Skip to content
Koralis AI

For the Head of AI · status as at 29 September 2026

You own the AI-use policy. Which of its rules actually stop anything?

Kovac is software that checks requests to your data against your policy before they reach it: requests from people and from pipelines built on it. It checks three of the seven data paths today, and all seven by October 2026. It is in beta.

This page is for whoever owns the AI-use policy, the AI register and the board's question: what can our AI reach, and what stopped it?

From written policy to enforced refusals

A policy says what AI must not reach. A refusal is what stops it.

The free Scoping Review is the first step: one working session with both founders, no data, nothing installed, and a written pack within 48 hours of the session. If you want it in writing before a pilot, the policy dry run is the paid second step. For each rule in your policy, it gives one of three answers:

  1. Enforced today

    On the data paths Kovac checks: three of seven today.

  2. By a date

    Only from a dated roadmap commitment, with its month. All seven data paths checked against your policy by October 2026.

  3. Not at all

    Said plainly, including rules neither Kovac nor, from what you tell us, anything you run today can enforce.

The policy dry run · £1,500 fixed, not credited

Send us your AI-use policy (or tell us you don't have one) and the AI and confidentiality clauses from up to five client contracts. Redacted extracts only, with no names, signatures or contact details; send nothing your client contracts forbid you to share. After a 90-minute working session with a founder, within two weeks, you get:

  • the refusals your policy and those clauses imply, as we read them, as plain-English rules (“a bid writer must not see another client’s rates”);
  • for each rule, whether Kovac can enforce it today and on which data paths, only from a dated roadmap commitment, or not at all (Kovac is in beta, not yet in production);
  • the gaps: rules neither Kovac nor, from what you tell us, anything you run today can enforce;
  • a one-page summary for your board, IT or compliance lead.

£1,500 fixed, not credited. A product in its own right, not a deposit on a pilot.

It starts once a data processing agreement is in place (no date yet), under a confidentiality agreement Koralis AI Limited signs at the same time. Send us nothing before then. It is not legal advice. Professional indemnity insurance: not held today.

On Microsoft 365? Ask for it as a Microsoft 365 (M365) gap check: the same session and price, working from your Microsoft 365 settings, not content. What the dry run and M365 gap check cover →

For the board

What can your AI reach, and what stopped it? What Kovac can show today, and what it can't yet.

Two of our buyer's guide's questions are the board's question put to a vendor. Our answers, as the guide gives them.

  • Show me a denial.

    3 of 7 data paths checked

    Yes, on the paths Kovac checks. An object, action or deploy request that policy refuses is denied, and the refusal is recorded. File reads, previews, code run directly (/execute) and connection reads are not checked today, so on those paths there is no denial to show. Ask to see the denial on the path you care about.

    When: All seven data paths checked against your policy by October 2026.

  • Who can read the audit log, and can they alter it?

    Not yet

    The record is searchable, but any signed-in user can add an entry in anyone's name, and entries are not signed or linked together when written. By question 4's own test – an audit trail that can be quietly edited is a log – ours is a log today.

    When: Only Kovac itself can write to the record by October 2026; every entry signed as it is written, permitted requests as well as refusals, by December 2026.

Data paths checked against policyToday:3 of 7By when:As the denial answer above.
Refusal recordToday:Refusals only, searchableA log any signed-in user can add to. Permitted requests are not recorded yet.By when:As the audit-log answer above.
Failure behaviourToday:3 failure cases let a request throughBy when:Every path blocks a request when the policy check cannot run, by October 2026.

What you can take to the board today: the refusals on three of seven data paths, in a searchable record. What you can't yet: a record of what was permitted, or a record only Kovac itself can write.

What Kovac does and doesn't touch

Where Kovac sits beside what you already run.

On your AI register, Kovac is one entry, not the register: it governs requests to data loaded into it.

What Kovac governs
Requests to data loaded into itFrom people and pipelines built on it, checked against your policy before they reach the data: on three of seven data paths today, all seven by October 2026. Fields you mark sensitive are swapped for placeholder tokens before Kovac passes them to an AI model or posts them to another system.
Not yet, with its month
AI models, through Kovac's checkFrom late October 2026, in pilots, AI models connect through Kovac's check.

Microsoft 365

What it does not
Microsoft Copilot and web chat assistantsKovac does not sit in front of them. Tools that bypass Kovac, it does not see.
Not shipping yet
SharePoint and OneDriveSharePoint and OneDrive, with Microsoft Entra ID sign-in, are in alpha testing, for release by October 2026. Until then, data held there can go into a pilot as an export, supplied as files, with the fields to mark agreed at the Scoping Review.

Google Workspace

What it does not
Gemini for Google Workspace and web chat assistantsKovac does not sit in front of them. Tools that bypass Kovac, it does not see.
Not shipping yet
Google Drive, Gmail, Docs and SheetsGoogle Drive and shared drives, Gmail, and Docs and Sheets content, with Google sign-in, by November 2026. Until then, data held there can go into a pilot as an export, supplied as files, with the fields to mark agreed at the Scoping Review.

Bring your Microsoft 365 or Google Workspace questions to a free Scoping Review →

Your regulatory frame

Kovac is designed to produce one part of your evidence, not to make you compliant.

You may answer to the EU AI Act, where your organisation is in scope; to ISO/IEC 42001, if you run an AI management system against it; and to the ICO, and a sector regulator such as the FCA or the SRA. We name them as context only. Kovac is designed to produce one part of the evidence: a record of which requests to your data were refused, and which clearance was missing, on the paths it checks. Today that record is a log that any signed-in user can add to; every entry signed as it is written from December 2026.

We give no dates for these frameworks here. When an obligation applies to you is a question for your own counsel, not for a vendor's website.

What we hold, and when each gap closes →

What Kovac is not

  • It does not make your organisation compliant with any of them. No product can on its own.
  • It is not certified or assessed against any of them. Koralis AI holds no certification today. Cyber Essentials: not held yet – in preparation.
  • Its record is a log today: any signed-in user can add an entry.
  • It is not advice. Designed to support your evidence; not legal compliance advice.

Three steps; the second is optional

Start free. Pay for the dry run only if you want it in writing.

Until December 2026 we run one pilot at a time. A pilot on personal data waits for a data processing agreement; it has no date yet.

  1. 1Step 1Scoping ReviewFreeOne working session with both founders. No data, nothing installed. A written pack within 48 hours of the session.
  2. 2Step 2Policy dry run or M365 gap check£1,500 fixed, not creditedYour policy or your Microsoft 365 set-up, checked in writing, without running a pilot.
  3. 3Step 3Quick-StartMid-sized businessesFixed price in writing after the Scoping ReviewOne workflow, on your own machines, four weeks from data access. Available from late October 2026.
  4. 3Step 3Proof PilotRegulated and larger organisationsFixed price in writing after the Scoping ReviewFour weeks from data access, on one of your real datasets, with the security and governance pack. On your own machines. Available from late October 2026.

Who you'll talk to

Two founders. The Scoping Review is with both of us.

Dylan Banks

Co-Founder · Strategy & Systems

  • Board-level AI strategy across growth-stage, mid-market and enterprise businesses
  • Cross-sector: infrastructure, commercial real estate, engineering, biotech, deep tech, consultancy
Dylan on LinkedIn ↗

Marko Krznaric, PhD

Co-Founder · AI & Architecture

  • Former Palantir Forward Deployed Engineer and Technical Lead
  • Former Chief Software Architect and Technical Director, Imperial College London
  • Architect of Kovac
Marko on LinkedIn ↗

Book a free Scoping ReviewOne session, with both of us.

Bring one rule from your policy. We'll tell you whether Kovac can enforce it.

The free Scoping Review, with both founders: which data path the rule sits on, whether that path is checked yet, and a written pack within 48 hours. No data, nothing installed.