Rogue-agent control across the suite
Detect, prevent and correct rogue AI agents.
No agent runs unguarded.
An AI agent goes rogue the moment it acts outside what it was given: beyond its delegation, on data it was not cleared for, with a tool it was never handed, on an instruction it found in a document, or carrying on after it was told to stop. AgentGUARD™ is the set of controls every Arrochar Labs product enforces on every agent it runs, so that moment is stopped, seen and put right.
Four classes of control, the ones internal auditors already use: directive, preventive, detective and corrective. Written as policy in AIG Sentinel, enforced at run time on Meshbone, carried inside every Nanolitte template, and evidenced on one tamper-evident chain.
Counts are generated from the control register on this page, as at September 2026. Ask and we will run the refusal suite in front of you.
Eight ways an agent goes rogue, and what answers each one
Rogue is not a mood. It is an agent acting outside what it was given. Each behaviour below names the controls that meet it, so a threat is never answered by a promise.
Four classes of control, 26 controls, each with where it runs
Directive controls say what an agent may do. Preventive controls stop it before it acts. Detective controls show when it goes wrong. Corrective controls stop it, reverse it and fix the rule. Every control names the products it runs in and whether it runs today.
Directive
What is this agent allowed to do?
The rules an agent is given before it runs a single step, held as data the platform can enforce rather than prose a person has to remember.
Agent charter as data
Every agent is registered with its purpose, the data it reads, the guardrails that hold its work and the person accountable for it. The register is generated from the platform, not typed into a spreadsheet, and the public transparency statement is produced from it.
Delegations as data
Who may decide what, and up to what amount, is loaded from the instrument of delegation. An agent cannot inherit an authority no person holds.
Guardrails as code
Each service carries named guardrails: a code, the rule in plain words and the line of code that enforces it. Agents stop at them, and the register is public on every service's governance page.
Model-use policy
Rules, thresholds, eligibility and deadlines are evaluated deterministically. A language model is used only where it is configured to draft or summarise, never to decide, and every run records which engine ran it.
Tool, action and budget allow-list
A charter that also names the tools an agent may call, the actions it may take, its spend ceiling and its rate, enforced before every call rather than reviewed after it.
Preventive
What stops it before it acts?
The controls that sit between an agent and an effect. A rogue action is refused before it exists, not reported after it has happened.
The hold-and-approve engine
When an agent reaches a decision with legal effect it holds, names the guardrail, the risk and the role that must decide, and stops. A person approving that hold is the only code path that executes the effect.
Delegation check before effect
One central check runs before any decision takes effect, with monetary limits. An attempt beyond the limit is refused with the limit named, and the attempt is logged.
Run-time blocking on the control plane
Meshbone enforces policy continuously on every agent and service it runs, on every cloud and model. An agent that falls outside policy is blocked, not written up later.
Content is data, never instruction
Text an agent reads in a document, a feed, an email or a web page is treated as data. It cannot redirect the agent's charter. Inputs are validated and outputs are held for a person, which is the design answer to prompt injection and excessive agency.
Data clearance
An agent reads only what it is cleared to read. Personal information is redacted before anything publishes, financial identifiers are stored masked and hashed, and Databallast classification and lineage say what a field is and whether it may be used.
Segregation of duties
The agent or person that prepares a thing cannot be the one that approves it. The reviewer of a decision is never the original decider, and the certifier is never the signer.
Agent-to-agent authority
Where one agent calls another, the authority of the chain is the lowest authority in it, checked at every hop. No agent gains a permission by asking a colleague.
Detective
How do we know when it goes wrong?
The record an agent cannot avoid leaving, and the signals that read it. Everything an agent does is on the chain before anyone has to ask.
Every run explained, step by step
An agent's reasoning is recorded as numbered steps with the actor, what it did and why, the records it read and the engine that ran it. A person deciding a held matter sees the steps before deciding.
The delegation attempt log
Every attempt to decide, allowed or refused, is on the record with the limit that applied. The internal audit agent reads that log as evidence, so the control is tested by the platform itself.
A tamper-evident evidence chain
Every audit event is hash-linked to the one before it, across every product on the platform. An agent, or a person, that alters a historical record breaks verification from that point, and verification runs on every overview.
Drift and shadow-AI discovery
Meshbone finds agents and services that are not on the register and detects drift from the approved configuration. AIG Sentinel surfaces the AI already in use across the organisation, including the AI hiding in everyday tools.
Live counts per agent
Runs, holds and human decisions per agent, and the provider, model, region and cost of every model call, in one view from first request to retirement.
Behavioural baselines
Each agent's normal is learned from its own record: action mix, volume, cost, refusal rate and the data it touches. A departure raises a signal in the risk register and, past a threshold, a hold.
Loop and runaway detection
Repeated identical actions, duplicate effects, retries past a ceiling and spend past the charter are stopped and surfaced, with the run that caused them.
Continuous canaries
The refusal test suite runs against live agents on a schedule, not only on the build, so a control that has stopped working is found by us before it is found by an auditor.
Corrective
How do we stop it, reverse it and fix the rule?
What happens after a control fires. The agent is stopped, what it did is undone, and the correction reaches the rule it runs on, not only the case in front of you.
The kill switch
Stop an agent, a service or the whole estate from Meshbone. The stop is immediate, and it is on the record with who pulled it and why.
Retirement by lifecycle
Every agent has a lifecycle from request to retirement, with re-attestation to keep its approval current. An agent that no longer meets policy is retired rather than tolerated.
Overturn to rule
A decision overturned on review requires a lesson, and the lesson opens a rules feedback item, so the correction reaches the rule the agent runs on and not just the case.
Quarantine
An agent that trips a guardrail it should never have reached is confined: it can read and draft, it cannot act, and everything it had queued is held for a person.
Rollback and replay
What an agent did is reversed from the evidence chain, record by record, then re-run under the corrected charter with the two results compared.
The incident record
Every stop, quarantine and rollback is an incident on the chain: who stopped it, why, what was reversed, what changed in the rule, and who signed the return to service.
Where it fits
Not a Meshbone module. The guard every product carries.
It is a fair question whether AgentGUARD™ belongs inside Meshbone, and the answer is that Meshbone is where it stops an agent, not where it lives. The rule is written in AIG Sentinel, the guardrails travel inside every Nanolitte template, Databallast decides what an agent may read, and the evidence lands on one chain that every product shares. Put the whole control set inside one product and the others would run unguarded. Spread it across the rails and no agent can.
The rule
AgentGUARD™ comes with the rails, on every deployment. There is no version of the platform without it.
The charter, the delegations and the frameworks each agent is assessed against are policy in AIG Sentinel, with the approval gates and the audit-ready evidence trail that boards, auditors and regulators read.
The enforcement point. Run-time blocking, the kill switch, quarantine, lifecycle and retirement, for every agent Meshbone runs, on every cloud and model, from one vendor-neutral control plane.
The hold-and-approve engine, the delegations and the guardrails travel inside every service template, so a made-to-measure build starts guarded rather than having the guard added later.
Classification, lineage and AI-readiness per dataset tell an agent what a field means, where it came from and whether it may be used, before the agent reads it.
The AgentGUARD record is data like any other. Execdive answers the plain-language question over it, holds, refusals, stops and cost, with a source for every number.
Every AI opportunity on a roadmap carries a risk profile, so the controls an agent will need are known at discovery, not discovered at audit.
All twenty-one government services run through the same engine, the same delegations and the same chain, which is where most of the refusals on this page were proven.
Read against the standards you are already held to
The controls are ours. The vocabulary is the one your auditor, your regulator and your security team already use. Each row names the controls that answer the standard.
| Standard | What it asks for | AgentGUARD™ controls |
|---|---|---|
| The four control classes internal auditors use | Directive, preventive, detective and corrective controls, so an auditor can see that a risk is addressed before, during and after the event, not only at one point. | |
| OWASP Top 10 for LLM Applications (2025) | Prompt injection (LLM01), sensitive information disclosure (LLM02), improper output handling (LLM05), excessive agency (LLM06) and unbounded consumption (LLM10). | |
| MITRE ATLAS | The adversary tactics and techniques used against AI systems, from initial access through the model to exfiltration and impact. | |
| EU AI Act, Regulation (EU) 2024/1689, Articles 9, 12, 14 and 15 | A risk management system, automatic record keeping, human oversight that can intervene or stop the system, and resilience against manipulation. | |
| ISO/IEC 42001:2023 | An AI management system with an inventory of AI systems, operational controls, monitoring, event logging and the handling of incidents and corrective action. | |
| NIST AI RMF 1.0 and the Generative AI Profile (AI 600-1) | Govern, map, measure and manage AI risk, with the generative-AI risks of confabulation, harmful content and information integrity named and controlled. | |
| Australia's Voluntary AI Safety Standard, guardrails 2, 4, 5 and 9 | A risk management process, testing before deployment and monitoring after, human control or intervention, and records that let a third party assess compliance. |
Built to align, evidenced in the product. Aligned is not certified: see Gold Standard AI Safety for the full standards map and the hard questions for what we claim and what we do not.
What we will show you
The fastest way to judge a guard is to watch it refuse. Ask for any of these before you buy and we will show you the platform, not a slide.
- A settlement over the delegated limit, refused with the limit named, and the refusal on the attempt log.
- The kill switch pulled on a running agent, and the stop on the record.
- A document with an instruction planted in it, read by an agent, and the instruction treated as data.
- A historical record altered, and chain verification breaking from that point.
- The guardrail register for a service, with the line of code behind each rule.
- The AI register and the transparency statement generated from it.
- The refusal test suite run in front of you, and the controls marked in development shown as what they are.
What we do not claim
A guard that overclaims is a guard nobody trusts. These are the edges.
- AgentGUARD™ is a control set, not a certificate. Alignment with the standards above is evidenced in the product; certification status is stated in writing, per deployment, on request, and we do not claim a certificate we do not hold.
- 18 of the 26 controls run today and are the same mechanisms described on the Gold Standard AI Safety page. 8 are in development and are labelled as such wherever they appear on this page. We do not sell the roadmap as the product.
- The run-time controls apply to agents that run on Meshbone. An agent outside the control plane is found by shadow-AI discovery and reported to AIG Sentinel; it is not stopped until it is brought onto the platform.
- A guardrail stops an agent. It does not replace a lawful decision-maker: where a decision needs a delegate, the platform waits for one.
- No control set makes a model safe on its own. The safety is in the engine, the delegations, the guardrails and the evidence chain built around the best available models.
Questions buyers ask
What is a rogue AI agent?
An agent that acts outside what it was given: beyond its delegation, outside its charter, on data it was not cleared for, with a tool it was never handed, on an instruction it found in content, in a loop, or after it was told to stop. AgentGUARD™ names eight of these behaviours and the controls that answer each one.
Is AgentGUARD™ a separate product?
No. It is the set of rogue-agent controls the governance rails, AIG Sentinel and Meshbone, enforce on every agent they run, carried inside every Nanolitte template and evidenced on the one chain. It comes with the rails on every deployment.
Does AgentGUARD™ live in Meshbone?
Meshbone is where AgentGUARD™ stops an agent: run-time blocking, the kill switch, quarantine and retirement. The rule is written in AIG Sentinel, the guardrails travel inside every Nanolitte template, Databallast decides what an agent may read, and the evidence lands on the shared chain. Each product carries part of the control set.
Does it guard agents we did not build on Arrochar Labs?
Agents that run on Meshbone get the run-time controls whatever model or cloud they use, because the control plane is vendor-neutral. Agents outside it are found by shadow-AI discovery and reported to AIG Sentinel, and can be brought onto Meshbone to be guarded.
Which of the controls run today?
18 of the 26 controls run today, and each is the same mechanism described on the Gold Standard AI Safety page: the hold-and-approve engine, delegations as data, guardrails as code, run-time blocking, the kill switch and the tamper-evident chain among them. 8 controls, including behavioural baselines, loop detection, quarantine and rollback, are in development and labelled as such.
How every deployment is structured
Standard rails. Made-to-measure services.
The governance platform is ready-made and the same for every customer, which is why it can be assessed once. The services that run on it are built to fit the way your organisation actually works. You get software that fits, and it is still governed.
Governance rails
Ready-made. Identical for every customer.
AIG Sentinel sets the policy and holds the evidence. Meshbone enforces it at run time on every agent and service. AgentGUARD™ is the set of rogue-agent controls the rails enforce on every agent they run. Because the rails are the same everywhere, an auditor assesses them once and every service built on them inherits the result.
Service templates
Productised. Drawn from the catalogue.
Grants, cases, permits, procurement, records, assets: each starts from a template that already runs on the rails, with intake, assessment, decision and record built in. A new service begins most of the way there rather than from a blank page.
Made to measure
Built for you. A small share of every build.
Your rules, your data model, your thresholds and your approval chain, configured and coded onto the template. Anything a second customer could use goes back into the template, so the custom share stays small and each build is faster than the last.
Run and support
Ongoing, on the platform.
Hosting, monitoring, policy re-attestation and upgrades, in your region. After go-live your own team changes a threshold or a form within guardrails, without waiting on us.
The rule
No made-to-measure build without the platform underneath it. That is the rule that keeps a custom service governed, upgradeable and provable, rather than a fork somebody has to maintain by hand forever.
One architecture, every product
A full AI-agentic experience
Every Arrochar Labs product is built the same way: agentic, event-driven, and governed with human-in-the-loop controls, so AI does the work while your people stay in control.
Agentic
AI agents do the work, end to end. Every product runs on autonomous agents that take action across your processes, not just a chat box, but software that actually gets the job done.
Event-driven
It reacts in real time. Products respond to what's actually happening (new data, a policy breach, an incoming request, a change in your estate) instead of waiting on a batch run or a person to press go.
Human-in-the-loop
Your people stay in control. Approval gates, oversight and a tamper-evident audit trail keep every agent accountable, so automation never runs unchecked.
See it stop the wrong thing
The wrong role, the wrong amount, the wrong instruction, the wrong order of steps. Watch the platform say no, then ask about the controls still in development.
The products it guards
AIG Sentinel
AI governance for any organisation
Orbit Roadmaps
Assess AI opportunities, build the roadmap
Meshbone
A microservices platform for AI
Nanolitte
Full-stack agentic AI for the enterprise
MeshGov
Transform government with AI automation
Databallast
Data ready for AI, at scale
Execdive
AI-driven analytics for executives