Runtime Authorization Infrastructure
The Enforcement
Layer of AI
Governance
FERZ determines whether an AI action is permitted before it happens, blocks execution when governance conditions are not met, and preserves evidence for review.
DOI-registered research corpus·Vendor-neutral published standard with public conformance suite·Patent filings across the engine portfolio
The Argument
Monitoring Tells You What Happened. It Cannot Tell You What Was Allowed.
Most AI governance today is monitoring. Monitoring can tell you what a system did. It cannot decide whether the action was allowed before it happened. That decision requires evaluation before the action executes, and evidence of that decision a third party can examine. This is authorization. FERZ builds that layer.
The full argument, and the research behind itThe Three Problems
AI Governance Is Three Problems, Not One
Most governance tools tell you what a system did, or shape what it tends to do. FERZ answers a different question: is this specific action permitted, before it executes.
Visibility
Knowing what a system did
Observability, logging and monitoring. They describe behavior after it occurs.
Alignment
Shaping what a system tends to do
Training, fine-tuning and guardrails. They influence tendencies, not individual actions.
Authorization
Deciding whether a specific action is permitted
Evaluated against codified rules before execution, with the basis recorded. This is the problem FERZ is built for.
A complete governance stack needs all three. FERZ sits alongside the monitoring and alignment tooling you already run.
How It Works
Every Governed Action Follows the Same Path
No engineering background is required to follow it.
Proposed Action
An AI system proposes an action, decision, or output.
Evaluation at the Boundary
Evaluated against codified rules at the runtime authorization boundary, before execution or release.
Verdict
ALLOW, DENY, or ABSTAIN. ABSTAIN blocks execution unless an authorized human override is recorded.
Authorization Artifact
The verdict and its basis are recorded as a tamper-evident, replayable artifact for examination and audit.
The FERZ Difference
Probably Compliant vs. Provably Compliant
FERZ moves AI governance from confidence estimates and post-hoc explanations to a recorded authorization basis that can be examined after the fact.
Traditional AI Governance
- Confidence score
- Log entry
- Post-hoc explanation
- Limited replayability
FERZ Governance
- Recorded authorization basis
- Tamper-evident authorization artifact
- Replayable evidence
- Independent examination
Correctness is not permission.
The Regulatory Moment
The Regulatory Baseline Is Already Set
Organizations deploying AI in regulated settings are no longer choosing whether to govern. They are choosing whether their governance produces evidence.
EU AI Act
Enforcement Active
Prohibited-practice enforcement is active, high-risk obligations are phasing in, and penalty exposure scales with global annual turnover.
FDA
PCCP Guidance Published
Change control is easier to defend when AI behavior is governed and examinable.
Financial Services
Examination Expectations
Deployments increasingly need defensible, reconstructable audit trails rather than after-the-fact explanations.
Sources: EU AI Act, FDA PCCP guidance. Specific obligations and timelines are addressed on the industry pages.
The Architecture
One Boundary. Multiple Engines.
Different engines address different classes of governed AI behavior: language, constraints, causality, behavioral adaptation, bias constraints, and distributed authority.
Industry Solutions
Governance for Your Vertical
Verify It Yourself
Everything Here Is Public, Dated, and Verifiable
FERZ argues that governance claims should be independently examinable. That standard applies to FERZ itself.
Stop
Can the action be halted before any side effect?
Ownership
Who authorized it, and is that authority recorded?
Replay
Can the verdict be deterministically reconstructed and re-verified?
Escalation
Where does control transfer when policy cannot resolve the action?
Provenance
Is the origin of every input established? Provenance is origin, not truth.
Normative · not yet assertable
The Five Tests Standard
A system that claims to authorize AI actions can be tested. The Five Tests Standard (5TS) is a vendor-neutral published standard defining five conformance tests. FERZ is architected around that standard.
Conformance Suite
Run the tests
Public test vectors and a verifier. The conformance suite runs without access to any FERZ system.
Open the repositoryResearch Corpus
Read the papers
The foundational corpus is published with DOIs on Zenodo. The core doctrinal claims on this site trace to dated, citable sources.
Browse the corpusPublished Standard
Examine the standard
The Five Tests Standard is vendor-neutral and independently adoptable. Its DOI record is the canonical citation.
View the 5TS recordThe current public conformance bundle verifies Stop, Ownership, Replay and Escalation. Provenance is normative in 5TS v1.2.0; Provenance conformance is not yet assertable, and the specification says so. An authorization verdict establishes that an action satisfied applicable constraints given the information available at decision time. It does not establish the factual correctness of the underlying AI outputs.
FERZ proves authorization, not correctness.
Next Step
From Governance Claims to Verifiable Evidence
A pilot on a single engine and a defined workflow is the typical starting point. Tell us what you are building and we will recommend an entry point and a pilot scope.
FERZ is raising. Investor materials at ferz.ai/investors.·Licensing and partnerships







