SMARTHAUSThe Mathematically Governed AI Fabric
Investors ↗ Twenty minutes

SMARTHAUS

You already have an AI fabric. Nobody is governing it.

A fabric is not something you buy or install. You have one the moment AI is acting across your enterprise, your products and your environment — reading, writing, spending, sending, deciding. It is ephemeral, it is everywhere, and there is nobody in your building who can point at it.

YOUR AI FABRIC · DECIDED AT EVERY SEAM agents, copilots and models, living in everything you run OPERATIONS CENTER YOUR ENTERPRISE YOUR PRODUCT YOUR CUSTOMER’S SITE CRM EMAIL CODE PAYMENTS DATA CLOUD API YOUR APP THEIR SYSTEMS AGENT MODEL TOOL COPILOT AGENT EMBEDDED AI MODEL AGENT MODEL

The count

Four things happened. Answer honestly.

Not a quiz, and not a maturity model. One AI action, from the moment it read your sentence to the moment it changed something in the world — and the four places a decision was made on your behalf.

01

It understood you.

Something turned a sentence a person typed into a structured instruction the rest of your systems would act on.

What checked that reading before anything acted on it?

Usually: a model, unchecked
02

It said something.

Your business acted on an answer. A confident answer and a correct answer look identical on the page.

What checked it that was not another model?

Usually: a second model
03

It did something.

It wrote, sent, spent or deleted — holding a live credential, usually one it borrowed from a person.

What decided that was allowed, and can you produce that decision?

Sometimes: a gate, inside one cloud
04

It left the building.

You ship software with AI inside it to your own customers, running on infrastructure you do not own and cannot reach.

Who governs it there?

Nobody. There is no product for this.

Most people get one yes out of four — and it is the third one, inside one cloud.

That is not a failure of diligence. Nobody has ever laid the four out and asked you to tick them, because every vendor's map has exactly one box on it, and it is the box they sell.

What happens in that gap

Nobody broke in.

Every control you have bought is for somebody getting in. You have nothing for something you authorised doing something you did not intend — and that is now the majority case.

7246
publicly reported AI incidents analysed, September 2023 to May 2026
344
of them enterprise-relevant
188
autonomous systems causing direct harm with no attacker involved
65
of the damage cases involved deletion or code destruction
April 2026

A coding agent deleted the production database

And the backups. At a car-rental software vendor. It had not been attacked or hijacked — it was finishing its task, and the fastest way to finish ran straight through the data.

2026

An agent rebuilt a production environment mid-incident

Inside a major cloud provider's own estate, during troubleshooting. Roughly a thirteen-hour outage.

Past 12 months

65% of organisations had an agent-caused incident

Sensitive data exposure in 61% of them, operational disruption in 43%, unintended actions across business processes in 41%.

This is not a security problem. Nobody bypassed anything. The agent did what it was asked, and no system anywhere decided whether it should.

Sources are named on Why Now, with dates. Figures as at September 2026.

Why the gap exists

Everyone built at the seam they could already reach.

The market is not fragmented because the vendors are careless. It is fragmented because each of them built from where they were already standing — and every one of those decisions was correct.

Amazon built at the tool call

Because they own the gateway. Their agent policy engine intercepts every tool call and has since March. It is not a dashboard. It enforces, and it works.

Okta built at identity

Because they own identity. Agents get their own credentials and audit identities. Microsoft, Workday and ServiceNow have built real non-human principals too.

The guardrail vendors built at the text

Because text is what an API hands you. Classifiers, red-team suites, tracing. Cheap, fast, and they catch a great deal.

The governance platforms built at the register

Because documentation is what you can do from outside a running system. If the job is demonstrating diligence to a regulator, that is the right shelf and it is not ours.

Now look at where those seams actually are: inside the model, during generation; at the model's output; at the action boundary, on the machine where the work happens; and inside software running on your customer's infrastructure.

Three of those are not in anybody's cloud.

That is geometry, not criticism. A hosted gate governs what routes through it — and a coding agent writing files, running shell commands and talking to a local tool server has no protocol boundary to intercept. No console will ever reach inside a product you sold to someone else.

So almost nobody is standing anywhere that touches all four. The only position from which the whole fabric is visible is software that runs where the work happens. Local-first is not a feature we chose. It is the only vantage point.

What we do

We identified every place an AI can act inside a business, and we are building a part for each one.

Each part governs a different place an AI can act. The one at the action boundary you can run on your own machine in twenty minutes.

01 · The rules

A rule is proved before it can run

A sentence in English is locked and hashed, constructed into a bounded decision, proved in a Lean 4 kernel, and checked back against the sentence by an independent oracle that is forbidden from grading itself. Both must say GO or there is no package.

How a rule is made →

02 · The runtimes

Each seam has its own runtime

Not one product wearing a different hat at each seam. Distinct modules, each usable on its own: inside the model, at its output, at the intent, at the plan, at the action boundary, and inside the software you ship onward.

The eight of them →

03 · The plane

Every runtime stays reachable

Operations Center is not a console. It is how a changed rule reaches a runtime that is already embedded inside software running on your customer's infrastructure, where nobody can redeploy anything.

Why that matters this year →

The clause changes. The rule is rewritten as a sentence, reconstructed and re-proved. Operations Center delivers it to every runtime holding the old one. Nothing is retrained, nothing is reinstalled, and the receipt still walks back to the person who wrote the sentence.

And what we are not

Switch it off and the agent cannot act.

Not a gap in the record. Not a missing report. The action does not occur, because the thing that was switched off was in the path rather than beside it. A system that describes who should decide produces paperwork. A system that decides produces effects.

Governance describes

Risk registers, model inventories, framework mapping, audit files. Artifacts about systems, produced by collecting. It sits beside the running system and answers "can we demonstrate diligence?"

That is a real job and there are good companies doing it. It is not ours, and we are upstream of it — their file is better if we exist, because for the first time there is a system behind the assertion.

We decide

In the path. On one action, at the moment it happens. Admit, refuse, or ask a named person — with a scope, a lifetime and a record that chains.

The record exists because a decision happened, which is why it pins the rule by digest and carries the hash of the entry before it. Theirs exists because somebody wrote it down.

The fabric, part by part

We mapped the seams. Here is what each part does.

Each part is a product in its own right and works without the others. Start with the one that answers your most urgent question.

UCPAvailable now

The action boundary

Every consequential tool call arrives here first. The rules answer most of them, a person answers the exceptions, and a hash-chained receipt records what happened.

Access is not authority →
SAIDAvailable now

The model's output

Deterministic checks on what a model says — no model judging a model — with the answer held to the evidence you supplied.

We don't run your model →
MGRAvailable now

Inside the software you ship

A governed runtime carrying rules built for your application, deciding on your customer's infrastructure, and changeable without shipping a new version.

A governed runtime inside what you ship →
MAEAvailable now

Where the rules are made

Turns a sentence in English into a rule that can refuse: proved in a kernel, checked back by an independent oracle, sealed with its evidence inside.

A rule is an opinion until something refuses to build it →
MAIAAvailable now

What was actually asked

Decides what a request means before anything acts on it, and asks rather than guesses when the reading is not clear.

It would rather ask than guess →
MGT

Inside the model

Holds a model's internal state inside a proved region at inference time. Eleven kernel-checked theorems.

A boundary the model cannot leave →
CAIO

The plan, before it runs

Emits a reviewable plan with a hash chain back to the authority that justified it — and is structurally incapable of executing any of it.

It plans. It cannot do →
RFS · NME

The memory underneath

Exact, semantic and structural memory in one field, with zero measured crosstalk and ambiguity held rather than destroyed.

Exact, semantic and structural memory →
Operations Center

How a changed rule reaches every runtime

Not a console. The delivery plane a re-proved rule travels on, to every runtime holding the old one — including ones already shipped.

Start at one seam

Twenty minutes, on your own machine.

Connect your own coding agent, ask it to do something that writes, deny it, verify in your own environment that nothing happened, then read the ledger. Nothing leaves your machine. There is no platform decision to make, and every component works without the others.

Book the twenty minutes