The problem

AI capability has outpaced enterprise control

Regulated organisations are moving agentic AI into production, but most lack control at the point of execution: policy enforcement on every agent call, real-time token cost control, architecture-aware compliance and sovereign control of inference and evidence.

When an incident happens, the evidence collection is scattered across provider logs, applications, approvals, security tools and cloud platforms.

The Grace Blackwell Platform closes this gap by combining Sovereign Edge IDN with HEX 165. IDN hosts sensitive workloads inside the approved UK / EU region. HEX 165 governs what runs on it: enforcing policy, assessing compliance, monitoring runtime behaviour, controlling token flow, optimising cost and recording every material decision to an immutable audit log.

The result is production AI that regulated enterprises can control, measure, evidence and trust.

The Grace Blackwell Platform

One system. Two integrated solutions.

The Sovereign Edge IDN provides the UK / EU sovereign infrastructure for hosting sensitive AI workloads. HEX 165 governs what runs on that infrastructure: controlling agents, tokens, compliance, runtime security, inference optimisation and audit evidence.

Each can be procured independently, but together they form a complete sovereign operating system for agentic AI in regulated environments.

Hosting infrastructure

Sovereign Edge IDN

A sovereign hosting environment with the Inference Distribution Network (IDN) at its core. Five platform layers operate inside the approved UK / EU region, with deployment options ranging from sovereign connected environments to fully air-gapped operation for the most sensitive workloads.

Data, models, prompts, logs, telemetry and encryption keys remain in region. Where air-gap mode is selected, inbound and outbound connectivity is disabled by design, with ingress and egress controlled through approved transfer procedures.

Explore the Sovereign Edge IDN
Governance platform: four engines

HEX 165

The operating platform that runs on the IDN substrate. Four engines govern policy, compliance, runtime security and token cost. Every agent call is enforced, scanned, monitored and priced, with a hash-chained audit log generated by design.

HEX 165 moves AI governance below the application layer and into the execution path itself. It controls what agents are allowed to do, what context reaches the model, how tokens are routed and optimised, when human approval is required, and what evidence is retained for audit, compliance and operational review.

Explore HEX 165
Architecture

The platform, top to bottom

AI Workloads & Agents
Agentic applications
LLM / models
Data sources
APIs & tools
Governance
Engine
  • Policy-as-code
  • Agent control
  • Model versioning
  • Human-in-the-loop
Control · Policy · Approval
Compliance
Engine
  • EU AI Act
  • DORA
  • GDPR
  • NIST AI RMF
Assess · Evidence · Report
STPM
Engine
  • OpenTelemetry / OTLP
  • OCSF event mapping
  • Sigma detection rules
  • OPA / Rego controls
Detect · Protect · Respond
Stakeholders
Boards
CIO / CISO
Compliance
Regulators
Auditors

Token, Optimisation, Policy, Auditability & Security · cost telemetry, sovereign routing and payload efficiency

Immutable Hash-Chained Audit Log

Every policy decision, agent call, model load, approval and system event cryptographically recorded and immutable

Sovereign Edge IDN

Inference Distribution Network · UK / EU air-gapped hosting infrastructure

UK EU
Physical sovereign PoP

UK / EU territory. Sovereign control of people, process and infrastructure.

Air-gapped hardware

LPU inference compute. No inbound or outbound network connectivity.

200 GbE RoCE fabric

Sub-10 ms intra-cluster fabric for compute and storage traffic.

Immutable secure vault

WORM storage for audit logs, evidence and cryptographic keys.

Sneakernet kiosk

Controlled physical ingress / egress via tamper-evident encrypted media.

SC / NPPV3 cleared ops

Cleared personnel. Two-person rule. Full operational assurance.

UK / EU data residency
By design
No CLOUD Act exposure
No FISA 702 exposure
No IEEPA exposure
Sovereign control
Zero Trust architecture
By design
Capability snapshot

What the platform delivers

Sovereign Edge IDNHEX 165 enginesOpen standards
Physical sovereign Point of Presence Governance: policy engine, access, versions, TokenOps, audit, HITL OPA and Rego (policy as code)
Air-gapped compute (High Performance Compute) Compliance: 648 criteria across 4 frameworks, 15 agentic risk flags OpenTelemetry and OTLP (telemetry)
200 GbE RoCE fabric, NVMe-oF storage STPM: eBPF telemetry, privacy gateway, autonomous detection OCSF (security event schema)
Immutable Secure Vault audit storage, UK / EU-controlled HSM keys TOPAS: cost telemetry, sovereignty-aware routing, payload compression, workload ROI Sigma (detection rules)
Sneakernet kiosk under two-person control Cross-engine audit log integration SPIFFE and SPIRE (workload identity)
Designed for

Highly regulated environments

UK / EU central government

SC clearance, sovereign data handling, NCSC alignment, CDDO compliance. AI workloads with citizen impact need defensible governance and audit.

Law enforcement and justice

NPPV3 clearance for policing, the NCA and criminal justice systems. Sensitive investigation topics protected through privacy-preserving telemetry.

Healthcare and the NHS

Special-category clinical data under GDPR and DPIA requirements. The audit log supports CQC, ICO and clinical governance reviews.

Banking, insurance and capital markets

FCA, PRA and DORA obligations. Real-time AI cost visibility for FinOps and CFO reporting. Audit evidence for SS1/23 model risk management.

Deployment

Four ways to deploy

OptionSubstrateTypical buyer
Full air-gapSovereign Edge IDN, UK / EU-controlled physical PoPDefence-adjacent, intelligence, classified caseloads
Sovereign cloudYour UK / EU sovereign cloud, HEX 165 installedUK central government, FCA-regulated firms, NHS Trusts
HybridHEX 165 on-premises, Sovereign Edge IDN for the sensitive subsetMixed estates with a classified subset
HEX 165 standaloneCustomer-managed infrastructure, no IDNCommercial regulated firms, EU enterprises

Scope a 90-day proof of value

Bring one regulated workflow, one named policy authority, one target environment and one compliance framework. We scope a controlled proof of value across all four components.

Book a Briefing