FERZ

Runtime Authorization Infrastructure

The Enforcement
Layer of AI
Governance

FERZ determines whether an AI action is permitted before it happens, blocks execution when governance conditions are not met, and preserves evidence for review.

DOI-registered research corpusVendor-neutral published standard with public conformance suitePatent filings across the engine portfolio

The Argument

Monitoring Tells You What Happened. It Cannot Tell You What Was Allowed.

Most AI governance today is monitoring. Monitoring can tell you what a system did. It cannot decide whether the action was allowed before it happened. That decision requires evaluation before the action executes, and evidence of that decision a third party can examine. This is authorization. FERZ builds that layer.

The full argument, and the research behind it

The Three Problems

AI Governance Is Three Problems, Not One

Most governance tools tell you what a system did, or shape what it tends to do. FERZ answers a different question: is this specific action permitted, before it executes.

Visibility

Knowing what a system did

Observability, logging and monitoring. They describe behavior after it occurs.

Alignment

Shaping what a system tends to do

Training, fine-tuning and guardrails. They influence tendencies, not individual actions.

Authorization

Deciding whether a specific action is permitted

Evaluated against codified rules before execution, with the basis recorded. This is the problem FERZ is built for.

A complete governance stack needs all three. FERZ sits alongside the monitoring and alignment tooling you already run.

How It Works

Every Governed Action Follows the Same Path

No engineering background is required to follow it.

1

Proposed Action

An AI system proposes an action, decision, or output.

2

Evaluation at the Boundary

Evaluated against codified rules at the runtime authorization boundary, before execution or release.

3

Verdict

ALLOW, DENY, or ABSTAIN. ABSTAIN blocks execution unless an authorized human override is recorded.

AllowDenyAbstain
4

Authorization Artifact

The verdict and its basis are recorded as a tamper-evident, replayable artifact for examination and audit.

The FERZ Difference

Probably Compliant vs. Provably Compliant

FERZ moves AI governance from confidence estimates and post-hoc explanations to a recorded authorization basis that can be examined after the fact.

Traditional AI Governance

  • Confidence score
  • Log entry
  • Post-hoc explanation
  • Limited replayability

FERZ Governance

  • Recorded authorization basis
  • Tamper-evident authorization artifact
  • Replayable evidence
  • Independent examination

Correctness is not permission.

The Regulatory Moment

The Regulatory Baseline Is Already Set

Organizations deploying AI in regulated settings are no longer choosing whether to govern. They are choosing whether their governance produces evidence.

EU AI Act

Enforcement Active

Prohibited-practice enforcement is active, high-risk obligations are phasing in, and penalty exposure scales with global annual turnover.

FDA

PCCP Guidance Published

Change control is easier to defend when AI behavior is governed and examinable.

Financial Services

Examination Expectations

Deployments increasingly need defensible, reconstructable audit trails rather than after-the-fact explanations.

Sources: EU AI Act, FDA PCCP guidance. Specific obligations and timelines are addressed on the industry pages.

The Architecture

One Boundary. Multiple Engines.

Different engines address different classes of governed AI behavior: language, constraints, causality, behavioral adaptation, bias constraints, and distributed authority.

LASO(f)DELIACausaCoreFERZ Behavioral EngineConstitutional BlockchainBiasConstraint Engine

Industry Solutions

Governance for Your Vertical

Verify It Yourself

Everything Here Is Public, Dated, and Verifiable

FERZ argues that governance claims should be independently examinable. That standard applies to FERZ itself.

S

Stop

Can the action be halted before any side effect?

O

Ownership

Who authorized it, and is that authority recorded?

R

Replay

Can the verdict be deterministically reconstructed and re-verified?

E

Escalation

Where does control transfer when policy cannot resolve the action?

P

Provenance

Is the origin of every input established? Provenance is origin, not truth.

Normative · not yet assertable

The Five Tests Standard

A system that claims to authorize AI actions can be tested. The Five Tests Standard (5TS) is a vendor-neutral published standard defining five conformance tests. FERZ is architected around that standard.

The current public conformance bundle verifies Stop, Ownership, Replay and Escalation. Provenance is normative in 5TS v1.2.0; Provenance conformance is not yet assertable, and the specification says so. An authorization verdict establishes that an action satisfied applicable constraints given the information available at decision time. It does not establish the factual correctness of the underlying AI outputs.

FERZ proves authorization, not correctness.

Next Step

From Governance Claims to Verifiable Evidence

A pilot on a single engine and a defined workflow is the typical starting point. Tell us what you are building and we will recommend an entry point and a pilot scope.

FERZ is raising. Investor materials at ferz.ai/investors.Licensing and partnerships