Frequently asked questions
What Arcus is, how active governance works, and how we help regulated industries put AI in front of an examiner.
Arcus is the intelligence layer for auditable, active AI governance. Instead of monitoring a model after the fact, Arcus structures every decision into a reasoning trace that is the computation — named, typed, verified, and scored steps you can inspect. It is built for industries where an AI’s answer is only as good as the reasoning behind it.
Passive governance records the reasoning a model reports about itself and files it — but a self-reported story is not guaranteed faithful to the computation that produced the answer. Active governance produces the reasoning trace as the decision is made, so the trace is the decision, not a report about it. That is what makes a determination defensible — the reasoning behind it is there to inspect, not asserted after the fact.
Regulated industries — financial services, insurance, healthcare, legal — anywhere an AI decision carries regulatory or fiduciary weight and has to be explained, audited, or defended to an examiner.
GRC platforms inventory which AI exists and whether it is approved; explainability tools validate a model’s self-reported behavior. Both work from a trace they have to take as given. Arcus focuses on producing that underlying trace — a verifiable reasoning record the other layers can file. We complement those platforms — together forming a complete, holistic governance stack.
The live beachhead is Reg E dispute adjudication for fintech — a complete fraud-dispute determination with cited evidence, drafted end-to-end in about a minute on an open-weight model, with every step auditable and a human attestation surface in the record. Insurance coverage governance and Model Risk Management (SR 26-2) are MVPs, and we are onboarding design partners for both.
Yes — the system drafts the determination; it does not discharge your oversight obligations. Every dossier includes an attestation surface where a designated reviewer signs the determination before it takes effect, and the reasoning trace exists precisely so that review is meaningful rather than a rubber stamp: the reviewer sees what was checked, what was uncertain, and why the conclusion followed — not just the conclusion. Where the reviewer sits in the workflow (per-decision, sampled by risk tier, or exception-based) is an institutional policy choice we configure with you; frameworks like EU AI Act Article 14 and consumer-protection rules such as Reg E’s error-resolution provisions are exactly why the attestation surface is built into the record rather than bolted on.
Iterative Reasoning Graphs break an AI decision into typed, traceable steps — generation, retrieval, verification, evaluation, synthesis — run through gates until a defined standard is met. Drafts are discarded; the reasoning behind them is kept. The result is a complete, inspectable trace for every decision. The Reasoning Library documents how the graphs are designed.
The Epistemic Integrity Engine scores every reasoning output across four dimensions — factual accuracy, logical coherence, source fidelity, and claim support. It gives regulators, auditors, and insurers a continuous integrity metric rather than a binary pass or fail — a score designed to be validated like any model output, with its dimensions and evidence exposed for effective challenge.
Reason is the language IRG graphs are authored in. It lets domain experts define how the AI reasons — the nodes, the gates, the iteration — as text, without graph-theory knowledge. Because strategy, tactics, and implementation are separate levels, the shape of the reasoning can change without rewriting every prompt.
Yes — IRG sits above the model layer and works with any provider, so you can switch or combine models without rebuilding your compliance infrastructure. That said, the architecture is designed to shine on right-sized open models you can run yourself, which is what makes the governance affordable and sovereign.
A governed graph makes more model calls than a single prompt — that is the cost of producing a defensible trace. The bet is that the quality and auditability are worth it, and right-sized open models keep the per-call cost low: a full Reg E determination runs in about a minute. We treat the quality-per-cost tradeoff as something to measure, not assert — the circuit-complexity note lays out how.
No. IRG runs on premises, on high-end commodity hardware — no hyperscale rent, no cluster required, and nothing that can be switched off from outside your perimeter. You can’t fully audit a model you don’t control; ownership is what makes the audit real.
Because it targets right-sized open models rather than frontier overkill, it runs on high-end commodity hardware rather than a data-center cluster. Exact sizing depends on the workload — schedule a call to scope yours.
Yes. Because it runs on your own hardware with open models, it can be deployed fully air-gapped, with no data leaving your environment. For regulated data, that sovereignty is much of the point — you keep the model, the reasoning, and the records inside your perimeter.
The EU AI Act (Articles 9–15), U.S. model-risk guidance (SR 26-2, which supersedes SR 11-7 — both supported), the Colorado AI Act, and cross-jurisdictional frameworks. Every jurisdiction asks for the same things — risk documentation, reasoning transparency, audit trails, quality management — and IRG produces them from one underlying trace.
IRG produces the technical documentation, automatic event recording, risk-management artifacts, and human-oversight trails Articles 9–15 require for high-risk systems. The reasoning trace itself is the documentation, not a separate report generated afterward.
SR 26-2 is the Fed/OCC model-risk guidance rewritten for AI in 2026. Arcus produces the three things it asks for — validation evidence, effective challenge (an adversary node that actively challenges the reasoning), and ongoing monitoring — from the same trace, under either SR 26-2 or the earlier SR 11-7. Our MRM suite is an MVP; we are onboarding design partners.
Yes. Verifiable IRG traces feed into platforms like OneTrust, ServiceNow, and IBM OpenPages. IRG adds the active-governance layer that complements those stacks — supplying the trace they inventory, validate, and file.
Every IRG determination can ship as a Regulator Dossier — an examiner-ready record of a single AI decision, generated with the decision itself. It carries provenance (artifacts pinned by SHA-256), a hash-linked integrity seal, the reasoning trace as a formal step-by-step proof, citation provenance, the statutory compliance timeline, standards mapping, and a human attestation page. You can request a sample dossier from a live Reg E case.
Every model call in a run is recorded in a hash-linked log: each entry chains the hashes of its prompt and response into the previous entry’s hash. Editing anything breaks the chain from that point on, so tampering is detectable by recomputing the chain from genesis — and the check is provider-independent.
The dossier pins the exact model, prompts, graph, and rule corpus by SHA-256, so an examiner with the repository can re-hash each artifact and verify byte-equality. Byte-identical replay of the model output also depends on a stable model snapshot — one more reason self-hosting the model matters — and we flag that limit explicitly in every dossier rather than overstating it.
Schedule a 30-minute introductory conversation. We’ll discuss your governance challenges and walk through a live reasoning trace so you can see exactly how IRG works with your use case.
Yes. Request the sample Regulator Dossier to see exactly what an examiner receives, and read the Reasoning Library and blog to see how the reasoning graphs are designed and measured.
We are onboarding design partners in insurance coverage governance and Model Risk Management now, and in early conversations on Reg E disputes for credit unions and community banks. Reach out and tell us where the regulated decision lives in your workflow.
Timelines vary by use case and integration complexity. Schedule a conversation to discuss your specific requirements and we’ll provide a tailored estimate.