Skip to main content
    Why ReignFor CISOs

    The perimeter moved. The controls did not.

    Applications and agents call model providers directly, from wherever they were built. The controls you run were designed for traffic crossing a boundary you own, and this traffic does not cross one. The first deliverable is not a policy. It is the list of what is reaching a model today.

    A single-tenant dedicated instance, in your own AWS or Azure account or in infrastructure iTmethods operates. Both available today; Google Cloud is planned for 2027. Air-gapped and sovereign are in development.

    Where the traffic goes every call
    Today With the boundary Sanctioned tools Everything else Agents providers No identity on the call no record, and no list of which applications are reaching what Tools Agents Your clients Gateway out Identity on every call refusals recorded with the rule that refused them NIST SP 800-218A PS.1.1 · least privilege to AI models RV.1.1 · log, monitor and analyze all inputs and outputs
    You cannot govern calls you cannot see. The first deliverable is the list of what is reaching a model today, and by what route.
    The decision you are actually making

    A policy that lives in a document is an intention.

    The question is not whether a model policy exists. It is whether a disallowed route fails at the boundary or merely gets written up afterwards — and whether you could produce the list of routes at all.

    01You cannot govern calls you cannot see
    The first question is which applications and agents are reaching models today, and by what route.

    IBM and Ponemon’s Cost of a Data Breach Report 2026, published 29 July 2026 from 602 breached organizations, found shadow AI incidents more than doubled to 43% and that 92% of organizations with AI-related breaches lacked proper AI access controls.

    02A policy in the path is a control
    Guard rails, budgets and identity applied at the point the call is made, rather than asserted in a standard and audited later.

    NIST SP 800-218A, the SSDF community profile for generative AI, states it directly under PS.1.1: follow the principle of least privilege to minimize direct access to AI models and model elements regardless of where they are stored or executed.

    03Every call carries an identity, or revocation is a fiction
    A key that works only on the routes you allow is a key you can turn off. One that works everywhere is one you can only rotate and hope.

    Agent identity is the open problem in this space: OWASP’s Top 10 for Agentic Applications 2026 lists Identity and Privilege Abuse at ASI03, and NIST’s NCCoE work on AI agent identity and authorization is still at concept-paper stage.

    04Response is a record question before it is an investigation
    When something goes wrong the question is what was authorized, by whom, and what came back.

    SP 800-218A asks for exactly that under RV.1.1: log, monitor and analyze all inputs and outputs for AI models to detect possible security and performance issues. If nothing was logged at the boundary, the reconstruction starts at the application layer and stops there.

    Four components

    Shadow AI, policy, identity, and the record.

    The four things AI infrastructure has to deliver before a security function can answer for it, and what each one looks like when it sits in the path rather than in a standard.

    See it

    Shadow AI

    One endpoint in front of the model traffic means the inventory is a by-product rather than a survey. What is reaching a model, from where, and under whose identity is a query rather than a project.

    The question under it. Could you produce that list this week?
    Available today Reign Gateway →
    Enforce it

    Policy

    Identity, budget and guard rails checked at the point the call is made. A call that is not permitted is refused, and the refusal is recorded with the rule that refused it.

    The question under it. Where is your model policy enforced today?
    Run it

    Identity and the substrate

    Agent runtimes, the MCP and tool layer, and the control plane underneath — identity, network boundary, secret store and the log pipeline — operated as one substrate rather than four separate gaps.

    The question under it. What happens today when you revoke?
    Available today The AI substrate →
    Prove it

    Response

    A record per call carrying who called, what policy decided, which model answered and when. Hash-linked as it is written, and exported write-once into storage you hold under your own retention.

    The question under it. How far back could you reconstruct?
    Available today Monitoring and records →
    Frameworks

    Mapped to the control that produces the evidence.

    Each row of a security framework is a real question. The useful mapping is not to a policy document but to the thing in the path that answers it.

    NIST SP 800-218ASSDF community profile for generative AI. Final, 26 July 2024. PS.1.1, PO.5.3, RV.1.1, PW.4.4. ISO/IEC 27001:2022Annex A. A.5.15–A.5.18 access and identity, A.8.15 logging, A.8.16 monitoring. ISO/IEC 42001:2023AI management system. Published December 2023, with a conformity assessment scheme. NIST AI RMF 1.0AI 100-1, and the Generative AI Profile at AI 600-1. Governance outcomes, not technical controls. SOC 2 TSCCC6 access, CC7 operations, CC9.2 vendor risk. No AI-specific criteria have been issued.

    Reign produces operating evidence against these. What it means for your control environment is a control-design determination, reached by the people who own that environment and defensible to your assessors, and we work alongside you on it in scoping rather than asserting the conclusion on a page.

    The edge of it

    What we do not claim, including about the frameworks.

    Three of the frameworks above are governance standards rather than control catalogues, and saying otherwise would not survive a first conversation with your assessor.

    NIST AI 600-1 does not require access controls or logging.

    It is a risk-and-governance profile organised around twelve risk categories. The access and logging obligations cited on this page come from SP 800-218A, which is a different document with a different purpose.

    AI RMF 1.0 is under revision.

    NIST states that AI RMF 1.0 is being revised as part of the White House AI Action Plan. We cite it as an organising frame, not as a settled baseline.

    There is no finalised standard for AI agent identity.

    NIST’s NCCoE concept paper on software and AI agent identity and authorization was published in February 2026 and is a draft. The nearest actionable guidance is OWASP’s ASI03. Anyone selling you compliance with an agent identity standard is selling you something that does not exist yet.

    Automatic failover across permitted models is not built.

    When a model does not answer, the call is recorded as failed. It does not fall back to a model your policy has not permitted, because it does not fall back at all.

    The shadow AI figures on this page are IBM and Ponemon’s, from 602 breached organizations surveyed between March 2025 and February 2026. They are not our measurements and we do not present them as such.

    Before the scoping call

    The questions that arrive before the scoping call.

    What is the first thing we would actually get?
    The list. One endpoint in front of the model traffic makes the inventory a by-product: which applications and agents are reaching which models, from where, under whose identity. Most security functions cannot produce that today, and it is the question every subsequent one depends on.
    Does this replace our existing controls?
    No. It gives the ones you have a place to apply. Your identity provider stays where it is; the boundary checks identity, budget and guard rails at the point the call is made and records the decision. ISO/IEC 27001 A.5.15 to A.5.18 and A.8.15 to A.8.16 are the Annex A controls it is applying, not replacing.
    What happens when a call is refused?
    It is refused at the boundary and the refusal is recorded with the rule that refused it. A call that gets no answer from a model is recorded as failed — it does not fall back to something else, because automatic failover is not built. Failure mode and change control →
    Where does the boundary itself run?
    A single-tenant dedicated instance inside your authorization boundary — your own AWS or Azure account, or infrastructure iTmethods operates. Both available today; Google Cloud planned for 2027. Air-gapped and sovereign are in development. Deployment options →
    AWS Advanced Tier Services Partner SOC 2 Type II on Reign Ops
    AWS Advanced Tier Services Partner and Validated Managed Service Provider. Twenty-one years operating critical infrastructure for regulated enterprises.
    Next step

    Bring us one traffic path you cannot see.

    We will look at what pointing it at a boundary would take in your estate, what you would be able to show that you cannot show today, and how far back a reconstruction would reach.