The Missing Infrastructure
AI Governance Evidence Infrastructure — what it is, why no one is building it, and why the next decade of regulated industry depends on it.
Every regulated organisation on Earth is about to be asked the same question by their supervisor, their auditor, their insurer, and their board:
Which AI agents are operating inside our walls right now, who authorised them, and can we evidence oversight under the regulation that applies to us?
Today there is no infrastructure to answer that question. There are consulting engagements. There are security alerts. There are GRC questionnaires. There are policy registers. None of these produce what a regulator, an auditor, or an underwriter actually wants to read.
This document names the category that has to exist for AI to be safely deployed at scale inside regulated industries. We call it AI Governance Evidence Infrastructure. AETHER Pulse is the first instance of it.
1. The question every regulator is converging on
The same question is being asked, in different vocabularies, by every major financial-services regulator and AI-supervisory body on the planet:
- European Union — AI Act Article 26 deployer obligations apply from 2 August 2026. Articles 14 (human oversight), 50 (transparency), 26 (governance, monitoring, record-keeping). Penalties up to €15M or 3% of global turnover.
- United Kingdom — FCA Consumer Duty (PRIN 12) requires firms to evidence oversight of AI in customer-facing journeys. SYSC 8 outsourcing obligations attach to AI agents performing critical functions. The ICO AI Governance & Accountability Framework sets eleven control measures DPOs and senior compliance roles are already being audited against, with explicit Article 22 solely-automated-decision-making safeguards. PRA / FCA joint AI Discussion Paper hardening into supervisory practice through 2026 and 2027.
- United States — Colorado AI Act, NYC Local Law 144, NIST AI Risk Management Framework as de facto federal standard, executive-branch directives on AI oversight by federal contractors.
- Singapore — MAS Veritas framework, AI model risk guidance to financial institutions.
- Canada — OSFI Guideline E-23 on model risk, expressly including AI.
- Australia — APRA CPS 230 on operational risk including AI used by APRA-regulated entities.
- Japan — FSA AI principles for financial services.
These regimes are not converging on whether AI is good or bad. They are converging on a procedural answer: the deployer must evidence oversight. Show us your inventory. Show us your authorisation chain. Show us your controls. Show us the signed record.
This is the question every regulated organisation will be asked. Nothing in the current market answers it.
2. What the question is not
To define a new category clearly, it helps to say what it is not — because each adjacent category has a real product trying to claim this space, and none of them actually fits.
It is not AI agent security.
Security platforms protect organisations from agent attacks at runtime. They detect prompt injection, lateral movement, over-permissioning, data exfiltration. Their buyer is the CISO. Their deliverable is a real-time alert stream. Their framework is OWASP / MITRE ATLAS. These are necessary products and several are well-built. But a security alert is not regulatory evidence. The Chief Risk Officer of a bank cannot hand a SOC alert log to the FCA and answer the SYSC 8 question. The CISO and the CRO are different seats with different procurement budgets and different deliverables.
It is not compliance posture management.
GRC platforms automate compliance frameworks via questionnaires and document storage. They evidence that policies exist. They do not evidence what is observed in the running system — they have no technical agent telemetry. They produce SOC 2 letters and policy registers. They do not produce per-agent, per-environment audit artefacts for an AI Act examination.
It is not AI model governance.
Model-governance platforms operate on the AI provider side — Article 16 obligations of the AI Act. They focus on model lifecycle: training data, bias evaluation, drift monitoring, fairness metrics. The buyer is the head of AI or data science at an AI-producing company. They do not cover the deployer surface — the regulated firm using third-party AI agents inside its operations.
It is not the Big 4 consulting engagement.
Big 4 firms deliver AI governance assessments as £80K–£200K-per- year manual engagements. The output is a beautifully formatted snapshot deck. The day after delivery, an employee clicks Allow on a new AI tool and the snapshot is stale. The Big 4 cannot produce continuous evidence. They cannot sign it. They cannot scale it to the thousands of firms that need it. Their consultants are good at what they do; the engagement model is structurally incapable of being the answer.
These four adjacent categories cover legitimate problems. None of them produce the artefact the regulator is asking for.
3. The four properties of AI Governance Evidence Infrastructure
We define the new category by what it must produce. Anything claiming to be AI Governance Evidence Infrastructure must satisfy all four of the following properties:
1. Continuous.
Not an annual consulting snapshot. Not a quarterly attestation cycle. The evidence must update when an employee authorises a new AI agent at 2pm on a Tuesday. The regulator's question can be asked at any time; the answer must be current at any time.
2. Multi-platform.
AI agents enter the firm through OAuth grants across Google Workspace, Microsoft 365, OpenAI Assistants, LangSmith, Salesforce Agentforce, Microsoft Copilot Studio, AWS Bedrock, Anthropic Claude API — and tomorrow, twenty more. Inventory must stitch agent identities across all of them, because the same agent (one Outreach instance, one Calendly account) may be authorised across multiple platforms simultaneously. Single-platform inventories miss the agent identity that matters.
3. Deterministic.
Findings must be reproducible. The same data must produce the same findings on every re-run, on every reviewer's machine, every time. Probabilistic LLM-generated findings cannot be defended under regulatory examination because they cannot be re-derived from first principles. A Boolean predicate matcher that says "this agent has send-capable scope and no human-intervention gate" is defensible. An LLM that says "this agent looks risky" is not.
4. Cryptographically signed.
The output must be a tamper-evident audit artefact. Board, underwriter, supervisor, and external auditor must all be able to verify the same signature against the same canonical representation. This is how an insurance underwriter prices against the evidence, and how a regulator re-examines the artefact two years later. Without this, the evidence is just a PDF anyone could have edited.
Continuous, multi-platform, deterministic, signed. Anything missing one of these properties is not AI Governance Evidence Infrastructure — it is an adjacent product solving an adjacent problem.
4. Why this becomes infrastructure, not a feature
Infrastructure categories share three structural properties: they are network goods, they become procurement-required, and switching costs are high. AI Governance Evidence Infrastructure has all three.
Network goods.
The first regulator or insurer that cites a specific evidence format in a thematic review or underwriting standard makes that format the de facto requirement for every firm in their supervisory perimeter. This is exactly how SOC 2 became universal — AICPA published a methodology, and once the first ten F500 buyers required SOC 2 from their vendors, every vendor had to produce SOC 2 reports. AI Governance Evidence Infrastructure has the same architecture: a published methodology, a signed evidence artefact, network-good amplification.
Procurement-required.
Once a single Fortune 500 insurance underwriter requires AETHER-format evidence to bind an AI cyber policy, every firm seeking that coverage must produce that evidence. Once a single regulator cites methodology v2 in an examination, every supervised firm must produce it. Procurement-required is the strongest possible market position for B2B infrastructure.
High switching cost.
A firm that has committed to a particular evidence format — built its board reporting, its underwriting submissions, its auditor briefings, and its supervisory engagement around it — does not switch to a different format casually. The format becomes the substrate. AI Governance Evidence Infrastructure is sticky in the way that the SAP financial chart-of-accounts is sticky, or that SOC 2 is sticky.
These three properties together describe a category that is large, durable, and globally addressable. Not a feature inside someone else's product.
5. Why now
Three forces converge in 2026 to make this category necessary and timely:
The regulatory clock.
EU AI Act Article 26 deployer obligations apply from 2 August 2026. UK FCA Consumer Duty attestation cycles already ask AI-governance questions firms cannot answer. The grace period is over.
The agent population.
A typical mid-market workspace surfaces 60–100 OAuth-authorised AI agents on first scan — a population that did not exist at this density in 2023. Shadow AI is not a future problem. It is the present, and most regulated firms cannot name a single agent in their estate beyond Microsoft Copilot.
The insurance product wave.
Cyber-insurance carriers are beginning to write AI-specific endorsements and standalone AI-liability policies. These products cannot be priced without an evidence standard. The first carrier to adopt a standard makes it the market standard.
The window in which a new infrastructure category can be defined and owned is narrow. Other vendors will notice. The winner is whoever publishes the canonical methodology and produces the first signed-evidence artefact that a regulator or insurer cites.
6. What AETHER is
AETHER Pulse is the first AI Governance Evidence Infrastructure. It is a read-only, metadata-only scanner that inventories every AI agent authorised inside a regulated organisation across seven platforms — Google Workspace, Microsoft 365, OpenAI Assistants, LangSmith, Salesforce Agentforce, Microsoft Copilot Studio, AWS Bedrock — classifies each by methodology v2 (autonomy tier, action capability, intervention model, persona, control attestation) and produces a cryptographically signed evidence pack mapped to EU AI Act Article 26, UK FCA SYSC 8 and Consumer Duty, the ICO AI Governance & Accountability Framework (controls 1, 3, 5, 9 and 10), GDPR Article 22, and NIST AI RMF.
The methodology is public at aetherpulse.app/methodology. The scope is minimum-privilege. The matcher is deterministic. The evidence is signed. The platform stays out of customer content — no mailbox bodies, no file contents, no calendar event details. Metadata only.
The wedge market is UK financial services. The category is global. The ambition is Fortune 500.
UK financial services is the beachhead because the regulatory clock there is sharpest and the buyer (Chief Risk Officer, Chief Compliance Officer, Head of AI Governance, MLRO, Data Protection Officer) is most acute. The global market is every regulated industry in every jurisdiction converging on deployer-side AI evidence — banking, insurance, asset management, healthcare, government, critical infrastructure. The path to Fortune 500 runs through reference customers, channel partnerships with Big 4 advisory practices and cyber-insurance underwriters, cloud marketplace distribution, and the analyst recognition that follows.
7. The honesty discipline
This manifesto would not survive its own argument without an honesty disclosure. AETHER applies the same labelling to every claim it makes about itself:
- IMPLEMENTEDMethodology v2 classifier, seven connectors implemented end-to-end, deterministic matcher, cryptographically-signed evidence pipeline, customer-facing dashboard, agent landscape, risk graph, controls inventory.
- PARTIALMicrosoft revoke action (real Graph DELETE). Google enterprise revoke is roadmap. Methodology v2 SYSC 8 + Consumer Duty cross-mapping (extension in flight).
- UNTESTEDFive of the seven connectors (OpenAI Assistants, LangSmith, Salesforce Agentforce, Microsoft Copilot Studio, AWS Bedrock). Cross-tenant agent identity stitching at scale.
- ROADMAPML-based vendor-similarity classifier. LLM-augmented attestation reviewer (load-bearing for the FCA Supercharged Sandbox Cohort 2 application).
- NOT BUILTSOC 2 Type I and Type II, ISO 27001, ISO 42001, external penetration test, SAML/SCIM enterprise IAM, customer-managed encryption keys, cyber-insurance cover. All scheduled at first paying enterprise commitment and explicitly disclosed to prospects as such.
The honesty discipline is itself a feature. Compliance and regulatory buyers reject vendors who overclaim. They reward vendors who label honestly. This document, like the product itself, is built to survive procurement scrutiny.
8. The invitation
If you are a Chief Risk Officer, Chief Compliance Officer, Head of AI Governance, MLRO, Data Protection Officer, or Head of Operational Risk — and you have been quietly worried about the question this manifesto opens with — we want to talk to you.
If you are an insurance underwriter beginning to price AI-specific cover, and you need a published evidence standard your portfolio firms can produce — we want to talk to you.
If you are a Big 4 advisory partner whose AI risk practice will spend the next three years answering Article 26, SYSC 8, ICO AI Governance Framework, and Consumer Duty questions for hundreds of clients — we want to talk to you about partnership.
If you are an investor who has been waiting for an AI governance infrastructure category to crystallise — and you can see this is it — we want to talk to you.
AETHER Pulse · May 2026
Read the methodology: aetherpulse.app/methodology
Contact: hello@aetherpulse.app
This manifesto is freely shareable. The category it names will exist regardless of which vendor builds it first. AETHER Pulse intends to be that vendor.