PF Systems

UK sovereign AI governance software

British-developed · Model-agnostic
PF SystemsOperational authority for agentic AIStart with one workflow

Operational authority for agentic AI

AI can propose.
It should not authorise itself.

PF Systems puts an independent authority boundary between AI and consequential action—checking what may proceed and preserving linked evidence of what was decided and done.

UK sovereign · model-agnostic · designed to work with existing systems
One governed actionYour existing estate stays in place
PF Memory knowsGoverned contextCan wrap an existing memory or retrieval system
Existing AIProposes

A data movement, software change, cyber response or machine instruction.

PF KernelDecides

Allow · Deny · Modify · Step Up · Stop the Line

Protected pathEnforces

Only the permitted, modified or escalated outcome can proceed.

PF Core provesLinked evidence of the governed evaluation

Existing AI proposes a consequential action.

PF Systems in plain EnglishA control checkpoint and black box for AI action.

PF Systems puts hard rules and approval checks in front of each consequential action proposed by any AI—or multiple AIs—that an organisation chooses to use. This keeps the organisation in control: PF Kernel can Allow, Deny, Modify, Step Up to a human (HITL), another AI (AITL) or a defined sequence, or Stop the Line before an action takes effect. PF Core then preserves linked, tamper-evident evidence of what was proposed, which authority was applied, the decision returned and the effective action recorded, so the governed evaluation can be traced, checked and deterministically replayed. This does not make the underlying probabilistic AI deterministic.

Built to integrate—not replaceKeep the systems you already use.

PF Systems can sit around existing AI models, agent frameworks, memory systems, identity services and operational software.

  • Models
  • Memory
  • Identity
  • Cloud
  • Business systems

One governed cyber action

What happens when an AI changes an approved action?

A synthetic incident-response agent is authorised to quarantine one endpoint. Before execution, it substitutes a critical finance server. The earlier authority no longer matches.

See PF Systems govern one AI actionSynthetic example · no live systems
AI AGENT

REQUESTS AN ACTION

Quarantine DEV-481

Proposed cyber response
PF SYSTEMS

CHECKING AUTHORITY

PF Kernel decides

GOVERNED RESULT

WAITING FOR DECISION

No action proceeds before a decision.

Allow · Deny · Modify · Step Up · Stop
PF Memory supplies governed contextPF Kernel decidesPF Core preserves linked evidence

An AI agent asks to quarantine endpoint DEV-481.

Illustrative synthetic scenario. It does not represent a customer deployment, certification, guaranteed security or production readiness.

The PF OS triad

Three clear responsibilities. Kept deliberately separate.

PF OS contains only PF Memory, PF Core and PF Kernel. They can work independently or together without turning knowledge into authority or evidence into a decision-maker.

PF OS is the triad onlyMemory knows. Core proves. Kernel decides.

Where PF Systems begins

Identity gives an agent a name. Access lets it reach a system. Neither automatically authorises this action.

PF Systems works alongside IAM, model safeguards and existing security controls. Its role is to apply organisational authority when a proposed action could create a real consequence.

  1. 01What did the AI propose?
  2. 02Which governed context applied?
  3. 03What was it authorised to do?
  4. 04What decision was returned?
  5. 05What effective action was recorded?
  6. 06Can the evidence be examined afterwards?

These vendor-sponsored surveys indicate a direction of travel; they do not represent every organisation or prove PF Systems performance.

A controlled first step

Start with one workflow—not a platform transformation.

A shadow pilot runs beside existing work. PF Systems evaluates what the AI would be allowed to do, but does not take the live action.

  1. 01Choose one consequential action
  2. 02Exercise all five governed outcomes
  3. 03Review evidence before any production decision

Governed workflow briefing

Which AI action should your organisation govern first?

Tell us the action, its consequence and where authority currently sits. We will help shape a practical discovery or non-actuating shadow-pilot boundary.

The briefing covers
  • The business action and value
  • The authority and escalation boundary
  • The evidence and integration needs
  • The smallest sensible deployment
Request a governed AI briefing

Prefer email? contact@pfsystems.ai