Your CTO group can build things. Your compliance team understands the law as written. The gap between them — translating DUAA purpose compatibility requirements and EU AI Act obligations into actual agent workflow architecture decisions — is where most organisations are currently exposed.
This is not an argument against US technology. Every regulated enterprise in the UK and EU runs on AWS, Azure, Microsoft Office, and US-domiciled SaaS — and will continue to. LGT.io's proposition is not that you replace your cloud provider. It is that the governed artifact proving each AI decision was lawful must be held by you, verifiable without calling back to any vendor, at the moment a regulator, counterparty, or auditor requires it. That artifact is what LGT.io builds. Your cloud infrastructure is unchanged. What changes is who holds the proof.
We published the five-layer governance architecture specification before the Szpruch framework was reviewed by senior model risk and governance leaders at eight major financial institutions. We understand the architecture required not because we consulted on it, but because we built the open specification that defines it.
That provenance is not a marketing claim. It is the practical reason the conversation with LGT.io is different from a conversation with a generalist AI consultant or a governance tooling vendor: we have already done the structural thinking, and we work with you to apply it to your specific deployment.

These are complementary but not dependant on Agentic AI implementation milestones. They are deliverable today, drawing on the open specification, the regulatory compliance mappings, and the architectural knowledge built into the LGT.io Agentic Governance Layer.
A structured assessment of your current agentic AI deployments against the DUAA and EU AI Act governance requirements. We map your exposure, identify the specific gaps in your existing controls, and produce a prioritised remediation roadmap — including which elements require a governance infrastructure substrate and which can be addressed through policy and process changes alone.
Deliverables
A technical engagement mapping your specific agent deployment — tooling, orchestration, data flows, and legacy system interactions — against the five-layer governance specification. We identify where your architecture satisfies governance requirements and where it does not, and produce an architecture recommendation that is both implementable by your team and defensible to a regulator.
Deliverables
A focused engagement for organisations that need to put a number on their ungoverned AI liability before they can justify the governance investment internally. We model the regulatory exposure from current agentic deployments — ICO enforcement, FCA supervisory intervention, EU AI Act penalties — against the cost of remediation. The output is a board-level business case, not a technical document.
Deliverables
The Early Access Programme is for regulated enterprises with a live or planned agentic AI deployment that crosses an institutional boundary — credit decisioning, KYC, settlement, compliance reporting, or model validation — and the internal technical capability to co-develop the governance layer alongside LGT.io.
What we build with partners: working implementations of one or more governance layers with your own developers, your own compliance teams, and the open specification as the architectural blueprint. LGT.io provides the specification expertise, the regulatory compliance mappings, and early access to truc as the reference substrate.
Early access partners receive direct input into the DUAA compliance toolkit and are named references in regulatory and academic submissions. The engagement is structured as a commercial arrangement — not a favour.
Program partners are required to have a live or planned agentic AI deployment with a genuine cross-institutional boundary crossing in scope — not a proof of concept. This programme is not available to vendors or consultancies.
The DUAA is already in force. Start with the Governance Readiness Assessment — it produces the board-ready risk summary you need before the question is asked at an FCA review.
The Agentic Architecture Review maps your specific deployment against the five-layer specification. You get a concrete architecture recommendation, not a generic framework.
The Regulatory Exposure Quantification engagement exists exactly for this. A number the board can act on, not a technical document they cannot.
The Alpha Partner Programme is for organisations that want to be building the standard, not buying it when everyone else already has. The window is open now.
We did not arrive at this problem through consulting engagements with clients who had it. We identified it independently, published the architecture, and are building the reference implementation. The services we offer are an extension of that work — not a separate business model.
Tell us what you are deploying, where the governance gap is, and what decision you need to make. We will tell you which engagement fits — or whether it does not.
Book a callEmail: hello@lgt.io