How it is set up: cost, access, data and budgets
Cost visibility, model governance, data protection and budget enforcement are usually four separate tools. AI Control Tower runs them off the same request path and the same ledger.
Cost visibility & budget allocation
Live spend attributed by department, model and vendor, taken from the gateway ledger rather than estimates.
Spend by department, model & vendor
Drill down from the company total to a single virtual key.
Anomaly detection
A default-model switch or a runaway team gets flagged with a projected month-end impact, not discovered on the invoice.
Provider invoice reconciliation
Metered ledger checked against actual vendor invoices monthly, variance reported to the tolerance you set.
Model access & policy governance
Zero Trust by default: a team with no catalog has no model access, and every assignment is explicit. Set up once, then inherited as people join and move.
Model catalogs by data class
You define the catalogs: a standard workplace set, an internal-only set for confidential data, a frontier set for engineering. Each is assigned per department or team.
Changes apply immediately
Catalog rules take effect on the next request, with no redeployment of the applications that use them.
New starters inherit automatically
Directory group membership maps to catalog assignment, so there’s no manual onboarding step.
Decide what each class of data is allowed to reach
Classify your data once. Then, for each class, choose which kinds of model may receive it: third-party models hosted outside the UK, third-party models hosted in the UK or your own internal models. The table below is that policy.
EU-hosted models are governed as a separate jurisdiction, with their own policy row. Rows can be overridden per team where a business case exists, and each override is recorded against the person who approved it. How this is enforced and evidenced
Budgets that enforce, not just report
Thresholds notify early, and at 100% the gateway blocks, throttles or downgrades. Enforcement works from held-and-settled usage, not a monthly estimate.
Multi-stage thresholds
50% notifies the team lead, 80% notifies IT & Finance, 100% triggers the enforcement action you’ve armed.
Block, throttle, or downgrade
Choose per team: a hard stop with a budget-exceeded error, a rate limit or a fall back to a cheaper approved model.
Fail-closed by default
If the control plane is unreachable, AI calls stop. Per-workload fail-open is a policy option for approved production paths.
Walk through your own scenario
Bring a real team, budget and data class, and we’ll configure it in front of you.


