How we think about controlling AI.
The frameworks, the threat analysis, and the opinions behind the product.
The guides
- The enterprise review questions. What an enterprise asks before an AI agent touches its systems, with what each answer has to satisfy and a concrete answer.
- The AI Control Maturity Model. Five levels, and why most of the market is stuck at level three.
- The Decision System Map. A vendor-neutral, seven-layer reference for any automated decision system — design yours against it, or check the one you already run.
- Prompt Injection: The Complete Defense Guide. The threat surface, eleven defense layers across four phases, an eight-step policy flow, and the honest limits of detection.
- The new PMI AI standard, chapter by chapter. What it asks you to build.
- Pet, Cattle, or Crew. Three agent architectures. The shape changes; the safety layer does not.
- Agent layer vs control layer. Why the rules a bank follows for model risk split into two layers, and which one Swiftward is.
Standards and regulation
What each one asks you to build, which parts a control layer covers, and which parts stay yours.
All standards · OWASP Agent Control Standard · EU AI Act · NIST AI RMF · ERC-8004 · PMI AI standard
Where we sit against the tools you already run is its own section: Compare.
Where does your stack sit? Book a demo.