The perimeter moved. The controls did not.
Applications and agents call model providers directly, from wherever they were built. The controls you run were designed for traffic crossing a boundary you own, and this traffic does not cross one. The first deliverable is not a policy. It is the list of what is reaching a model today.
A single-tenant dedicated instance, in your own AWS or Azure account or in infrastructure iTmethods operates. Both available today; Google Cloud is planned for 2027. Air-gapped and sovereign are in development.
A policy that lives in a document is an intention.
The question is not whether a model policy exists. It is whether a disallowed route fails at the boundary or merely gets written up afterwards — and whether you could produce the list of routes at all.
IBM and Ponemon’s Cost of a Data Breach Report 2026, published 29 July 2026 from 602 breached organizations, found shadow AI incidents more than doubled to 43% and that 92% of organizations with AI-related breaches lacked proper AI access controls.
NIST SP 800-218A, the SSDF community profile for generative AI, states it directly under PS.1.1: follow the principle of least privilege to minimize direct access to AI models and model elements regardless of where they are stored or executed.
Agent identity is the open problem in this space: OWASP’s Top 10 for Agentic Applications 2026 lists Identity and Privilege Abuse at ASI03, and NIST’s NCCoE work on AI agent identity and authorization is still at concept-paper stage.
SP 800-218A asks for exactly that under RV.1.1: log, monitor and analyze all inputs and outputs for AI models to detect possible security and performance issues. If nothing was logged at the boundary, the reconstruction starts at the application layer and stops there.
Shadow AI, policy, identity, and the record.
The four things AI infrastructure has to deliver before a security function can answer for it, and what each one looks like when it sits in the path rather than in a standard.
Shadow AI
One endpoint in front of the model traffic means the inventory is a by-product rather than a survey. What is reaching a model, from where, and under whose identity is a query rather than a project.
Policy
Identity, budget and guard rails checked at the point the call is made. A call that is not permitted is refused, and the refusal is recorded with the rule that refused it.
Identity and the substrate
Agent runtimes, the MCP and tool layer, and the control plane underneath — identity, network boundary, secret store and the log pipeline — operated as one substrate rather than four separate gaps.
Response
A record per call carrying who called, what policy decided, which model answered and when. Hash-linked as it is written, and exported write-once into storage you hold under your own retention.
Mapped to the control that produces the evidence.
Each row of a security framework is a real question. The useful mapping is not to a policy document but to the thing in the path that answers it.
Reign produces operating evidence against these. What it means for your control environment is a control-design determination, reached by the people who own that environment and defensible to your assessors, and we work alongside you on it in scoping rather than asserting the conclusion on a page.
What we do not claim, including about the frameworks.
Three of the frameworks above are governance standards rather than control catalogues, and saying otherwise would not survive a first conversation with your assessor.
It is a risk-and-governance profile organised around twelve risk categories. The access and logging obligations cited on this page come from SP 800-218A, which is a different document with a different purpose.
NIST states that AI RMF 1.0 is being revised as part of the White House AI Action Plan. We cite it as an organising frame, not as a settled baseline.
NIST’s NCCoE concept paper on software and AI agent identity and authorization was published in February 2026 and is a draft. The nearest actionable guidance is OWASP’s ASI03. Anyone selling you compliance with an agent identity standard is selling you something that does not exist yet.
When a model does not answer, the call is recorded as failed. It does not fall back to a model your policy has not permitted, because it does not fall back at all.
The shadow AI figures on this page are IBM and Ponemon’s, from 602 breached organizations surveyed between March 2025 and February 2026. They are not our measurements and we do not present them as such.
The questions that arrive before the scoping call.
What is the first thing we would actually get?
Does this replace our existing controls?
What happens when a call is refused?
Where does the boundary itself run?
The same estate, three other questions.
Whoever else is in the room is reading a different page about the same infrastructure. These are theirs.
Bring us one traffic path you cannot see.
We will look at what pointing it at a boundary would take in your estate, what you would be able to show that you cannot show today, and how far back a reconstruction would reach.