Compliance is architecture.
AI governance at Pexon is built rather than documented. We route AI traffic through one gateway, intercept personal data and secrets before they leave, log prompts and outputs to an audit standard, and where the law requires it run open-weight models entirely inside your own data centre.
Governance decided late is governance that fails.
A system that shows everyone everything cannot go to production, and no amount of documentation fixes it afterwards. The entitlement model and the audit trail are part of the first sprint.
Governance capabilities
- EU AI Act Readiness — Classification, Logs, Eval EvidenceRisk classification under Article 6 and Annex III, event logging that meets Articles 12 and 19, and evaluation evidence produced on every release.
- Shadow AI Lockdown — One Gateway, Full Audit TrailUnauthorised AI endpoints found across corporate proxies, replaced by one internal gateway with PII interception and audit-grade logging.
- Sovereign Private AI — Open Weights in Your Own Data CentreOpen-weight models and vector search running on your hardware, with GPU sizing, quantisation and local access control bound to your directory.
Common questions
Is a policy document not enough for the EU AI Act?
Not for a system in production. The obligations that bite are technical: knowing which data went into which output, being able to show it, and being able to stop a class of use. Those are build decisions.
Our public cloud use is restricted. Is that a blocker?
No. Where the data classification or the law requires it we deploy open-weight models on your own hardware, with retrieval and access control bound to your existing directory.
Not a sales call. An architecture call.
Thirty minutes with the architect who would actually run the engagement.