+33 (0)1 87 66 00 65 · Monday to Friday, 9am–6pm Free audit (15 min)
This agent is priced on quotation. This agent is available, and its capabilities really are the ones described below. Its price depends on your estate: how many systems are covered, the volume handled, the connections to open and the service level expected. We therefore price it on quotation, after scoping your need — and the quotation commits the scope. If you already run an agent covering part of this scope, that part is not charged again: only the real extension is priced. Request a quote
● B2B offer — AI governance

AI governance: a living register, evidence attached, decisions signed

Inventory every AI use case, assign accountable owners, assess risks and build audit-ready evidence — without outsourcing legal or business decisions. The agent connects AI systems, models, suppliers, data, evaluations, approvals, incidents and deadlines in a living register. Material conclusions remain sourced, explainable and subject to accountable human review.

Hosted in France System metadata, not your data Dated, versioned sources Named human approval

Updated on

Deployed in a few weeks
AI Governance & AI Systems Register · hosted in France
How many AI use cases are actually running here?
37 declared, 32 once duplicates are reconciled. Eight records are incomplete, and I tell you which field is missing from each.
Is that one high-risk?
I hand you a reasoned, sourced and dated proposal. Your lawyer approves it — and until they do, it carries the label "not approved".
Local inference · no data outside the EU
Register hosted in France
Sovereign by designLocal inference or French hosting
Every rule carries its sourceURL, consultation date and version
TurnkeyDesigned, installed and operated for you
Your accountable people decideThe agent prepares; it never qualifies alone
✦ In brief

A Blue Lemon Agent AI governance agent keeps the living register of your systems, models, versions and suppliers, connects risks, requirements, controls, evidence and deadlines, and prepares your regulatory qualifications with their dated sources. On screen and in exports alike, it separates what is established, what is assumed, what is proposed and what has been decided. Qualification, risk acceptance and go-live authorisation are signed by your accountable people, named and dated.

100 %
hosted in France in the target architecture
0
transfers outside the EU in the target architecture
11
governance modules included in the core offer
0
regulatory qualifications issued without human approval

Reference points describing our offer, not results measured at a client. The scale of the gain on systems inventoried and on the time taken to prepare an audit file is confirmed by a pilot.

The context

What does an AI agent bring to the governance of your AI systems?

Organisations rarely know how much AI they run, who answers for it, and where the evidence sits. The question always lands at the worst moment: an audit, a client, an authority.

! What is at stake

Governing AI requires three mechanical things, and that is exactly what makes them tractable: knowing what is running, knowing who answers for it, and being able to show the evidence attached to the right version. Today those three live in spreadsheets, mailboxes and people's heads. Rebuilding the picture takes weeks, and it is out of date the day it is finished. The agent keeps it continuously: every system carries its purpose, owner, version, supplier and dated evidence; every rule cited carries its address, its consultation date and its version.

Our answer

The AI committee, the executive team and the control functions work from one shared body of material, dated and traceable, instead of rebuilding the inventory for every request. What the agent has prepared is visibly distinct from what has been decided: a proposed classification carries the label "not approved" everywhere, exports included. Qualifying under the regulation, accepting a residual risk, authorising a go-live and notifying an authority are binding acts: they stay signed by the accountable people, named and dated. Local inference or an isolated resource hosted in France.

The decisive point

What the register holds, and what it never holds

A governance register holds system metadata. That is an architectural rule, and it protects your data as much as your exposure.

Local inference

The agent can run on a machine of your own: no register data and no audit file leaves your network.

Metadata, not your data

The register holds a system's name, purpose, version, supplier and owner — never the data that system processes.

Evaluation datasets stay with you

A test set containing personal data stays on your side. The register keeps its reference, its protocol and its result.

Access by role and by entity

Qualifying, accepting a risk and authorising a go-live are named roles, separate from the role that enters data. No implicit cross-entity access.

Every rule carries its source

Address, consultation date and version. A rule without those three is not applied by the agent.

Full, reversible export

You take your whole register back in an open format, with no dependency on the tool.

What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.

  • The applicable location is that of the architecture set out in the quotation and verified before commissioning.
  • Local execution is announced only for the configuration explicitly described and accepted in the quotation.
  • Roles and permissions are configured and accepted for the identities and systems actually connected.
  • The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
For organisations under supervision by an authority or exposed to third-party requests, SecNumCloud and reinforced hosting options are available according to your requirements. A single architecture is designed to answer both GDPR and extraterritorial exposure.
Demonstration

See the agent at work

4 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.

A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.

The company in this demonstration

Fictional company

Vaubrenne Mutuelle — a mutual health and protection insurer, six legal entities including a union and two brokerage arms

Sector
Personal lines insurance: individual and group health cover, protection, direct settlement and a care provider network
Headcount
1,400 staff, including a nine-strong risk function, a head of compliance and an actuarial team of six
Members served
620,000 people covered, 4,300 group contracts, and two managing general agents under delegated authority
Orders of magnitude
4.1 million claims processed a year, 38,000 complaints, 37 declared AI use cases across nine suppliers and four environments
Tools in place
Model inventory kept on a spreadsheet by the risk function, claims system, configuration database, contract vault, complaints tool, internal control document store
Who decides
The head of compliance settles every regulatory qualification; the risk committee accepts residual risks and authorises go-lives; the technical director approves any model touching pricing or the assessment of a benefit claim
Room for improvement
Five use cases are declared two or three times under different names depending on the entity, eight records are incomplete, and four of the 22 controls have no evidence dated within the last twelve months

Vaubrenne's risk committee has always overseen its actuarial models, with independent validation and a file for each. AI came in through other doors: automated claim reading, complaint triage, assistance with protection claim assessment, fraud detection. Those use cases have no file, and three of them bear directly on a member's access to a benefit. The last stocktake requested by the reinsurer took the head of compliance eleven days. The agent is connected to four internal sources and works continuously; every qualification, every risk acceptance and every go-live authorisation goes through the person who answers for it.

This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.

AI Governance & AI Systems Register · hosted in France
Overnight I reconciled your four sources: 37 declared AI use cases, 32 real ones once duplicates are resolved, across your six entities.
The five duplicates, and where I get them from:
· Three entities declare the same claim-reading engine under three in-house names — "Health OCR", "Claim Reader", "Benefits Flow". Same supplier, same version 4.2, same contract number in your vault.
· Two complaint-triage use cases are a single deployment, seen from the parent mutual and from the union.
The eight incomplete records, field by field: four with no named owner — two of them at your managing general agents under delegated authority —, three with no written purpose, one with no model version.
The figure that will interest you most is this one: I cover four of the six sources you named to me. Off-framework purchasing and end-user devices are not open to me. I can therefore assert nothing about what sits there, and I would rather that be written down than counted as zero.
What I have already done: the 32 records are drafted, each with the source it comes from and the date of the finding; the eight incomplete ones carry a precise question addressed to their presumed owner. inventory-status_37-declared-32-real.pdf5 duplicates resolved, 8 incomplete records, coverage 4 sources out of 6
⛓ Source · configuration database, contract vault, complaints tool, internal control document store
The two use cases at the agents — what exactly are we responsible for? They run the book.
That is the most useful question in your portfolio, and I hand you the matrix rather than an answer.
Delegated authority moves the execution, not the duty to know what runs on your members. So for each of the two use cases I have built three lines: what the delegation agreement says, what the agent declares, and what I can verify myself.
· Agent A — pre-assessment tool for pre-authorisation requests. The delegation agreement mentions no automated processing. The agent has declared it since March. A contractual gap, not an inventory gap: the clause did not follow the tool.
· Agent B — incoming document classification. Declared, documented, version known. Nothing to report, and that is worth knowing too.
The possible roles are prepared, not settled: depending on whether you supply the tool, mandate it in the contract, or the agent chose it alone, the role you hold under the regulation changes — and with it your obligations. I have written the three hypotheses with their consequences; your head of compliance settles which one applies. delegated-authority_roles-to-settle.pdf2 use cases, 3 role hypotheses each, consequences in obligations duplicates-reconciled_5-rows.csv3 confirmed by contract, 2 by deployment identifier
⛓ Source · delegation agreements, declarations from both agents, configuration database
And the missing internal owners — how do we find them?
The campaign is ready; it goes out when you say so.
For the four use cases with no owner, I have found who signed the contract, who raised the installation ticket, and which department calls the service most often — three indications, never a conclusion. Each message names the most likely candidate and asks them to confirm or point to the right person.
The message is written, the list is made, the send awaits your mandate. You set the list, the tone and the date; I follow up at day 7 and day 21, and I report the response rate back to you.
Data and rights — the first question your DPO will ask, and I have already worked it through: of the 32 real use cases, 19 process members' personal data. For each one I have brought together the stated purpose, the declared legal basis, the announced retention period and whether a transfer outside the Union takes place, and I have set against it the line of the record of processing your DPO keeps. It exists for 14. The other five are AI use cases that no declared processing activity accounts for: I hand them to the DPO by name, with the source that surfaced them and the date of the finding. The record of processing stays theirs — I do not keep it, I give them what they were missing to keep it.
What I do on top, and that nobody has time for: I watch new supplier contracts and new application endpoints continuously. A use case opened next month by the commercial division will appear in your register without anyone having to think about it, with the source that flagged it and the date.
⛓ Source · contract vault, installation tickets, application service call logs
Local inference · no data outside the EU

Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit

Use cases

What does the agent actually do?

Eleven modules included in the core offer. All operate in support, under the approval of the people you name.

Included in your agent The 11 capabilities essential to this promise are included, at no extra cost.

Discovery and inventory

Reconciles the sources you open to it, de-duplicates, flags incomplete records and runs confirmation campaigns with the owners.

Register of systems and models

System, model, version, deployment and use lineage, with a dated history and a dependency map.

Roles and accountabilities

Prepares the role held under the regulation, builds the responsibility matrix and names the points left to settle.

Regulatory qualification prepared

Works through the sourced decision tree, returns a reasoned proposal with its reservations, and flags missing information.

Risks, requirements, controls and evidence

Connects each risk to its requirements, controls, evidence, owner and deadline.

Data and rights

Reconciles sources, purposes, legal bases, retention and transfers with the record held by your DPO, and hands over to them.

Evaluations before go-live

Versioned protocol, authorised datasets, thresholds written in advance, reproducible results with their gaps and their limits.

Suppliers and general-purpose AI models

Checks the completeness of the supplier file, tracks dependencies, restrictions, reversibility and announced changes.

Approvals, changes and versions

Impact analysis, revalidation requirements, approval workflow, change log and rollback plan.

Incidents and corrective actions

Triage, timeline, linkage to the deployed version, action plan and follow-up to closure.

Evidence file, deadlines and AI literacy

Regulatory deadline schedule, log of awareness activities and an exportable audit file.

Controls and safeguards These 8 controls are built into the agent: they frame what it does, whatever plan you pick. They are not chosen and are not added to your order.
Named and dated human approval on every qualification, risk acceptance and go-live Separate established fact, assumption, proposal and approved decision everywhere, exports included Cite every rule with its address, its consultation date and its version, and apply no rule that lacks them Log actions, sources, versions, approvals and exports, with no data leakage Access by role and isolation between organisations, with no implicit access across them Minimise: system metadata in the register, never the data those systems process Display confidence indicators, coverage rates and missing information rather than a zero Replay the regression tests on every change of model or of rule

Need to go further?

These agents handle a different business process, with their own owner and their own price. They are added to this one.

DPO / GDPR support

The record of PROCESSING activities, impact assessments and processor monitoring belong to the DPO support agent. This agent keeps the register of AI SYSTEMS, including those that touch no personal data at all. When an AI use does touch it, this agent flags it and hands the line to the DPO: it does not keep a second record of processing.

DPO / GDPR support from 668 € excl. VAT / month Discover the agent

Regulatory control

Applying a rulebook to documents and returning qualified findings is the business of the regulatory control agent. This agent inventories the system, cites the rule with its address and version, and names the question to be settled; the regulatory control agent then answers it on the documents.

Regulatory control from 721 € excl. VAT / month Discover the agent

Cybersecurity & logs

Correlating events and running the technical investigation of a security incident belong to security monitoring. This agent ties the incident to the deployed model version and follows the corrective action through to closure: a handover, not a duplicate.

Cybersecurity & logs from 601 € excl. VAT / month Discover the agent

End-to-end contracts

Drafting, negotiating and tracking a clause is the business of the contracts agent. This agent reads a model's supplier file — documentation, usage restrictions, announced changes, exit terms — and flags what is missing or what the contract failed to follow.

End-to-end contracts from 702 € excl. VAT / month Discover the agent
Does your need fall outside this?

In 15 minutes we identify the most relevant agent — without oversizing the project.

Book the free audit Build your agent
The gain

How long does preparing a file take today?

By keeping the inventory and the evidence current, effort shifts towards the decisions that need an accountable person. The scale of the gain depends on your portfolio and is confirmed by a pilot.

Rebuilding the inventory of AI use cases
Today · rebuilt for every request
Kept current
Gathering the evidence for an audit file
Today · searched through mailboxes
Attached to the version, exportable
Tracking deadlines and expired evaluations
Today · listed by hand
Schedule kept
Illustrative, non-contractual reference points, to be confirmed by a pilot on your number of systems and your volume of evidence. Qualifying under the regulation, accepting a risk and authorising a go-live are binding acts: they belong to your accountable people.
How it works

The stages of your AI agent project

1

Audit & scoping

15 minutes to target the use case with the best return.

2

Quote or direct sign-up

A catalogue offer is bought online; a specific need gets a costed quote.

3

Design

We design the agent and its guardrails.

4

Integration & testing

We connect your tools to the agent, which is itself hosted in France.

5

Rollout

Going live and training your team.

6

Operation

Continuous supervision and improvement.

Pricing

On quotation

Scoping, perimeter, integrations and level of oversight to be confirmed. The price depends on the number of systems, entities and connected sources: it is set after a scoping session, never before.

This agent is priced on quotation. This agent is available, and its capabilities really are the ones described below. Its price depends on your estate: how many systems are covered, the volume handled, the connections to open and the service level expected. We therefore price it on quotation, after scoping your need — and the quotation commits the scope. Request a quote
Our commitment

Four commitments that matter for your governance

Your data stays with youLocal inference or an isolated resource hosted in France; no register data entrusted to a third party, no data used to train a model.
Every rule cited is datedAddress, consultation date and version. The law changes: an undated reference does not say which point in time it speaks from.
Your accountable people signQualification, risk acceptance, go-live authorisation and incident closure each carry a name, a date and a reason.
A file, not a certificateThe exported audit file states on its first page that it is neither a certification nor an attestation of conformity. Those acts belong to the conformity assessment procedures and the competent authorities.
Frequently asked questions

Your questions, our answers

Does the agent certify compliance with the AI Act?
No. It structures the inventory, prepares the analyses and gathers the evidence. Qualifications and decisions remain approved by the accountable people, and the exported file states on its first page that it is not a certificate.
Can it detect every AI used across the organisation?
It reconciles the sources it is given access to — purchasing, contracts, the application catalogue, the configuration database, code repositories, business declarations — and runs confirmation campaigns with the owners. The coverage reached is displayed, and the areas no source covers are named.
Does it replace the GDPR record of processing?
No. It connects AI use cases to the DPO's work and to the record of processing without replacing them. An AI use case that processes personal data is flagged and handed over to the DPO / GDPR support agent.
Can it handle external suppliers' models?
Yes, for the documents, dependencies, restrictions, changes and evidence that are available. Where a supplier publishes nothing, the agent records the information as missing and names the question to put to them.
How are decisions controlled?
Every classification, risk acceptance, go-live authorisation and incident closure carries a named accountable person, a date, a reason and an audit trail. Until a proposal is approved it carries the label "not approved", on screen and in exports.
Can sensitive data be used?
The register holds system metadata, not the data those systems process. An evaluation dataset containing personal data stays with you: the register keeps its reference, its protocol and its result. The demo uses fictional data only.
Let's talk

Let us scope your AI portfolio

15 minutes to scope your systems, entities and sources — hosted in France, supervised, no commitment.