Archer Evolv puts runtime guardrails on enterprise AI use

Archer Evolv puts runtime guardrails on enterprise AI use

Archer, GRC provider, has launched Archer Evolv AI Compliance, a product designed to convert the regulations and internal policies that bind an enterprise into runtime controls that stop non-compliant AI prompts before a model can answer them.

The launch addresses a problem facing businesses that now operate two AI workforces at once: staff who feed contracts, customer records and source code into large language models and copilots, and autonomous agents acting on the company’s behalf at machine speed.

Risk, compliance and security teams already own the policies covering this activity, but they have had no way to apply those rules at the moment a prompt reaches a model.

Archer Evolv AI Compliance translates obligations into approved Amazon Bedrock Guardrails, which are deployed natively within each customer’s own AWS account. Each control links back to the obligation that created it, and every breach is logged in the customer’s existing GRC system of record.

Archer argues that much of this year’s AI governance debate has focused on access, such as identity and zero trust, which determines who may reach a system rather than whether a given action is permitted.

A user or agent can be properly authenticated and still submit a prompt that breaches an untranslated regulation. The company positions its product as the link between policy repositories and runtime guardrails, giving the CRO, CCO and CISO shared enforcement and real-time risk visibility from a single platform.

The product operates as a five-stage loop. It first converts regulations, privacy sources and company policies into tracked controls, drawing on Archer’s library of 22 million regulatory documents maintained by legal experts.

Enforceable controls are then drafted as guardrails and only deployed after a named owner signs them off. Every prompt is checked ahead of inference, with violations blocked and recorded. Guardrails are tested on a fixed schedule against their approved control, enabling continuous risk scoring and flagging of drift or tampering. Findings then flow into Archer issue management for tracking through to resolution.

No proxy sits within the inference path, and models running outside Bedrock can adopt the same controls via the Amazon Bedrock Apply Guardrail API. Each promotion, edit and rollback is attributed to a named owner, producing a single audit trail covering source, obligation, control, guardrail and violation that firms can present to examiners on request.

The guardrails cover two categories. Organisational obligations include credentials such as API keys and tokens, source code, confidential business information including pricing and M&A activity, and bespoke usage rules.

Regulatory obligations span personal data under GDPR, CCPA and US state privacy law, health information under HIPAA, cardholder data under PCI DSS, and categories such as export-controlled, securities and biometric data.

Archer offers GRC technology and has been building regulatory intelligence since 2017, training 492 purpose-built models over that period. The day before this launch, the company deployed a governed digital workforce within its own GRC harness.

On data handling, Archer connects through a single scoped, least-privilege AWS IAM role and reads only guardrail configuration and event data. Prompts, model outputs, documents, embeddings, PII, model weights and training data remain within the customer’s environment. Archer receives details of which control triggered, who was involved, when, the confidence score and version history.

Should connectivity drop, the native Bedrock guardrails keep enforcing in their last deployed state. Customers can roll out enforcement gradually through three modes: Observe, which logs what would have been blocked; Advise, which sends evidence to a named owner; and Enforce, which blocks violations before inference. Moving between modes requires approval, and every version can be reversed. The product is available now.

Archer chief product & technology officer Kayvan Alikhani said, “A guardrail is only as good as the obligation behind it. Someone must capture the regulation, identify the requirement, map it to a control and keep that mapping current as the rule changes.

“That is the work Archer has done since 2017 with legal and regulatory experts in the loop, and it is why the guardrail knows which regulation it is enforcing and not just which words to block. Our customers do not have to build that chain. We already did. Every guardrail is clear on what it reads, what it blocks and who approved it, so experts stay in control of enforcement,”

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.