Jointli Start the four minute checkFour minute check

AI you can defend.

Principled, documented, and yours to stand behind.

Most vendors scale your operation, and they scale your risk with it.

Scalable operations without duty of care is a bill that arrives later. The exposure compounds at exactly the rate the capability does, and by the time it surfaces it is priced into everything you built on top of it. That is not a tooling failure. Nobody was answerable for whether the decisions were reasonable in the first place.

Right the first time, because the second time is not free.

An AI system you rushed is a rebuild you have not scheduled yet. The work runs on a published standard rather than a house opinion: duty of care risk analysis, assessed against the Three Tenet Test of harm prevention, functional integrity and risk acceptability. You get a method with the criteria stated in the open, so the decisions you make now still make sense to whoever inherits them.

Do the right thing, including where it costs us something.

Judgment is adjudicated against written doctrine, not negotiated. Impact is taken at its highest and never averaged down. Catastrophic exposure is called unacceptable before arithmetic gets a chance to soften it. Nothing is built, governed or operated in your environment before an accepted risk assessment, including when the larger engagement is the one we would rather sell.

It keeps doing what you meant, and keeps showing you so.

What you end up with is a working capability, operating under authority you set, reporting on its own behaviour as a by-product of running rather than as a report someone assembles later. When it drifts from what you intended, you find out then, not at the end of the year. Autonomy expands as the track record earns it.

What happens after launch.

The industry is very good at launching AI and very bad at keeping it right. Adoption was never the constraint. Organizations moved fast, and the things they built did not survive contact with a changing business. Nothing in the stack was designed to hold its shape, so the drift went unnoticed until the results stopped arriving.

95%

of enterprise generative AI pilots produced no measurable P&L impact.

MIT Project NANDA, 2025

80%+

of AI projects fail by estimates cited by RAND, about twice the rate of IT projects without AI.

RAND Corporation, 2024

28%

of AI use cases in infrastructure and operations fully meet return expectations.

Gartner, April 2026

42%

of companies abandoned most of their AI initiatives, up from 17% a year earlier.

S&P Global Market Intelligence, 2025

Third party research, linked so you can check it rather than take our framing of it. These are not adoption numbers. They are what happens after launch.

Who we serve.

Where being wrong is expensive: the work pays for itself where an AI decision carries a consequence somebody personally answers for, and where the answer has to survive contact with people outside the building.

Financial services

Banking, insurance and regulated finance, where model risk and examiner scrutiny already have an owner, and agents are arriving faster than the review cycle can absorb them.

Security operations

Teams and service providers who already run least privilege and evidence discipline, now applying it to systems that can write, deploy and approve.

Healthcare and life sciences

Compliance, privacy, policy interpretation and research administration, where clinical and operational use has outrun published policy.

Counsel and capital

Law firms advising on AI exposure, and investors who need a portfolio company's AI position to hold up in diligence rather than in a pitch.

One engagement, five depths.

You enter where you are and go as far as the problem actually requires. Work you have already paid for is credited forward rather than repeated. Open any step for what it produces.

Governance work product

Sample AI Risk Register
Risk IDRiskLikelihoodImpactTreatmentOwner
AI-014Model driftPossibleHighThreshold monitoring and rollbackModel Ops
AI-021Data lineage gapLikelyHighProvenance capture at ingestionData Lead
AI-027Prompt-injection exposureLikelyHighInput isolation and adversarial testsSecurity
AI-032Vendor model changePossibleMediumVersion pinning and change gateVendor Mgmt
AI-039Unlogged sensitive-data accessPossibleHighREDACTEDPrivacy
AI-044Evaluation gapLikelyHighScenario coverage reviewAssurance
Stands alone, no prerequisite

A direct read on where automation would actually pay in your environment, and which obligations already attach to you whether or not you have looked. Short, scoped, and it commits you to nothing further.

  • An opportunity map naming the workflows worth automating and the ones that are not
  • Your obligation profile: which regimes actually reach you, and which do not
  • A candid read on what is blocking you today, whether technical, organizational or legal
  • A recommended entry point, including the recommendation to stop here if that is the honest answer

Who it is for. Executives who know AI matters to the business and want a straight answer on where to begin before committing budget.

Required before we build, govern or operate. Not waived.

Duty of care risk analysis run against the Three Tenet Test: harm prevention, functional integrity and risk acceptability, assessed together rather than traded off quietly. Impact is taken at its highest, never averaged down. Most assessments are a checklist with a score on the end. This is a balancing test, so what comes out of it is a plan for the failure modes that actually apply to you, in the order they are likely to bite.

  • A written risk analysis with explicit criteria, a stated risk appetite, and the balancing test shown rather than asserted
  • A register where every finding traces to the observation behind it, and nothing is asserted without a source
  • Accepted risks recorded properly: who accepted, under what authority, bounded how, revisited when
  • A defensibility packet fit for a regulator, a board, an insurer, an acquirer or opposing counsel

Who it is for. The General Counsel, CISO or Chief Risk Officer who personally carries the exposure and needs a position that survives scrutiny.

Requires an accepted assessment

Codified policy covering risk, ethics, acceptable use, model lifecycle and data handling, mapped to the obligations that actually reach you and written to survive a customer's procurement review rather than to satisfy an internal checkbox. Add a new obligation later and the model tells you what you already satisfy and what is genuinely new. You are not paying to re-run the same assessment once per regime.

  • A governing system with named owners, decision rights, and escalation that works at speed
  • A treatment plan where safeguards are earned through verification, never marked done on request
  • Board level accountability written so a director can actually discharge it
  • A control register that answers, for any row, why it says what it says

Who it is for. Whoever has been handed "we need to govern AI" and has to turn it into something with owners and teeth.

Requires governance. Run cost quoted separately.

The workflows, tools and agents themselves, built where you work and operating under governance rather than having governance bolted on afterward. Most builds die between pilot and production, and the named reason is usually that nobody could approve them. This is also where we tell you the truth about tool sophistication. There is a wide gap between a chat interface with a system prompt, a retrieval pipeline, a workflow with tool access, and an agent that holds state and acts across systems. They fail differently, they cost differently, and they demand different controls. We will show you which one your problem actually needs, and say so when the honest answer is the cheapest one.

We grade what you own against a verification ladder, not a feature list.

  1. present
  2. unit verified
  3. integration verified
  4. adversarially verified
  5. certified

Those are five different things. Most capability claims in this market sit on the first or second rung and are sold as the fifth. Knowing which rung you are actually on tells you which parts of your stack will hold under load and which are waiting to surprise you.

The same discipline separates what is exposed from what is merely shipped.

  1. code present
  2. deployed
  3. reachable
  4. actively used
  5. exploitable

Treating those as one condition is how organizations end up either ignoring a live problem or rewriting something dormant and harmless. Where something cannot be observed, we record it as unobserved rather than as fine. Absence of evidence is not evidence of absence.

  • Working systems in your environment, with authority boundaries enforced rather than documented
  • A capability assessment of what you already own, each component placed on the verification ladder with the evidence for that placement
  • A triage of what is genuinely exposed against what is shipped but dormant, so remediation money goes where the risk actually is
  • An evidence trail produced as a by-product of the work, not assembled before an audit
  • Build cost and run cost quoted as separate lines, so you can see the commitment past signature
Standard deploymentRegulated deploymentPrivate and sovereign

Who it is for. The operating leader whose AI program stalled short of production, or who intends to get it right the first time.

Requires deployment. Ongoing.

Design, build, operate and improve on your behalf, run continuously by the same people who governed it. Accountability sits with the outcome rather than with a deliverable handed over at the door. Regulated operation adds evidence depth, tighter control coverage and a stronger assurance cadence. Private and sovereign operation runs inside your own boundary, on your infrastructure or in an enclave, with a controlled release channel. Continuous assurance runs underneath all of it: regression testing, adversarial validation before any release, drift checks, and evidence packages kept current rather than reconstructed.

  • An operated capability, with governance maintained live instead of reconstructed annually
  • Evidence current on the day anyone asks, not gathered in the two weeks after they do
  • Reassessment triggered by change in your business, not by the calendar
  • Release management, upgrades and incident support under one accountable party
  • Insurance and indemnity standing behind the result
Managed operationRegulated operationSovereign operationContinuous assurance

Who it is for. The owner or chief executive who wants the outcome of an AI operated business without standing up and holding the team to run it.

How we price.

Every engagement is scoped before it starts and quoted as a single fixed fee. No hourly rates and no meter running. If scope changes partway we requote and you decide whether to proceed. You know what the work costs before anyone begins it.

What moves the number

How much of your environment is in scope, how many obligations genuinely reach you, and whether you want a point in time position or an ongoing program. Settled on the first call, before a proposal is written.

What is always included

The practitioner doing the work, an independent review of that work before it reaches you, and a written deliverable fit to put in front of your board, your client or your insurer. None of that is a line item.

What you already have counts

Prior work is assessed against the same standard and credited into the engagement. Nobody is made to start over or to buy a step they have already earned.

How we work.

Authority

It acts on your order, not its own

Explicit rules define what an AI system may recommend, prepare or execute, and where it stops and waits for you. It does not take consequential action outside the authority you have granted it, and a named person is accountable for every conclusion that reaches you. That boundary is enforced in the system rather than promised in a policy.

Evidence

Findings carry their source

Every conclusion traces to the observation behind it. A verdict with no surviving observation is refused by the system that produced it, which is why the register still means something months later instead of quietly going stale.

Review

The author is never the last reader

Work is reviewed independently by someone other than whoever produced it, against the same criteria every time. Self certification is structurally unavailable.

Progression

Maturity is earned, not declared

A safeguard reaches "in place" by passing verification with a completion record behind it. Nothing advances because someone marked it done, which is why the maturity picture still describes reality a year in.

Portability

Governance above the model

The method does not depend on which model or vendor you standardize on, so it survives your stack changing underneath it. Model consumption stays yours and stays visible.

Containment

Your environment, your data

Work happens inside your environment. We do not hold, store or retain client data, and only the engaged practitioner has access. At close, access stands down and nothing of yours leaves with us.

Check the work. That is the point of how it is built.

Anything can look right on the day it ships. Everything below exists so you can tell whether it is still right months later, without taking our word for it.

Decision record  ·  Illustrative

System

Claims-triage agent

Action

Flagged application REDACTED for human review

Checked against

Fairness policy v3 - adverse-action rules

Outcome
HELD

Confidence below policy floor - routed to a person

PASS

Adverse-action reasons attached - bias check within threshold

Evidence

Reasoning trace attached REDACTED

Assurance

Re-checked daily - last check clear

The method is published

The AI governance system this work runs on is public and openly licensed. You can read the standard we hold ourselves to before you hire us, and hold us to it afterward. Very little in this market can be inspected before purchase.

Built to still make sense to someone else

Duty of care risk analysis exists so an analysis can be communicated to and accepted by others. That matters most later, when the people reading it are not the people who commissioned it and the context has moved on.

We are in the room when it is challenged

If your assessment is questioned by an examiner, an auditor, an insurer or opposing counsel, the methodology is ours to defend and we defend it with you. Our name is on the reasoning too.

We take the same scrutiny

The platform behind this work is submitted to external adversarial assessment against the same ladder, by reviewers who do not work for us and are not asked to be kind. We hold our own capability claims to the rung the track record supports, which is the only reason we are willing to grade yours.

Five questions you will probably be asked anyway.

Your answers compose a brief you can edit and send yourself.

Question 1 of 5

What is prompting this for you right now?

Question 2 of 5

How much AI is operating in your environment today?

Question 3 of 5

What obligations do you answer to?

Question 4 of 5

What outcome do you need?

Question 5 of 5

Has anything already gone wrong?

Next step.

Scope an engagement

You know roughly what you need and want it scoped and priced.

The five depths

Pressure test the argument

Start at the problem and decide whether our read of it matches yours.

The problem

Interrogate the method

Read the standard, then decide whether it survives your scrutiny.

The proof

Join the collective

You run your own practice and want engagements worth having.

For practitioners

Contact us with your problem.

Send us an email and we will evaluate it with you.

hello@jointli.io