LatticeFlow AI, a Swiss company that builds evidence-based AI risk tools, launched a single platform on July 15, 2026, meant to discover, evaluate, and govern AI risk in one place. The company describes the LatticeFlow AI Platform as a way to connect governance frameworks directly to technical controls, so that a requirement written into a framework becomes a measurement a company can actually run. Its foundation is AI Atlas, a public registry that maps more than forty frameworks, among them the EU AI Act, NIST, ISO 42001, OWASP, and Switzerland's FINMA rules, to ready-to-run evaluations. The argument behind the launch is that governance should produce technical evidence on a continuous basis rather than a stack of documents reviewed once and filed away.
The release is aimed squarely at agentic systems, the kind of AI that plans, calls tools, and takes actions without a person approving each step. LatticeFlow says the platform combines evaluations tailored to a specific use case, red teaming that adapts to how an agent behaves, and monitoring that re-runs those checks as models, data, and threats shift. Chief executive Petar Tsankov framed the core problem as a longstanding gap between what governance frameworks demand and what organizations can actually measure.
"By mapping AI frameworks to technical controls, we enable enterprises to understand, control and govern AI risk with evidence, continuously,"
Dr. Petar Tsankov, CEO at LatticeFlow AI
The value in governance is moving from documenting a decision toward proving, with evidence, how a system behaves once it is live. LatticeFlow is planting itself firmly on the evidence side of that line, and the launch reads as a bet that agentic AI will make paper-based governance untenable.
Conditions Driving This Change
Enterprises are pushing AI into core business processes faster than their governance can keep up, and autonomous agents change their own behavior in the gaps between the point-in-time reviews that most programs still rely on.
Agentic systems plan, call tools, and act without a human approving each step, which means a policy document written before deployment says very little about what the agent does once it is running.
Regulators and standards bodies have multiplied the frameworks a company must answer to, including the EU AI Act, the NIST AI Risk Management Framework, ISO 42001, and sector rules such as Switzerland's FINMA, and reconciling them by hand is slow and prone to error.
A senior NIST scientist, Apostol Vassilev, has argued publicly that governance has to move out of cyclical, paper-driven reviews and into the operational runtime, measuring and constraining risk while the system runs.
Gartner published its first Magic Quadrant for AI Governance Platforms in 2026, a sign that buyers now treat governance as a distinct category with its own budget rather than a feature bolted onto existing risk and compliance tools.
Regulated industries such as banking and healthcare are moving first, because they carry both the heaviest accountability and the strongest incentive to show a regulator measured evidence rather than written assurances.
Buyers have grown skeptical of check-the-box governance after watching documented, approved systems drift in production, which has created demand for tools that generate proof tied to real behavior.
What AI Governance Looked Like Before This
For most of the past few years, AI governance meant assembling documentation. A company catalogued its models, wrote policies, mapped those policies to whatever regulations applied, and routed the package through an approval workflow that ended in a signature. The record showed that a system had been reviewed and cleared at a moment in time, and for audit purposes that record was the deliverable.
The approach borrowed its shape from the older world of governance, risk, and compliance software, where the artifact that mattered was the attestation. It held up reasonably well when a model was static, because a system that behaved the same way in December as it had in June could be judged once and trusted for a while. Reconciling the growing list of frameworks was tedious work, though a team could map a single control to the EU AI Act and to NIST and consider the obligation met.
The weakness showed up after deployment. A framework could tell a company what good governance required, and yet the company often had no direct way to measure whether its live system still cleared that bar. The distance between the paperwork and the running model was left to periodic reassessment, which meant a system could drift for months before anyone looked again.
What It Looks Like Now
LatticeFlow's launch reframes the deliverable from a document into a measurement. AI Atlas takes a framework and breaks it into technical controls with evaluations attached, so that an obligation written in legal language becomes a test the platform can run and score. The output is evidence, a record of how the system performed against the control, in place of an attestation that someone reviewed it.
The platform stretches that idea across the lifecycle, from foundation models to enterprise applications to agents. It discovers where AI is running inside an organization, evaluates performance and security against the mapped controls, and re-runs those checks as conditions change. For an agent, LatticeFlow adds red teaming that adapts to the agent's behavior, which matters because an agent's actions depend on inputs that keep shifting after it goes live.
The company points to adoption in regulated settings to argue the approach holds up in practice, naming the enterprise software maker SAP, the Swiss energy firm Axpo, and the fintech Unique AI among its customers, alongside its recognition in the inaugural 2026 Gartner Magic Quadrant for AI Governance Platforms. Whether the continuous claim means observing live production behavior or re-running scheduled evaluations is the detail a careful buyer will want pinned down, because those describe two different depths of oversight.
Our Take
AI Governance Take
LatticeFlow is making the right argument at the right time, and it is making it on the axis that separates real governance from its imitation. The claim that governance must produce continuous technical evidence, and that agentic AI makes documentation alone untenable, matches what much of the market has been learning the hard way. Having a NIST scientist and a bank innovation lead make the same case inside the launch gives it weight beyond a vendor's own marketing.
The claim also sets a bar the company now has to clear. Evidence-based governance is only as strong as the connection between the evaluation and the system as it actually runs, and there is a real difference between a platform that re-scores a model on a schedule and one that watches behavior as it happens. Buyers should ask LatticeFlow how often its evaluations run against a live agent, what event triggers a re-evaluation, and where the evidence is captured, because the answers decide whether this is continuous oversight or a faster series of snapshots.
The launch is another sign that the governance category is consolidating around evidence rather than paperwork, the same shift GAIG has documented across the platforms it tracks. Buyers weighing LatticeFlow against other governance and monitoring tools can compare where each one connects to live systems in the AI Governance category at GetAIGovernance.net, where the platforms that generate evidence from real behavior are grouped apart from those that stop at the document layer.