Trust

Standards, sourcing, and the things we will not do.

A company selling accountability has to be legible about its own. These are the commitments we expect to be held to.

The commitments we expect to be held to

Fig. TRU-09

Data

T1

No training on customer execution data

Ever, under any tier.

T2

Residency honored in path

Enforced by the Data Control Gateway.

Evidence

T3

Customer-held ledger

Evidence is exportable and readable without us.

T4

Sourced claims

Public figures cite the page they came from.

A company selling accountability has to be legible about its own
A security lattice intercepting streaming data paths
Every commitment on this page is enforced as a control, not a promise.

Provider neutrality

We sell no model and resell no capacity. Orcher can refuse any provider, including the ones we integrate most deeply.

Evidence over telemetry

Every claim we make about an execution is backed by a hashed record, not a log line that can be rotated away.

Sourced numbers

Public figures carry a citation and a date. Internal analysis is labelled as internal analysis, not independently verified.

Customer data is not training data

Directive content, systems-of-record data, and execution paths belong to the enterprise. We do not train on them.

Landscape

The regimes we build against.

Standards for agentic accountability are still forming. We build to the strictest reading available and update as they settle.

OWASP Agentic Top 10 (2026)

Including ASI03 Identity & Privilege Abuse — the failure the Role Identity Fabric exists to close. Read alongside AISVS and the MCP Top 10, which already tracks 30+ CVEs.

MITRE ATLAS

Sixteen adversary tactics and eighty-four techniques against AI systems, used to red-team the execution path rather than the model alone.

NIST AI RMF & Agent Standards Initiative

The February 2026 initiative on agent standards, plus the RMF's oversight expectations that HITL in practice fails to satisfy.

EU AI Act & Omnibus

Article 14 human oversight obligations, and the Omnibus amendments that shifted timing without shifting the burden of proof.

CISA / Five Eyes

May 2026 joint guidance and the July 2026 DHS-CISA follow-on on securing agentic deployments.

China AI Agent Law

Effective 15 July 2026, with three-tier decision authorization — the first regime to legislate the authority question directly.

Illinois SB 315

Third-party audit requirements from 6 July 2026; part of roughly 100 measures across 38 US states.

Singapore MAGF

Model AI Governance Framework guidance applied to agentic systems operating across jurisdictions.

FDA 2026 CDS guidance

Clinical decision support expectations where a named clinician, not a system, must remain accountable.

Standards landscape
Vol. I · p.29Standards landscape

Governance velocity

Six days, not eleven weeks.

When a new requirement lands, the question is how long it takes to prove you meet it. Orcher deployments map a new regulatory requirement onto existing controls in about six days, against an industry baseline measured in weeks.

6 days

to map a new requirement onto existing controls

11 weeks

typical baseline without a control plane

6

compliance regimes commonly in scope at once

8–12%

of AI budget now spent on governance (from 3–5%)

Dipp AI Research: internal analysis, not independently verified.

Regulatory clock

What changed in 2026

12 Jul 2026

Nadella's intelligence-exhaust essay

Control, Capability, Choice, Cost, Compound — a platform CEO naming the control layer as the contested one.

13 Jul 2026

"We Must Act Now"

200+ economists and 16 Nobel laureates call for enforceable accountability on autonomous systems.

15 Jul 2026

China AI Agent Law in force

Three-tier decision authorization becomes a legal requirement, not a design preference.

17 Aug 2026

Case File: "The Switch"

A default training-policy change reaching roughly 300,000 organizations, with retention of up to seven years.

Two open letters and one regulation: the July 2026 policy window
Vol. I · p.10Two open letters and one regulation: the July 2026 policy window

Ask us the hard questions early.

Security review, data-flow diagrams, and residency posture are part of the first briefing, not the last.