- Modell
- qwen2.5:7b (lokal via Ollama, aihub.iio.space Fallback)
- Erzeugt
- 2026-08-05
- Felder
- 77
- Norm
- Einfache Sprache ~B1 — nicht Leichte Sprache (DIN SPEC 33429)
- Geprüft von
- Operator-Chat-Freigabe (gate.iio-space-einfache-sprache-content-review-v2, Session AGT-1DED3AED) · 2026-08-05
Real governance means:
it actually stops things.
The difference between a policy PDF, an annual audit and real operation is: what happens when the AI is about to do something you don't want to allow?
At IIO: the action stops. A gate opens. A human decides. Evidence is created.
That's real. The annual audit is only proof after the fact.
One gate in 5 steps.
Concrete, not abstract.
Say an agent wants to move Keycloak to production (a risky action). Here's how IIO decides automatically across 5 HITL levels:
Agent submits request: 'Move Keycloak to prod.'
Deterministic engine checks 5 sources: action_type=infra-deploy + scope=prod + risk=HIGH → decides: HITL required
Action STOPS. Operator is notified (Matrix/email), sees the gate details with policy rationale
Operator reviews, may consult colleagues, decides: 'APPROVE' or 'REJECT'. Rationale is documented.
Immediately after the decision: evidence written (operator_id, timestamp, policy_rule, decision, rationale). Immutable, 10 years.
Action runs immediately (low risk, pre-approved policy)
Action runs, but the operator is notified (can review afterward)
Action STOPS. Operator must actively APPROVE or REJECT. Standard for production.
Action is rejected immediately (policy says: not allowed). Operator is notified and can view the rationale.
Action goes to a higher approval authority (e.g. CISO, not the operator)
Seven reasons why
governance is different at IIO
You decide where your data is processed
EU data residency at Hetzner Ludwigsburg. Local models (Ollama) run by default in our own cluster. Cloud providers (OpenAI, Anthropic, US cloud) are only used when local models can't meet the requirement — every request classified and logged, never automatically without control.
The human decides, not the AI
Deterministic policy engine + human HITL gates. No LLM in the compliance path. Zero shadow logic.
EU AI Act Art. 4, 14, 52
Art. 4 AI Literacy (mandatory training) | Art. 14 Human Oversight (HITL gates) | Art. 52 Transparency (retrievable audit trail)
Zero EUR token cost locally
Local inference (Ollama) runs on your own hardware. No API costs for compliance decisions.
Operated in Germany
Intelego GmbH, Ludwigsburg, founded 2004. IT partner with 20+ years of cloud operations.
Evidence is machine-readable
Not a PDF audit report. Real data: gate log, decision rationale, evidence with hashes, retrievable via API. Audit-proof.
Specifically for governance customers:
- No blanket consent to US data transfer: everything runs EU-internally. Your auditor doesn't need to check whether you're secretly running on the OpenAI API.
- Your governance team decides for itself: not IIO's policy, but yours. HITL gates are your tool — you set the rules.
- Evidence is legally cleaner: immutable evidence log instead of an audit report. Timestamps, operator ID, hashes. If you end up in court: "Here's the log."
Four standards. One system.
- Automatic risk classification
- Transparency obligations documented via HITL gates
- Art. 4 AI Literacy — training for all staff
- Audit trail for regulators on demand
- AI Management System (AIMS) documented
- Control catalog with evidence per control
- Continuous posture measurement
- ISMS integration
- EU hosting (Hetzner DE)
- Art. 28 DPA with subprocessors
- Local models as default path, cloud routing only on explicit need — traceably logged
- Cookieless analytics (Matomo)
- Govern / Map / Measure / Manage
- Risk register per AI system
- Incident severity matrix
- Federated wisdom across tenants
When the audit comes,
you're ready.
| Evidence | Status |
|---|---|
| Risk classification per AI system | ✓ automatic |
| HITL decision log | ✓ complete |
| Art. 4 AI Literacy training evidence | ✓ available |
| Data flow documentation (EU residency) | ✓ gapless |
| ISO 42001 control evidence | ✓ 82% PASS |
| Incident history + severity | ✓ retrievable |
| Subprocessor list (DPA) | ✓ current |
What IIO delivers.
And what it doesn't.
What IIO delivers
- ✓ Policy-driven gating: every production-relevant action passes through the PDP
- ✓ Immutable audit trail: every gate decision + rationale + timestamp + operator
- ✓ 5 HITL levels: AUTO < WARN < HITL < BLOCK < ESCALATE (prioritized by risk)
- ✓ EU data residency: Hetzner DE, no US cloud transfer, local models
- ✓ Human decides: no LLM in the compliance path, deterministic logic only
- ✓ GDPR privacy by design: cookieless analytics, Art. 28 DPA, subprocessor list
- ✓ ISO 42001 controls: 82% PASS, control evidence per catalog, continuous measurement
- ✓ EU AI Act Art. 4 Literacy: mandatory training, evidence available
- ✓ Evidence on demand: risk classification, HITL log, training records, incident history
What IIO is not
- – No legal advice: IIO is a technical solution, not legal interpretation. Consult your legal department.
- – No certification by IIO: we are not an accredited body for ISO 42001 or EU AI Act classification. Audits by an external auditor.
- – No liability for customer decisions: if you click APPROVE despite an IIO warning, you make the decision — not IIO.
- – Not automatically compliant: IIO is a framework. You must actively maintain policies, make gate decisions, review evidence.
- – No substitute for a governance team: IIO automates evidence, not strategic decisions. You need a governance team.
- – Not compatible with every LLM: only local models (Ollama, Llama2) or API-bound ones (OpenAI/Claude) — no arbitrary LLM mix.
The rule of three: we name three central things we are NOT. So you're never surprised, and so it's clear: governance is your responsibility. We're the tool.
We say where we stand.
Governance trust doesn't come from claiming perfection. It comes from honesty about the status quo.
Governance check: where does your AI usage stand?
30-minute consultation: EU AI Act classification, policy maturity, next steps. Free.