Sovereign Provenance · §08
AI AGENT ECOSYSTEM
15 June 2026 · Institutional Memorandum
17-Agent Sovereign Intelligence Ecosystem
A single 17-agent intelligence spine absorbs each asset class without duplicating logic. Agents are organised into functional layers — sourcing and provenance, integrity and audit, pricing and yield, and a portfolio Trust ROI engine — and operate against 1,550+ verified sovereign and institutional data sources.
The ecosystem is architected to compress audit cycles from months to minutes, surface hash-divergence and counterparty drift in real time, and translate operational telemetry into capital-markets-grade disclosure.
Outputs are deterministic, cryptographically signed, and exportable into institutional reporting formats consistent with Article 8/9 fund disclosure, CBAM verification, and EU and UK sanctions frameworks.
Specific agent functions, model architectures and decision logic are disclosed under qualifying NDA to institutional counterparties.
Regulatory & Governance
TIAKI is architecturally compliant with GDPR, EU Data Sovereignty, DORA, the EU AI Act (High-Risk Category), and the EU Digital Services Act Article 22 (Trusted Flagger). The architecture also satisfies the technical control requirements of SOC 2 (Trust Services Criteria) and ISO 27001:2022 Annex A.
GDPR & EU Data Sovereign
Full data-residency and processing sovereignty across EU member states
DORA-Aligned
Digital Operational Resilience Act alignment for financial-sector infrastructure
EU AI Act (High-Risk Category)
Conformity assessment and risk-management systems for high-risk AI deployment
DSA Article 22 (Trusted Flagger)
Trusted flagger status under the EU Digital Services Act for systematic content and risk flagging
SOC 2 (Trust Services Criteria)
Technical control architecture satisfying security, availability and confidentiality trust criteria
ISO 27001:2022 Annex A
Information security management controls mapped across 93 Annex A objectives
Control Evidence Matrix
Each control below is implemented in the production codebase today and maps to named clauses in the cited frameworks. Operational deployment artefacts (penetration testing, ISMS audit, SOC 2 Type II window) are scheduled ahead of first institutional pilot.
Mapping reflects architectural alignment and design intent. Formal SOC 2 and ISO 27001:2022 certification will be obtained at pilot scale; sequencing and target windows are disclosed under NDA. See our Forward-Looking Statements notice.
Trust ROI Engine · Agent #17
Verifiable AI Provenance — institutional trust, priced as capital.
Every engagement of the 17-agent ecosystem emits a deterministic Source Authenticity Certificate — a cryptographically signed attestation of the data mix, regulatory anchors, and model lineage that produced the output. Institutional buyers receive evidence-by-default, not assurance-by-marketing.
Outputs are grounded in TIAKI's proprietary Knowledge Base via retrieval-augmented generation, cross-referenced against 1,550+ verified sovereign and institutional sources, and rendered through a fixed 6-dimension spine with vertical-specific weight matrices.
A composite Trust score translates qualitative governance posture into a basis-point capital-cost compression band that the treasury, audit committee and underwriter can defend in the same room — closing the gap between ESG narrative and capital-markets pricing.
Specific weight matrices, dimension calibrations, and signing keys are TIAKI trade secrets and are disclosed only to contracted institutional counterparties under NDA.
Verifiable AI Provenance — Three Pillars of Truth
Sovereign Vault
Proprietary, EU-resident knowledge graph and primary-source register — your data, your models, your jurisdiction. Internal-to-external data ratio engineered at 10:1.
Regulatory Tether
Every output is anchored to a named legal instrument — GDPR, DORA, EU AI Act, DSA Art. 22, CSDDD, CBAM, EUDR, EU and UK sanctions regimes — with a clause-level citation surfaced in the certificate.
Market Intelligence Stream
Continuously synchronised pricing, sanctions, MRV and counterparty telemetry. Static snapshots are explicitly rejected; freshness windows are encoded in the signed payload.
6-Dimension Spine
Cross-vertical scoring architecture with asset-specific weight matrices
Certificate per Engagement
Source Authenticity Certificate emitted on every agent invocation
Capital-Cost Compression
Architected to translate Trust posture into a basis-point band
Deterministic & Replayable
Same inputs → same signed output; full audit-cycle compression
Agent Governance & Infrastructure Trust
The sovereign control layer behind every agent output — governance, residency, and trusted infrastructure, disclosed to institutional standards.
Institutional buyers, sponsors, and underwriters require evidence that the 17-agent ecosystem is operated under defensible governance and on infrastructure that meets EU regulatory expectations. The disclosures below summarise the posture maintained today; the full posture page is available to qualified counterparties under NDA.
Responsible AI · Model Governance
Human-in-the-loop on every high-risk pathway.
- · EU AI Act Art. 6 high-risk classification posture; Art. 11 technical documentation maintained per agent family.
- · Art. 14 human oversight enforced via Digital Bodyguard, Trusted-Flagger, and MRV hash-divergence adjudication.
- · Model-drift, prompt, and output controls versioned alongside the deterministic Source Authenticity Certificate.
- · No autonomous capital action — every settlement-grade output is gated by human adjudication.
Data Sovereignty & Residency
EU-resident by architecture; pseudonymised at ingress.
- · Primary infrastructure operated in EU regions; no third-country processors in the critical path.
- · GDPR Art. 25 privacy-by-design: SHA-256 tokenisation and raw-PII wipe at ingress.
- · Identity, risk, and provenance data isolated across independently controlled tables.
- · Row-level security and
has_role()security-definer pattern on every public surface; no client-side role checks.
Trusted Infrastructure · Sub-processors
Controlled vendor surface, disclosed in full under NDA.
- · Minimal sub-processor footprint, each contracted under GDPR Art. 28 data-processing terms.
- · Service-role credentials held in managed vault; never exposed to the browser surface.
- · Auto-generated client SDK eliminates ad-hoc secret handling in application code.
- · Full sub-processor register, region map, and change-notification policy provided to qualified counterparties.
Compliance Posture Snapshot
Architected to meet institutional certification thresholds.
- · SOC 2 Type II — control environment in place; audit window sequenced ahead of first institutional pilot.
- · ISO 27001:2022 — Annex A controls mapped across the 93 objectives; ISMS scoping under way.
- · Cyber Essentials Plus — secure-configuration baseline operational; certification scheduled.
- · DORA Art. 6–16 ICT risk-management posture maintained from inception.
Sequencing and target windows disclosed under NDA. See our Forward-Looking Statements notice.
Full trust & compliance posture — including sub-processor register, data-residency attestation, responsible-AI policy, and security disclosure programme — available to qualified institutional counterparties via investors@tiaki.ai.
Intellectual Property
7 Pending USPTO Utility Patents
Comprehensive utility-patent portfolio covering cryptographic provenance, multi-asset pricing engines, and agent-orchestration architectures
PCT International Stage
Global patent cooperation treaty filings extending protection to 157 jurisdictions
Priority Date: March – May 2026
Early filing window securing first-mover IP position across core invention families
AI AGENT ECOSYSTEM · 17-AGENT SOVEREIGN SPINE · AS OF 15 JUNE 2026
17-Agent Sovereign Intelligence Ecosystem
A single intelligence spine absorbs each asset class without duplicating logic. Agents are organised into functional layers and operate against 1,550+ verified sovereign and institutional data sources.
A single 17-agent intelligence spine absorbs each asset class without duplicating logic. Agents are organised into functional layers — sourcing and provenance, integrity and audit, pricing and yield, and a portfolio Trust ROI engine — and operate against 1,550+ verified sovereign and institutional data sources.
Agent outputs are not predictions. They are verifiable certificates — timestamped, hash-linked, and bound to a specific provenance batch with an immediate source authenticity certificate. This transforms AI from a black-box cost centre into a TIAKI capital-grade trust instrument.
The ecosystem is architected to compress audit cycles from months to minutes, surface hash-divergence and counterparty drift in real time, and translate operational telemetry into capital-markets-grade disclosure.
Outputs are deterministic, cryptographically signed, and exportable into institutional reporting formats consistent with Article 8/9 fund disclosure, CBAM verification, and EU and UK sanctions frameworks.
§01 Regulatory & Governance
GDPR Art. 22
Full data-residency and processing sovereignty across EU member states
DORA
Digital Operational Resilience Act alignment for financial-sector infrastructure
EU AI Act
Conformity assessment and risk-management systems for high-risk AI deployment
DSA Art. 22 (Trusted Flagger)
Trusted flagger status under the EU Digital Services Act for systematic content and risk flagging
SOC 2 TSC
Technical control architecture satisfying security, availability and confidentiality trust criteria
ISO 27001:2022 Annex A
Information security management controls mapped across 93 Annex A objectives
§02 Control Evidence Matrix
Each control is implemented in the production codebase today and maps to named clauses in the cited frameworks.
Agent Provenance Log
Immutable timestamped record of every agent invocation, input set, and output signature
Cryptographic Hash Chain
SHA-256 linked chain binding each output to its predecessor and source batch
Data Source Register
1,550+ verified sovereign and institutional sources with freshness metadata
Model Version Control
Every agent model versioned, signed, and traceable to a deterministic build
Human Override Log
Mandatory human-in-the-loop gating on every settlement-grade output pathway
Third-Party Risk Register
Continuous sub-processor and counterparty risk monitoring with drift alerts
Incident Response Trail
Structured incident logging with automated escalation and regulatory notification
Audit-Ready Certificate Export
One-click export of Source Authenticity Certificates in institutional formats
Continuous Control Monitoring
Real-time control-effectiveness telemetry with threshold-based alerting
§03 Trust ROI Engine · Agent #17
Verifiable AI Provenance — institutional trust, priced as capital.
Every engagement of the 17-agent ecosystem emits a deterministic Source Authenticity Certificate — a cryptographically signed attestation of the data mix, regulatory anchors, and model lineage that produced the output.
A composite Trust score translates qualitative governance posture into a basis-point capital-cost compression band that the treasury, audit committee and underwriter can defend in the same room — closing the gap between ESG narrative and capital-markets pricing.
§04 Three Pillars of Truth
Deterministic Replay
Same inputs → same signed output, every time. Full audit-cycle compression from months to minutes.
Cryptographic Binding
Every certificate is hash-linked to its source batch, model version, and regulatory anchor.
Institutional Auditability
Export-ready formats compatible with Article 8/9 disclosure, CBAM verification, and sanctions frameworks.
§05 Differentiator Metrics
6-Dimension Sovereign Spine
Cross-vertical scoring architecture with asset-specific weight matrices
Source Authenticity Certificate per Engagement
Every user interaction, every batch query, every capital decision generates a unique, hash-linked certificate instantly. Not a log entry. A provenance artefact.
Capital-Cost Compression
Architected to translate Trust posture into a basis-point band
Deterministic & Replayable
Same inputs → same signed output; full audit-cycle compression
"One spine. Seventeen agents. Evidence by default."
Specific agent functions, model architectures and decision logic are disclosed under qualifying NDA to institutional counterparties. Formal SOC 2 and ISO 27001:2022 certification sequencing and target windows are also disclosed under NDA. See our Forward-Looking Statements notice.


