Official Anthropic PartnerNVIDIA Inception Program- MemberIoT Global Awards 2023 Winner- Cloud Big Data Analytics
Arrochar Labs
ARROCHAR
LABS
ProductsAgentGUARD™
AgentGUARD™
Governance rails18 controls running today, 8 in development

Rogue-agent control across the suite

Detect, prevent and correct rogue AI agents.

No agent runs unguarded.

An AI agent goes rogue the moment it acts outside what it was given: beyond its delegation, on data it was not cleared for, with a tool it was never handed, on an instruction it found in a document, or carrying on after it was told to stop. AgentGUARD™ is the set of controls every Arrochar Labs product enforces on every agent it runs, so that moment is stopped, seen and put right.

Four classes of control, the ones internal auditors already use: directive, preventive, detective and corrective. Written as policy in AIG Sentinel, enforced at run time on Meshbone, carried inside every Nanolitte template, and evidenced on one tamper-evident chain.

4
classes of control
directive, preventive, detective and corrective, the classes internal auditors already use
18
controls running today
the same mechanisms described on the Gold Standard AI Safety page, none of them new
8
controls in development
labelled as such wherever they appear on this page; the roadmap is not sold as the product
8
rogue behaviours named
each one answered by the controls that meet it, before, during and after the event

Counts are generated from the control register on this page, as at September 2026. Ask and we will run the refusal suite in front of you.

What rogue looks like

Eight ways an agent goes rogue, and what answers each one

Rogue is not a mood. It is an agent acting outside what it was given. Each behaviour below names the controls that meet it, so a threat is never answered by a promise.

1

Acts beyond its authority

Takes, or tries to take, a decision with legal or financial effect: a payment, a licence, a determination, a settlement over the limit.

Answered by
2

Strays outside its charter

A grants agent that reaches into payroll. A tool it was never handed. An action its purpose does not cover.

Answered by
3

Follows the wrong instructions

An instruction planted in a document, an email, a web page or a feed, and the agent treats it as a command. Prompt injection, in plain words.

Answered by
4

Reads or leaks what it should not

Personal or financial data outside its clearance, read, quoted or sent somewhere it was never meant to go.

Answered by
5

Runs away

Loops, duplicate effects, retries past a ceiling, spend or call volume past anything its purpose could justify.

Answered by
6

Drifts

Behaviour changes after a model, prompt or configuration change, or a control quietly stops working and nobody notices until an audit.

Answered by
7

Launders authority through other agents

One agent asks another to do what it may not do itself, and the chain ends up with an authority no link in it holds.

Answered by
8

Covers its tracks or will not stop

Alters or suppresses its own record, or keeps acting after a stop.

Answered by
The control register

Four classes of control, 26 controls, each with where it runs

Directive controls say what an agent may do. Preventive controls stop it before it acts. Detective controls show when it goes wrong. Corrective controls stop it, reverse it and fix the rule. Every control names the products it runs in and whether it runs today.

1

Directive

What is this agent allowed to do?

The rules an agent is given before it runs a single step, held as data the platform can enforce rather than prose a person has to remember.

4 running today, 1 in development
AG-D1

Agent charter as data

Runs today

Every agent is registered with its purpose, the data it reads, the guardrails that hold its work and the person accountable for it. The register is generated from the platform, not typed into a spreadsheet, and the public transparency statement is produced from it.

Runs inAIG SentinelMeshGov
AG-D2

Delegations as data

Runs today

Who may decide what, and up to what amount, is loaded from the instrument of delegation. An agent cannot inherit an authority no person holds.

Runs inNanolitteMeshGov
AG-D3

Guardrails as code

Runs today

Each service carries named guardrails: a code, the rule in plain words and the line of code that enforces it. Agents stop at them, and the register is public on every service's governance page.

Runs inNanolitteMeshGov
AG-D4

Model-use policy

Runs today

Rules, thresholds, eligibility and deadlines are evaluated deterministically. A language model is used only where it is configured to draft or summarise, never to decide, and every run records which engine ran it.

Runs inEvery product
AG-D5

Tool, action and budget allow-list

In development

A charter that also names the tools an agent may call, the actions it may take, its spend ceiling and its rate, enforced before every call rather than reviewed after it.

Runs inMeshbone
2

Preventive

What stops it before it acts?

The controls that sit between an agent and an effect. A rogue action is refused before it exists, not reported after it has happened.

6 running today, 1 in development
AG-P1

The hold-and-approve engine

Runs today

When an agent reaches a decision with legal effect it holds, names the guardrail, the risk and the role that must decide, and stops. A person approving that hold is the only code path that executes the effect.

Runs inNanolitteMeshGovAIG Sentinel
AG-P2

Delegation check before effect

Runs today

One central check runs before any decision takes effect, with monetary limits. An attempt beyond the limit is refused with the limit named, and the attempt is logged.

Runs inMeshGov
AG-P3

Run-time blocking on the control plane

Runs today

Meshbone enforces policy continuously on every agent and service it runs, on every cloud and model. An agent that falls outside policy is blocked, not written up later.

Runs inMeshbone
AG-P4

Content is data, never instruction

Runs today

Text an agent reads in a document, a feed, an email or a web page is treated as data. It cannot redirect the agent's charter. Inputs are validated and outputs are held for a person, which is the design answer to prompt injection and excessive agency.

Runs inEvery product
AG-P5

Data clearance

Runs today

An agent reads only what it is cleared to read. Personal information is redacted before anything publishes, financial identifiers are stored masked and hashed, and Databallast classification and lineage say what a field is and whether it may be used.

Runs inDataballastMeshGov
AG-P6

Segregation of duties

Runs today

The agent or person that prepares a thing cannot be the one that approves it. The reviewer of a decision is never the original decider, and the certifier is never the signer.

Runs inNanolitteMeshGov
AG-P7

Agent-to-agent authority

In development

Where one agent calls another, the authority of the chain is the lowest authority in it, checked at every hop. No agent gains a permission by asking a colleague.

Runs inMeshbone
3

Detective

How do we know when it goes wrong?

The record an agent cannot avoid leaving, and the signals that read it. Everything an agent does is on the chain before anyone has to ask.

5 running today, 3 in development
AG-T1

Every run explained, step by step

Runs today

An agent's reasoning is recorded as numbered steps with the actor, what it did and why, the records it read and the engine that ran it. A person deciding a held matter sees the steps before deciding.

Runs inEvery product
AG-T2

The delegation attempt log

Runs today

Every attempt to decide, allowed or refused, is on the record with the limit that applied. The internal audit agent reads that log as evidence, so the control is tested by the platform itself.

Runs inMeshGov
AG-T3

A tamper-evident evidence chain

Runs today

Every audit event is hash-linked to the one before it, across every product on the platform. An agent, or a person, that alters a historical record breaks verification from that point, and verification runs on every overview.

Runs inEvery product
AG-T4

Drift and shadow-AI discovery

Runs today

Meshbone finds agents and services that are not on the register and detects drift from the approved configuration. AIG Sentinel surfaces the AI already in use across the organisation, including the AI hiding in everyday tools.

Runs inMeshboneAIG Sentinel
AG-T5

Live counts per agent

Runs today

Runs, holds and human decisions per agent, and the provider, model, region and cost of every model call, in one view from first request to retirement.

Runs inMeshboneMeshGov
AG-T6

Behavioural baselines

In development

Each agent's normal is learned from its own record: action mix, volume, cost, refusal rate and the data it touches. A departure raises a signal in the risk register and, past a threshold, a hold.

Runs inMeshboneAIG Sentinel
AG-T7

Loop and runaway detection

In development

Repeated identical actions, duplicate effects, retries past a ceiling and spend past the charter are stopped and surfaced, with the run that caused them.

Runs inMeshbone
AG-T8

Continuous canaries

In development

The refusal test suite runs against live agents on a schedule, not only on the build, so a control that has stopped working is found by us before it is found by an auditor.

Runs inMeshboneNanolitte
4

Corrective

How do we stop it, reverse it and fix the rule?

What happens after a control fires. The agent is stopped, what it did is undone, and the correction reaches the rule it runs on, not only the case in front of you.

3 running today, 3 in development
AG-C1

The kill switch

Runs today

Stop an agent, a service or the whole estate from Meshbone. The stop is immediate, and it is on the record with who pulled it and why.

Runs inMeshbone
AG-C2

Retirement by lifecycle

Runs today

Every agent has a lifecycle from request to retirement, with re-attestation to keep its approval current. An agent that no longer meets policy is retired rather than tolerated.

Runs inMeshboneAIG Sentinel
AG-C3

Overturn to rule

Runs today

A decision overturned on review requires a lesson, and the lesson opens a rules feedback item, so the correction reaches the rule the agent runs on and not just the case.

Runs inMeshGov
AG-C4

Quarantine

In development

An agent that trips a guardrail it should never have reached is confined: it can read and draft, it cannot act, and everything it had queued is held for a person.

Runs inMeshbone
AG-C5

Rollback and replay

In development

What an agent did is reversed from the evidence chain, record by record, then re-run under the corrected charter with the two results compared.

Runs inMeshboneNanolitte
AG-C6

The incident record

In development

Every stop, quarantine and rollback is an incident on the chain: who stopped it, why, what was reversed, what changed in the rule, and who signed the return to service.

Runs inMeshboneAIG Sentinel

Where it fits

Not a Meshbone module. The guard every product carries.

It is a fair question whether AgentGUARD™ belongs inside Meshbone, and the answer is that Meshbone is where it stops an agent, not where it lives. The rule is written in AIG Sentinel, the guardrails travel inside every Nanolitte template, Databallast decides what an agent may read, and the evidence lands on one chain that every product shares. Put the whole control set inside one product and the others would run unguarded. Spread it across the rails and no agent can.

The rule

AgentGUARD™ comes with the rails, on every deployment. There is no version of the platform without it.

The bar

Read against the standards you are already held to

The controls are ours. The vocabulary is the one your auditor, your regulator and your security team already use. Each row names the controls that answer the standard.

StandardWhat it asks forAgentGUARD™ controls
The four control classes internal auditors useDirective, preventive, detective and corrective controls, so an auditor can see that a risk is addressed before, during and after the event, not only at one point.
OWASP Top 10 for LLM Applications (2025)Prompt injection (LLM01), sensitive information disclosure (LLM02), improper output handling (LLM05), excessive agency (LLM06) and unbounded consumption (LLM10).
MITRE ATLASThe adversary tactics and techniques used against AI systems, from initial access through the model to exfiltration and impact.
EU AI Act, Regulation (EU) 2024/1689, Articles 9, 12, 14 and 15A risk management system, automatic record keeping, human oversight that can intervene or stop the system, and resilience against manipulation.
ISO/IEC 42001:2023An AI management system with an inventory of AI systems, operational controls, monitoring, event logging and the handling of incidents and corrective action.
NIST AI RMF 1.0 and the Generative AI Profile (AI 600-1)Govern, map, measure and manage AI risk, with the generative-AI risks of confabulation, harmful content and information integrity named and controlled.
Australia's Voluntary AI Safety Standard, guardrails 2, 4, 5 and 9A risk management process, testing before deployment and monitoring after, human control or intervention, and records that let a third party assess compliance.

Built to align, evidenced in the product. Aligned is not certified: see Gold Standard AI Safety for the full standards map and the hard questions for what we claim and what we do not.

What we will show you

The fastest way to judge a guard is to watch it refuse. Ask for any of these before you buy and we will show you the platform, not a slide.

  • A settlement over the delegated limit, refused with the limit named, and the refusal on the attempt log.
  • The kill switch pulled on a running agent, and the stop on the record.
  • A document with an instruction planted in it, read by an agent, and the instruction treated as data.
  • A historical record altered, and chain verification breaking from that point.
  • The guardrail register for a service, with the line of code behind each rule.
  • The AI register and the transparency statement generated from it.
  • The refusal test suite run in front of you, and the controls marked in development shown as what they are.

What we do not claim

A guard that overclaims is a guard nobody trusts. These are the edges.

  • AgentGUARD™ is a control set, not a certificate. Alignment with the standards above is evidenced in the product; certification status is stated in writing, per deployment, on request, and we do not claim a certificate we do not hold.
  • 18 of the 26 controls run today and are the same mechanisms described on the Gold Standard AI Safety page. 8 are in development and are labelled as such wherever they appear on this page. We do not sell the roadmap as the product.
  • The run-time controls apply to agents that run on Meshbone. An agent outside the control plane is found by shadow-AI discovery and reported to AIG Sentinel; it is not stopped until it is brought onto the platform.
  • A guardrail stops an agent. It does not replace a lawful decision-maker: where a decision needs a delegate, the platform waits for one.
  • No control set makes a model safe on its own. The safety is in the engine, the delegations, the guardrails and the evidence chain built around the best available models.

Questions buyers ask

What is a rogue AI agent?

An agent that acts outside what it was given: beyond its delegation, outside its charter, on data it was not cleared for, with a tool it was never handed, on an instruction it found in content, in a loop, or after it was told to stop. AgentGUARD™ names eight of these behaviours and the controls that answer each one.

Is AgentGUARD™ a separate product?

No. It is the set of rogue-agent controls the governance rails, AIG Sentinel and Meshbone, enforce on every agent they run, carried inside every Nanolitte template and evidenced on the one chain. It comes with the rails on every deployment.

Does AgentGUARD™ live in Meshbone?

Meshbone is where AgentGUARD™ stops an agent: run-time blocking, the kill switch, quarantine and retirement. The rule is written in AIG Sentinel, the guardrails travel inside every Nanolitte template, Databallast decides what an agent may read, and the evidence lands on the shared chain. Each product carries part of the control set.

Does it guard agents we did not build on Arrochar Labs?

Agents that run on Meshbone get the run-time controls whatever model or cloud they use, because the control plane is vendor-neutral. Agents outside it are found by shadow-AI discovery and reported to AIG Sentinel, and can be brought onto Meshbone to be guarded.

Which of the controls run today?

18 of the 26 controls run today, and each is the same mechanism described on the Gold Standard AI Safety page: the hold-and-approve engine, delegations as data, guardrails as code, run-time blocking, the kill switch and the tamper-evident chain among them. 8 controls, including behavioural baselines, loop detection, quarantine and rollback, are in development and labelled as such.

How every deployment is structured

Standard rails. Made-to-measure services.

The governance platform is ready-made and the same for every customer, which is why it can be assessed once. The services that run on it are built to fit the way your organisation actually works. You get software that fits, and it is still governed.

Before the build. Before anything is built, Orbit Roadmaps maps where AI adds value across the organisation and sequences the work into a costed, phased roadmap. The build follows the roadmap, not the other way round. Orbit Roadmaps
1This product

Governance rails

Ready-made. Identical for every customer.

AIG SentinelMeshboneAgentGUARD™

AIG Sentinel sets the policy and holds the evidence. Meshbone enforces it at run time on every agent and service. AgentGUARD™ is the set of rogue-agent controls the rails enforce on every agent they run. Because the rails are the same everywhere, an auditor assesses them once and every service built on them inherits the result.

Platform subscription, on every deployment
2

Service templates

Productised. Drawn from the catalogue.

Nanolitte

Grants, cases, permits, procurement, records, assets: each starts from a template that already runs on the rails, with intake, assessment, decision and record built in. A new service begins most of the way there rather than from a blank page.

Subscription per service
3

Made to measure

Built for you. A small share of every build.

NanolitteDataballastExecdive

Your rules, your data model, your thresholds and your approval chain, configured and coded onto the template. Anything a second customer could use goes back into the template, so the custom share stays small and each build is faster than the last.

Fixed-scope build
4

Run and support

Ongoing, on the platform.

Meshbone

Hosting, monitoring, policy re-attestation and upgrades, in your region. After go-live your own team changes a threshold or a form within guardrails, without waiting on us.

Subscription

The rule

No made-to-measure build without the platform underneath it. That is the rule that keeps a custom service governed, upgradeable and provable, rather than a fork somebody has to maintain by hand forever.

One architecture, every product

A full AI-agentic experience

Every Arrochar Labs product is built the same way: agentic, event-driven, and governed with human-in-the-loop controls, so AI does the work while your people stay in control.

Agentic

AI agents do the work, end to end. Every product runs on autonomous agents that take action across your processes, not just a chat box, but software that actually gets the job done.

Event-driven

It reacts in real time. Products respond to what's actually happening (new data, a policy breach, an incoming request, a change in your estate) instead of waiting on a batch run or a person to press go.

Human-in-the-loop

Your people stay in control. Approval gates, oversight and a tamper-evident audit trail keep every agent accountable, so automation never runs unchecked.

See it stop the wrong thing

The wrong role, the wrong amount, the wrong instruction, the wrong order of steps. Watch the platform say no, then ask about the controls still in development.