← Insights

·AI governance, compliance

A contractual promise is not an operating control

Contracts matter, but regulated AI also needs technical controls, customer-owned operations and evidence of what actually happened.


Enterprise AI contracts address training, retention, security, incidents and deletion. Those commitments matter. The mistake is treating the contract as the whole control system.

When a supervisor asks where client data was processed, the answer has several layers: which provider and jurisdiction were involved, what the provider could technically see, which contractual and transfer terms applied, what the customer configured, and what evidence remains. No single clause or architecture answers all of them.

Technical measures can reduce particular risks. Customer-hosting can keep the application and evidence store under the firm’s control. Least-authority retrieval can restrict which source enters a model context. Protected-value substitution can prevent supported identifiers from appearing in an external payload. Logs can make later review less dependent on memory.

None of those is a universal guarantee. Residual context can still identify a person or transaction. Detectors have false negatives. Administrators and support arrangements create their own trust boundaries. External models remain external providers. A technically elegant design with the wrong configuration or operating process can still fail.

The defensible approach is layered: contracts, technical controls, deployment ownership, human review, monitoring and evidence. GAIA25 works on the technical and evidence layers while stating their limits plainly. The goal is not to replace trust with a slogan about certainty. It is to replace invisible assumptions with controls that can be tested.