Latest News Loading latest insight… All insights →

For UK / EU government departments and regulated industries

Sovereign Edge IDN + HEX 165: the complete operating system for governed agentic AI

Grace Blackwell combines its sovereign inference infrastructure with token-level AI governance. Sovereign Edge IDN hosts sensitive workloads inside a controlled UK / EU region, while HEX 165 governs agents, tokens, compliance, runtime security, inference optimisation and immutable audit evidence.

The Grace Blackwell Platform

One system. Two integrated solutions.

The Sovereign Edge IDN (Inference Distribution Network) provides the UK / EU sovereign infrastructure for hosting sensitive AI workloads. HEX 165 governs what runs on that infrastructure: controlling agents, tokens, compliance, runtime security, inference optimisation and audit evidence.

Each can be procured independently, but together they form a complete sovereign operating system for agentic AI in regulated environments.

Hosting infrastructure

Sovereign Edge IDN

A sovereign hosting environment with the Inference Distribution Network (IDN) at its core. Five platform layers operate inside the approved UK / EU region, with deployment options ranging from sovereign connected environments to fully air-gapped operation for the most sensitive workloads.

Data, models, prompts, logs, telemetry and encryption keys remain in region. Where air-gap mode is selected, inbound and outbound connectivity is disabled by design, with ingress and egress controlled through approved transfer procedures.

Explore the Sovereign Edge IDN
Governance platform

HEX 165

The operating platform that runs on the IDN substrate. Four engines govern policy, compliance, runtime security and token cost. Every agent call is enforced, scanned, monitored and priced, with a hash-chained audit log generated by design.

HEX 165 moves AI governance below the application layer and into the execution path itself. It controls what agents are allowed to do, what context reaches the model, how tokens are routed and optimised, when human approval is required, and what evidence is retained for audit, compliance and operational review.

Explore HEX 165
HEX 165 Engines

Four engines. One Platform.

HEX 165 governs more than agent behaviour. It governs the policy they operate under, the compliance obligations they must satisfy, the runtime environment they execute in, and the token cost they generate.

The four engines work as one control plane: Governance, Compliance, STPM and TOPAS. Each is designed to be deterministic, auditable and repeatable, so the same input produces the same authorisation, finding, risk signal or routing decision.

Governance Engine

Policy-as-code for agentic AI. Every agent call is checked before it runs, against identity, scope, clearance band, model permissions, budget and approval rules.

It enforces policy at machine speed, pins model versions to signed manifests, enables rollback when behaviour changes, routes human approvals where required, and records every decision to the hash-chained audit log.

Compliance Engine

Deterministic compliance assessment for agentic AI. One scan evaluates agent code, architecture and documentation across all 16 supported regulatory, security and assurance frameworks, including the EU AI Act, DORA, GDPR and NIST AI RMF.

It surfaces regulatory gaps, cross-framework obligations and agentic risk flags that standard legal checklists often miss. Every finding is traceable to the relevant framework, article, control, paragraph or evidence requirement, producing audit-ready evidence without probabilistic interpretation.

STPM Engine

Sovereign Threat Protection and Monitoring. Kernel-level eBPF telemetry for sensitive AI and data environments, minimised and anonymised at source before export.

The STPM Engine detects abnormal runtime behaviour inside the approved UK / EU region, protects sensitive file paths, identities, commands and network context, and routes high-impact response or evidence reveal through human-authorised controls.

NCSC-aligned and built on open standards including OpenTelemetry, OCSF, Sigma and OPA/Rego, it provides runtime protection without turning telemetry into a second data leak.

TOPAS Engine

Token, Optimisation, Policy, Auditability and Security. Real-time control for AI cost, token flow and inference efficiency.

TOPAS measures cost per completed task, not just cost per token. It applies sovereignty-aware routing, optimises context layout, reduces repeated or structured payloads through GOT (Group of Tokens), and supports reversible compression with restore and validation controls.

It is designed to prevent AI cost overspend before it happens, while preserving policy control, residency, accuracy and auditability.

Explore TOPAS
The Power of Trust

Five-stage validation and assurance

From deployment to governance, token optimisation, runtime protection and reporting, the Grace Blackwell Platform creates a single source of truth for agentic AI operations.

1

Hosting

Deploy AI workloads on our Sovereign Edge IDN or the customer's own infrastructure with HEX 165 installed. Each agent is registered with a defined identity, scope, clearance band and budget from the start, creating the control baseline for everything that follows.

2

Govern

The Governance Engine evaluates every agent call against active policy before it runs. Requests that fall outside the approved scope, clearance, model permissions, or budget fail-safe by design. Where policy requires human oversight, approvals are routed to authorised reviewers and recorded in the immutable audit log.

3

Monitor

The STPM Engine captures minimised and anonymised runtime telemetry from sensitive AI and data workloads. Autonomous detection identifies abnormal behaviour inside the approved UK / EU region, while high-impact response, evidence reveal or de-anonymisation is routed through human-authorised controls.

4

Assess

The Compliance Engine reads the audit log, scans agent code, architecture and documentation, and evaluates the AI estate against the active regulatory and assurance frameworks. Findings are produced deterministically, mapped to the relevant framework obligations, and supported by evidence from the same immutable audit log used for governance, reporting and assurance.

5

Report

Reports per engine produce real-time dashboards and audit log exports, providing stakeholders with a single source-of-truth evidence base. Boards, regulators, internal audit, and external assurance teams can review decisions from a hash-chained audit log created during the platform's runtime rather than reconstructed after an incident.

The Power of Trust

Built on evidence

Sovereign by design

Workload, data, audit evidence and encryption keys stay inside UK / EU territory. Air-gap option for the most sensitive estates. No US-jurisdictional services in the control plane. No CLOUD Act, FISA 702 or IEEPA exposure.

Deterministic by architecture

Policy and regulatory rules run on deterministic engines. No AI interprets law or internal policy. The same input always produces the same authorisation or finding, auditable rule by rule.

Audit by design

Every agent call, model load, approval and policy change is hash-chained to immutable storage as part of normal operation. The chain is independently verifiable by an external auditor.

Open standards, closed boundary

OPA and Rego for policy, OTLP and OCSF for telemetry, Sigma for detection, signed manifests for models. Open at the protocol layer, sealed at the jurisdictional boundary.

Built for those who cannot afford to get it wrong

UK / EU central government. Financial services. Insurance. Healthcare. Energy. Where sovereignty and compliance are not optional.

Book a Briefing