ORCA Opti
Back to Insights

Insights

You can control AI and get the productivity wins: putting governance and security around the AI your business uses

You cannot control whether frontier AI is dangerous. You can control what it reaches, and prove it: the layers that govern and secure business AI.

Kathryn GiudesFounder & Managing Director, ORCA Opti22 September 20268 min read
A lone hooded figure stands on a walkway before a towering faceted cage of glowing teal geometric panels, a brilliant contained sun of energy held at its centre, inside a dark cavernous facility

The people who build frontier AI spent 2026 restricting their own most capable models, and some of their own researchers resigned rather than keep going. If that unsettles you, it should. But if you run a business, notice what kind of worry it is. Whether the model itself is dangerous is not a lever you hold. It never was.

The lever you do hold. You decide what that AI runs on, what it can see, what it is allowed to do, and whether you can prove any of it. That is the part of AI risk you can control, and it is the part almost nobody talks about, because it doesn't sell headlines.

What you can actually control about AI risk

You cannot govern the model. You can govern what you put around it. In practice that is five layers between a large AI model and your business:

  • Where the AI runs,
  • what goes into it and comes out of it,
  • what actions it is allowed to take,
  • how the AI itself is governed, and
  • whether you can prove the controls hold.

Get those five right and it doesn't matter how clever or how dangerous the underlying model becomes. You set the boundaries and you can see the evidence.

That is what ORCA Opti does. Not one feature, five layers, each one a thing you can turn on, see, and show. The layers explained:

Layer 1: where the AI runs

Opti Assist, our governed AI assistant, runs with your own Microsoft 365 or Google Workspace tenant security. The prompts your team types are never sent to, retained by, or used to train the frontier providers such as OpenAI, Anthropic or Google. For everyday work you can run ORCA's own Australian-built, Australian-hosted service, so the conversation stays onshore and inside your environment.

Residency is not the same as sovereignty. Residency is where the data physically sits. Sovereignty is whose laws can reach it. A US-incorporated provider can be compelled under the US CLOUD Act to produce data held in an Australian region, so "hosted in Australia" on its own does not settle the question. ORCA Opti is Australian-incorporated, which is the part residency alone cannot give you.

Safe Zone, the badge at the top of Opti Assist, tells you which of five levels your current session qualifies for. It always shows the weakest part of what is happening right now, not the best feature you happen to own. If chat content is leaving your environment, the badge says so, plainly, rather than reassuring you while your data walks out the door.

Layer 2: what goes in, and what comes out

AI Guardian inspects every prompt before it reaches a model, and every response before it reaches a person. On the way in it blocks prompt injection, jailbreaks and attempts to extract secrets. On the way out it catches leaked credentials, personal data, your IP, and confirms answers are grounded in approved knowledge rather than invented.

Its coverage is mapped to two independent industry leading external frameworks: the OWASP Top 10 for Large Language Model Applications and MITRE ATLAS. Instead of a silent leak, AI Guardian marks it and calls out the concern, rather than implying it's covered. That honesty is deliberate. A control that quietly overstates itself is worse than no control, because you trust it.

Layer 3: what the AI is allowed to do

The dangerous part of modern AI is not that it answers questions. It is that it can act: send an email, call an API, move data between systems. AI Guardian inspects an action before an agent runs it, and can either block it or hold it for a person to approve. Grants are least privilege by default, and anything risky, such as sending data to an outside recipient, waits for a human.

This is the layer the recent sandbox-escape incidents were really about: a model that could reach further than anyone intended. The answer to that is not a cleverer model. It is a narrow boundary and a person in the loop for the actions that matter.

Layer 4: how the AI itself is governed

Every AI system your organisation uses gets registered, classified by risk, given an owner and a review date, and assessed for impact before it goes live. This is what the ISO/IEC 42001 standard for AI management asks for, and ORCA keeps the inventory, the impact assessments and the risk assessments in one place, aligned to the standard rather than described as compliant with it.

This is the layer that turns "we use AI responsibly" from a sentence in a policy, to enforced, and a director can see.

Layer 5: whether you can prove it holds

Opti Cyber runs automated checks against your Microsoft or Google Directory configuration. Controls are mapped to ISO 27001 technical controls (ISM Essential 8 or NIST SP 800, rev 2 or 3), so one check can evidence all frameworks. Crucially, it separates what a scan has monitored from what a human has assessed to audit grade, and shows both numbers even when the assessed one is lower.

That gap is the honest one. It is exactly what the Australian Signals Directorate means when it asks boards for assurance rather than a green tick. A scan is not an attestation.

Opti Core holds the rest: the policies, procedures, controls, risks, incidents and obligations, and the board reporting that turns all of it into something you can put in front of a director or a customer's security team.

How this compares with the other options

To be straight with you: we build one of the things on this list, so read the comparison with that in mind. If you are weighing up how to put governance and security around your AI, you have four honest options besides us. None of them is useless. The question is where each one stops.

  • The model's own guardrails. They protect the provider and its model. They are gated or changed at the provider's discretion, not yours to configure, and they produce no evidence you can hand to an auditor. Useful, but not a business control.
  • A GRC or evidence platform. Strong at proving compliance and collecting evidence about work that happens elsewhere. It does not run the AI or gate it at runtime. This is where a lot of Australian buyers already sit, usually on Vanta, and it is genuinely good at what it does. The distinction that matters is simple: Vanta proves you are compliant; ORCA both proves you're compliant and does the work to keep you compliant.
  • A standalone AI guardrail or gateway. They may do "layer two" well and sometimes "layer three", but it is not connected to your governance or your evidence. What it blocks never becomes proof, and your auditor never sees it.
  • A cyber posture scanner. Tells you your configuration state, which is the monitoring half of "layer five". But a scan is not an attestation, and it says nothing about what your AI can reach.

Multiple systems create multiple seams. Each product will do one or two layers well. Buy them separately and the layers do not talk to each other, creating seams and that is where the risk is. You end up with protection you cannot prove and proof that does not reflect what is actually protected.

LayerModel's own guardrailsGRC / evidence platformStandalone AI guardrailPosture scannerORCA Opti
1. Where the AI runsProvider decidesNot its jobNot its jobNot its jobYour tenant, onshore
2. What goes in and outProvider decidesNot its jobYesNot its jobYes
3. What the AI can doPartlyNot its jobSometimesNot its jobYes, with human approval
4. How the AI is governedNoPartlyNoNoAligned to ISO 42001
5. Prove it holdsNoYesNoPartlyYes, monitored and assessed

The part that does not come as separate parts

What multiple tools won't give you. ORCA does the work and produces evidence as the same activity. A finding links to the control it tests, to the policy behind it, to the owner and the review date, to the incident if it ever fires. The record is not gathered up afterwards, it stays current to the work.

You cannot buy that as a bundle, because it is not a bundle. Four tools that each do one layer will hand you four dashboards and no true-up. One system hands you the answer, which is the only thing a board or a customer needs: show me it's fixed and show me it continues to work.

See the layers working

On Thursday 15 October at 12pm AEDT I am spending an hour showing exactly this, in a real environment. Where the organisation stands. A control that reads implemented and ineffective on the same row. What an AI agent can and cannot reach, and what it has to ask a person before it does. No slides after the first few minutes, and half the session is for your questions.

Register for the session on 15 October

Related reading: Best AI governance platforms for Australian businesses and a straight ORCA Opti and Vanta comparison.

Have a question? Let's talk.

Get in touch with the ORCA Opti team to see how governed, sovereign AI fits your organisation.

Únase a nuestra lista de correo

Noticias y novedades de ORCA Opti.