Datastreams
    AI governance begins with data governance

    Do not give AI an uncontrolled route
    through your business data.

    Adding AI to an existing pipeline does not automatically create a legal breach. It can, however, expose an existing control gap: the organisation may be unable to show which data the model received, for which purpose, under whose authority and what action followed.

    Datastreams supports technical and operational governance. It does not replace organisational accountability, legal assessment or the obligations of an AI provider or deployer.

    AI inherits the pipeline

    A model cannot repair data governance that was never operational.

    A static policy cannot constrain a live prompt, tool call or generated action. Before AI participates, the surrounding data service needs explicit quality, purpose, access, provider and execution controls.

    Personal data

    An AI request can introduce a new purpose, recipient, inference or action. Access must remain tied to an approved task, permitted context and accountable outcome.

    Financial and strategic data

    Confidential data, forecasts, pricing, transactions and internal decisions require the same explicit authority, provider boundary and traceability.

    Operational actions

    Risk increases when AI can change state or trigger services. Interpretation should remain separate from permission and execution.

    The missing governance plane

    The model may be replaceable. Business state and authority cannot be disposable.

    Agents from different providers can participate without becoming the system of record, receiving unrestricted pipeline access or becoming the final source of operating permission.

    Authoritative state

    The business keeps its own data, events, objectives and commitments instead of treating model context as permanent memory.

    Explicit authority

    An agent receives defined data access and permitted actions for a purpose, rather than broad implicit control.

    Decision evidence

    Relevant input context, configuration, policy result, actor, action and resulting state remain inspectable.

    Agent interaction lifecycle

    Separate interpretation from authority and execution.

    AI can contribute where it is strong while declared rules and application contracts control what may affect the business.

    1. 01

      Observe

      Supply only the data and context permitted for the task.

    2. 02

      Propose

      Let the model interpret, generate or recommend without silently changing business state.

    3. 03

      Evaluate

      Apply deterministic business rules, policy conditions and authority checks.

    4. 04

      Act

      Execute only an allowed action through a controlled application or runtime contract.

    5. 05

      Record

      Retain the outcome and evidence needed for operations, review and improvement.

    Provider independence

    Agents can come and go without taking the business with them.

    OpenAI, Claude, internal models or future systems can be selected per task. DataInbox keeps business state and objectives; runtime contracts keep actions controlled.

    See the independent architecture

    business state → permitted context → agent proposal → policy gate → action → evidence

    The provider may change at the proposal step. The surrounding business contract remains authoritative.

    Questions the architecture should answer

    Governance becomes operational when responsibility is testable.

    Before an agent receives access, the organisation should be able to answer these questions.

    Which objective is the agent helping to maintain?

    Which first-party data may it observe, and for which purpose?

    Which actions may it propose or execute?

    Which policy gate or person can refuse the action?

    Which model and configuration version participated?

    Which evidence and resulting state must remain?

    Regulatory direction

    Outsourcing execution does not outsource accountability.

    Applicable obligations differ by organisation and use case. The common direction is clear: data quality, third-party dependencies, logging, oversight and control must remain operationally manageable.

    AI systems

    For high-risk AI systems where the relevant provisions apply, the EU AI Act includes requirements concerning data governance, record-keeping, transparency and human oversight.

    EU AI Act on EUR-Lex

    Financial operations

    DORA requires financial entities to manage ICT third-party risk within their own risk framework and states that using third-party ICT services does not remove their responsibility for compliance.

    DORA on EUR-Lex

    Datastreams can support the surrounding operating controls without claiming that every AI use case is high-risk, that every organisation falls under DORA or that runtime evidence alone establishes compliance.

    Start with one agent action that would matter if it were wrong.

    Map the state, purpose, authority, policy gate and evidence before selecting the model.

    Map the agent boundary