Summary
- LatticeFlow AI has launched Risk Center, combining governance software with specialist services for continuing technical assessment of deployed AI systems.
- Customers select systems, frameworks, thresholds, and assessment frequency while LatticeFlow performs evaluations and produces evidence and mitigation guidance.
- The service arrives as parts of the EU AI Act move from rulemaking into active enforcement.
Zurich-based LatticeFlow AI has launched a managed governance service that will continuously test enterprise AI systems against customer-defined risk thresholds, turning part of model assessment and control into an outsourced operational function. Risk Center combines the company’s existing technical-governance platform with specialist services rather than treating compliance as a one-off review before deployment.
Customers decide which AI systems should be assessed, which frameworks and thresholds apply, how often testing should occur, and how mitigation decisions will be handled. LatticeFlow then performs the technical evaluations and produces evidence, risk metrics, reports, and mitigation guidance, while accountability for accepting or changing a deployment remains with the customer.
The approach addresses a weakness that becomes more obvious as AI systems move into production. Governance documents can become stale when models, data, prompts, tools, and connected systems continue changing after an initial approval, particularly where agents are able to interact with other enterprise software.
Managed assessment consequently turns AI governance into a recurring operational activity rather than a policy project with a completion date. That resembles established service markets in cybersecurity and cloud operations, where organisations buy continuing specialist capability because maintaining every discipline internally is difficult.
Governance moves closer to technical operations
Enterprise AI programmes already spread responsibility across legal, compliance, security, model owners, and business teams, each of which sees a different part of the risk. The difficulty grows when systems are updated frequently or when an agent can reach external tools and applications rather than producing an answer in isolation.
A model may behave acceptably during an initial assessment and later receive different data, gain access to another tool, adopt a new underlying version, or move into a workflow where an error triggers an action. Risk Center is designed to repeat technical assessments as that environment changes instead of assuming the original evaluation remains valid indefinitely.
That does not outsource accountability because the organisation still decides which systems are tested and which thresholds are acceptable. An external provider can measure and report a risk, but the customer still has to decide whether the result blocks deployment, triggers mitigation, or falls within its tolerance.
The distinction becomes particularly important for agentic systems, where model quality is only one component of risk. Permissions, connected applications, data access, and workflow behaviour all influence the consequences of an error, so assessing the model without the surrounding system can provide an incomplete picture.
Europe’s rules are becoming operational
The launch arrives as more of the EU AI Act moves into application and enforcement. Techopia recently examined how Europe’s AI regime is shifting from legislation towards surveillance, incident handling, and enforcement, increasing demand for evidence that systems behave as organisations say they do.
The regulatory timetable remains staggered, so not every enterprise application carries the same obligations today. General-purpose model providers, deployers of high-risk systems, and organisations using lower-risk internal applications can sit in materially different positions, while security, privacy, procurement, and internal-risk requirements may add controls beyond the statutory minimum.
LatticeFlow has previously worked on translating legal and governance requirements into technical evaluations, including through its COMPL-AI work with research partners. The company’s broader proposition is built around producing measurable evidence rather than relying solely on written policies.
That emphasis becomes more useful as regulators begin asking what actually happened inside a system rather than whether a governance framework exists on paper. Policies establish responsibility, but they do not demonstrate whether a particular model remains secure, robust, or within an organisation’s thresholds after deployment.
Managed governance fills a specialist-skills gap
Deep model evaluation can combine machine learning, statistics, security, application behaviour, and regulatory interpretation, which makes it expensive to maintain as an internal capability where only a small number of systems require it. A managed service can spread that specialist capacity across several customers in the same way that managed security providers do.
Outsourcing creates its own supplier questions, however, because customers need to understand how assessments are performed, whether evidence can be inspected independently, how data is handled, and how quickly methods change when models or regulations evolve. A governance supplier can become another critical dependency if its output determines whether systems are allowed to operate.
There is also a risk that recurring reports become a substitute for understanding the business process itself. A score is useful only if the organisation has defined what failure means in the relevant workflow and who has authority to respond when the threshold is breached.
LatticeFlow’s launch reflects the point enterprise AI has reached: organisations increasingly need operating controls for live systems rather than another set of principles. Whether managed governance becomes a large software-and-services category will depend on how much of that work companies are prepared to outsource, but the demand is now being created by production systems rather than hypothetical future adoption.












