MD / Senior Partner / CEO
MD / Senior Partner / CEO
What a board-level control actually looks like
A governance layer does not need to be complicated to be effective, and at board level it should not be described as if it were. CattleGrid sits between your organisation's applications and the AI providers they call, inspecting what leaves before it leaves. It blocks or redacts content that matches your configured rules, keeps an unalterable record of what happened, and does this on every request, not on a sample. Deployment is a change to a web address in your application configuration — not a project, not a procurement cycle, not months of integration work.
The governance record itself is the asset a board can point to. Every decision — what was sent, what was blocked, what was redacted — is written to a cryptographically verifiable audit trail, tamper-evident by design rather than by policy. If a regulator, an enterprise client's due-diligence team, or your own auditors ask what control exists, the answer is a timestamped record, not an assurance.
On sovereignty, the precise position is this: what CattleGrid knows about your organisation never touches US jurisdiction. What reaches the AI provider has already been cleaned. CattleGrid is a UK-registered company running on UK infrastructure, with no US parent entity, so the governance layer itself — your policy configuration, your audit logs, your enforcement records — sits outside CLOUD Act jurisdiction. This is not a claim that AI processing as a whole becomes sovereign: the AI providers your organisation calls remain US-domiciled companies, and inference still reaches them. What changes is that what reaches them has been governed first, and what CattleGrid holds about you never leaves UK jurisdiction.
Set against the numbers above, the cost of putting this control in place is not the board's real question. The real question is what an unmanaged AI data flow costs when it surfaces on someone else's timetable rather than yours — and that figure is already quantified, above.
What this looks like once it's in place
A board that has deployed this can answer the exposure question before it is asked, with a governance record rather than a promise. It is in a materially stronger competitive position with enterprise and public sector clients who now ask AI governance questions as standard due diligence. And it has drawn a clear, defensible line between "we govern AI use" and "we hope nothing goes wrong" — a distinction regulators and clients are increasingly testing for directly.
What CattleGrid does not do
CattleGrid is a technical control, not a substitute for governance decisions your organisation still has to make. It does not provide FCA-regulated advice of any kind, does not produce SMCR Statements of Responsibilities, and does not conduct Data Protection Impact Assessments. It does not assess the suitability of AI-generated outputs — legal, financial, or otherwise — and it does not replace the judgement of the people accountable for those outputs. What it provides is the evidence base that makes those judgements defensible.