Put your AI to work. Control and prove what it’s allowed to do.

Lokorium — the independent control and evidence layer for enterprise AI.
Independent authority layer for AI
— / intro

Lokorium is the go or no go layer between what an AI decides and what it is allowed to do.

And the record of it, held by the business, not the vendor.

Regulated businesses have paid for AI and cannot get it past their own security review, because nobody can prove what the AI is permitted to do. Lokorium is how they move.

LOKORIUM · the independent referee between an AI decision and its consequence

The problem
01 / 08

Two anonymised pictures. Whichever camp you are in, one of these is you.

The regulated market is splitting two ways against the same wall. One is quietly exposed. One is quietly frozen. Neither of them can prove what the AI is allowed to do.

Character 01 · The lender who moved

Live, getting value, quietly sailing close to the wind.

A regulated consumer lender has put AI right across the business. It is getting real value. In its own words, its boundaries are stated positions rather than things it can prove are enforced, and nothing inspects the data leaving. It is not looking to start. It is looking to close a gap it already knows is there.

State · Exposed

Character 02 · The programme that stalled

Budget approved, business case signed, dead in the security review.

A second regulated business has the money and the mandate. The programme dies in the security review because nobody can answer the two questions that matter: what is the AI allowed to do, and how would you know if it did something else. Value sits unrealised while a competitor moves.

State · Frozen

One is exposed. One is frozen. Both are waiting on the same missing thing.

Permit · The decision
02 / 08

Yes or no. Signed. Bounded. Before it happens.

Every time the AI tries to do something that matters, send data somewhere, run code against a system, move money, make a promise, Lokorium decides yes or no against the rules the business set, at the moment it tries to act. Not a filter after the fact.

The artifact is a permit. One signed, bounded, expiring permit describes one consequence, with eight parts. Change any of them and the permit no longer matches.

Execution permit · illustrativevalid

01 · Who

agent id · signed session

02 · Why

stated business intent

03 · What

exact action, one consequence

04 · Where

named target system

05 · Limits

amount · scope · rate

06 · When

valid from · valid until

07 · Freshness

issued at · nonce

08 · Proof

signature · rule hash

permit 0xB204…7A · sig 3F9C…D1Bound
Prevent · The enforcement
03 / 08

A decision that cannot be enforced is advice.

Without Lokorium, a gateway can say no and the target can still say yes through another route or credential. With Lokorium in place, the target only accepts requests that carry a valid permit. A different route does not create authority. The bypass reaches the target and dies there.

Honest note on altitude: enforcement is strongest at target-native deployment. Where the target is instrumented to check the permit, the refusal holds. Where it is not, we’ll tell you plainly what the enforcement rests on, per workflow.

Without LokoriumBypass reaches target
AGENTintentCLOUD GATEWAYsays noANOTHER ROUTEdifferent credentialblocked at gatewayno check at consequenceTARGETaccepts

Illustrative · scroll to follow the full path

With LokoriumBypass refused at target
AGENTintentCLOUD GATEWAYsays noANOTHER ROUTEdifferent credentialblocked at gatewayLOKORIUMcheck permit at targetno permitTARGETrefuses

Illustrative · scroll to follow the full path

Prove · The evidence
04 / 08

A record the business holds. Not each vendor’s word.

When a regulator or a board asks how you know, the answer is a record the business holds, spanning every vendor. Not the cloud’s logs. Not the model vendor’s logs. Both are interested parties.

Two artifacts. A chain of five linked records per request. And a ladder that grades the evidence honestly, because a log is not proof.

Evidence chain · illustrativefive linked records
  1. 01

    Proposal

    the intended action

  2. 02

    Policy decision

    rule matched

  3. 03

    Signed authority

    the permit

  4. 04

    Execution gate

    target check result

  5. 05

    Outcome receipt

    what actually happened

Illustrative · records signed and chained · scroll to follow the chain

Evidence ladder

A log is not proof. Not all evidence is equal.

The chain is graded. A decision log is the floor. A corroborated outcome, matched against the customer’s own system of record, is the ceiling. We do not pretend a log is proof. We aim, per workflow, for the highest rung the target and the estate allow.

  1. L4
    Corroborated outcome
    the outcome receipt matched to the customer’s own system of record or telemetry.
  2. L3
    Signed outcome receipt
    the target’s confirmation, signed and held by the business.
  3. L2
    Execution gate result
    the target either accepted the permit or refused, with reason.
  4. L1
    Policy decision
    the rule that matched, or the reason none did.
  5. L0
    Decision log
    a proposal was received. Not proof of anything on its own.

Illustrative · graded evidence, per workflow

A go or no go, illustrated
05 / 08

An action is attempted. A permit is checked at the target. It is allowed or refused. A receipt is written.

The panel below is a concept, not a live product demo. Two example sessions: a legitimate request, then a bypass that tries another route and dies at the target because it has no valid permit.

Session0xB204·idleillustrative

A legitimate request

  • 01ingestsupport conversation, signed session
  • 02readrefund request, £148.00, account 4471
  • 03intentissue refund via billing system
  • 04checkconsent on file · daily cap not reached
Allowed with permitLokorium decision. Rule set by the business: refunds under £500 are allowed on accounts with a signed customer consent on file, subject to a daily cap.

A permit is issued, bound to this action. The target accepts it and executes.

receipt 2D91…E5 · held by the businesssealed
Why it is different
06 / 08
Point 01 · Independence

Position, not guarantee

No cloud can referee its rivals.

A business uses one provider to reason, another for identity, another for the estate. None of them will ever sit in judgement over the others. A control sold by one vendor exists to sell you more of that vendor.

Lokorium has no incentive to favour any one vendor. That is the structural position we design toward. Structural, and intended. Not a stamped guarantee.

Point 02 · Boundary

Enforcement at the consequence, not at one cloud’s gateway.

Every system in the business is reached by paths that never pass through one vendor’s edge. So the thing that must refuse an action is the system it would affect. Lokorium is designed to sit at that point, across every vendor the business uses.

Point 03 · Evidence

A graded evidence chain you hold, not each vendor’s word.

When a regulator asks how you know, the answer is a chain the business holds, spanning every vendor. Not the cloud’s logs. Not the model vendor’s logs. Both are interested parties. The chain is graded, from a decision log up to an outcome corroborated against the customer’s own system of record.

Who it is for
07 / 08

Regulated businesses where the AI has to answer to something.

Not every business needs Lokorium. If your programme has no rules an auditor would ever ask about, it does not. If it does, this is for you. For each sector, the one action that would be career ending if the AI got it wrong.

Financial services
FCA scope. Client facing workflows.

Career ending

Moving customer funds or data outside a named, current authority.

Legal
Regulated advice and matter management.

Career ending

Filing or disclosing without a partner sign off, or breaching legal privilege.

Healthcare
Patient data, clinical decision support.

Career ending

Reading, writing to or acting on the wrong patient record.

Insurance
Underwriting, claims, complaints handling.

Career ending

Paying, or refusing, a claim outside underwriting authority.

Public sector
Casework, benefits, citizen services.

Career ending

Issuing a case decision without the delegated authority to make it.

Where it is going
08 / 08

Data. Agents. The physical world.

The permit layer follows an arc. Today it lives in enterprise data and action paths. As agents take on more, it moves with them. As robots arrive, it moves again. One layer, three eras.

Today

Data and actions

Lokorium governs what AI is allowed to do with sensitive data and actions inside regulated businesses.

Next

Autonomous agents

The same permit layer extends to agents acting across systems on the business’s behalf.

Later

The physical world

Embodied AI. Robots acting in the real world. The question is identical: is this allowed to happen, before it happens.

A plain exampleIllustrative
Allowed

Bring an adult a glass of water.

Permit matches. Target accepts.

Refused

Bring a child a glass of alcohol.

No matching permit. Target refuses.

Software today, or a robot arm tomorrow. The question is the same in every era: is this allowed to happen, before it happens.

A horizon, not today’s product. Today Lokorium works on the first of the three.

Get in touch
— / close

Request a briefing.

Tell us where you are stuck, or where you have gone live and cannot yet prove what the AI is allowed to do. We will come back with what a briefing would cover for your workflow, and what we would need from you to make it useful.

Direct email: enquiries@lokorium.io