Trust
Standards, sourcing, and the things we will not do.
A company selling accountability has to be legible about its own. These are the commitments we expect to be held to.
The commitments we expect to be held to
Fig. TRU-09
Data
T1
No training on customer execution data
Ever, under any tier.
T2
Residency honored in path
Enforced by the Data Control Gateway.
Evidence
T3
Customer-held ledger
Evidence is exportable and readable without us.
T4
Sourced claims
Public figures cite the page they came from.

Provider neutrality
We sell no model and resell no capacity. Orcher can refuse any provider, including the ones we integrate most deeply.
Evidence over telemetry
Every claim we make about an execution is backed by a hashed record, not a log line that can be rotated away.
Sourced numbers
Public figures carry a citation and a date. Internal analysis is labelled as internal analysis, not independently verified.
Customer data is not training data
Directive content, systems-of-record data, and execution paths belong to the enterprise. We do not train on them.
Landscape
The regimes we build against.
Standards for agentic accountability are still forming. We build to the strictest reading available and update as they settle.
OWASP Agentic Top 10 (2026)
Including ASI03 Identity & Privilege Abuse — the failure the Role Identity Fabric exists to close. Read alongside AISVS and the MCP Top 10, which already tracks 30+ CVEs.
MITRE ATLAS
Sixteen adversary tactics and eighty-four techniques against AI systems, used to red-team the execution path rather than the model alone.
NIST AI RMF & Agent Standards Initiative
The February 2026 initiative on agent standards, plus the RMF's oversight expectations that HITL in practice fails to satisfy.
EU AI Act & Omnibus
Article 14 human oversight obligations, and the Omnibus amendments that shifted timing without shifting the burden of proof.
CISA / Five Eyes
May 2026 joint guidance and the July 2026 DHS-CISA follow-on on securing agentic deployments.
China AI Agent Law
Effective 15 July 2026, with three-tier decision authorization — the first regime to legislate the authority question directly.
Illinois SB 315
Third-party audit requirements from 6 July 2026; part of roughly 100 measures across 38 US states.
Singapore MAGF
Model AI Governance Framework guidance applied to agentic systems operating across jurisdictions.
FDA 2026 CDS guidance
Clinical decision support expectations where a named clinician, not a system, must remain accountable.

Governance velocity
Six days, not eleven weeks.
When a new requirement lands, the question is how long it takes to prove you meet it. Orcher deployments map a new regulatory requirement onto existing controls in about six days, against an industry baseline measured in weeks.
6 days
to map a new requirement onto existing controls
11 weeks
typical baseline without a control plane
6
compliance regimes commonly in scope at once
8–12%
of AI budget now spent on governance (from 3–5%)
Dipp AI Research: internal analysis, not independently verified.
Regulatory clock
What changed in 2026
12 Jul 2026
Nadella's intelligence-exhaust essay
Control, Capability, Choice, Cost, Compound — a platform CEO naming the control layer as the contested one.
13 Jul 2026
"We Must Act Now"
200+ economists and 16 Nobel laureates call for enforceable accountability on autonomous systems.
15 Jul 2026
China AI Agent Law in force
Three-tier decision authorization becomes a legal requirement, not a design preference.
17 Aug 2026
Case File: "The Switch"
A default training-policy change reaching roughly 300,000 organizations, with retention of up to seven years.

Ask us the hard questions early.
Security review, data-flow diagrams, and residency posture are part of the first briefing, not the last.
