Archer, the GRC specialist, has introduced Archer Evolv AI Compliance, a tool that converts an organisation’s existing regulatory and internal policy obligations into enforceable controls applied before an AI model produces a response.
The offering translates rules into policy as code in the form of approved Amazon Bedrock Guardrails, which run natively within the client’s own AWS environment. Checks apply equally to prompts written by staff and to those generated by autonomous agents.
Each control links back to the specific obligation that prompted it, and any breach is logged in the GRC platform firms already rely on. The product is available now and draws on Archer’s proprietary regulatory intelligence along with 492 dedicated models developed since 2017.
Archer argues that much of this year’s debate on AI governance has focused on access, identity and zero trust. In its view, identity management determines who may act, while runtime guardrails judge whether a given action is permitted. A user or agent may be fully authenticated yet still submit a prompt that breaches a rule never turned into a control.
The company says many vendors provide either a policy repository or a guardrail, but seldom link the two. Because one AI action can simultaneously represent a risk event, a compliance obligation and a security exposure, the platform aims to give the CRO, CCO and CISO shared enforcement and real-time visibility from a single record.
The system operates as a continuous five-stage cycle. Regulations and company policies are first converted into tracked controls, supported by a library of 22 million regulatory documents maintained by legal experts.
Enforceable controls then become draft guardrails, which go live only after sign-off from a named owner. Every prompt is screened before inference, with breaches blocked and recorded. Guardrails are retested on a fixed schedule to score risk and detect drift or tampering, and findings feed into Archer’s issue management for resolution.
No proxy is placed in the inference path, and models hosted outside Bedrock can use the same controls through the Amazon Bedrock Apply Guardrail API. Each promotion, change and rollback is attributed to a named owner, creating an audit trail from source regulation through to violation event that can be presented to examiners on request.
The guardrails address two categories of risk. The first covers internal obligations, including credentials and API keys, source code, confidential commercial material such as contracts, pricing and M&A details, and bespoke usage rules. The second covers external regulation, including personal data under GDPR, CCPA and US state privacy law, health data under HIPAA, cardholder data under PCI DSS, and sensitive areas such as export-controlled, securities and biometric information.
Archer accesses client environments via a single least-privilege AWS IAM role and reads only guardrail settings and events. Prompts, model outputs, documents, embeddings, personal data, model weights and training data remain with the customer. Archer receives only details of which control triggered, who was involved, when, the confidence score and version history. Should the connection drop, the Bedrock guardrails keep enforcing their last deployed configuration.
Firms can phase in enforcement across three modes. Observe records what would have been blocked, Advise sends findings with evidence to a named owner, and Enforce stops breaches before inference. Progression between modes requires approval, and every version can be reversed.
The launch follows Archer’s deployment, a day earlier, of a governed digital workforce within its own GRC environment.
Archer chief product and technology officer Kayvan Alikhani said, “A guardrail is only as good as the obligation behind it. Someone must capture the regulation, identify the requirement, map it to a control and keep that mapping current as the rule changes. That is the work Archer has done since 2017 with legal and regulatory experts in the loop, and it is why the guardrail knows which regulation it is enforcing and not just which words to block.
“Our customers do not have to build that chain. We already did. Every guardrail is clear on what it reads, what it blocks and who approved it, so experts stay in control of enforcement.”
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





