Insights
You can control AI and get the productivity wins: putting governance and security around the AI your business uses
You cannot control whether frontier AI is dangerous. You can control what it reaches, and prove it: the layers that govern and secure business AI.

The people who build frontier AI spent 2026 restricting their own most capable models, and some of their own researchers resigned rather than keep going. If that unsettles you, it should. But if you run a business, notice what kind of worry it is. Whether the model itself is dangerous is not a lever you hold. It never was.
The lever you do hold. You decide what that AI runs on, what it can see, what it is allowed to do, and whether you can prove any of it. That is the part of AI risk you can control, and it is the part almost nobody talks about, because it doesn't sell headlines.
What you can actually control about AI risk
You cannot govern the model. You can govern what you put around it. In practice that is five layers between a large AI model and your business:
- Where the AI runs,
- what goes into it and comes out of it,
- what actions it is allowed to take,
- how the AI itself is governed, and
- whether you can prove the controls hold.
Get those five right and it doesn't matter how clever or how dangerous the underlying model becomes. You set the boundaries and you can see the evidence.
That is what ORCA Opti does. Not one feature, five layers, each one a thing you can turn on, see, and show. The layers explained:
Layer 1: where the AI runs
Opti Assist, our governed AI assistant, runs with your own Microsoft 365 or Google Workspace tenant security. The prompts your team types are never sent to, retained by, or used to train the frontier providers such as OpenAI, Anthropic or Google. For everyday work you can run ORCA's own Australian-built, Australian-hosted service, so the conversation stays onshore and inside your environment.
Residency is not the same as sovereignty. Residency is where the data physically sits. Sovereignty is whose laws can reach it. A US-incorporated provider can be compelled under the US CLOUD Act to produce data held in an Australian region, so "hosted in Australia" on its own does not settle the question. ORCA Opti is Australian-incorporated, which is the part residency alone cannot give you.
Safe Zone, the badge at the top of Opti Assist, tells you which of five levels your current session qualifies for. It always shows the weakest part of what is happening right now, not the best feature you happen to own. If chat content is leaving your environment, the badge says so, plainly, rather than reassuring you while your data walks out the door.
Layer 2: what goes in, and what comes out
AI Guardian inspects every prompt before it reaches a model, and every response before it reaches a person. On the way in it blocks prompt injection, jailbreaks and attempts to extract secrets. On the way out it catches leaked credentials, personal data, your IP, and confirms answers are grounded in approved knowledge rather than invented.
Its coverage is mapped to two independent industry leading external frameworks: the OWASP Top 10 for Large Language Model Applications and MITRE ATLAS. Instead of a silent leak, AI Guardian marks it and calls out the concern, rather than implying it's covered. That honesty is deliberate. A control that quietly overstates itself is worse than no control, because you trust it.
Layer 3: what the AI is allowed to do
The dangerous part of modern AI is not that it answers questions. It is that it can act: send an email, call an API, move data between systems. AI Guardian inspects an action before an agent runs it, and can either block it or hold it for a person to approve. Grants are least privilege by default, and anything risky, such as sending data to an outside recipient, waits for a human.
This is the layer the recent sandbox-escape incidents were really about: a model that could reach further than anyone intended. The answer to that is not a cleverer model. It is a narrow boundary and a person in the loop for the actions that matter.
Layer 4: how the AI itself is governed
Every AI system your organisation uses gets registered, classified by risk, given an owner and a review date, and assessed for impact before it goes live. This is what the ISO/IEC 42001 standard for AI management asks for, and ORCA keeps the inventory, the impact assessments and the risk assessments in one place, aligned to the standard rather than described as compliant with it.
This is the layer that turns "we use AI responsibly" from a sentence in a policy, to enforced, and a director can see.
Layer 5: whether you can prove it holds
Opti Cyber runs automated checks against your Microsoft or Google Directory configuration. Controls are mapped to ISO 27001 technical controls (ISM Essential 8 or NIST SP 800, rev 2 or 3), so one check can evidence all frameworks. Crucially, it separates what a scan has monitored from what a human has assessed to audit grade, and shows both numbers even when the assessed one is lower.
That gap is the honest one. It is exactly what the Australian Signals Directorate means when it asks boards for assurance rather than a green tick. A scan is not an attestation.
Opti Core holds the rest: the policies, procedures, controls, risks, incidents and obligations, and the board reporting that turns all of it into something you can put in front of a director or a customer's security team.
How this compares with the other options
To be straight with you: we build one of the things on this list, so read the comparison with that in mind. If you are weighing up how to put governance and security around your AI, you have four honest options besides us. None of them is useless. The question is where each one stops.
- The model's own guardrails. They protect the provider and its model. They are gated or changed at the provider's discretion, not yours to configure, and they produce no evidence you can hand to an auditor. Useful, but not a business control.
- A GRC or evidence platform. Strong at proving compliance and collecting evidence about work that happens elsewhere. It does not run the AI or gate it at runtime. This is where a lot of Australian buyers already sit, usually on Vanta, and it is genuinely good at what it does. The distinction that matters is simple: Vanta proves you are compliant; ORCA both proves you're compliant and does the work to keep you compliant.
- A standalone AI guardrail or gateway. They may do "layer two" well and sometimes "layer three", but it is not connected to your governance or your evidence. What it blocks never becomes proof, and your auditor never sees it.
- A cyber posture scanner. Tells you your configuration state, which is the monitoring half of "layer five". But a scan is not an attestation, and it says nothing about what your AI can reach.
Multiple systems create multiple seams. Each product will do one or two layers well. Buy them separately and the layers do not talk to each other, creating seams and that is where the risk is. You end up with protection you cannot prove and proof that does not reflect what is actually protected.
| Layer | Model's own guardrails | GRC / evidence platform | Standalone AI guardrail | Posture scanner | ORCA Opti |
|---|---|---|---|---|---|
| 1. Where the AI runs | Provider decides | Not its job | Not its job | Not its job | Your tenant, onshore |
| 2. What goes in and out | Provider decides | Not its job | Yes | Not its job | Yes |
| 3. What the AI can do | Partly | Not its job | Sometimes | Not its job | Yes, with human approval |
| 4. How the AI is governed | No | Partly | No | No | Aligned to ISO 42001 |
| 5. Prove it holds | No | Yes | No | Partly | Yes, monitored and assessed |
The part that does not come as separate parts
What multiple tools won't give you. ORCA does the work and produces evidence as the same activity. A finding links to the control it tests, to the policy behind it, to the owner and the review date, to the incident if it ever fires. The record is not gathered up afterwards, it stays current to the work.
You cannot buy that as a bundle, because it is not a bundle. Four tools that each do one layer will hand you four dashboards and no true-up. One system hands you the answer, which is the only thing a board or a customer needs: show me it's fixed and show me it continues to work.
See the layers working
On Thursday 15 October at 12pm AEDT I am spending an hour showing exactly this, in a real environment. Where the organisation stands. A control that reads implemented and ineffective on the same row. What an AI agent can and cannot reach, and what it has to ask a person before it does. No slides after the first few minutes, and half the session is for your questions.
Register for the session on 15 October
Related reading: Best AI governance platforms for Australian businesses and a straight ORCA Opti and Vanta comparison.