Archer® Launches Archer Evolv™ AI Compliance, Bringing Runtime Guardrails to AI Governance

via Business Wire
ⓘ This article is third-party content and does not represent the views of this site. We make no guarantees regarding its accuracy or completeness.

Regulation and company policy become native Amazon Bedrock Guardrails, enforced on every prompt from employees or agents before the model responds, with every control traced to the obligation behind it

Every enterprise now runs two AI workforces. Employees prompt large language models and copilots all day, sharing contracts, customer records and source code. Agents act on the company's behalf at machine speed. Both take actions regulation and company policy already govern, and neither is stopped by a policy document. Risk, compliance and security teams already own the policies that govern this. What they have lacked is a way to enforce them at machine speed, in the moment a prompt reaches a model.

Archer® today launched Archer Evolv™ AI Compliance to close that gap. It turns the regulations and policies that already govern an enterprise into policy as code: approved Amazon Bedrock Guardrails, deployed natively inside the customer's own AWS account and enforced before a model responds, whether the prompt came from an employee or an agent. Every control traces back to the obligation that required it, and every violation is recorded in the GRC system of record enterprises already trust.

Yesterday, Archer put a governed digital workforce to work inside its own GRC harness. Today it extends the same discipline to the secure, compliant use of AI across the enterprise. Powered by Archer's proprietary regulatory intelligence and 492 purpose-built models trained since 2017, Archer Evolv AI Compliance is available today.

Most of this year's AI governance conversation has centered on access: identity, zero trust, and who may reach which system. It answers a different question than compliance does. IAM governs identity. Runtime guardrails govern intent. An employee or agent can be correctly scoped, authenticated and logged and still submit a prompt that breaks a regulation no one translated into a control. Permission says who can act, not whether the action was allowed.

AI governance platforms are meant to link responsible AI principles, policies, regulations and risk frameworks to the runtime controls that govern AI systems. Much of the market delivers the repository or the guardrail, rarely the connection between them. Archer Evolv AI Compliance is that connection. A single AI action can be risk event, an obligation and a security exposure at once, landing on the CRO, CCO and CISO together. Archer gives all three continuous controls enforcement where the model runs, traced to the obligation behind it, with real-time risk visibility from one system of record.

Prevent the violation, then prove it was prevented

Stopping a violation and proving why it was stopped are two separate problems. Observability tools detect and report. Prompt filters block. Neither connects to the regulation or policy that required the control. Archer Evolv AI Compliance runs both halves as one continuous loop inside a customer's own AWS account:

  1. Listen. Regulations, privacy sources and a company's own policies become tracked controls, drawing on Archer's 22 million regulatory documents and the legal experts who version-track them.
  2. Decide. Enforceable controls become draft Amazon Bedrock Guardrails, deployed only once a named owner approves them.
  3. Act. Every prompt, from an employee or an agent, is checked before inference, and violations are blocked and logged.
  4. Assure. Guardrails are tested on a set cycle against the approved control, so risk is scored continuously and drift or tampering is flagged.
  5. Learn. Findings route into Archer issue management and are tracked to closure on the same system of record.

No proxy sits in the inference path, and models outside Bedrock can apply the same control through the Amazon Bedrock Apply Guardrail API. Every promotion, edit and rollback is recorded with a named owner. Source, obligation, control, guardrail and violation event form one audit trail a customer can hand to an examiner on demand. That turns "we have a policy" into "we can show you the control."

What the runtime guardrails govern

Guardrails keep governed content out of a model and its output, across two classes of obligation.

Organizational obligations (security and business risk). Content the customer's own policies place off-limits: credentials and secrets such as API keys and tokens, the highest-severity exposure, because a leaked secret turns a data-loss event into an access event; source code and proprietary technical assets; confidential business information such as contracts, pricing and M&A activity; and customer-defined usage rules on what a model may address, do or combine.

Regulatory obligations (compliance risk). Content whose exposure violates an external law, regulation or standard: personal data under GDPR, CCPA and state privacy law; protected health information under HIPAA; payment and cardholder data under PCI DSS; and regulated categories such as export-controlled data, securities information and biometric data.

What stays inside the customer's AWS account

Archer connects through one scoped, least-privilege AWS IAM role and reads guardrail configuration and events, never customer traffic. Prompt content, model responses, documents, embeddings, PII, model weights and training data never reach Archer. Archer receives the violation event, which control fired, who and when, the confidence score and version history. If connectivity is interrupted, the native Amazon Bedrock Guardrails continue enforcing as last deployed.

Customers control how enforcement is introduced. Observe logs what a guardrail would block. Advise routes a finding to a named owner with evidence. Enforce blocks violations before inference. Nothing moves up that dial without approval, and each version can be rolled back. The exam question has changed from "show us your policy" to "show us the control."

"A guardrail is only as good as the obligation behind it. Someone must capture the regulation, identify the requirement, map it to a control and keep that mapping current as the rule changes. That is the work Archer has done since 2017 with legal and regulatory experts in the loop, and it is why the guardrail knows which regulation it is enforcing and not just which words to block. Our customers do not have to build that chain. We already did. Every guardrail is clear on what it reads, what it blocks and who approved it, so experts stay in control of enforcement," said Kayvan Alikhani, Chief Product & Technology Officer at Archer.

Availability

Archer Evolv™ AI Compliance is available today, directly from Archer and in the AWS Marketplace. To learn more, visit https://www.archerirm.com/archer-ai-compliance

About Archer

Archer powers how the world's leading enterprises govern risk, compliance, and regulatory change. More than 1,300 organizations run on Archer, including half the Fortune 500 and 37 of the top 50 global banks. A new regulatory change lands somewhere in the world every seven minutes, and agentic AI is outpacing most teams' ability to govern it. Archer replaces static controls and periodic reviews with purpose-built AI grounded in the deepest regulatory data and domain expertise in GRC: 22 million regulatory documents and 250 million GRC records, validated by more than 200 AI engineers and GRC domain experts. Every result traces back to its source, and every decision can be defended. Archer delivers solutions across the full range of GRC, including regulatory change management, AI governance, third-party risk, and IT and security risk.

"Every guardrail is clear on what it reads, what it blocks and who approved it, so experts stay in control of enforcement." Kayvan Alikhani, Chief Product & Technology Officer at Archer.

Contacts

Report this content

If you believe this article contains misleading, harmful, or spam content, please let us know.

Report this article