatives and increase reuse.
The records AIZEC produces feed the evidence needs of four different frameworks at once. Record once, use in every audit.
A data model built to support risk classification, technical documentation, record-keeping and human oversight obligations.
Policy, role, risk assessment and continual improvement records for the first AI management system (AIMS) standard.
Each of the Govern, Map, Measure and Manage functions maps to a concrete module in the platform.
Flagging of use-cases involving personal data, sensitivity records, and input into DPIA processes.
Teams preparing for ISO 42001 certification, personal data processes under KVKK and GDPR, and EU AI Act files all draw on the same record set. AIZEC is not a legal advisory service; it provides the evidence and process infrastructure that supports your compliance decisions.
No. The core assumption of the product is that prohibition does not stop usage; it only makes it invisible. AIZEC leaves low-risk usage free, records it, and asks for approval only where risk actually increases.
The platform is tool-agnostic. Claude, Copilot, OpenAI, n8n or in-house models all enter the same inventory. Traffic control comes from logs collected from the gateway/proxy layer owned by your security team.
Yes. Each tenant can configure its own OIDC provider (for example Microsoft Entra ID). Alternatively, local password login with mandatory TOTP MFA is supported.
No. Every tenant is an Organization, and every row in a tenant table carries an organisation identifier. Isolation is enforced at the application layer and continuously verified by automated tests.
A standard deployment starts with tenant creation, SSO connection and business unit/role definitions. The inventory campaign and the first triage cycle are usually addressed within the first 90-day rollout plan.
The platform is container-based and can run inside your enterprise environment. The deployment model is assessed together with your data residency requirements.
Book a 30-minute session to discuss your team's real AI usage, your open risk exposure and a 90-day rollout plan.
For pre-sales technical questions you can talk directly to the engineering team.