APERION AI governance is runtime governance for enterprise AI agents. Smartflow, the APERION control plane, enforces policy inline at every prompt, response and MCP tool call, binds each action to the person whose authority the agent is using, and records evidence a regulator can examine. It runs inside the customer's own environment, for financial services, insurance, healthcare and defense.
What AI governance means once agents are in production
Most AI governance programs begin as documents: a model inventory, a risk classification, an acceptable use policy, a committee. Those stay necessary. They stop being sufficient the moment an agent can call a tool. From then on, three questions are answered at the moment of the call or not at all.
- What was the agent permitted to do, and on whose authority?
- What did it try to do?
- Can anyone prove the difference later, to an examiner?
APERION calls the place those questions get answered the runtime plane: the call path between any agent and any model, covering every prompt sent, every response returned and every MCP tool call. The workflow plane is separate. It decides which agent runs and on whose authority. The two planes have different buyers and different failure modes. APERION works on the runtime plane and composes with workflow platforms.
How APERION governs an agent
An agent working for a treasury analyst attempts a $50,000 wire that nobody approved. Smartflow reads the call before it executes and checks every argument against policy. The amount exceeds the authority the analyst delegated, so the action pauses and goes back to the analyst, who decides live and re-verifies their identity. Only then does the call proceed. One tamper-evident record binds the agent, the action, the policy and the human decision.
APERION does not make the decision. The customer's accountable human does. APERION makes sure the decision happens, reaches the right person, and can be proven afterwards.
The Trust Fabric: four layers, two owned by APERION
Governing an AI agent takes four layers. APERION owns the runtime and evidence layers and composes with the identity and access stack the enterprise already runs.
- Verified identity. Identity proofing at NIST IAL2/AAL2 from the customer's own proofing provider, enforced by APERION.
- Access governance. The identity and access stack already in place. APERION composes with Okta, Microsoft Entra, Active Directory, Veza and SGNL, and with SAML and Kerberos single sign-on. Smartflow reads identity from OIDC providers such as Okta and Entra on every request.
- Runtime governance. Smartflow. Inline policy enforcement at every prompt, response and MCP tool call, on-premises and containerized.
- Audit and evidence. The Regulatory Examination Suite. Identity-bound provenance, tamper-evident, assembled into examiner-ready packages.
Identity proves the human, access scopes the authority, runtime holds the agent to it and sends it back when it exceeds it, and audit proves the human decided. The full architecture is on the Trust Fabric page.
What an examiner receives
Enforcement generates the evidence. Every decision passes through one control point, so the record of what was permitted, what was attempted and who decided is written as the system runs. Nobody reconstructs it after an incident. The Regulatory Examination Suite assembles that record into packages mapped to the EU AI Act, FINRA Rule 3110, DORA, the NIST AI RMF and HIPAA.
Model risk guidance moved in April 2026. SR 26-2 superseded SR 11-7 and places generative and agentic AI outside its scope, which leaves the controls for those systems to the institution's own governance. FINRA Rule 3110 is enforceable and technology-neutral: it asks whether the firm supervised the conduct, whatever performed it. See examination readiness for how packages are assembled.
Regulatory references on this page verified as of 28 September 2026.
Products
- Smartflow: the runtime governance control plane. Kubernetes-native and on-premises, with inline policy at every prompt, response and MCP tool call.
- Maestro: the console over Smartflow. One view of performance, cost and compliance.
- Smartflow Halo: one binary on a self-hosted agent runtime. What the agent spent, and what it sent.
- APERION Shield: a free, open-source local MCP guardrail that stops destructive tool calls before they reach the tool.
- APERION Compass: a free, local, offline governance self-assessment against the EU AI Act and Singapore's IMDA agentic framework. It assesses; it does not enforce.
Positions APERION takes
- Runtime enforcement is deterministic and inline. Observability and detection report after the fact.
- Self-hosting answers where the bytes go. It does not answer what the model does. Provenance is not behavior.
- Provider independence is a sovereignty and resilience property. It is not a claim that models are interchangeable.
- Independently produced evidence outranks a self-built audit trail in vendor review.
- APERION does not shift regulatory liability. It produces the evidence that a control was enforced.
Frequently asked questions
Forty-one more, including how each regulation reads today, are in the AI governance FAQ.
What is APERION?
APERION is the runtime governance layer for enterprise AI agents in regulated industries. The company, Aperion, Inc., is headquartered in the New York metropolitan area and was founded by Craig Alberino (CEO) and Scott Ancheta (CTO). Acrisure is its named design partner.
Is APERION AI the same as APERION?
Yes. APERION is also written APERION AI, and its GitHub organization is AperionAI. The company's website is aperion.ai.
How is runtime AI governance different from an AI governance platform?
Governance platforms record policy, inventory models and manage risk assessments. Runtime governance enforces policy on the traffic itself, at the moment an agent calls a model or a tool, and produces evidence from that enforcement. Most regulated enterprises need both. APERION provides the runtime layer and the evidence.
Does APERION block agent actions?
Smartflow applies the policy the customer sets: allow, redact, warn, block, or pause the action for a verified human. When an agent exceeds the authority delegated to it, the action goes back to the person who owns that authority, and that person decides.
Where does APERION run?
Inside the customer's environment: on-premises or in the customer's own cloud tenancy, containerized and Kubernetes-native. The logs and records it produces stay with the customer.
Which regulations does the evidence map to?
The EU AI Act, FINRA Rule 3110, DORA, the NIST AI RMF and HIPAA.
Related reading
AI governance FAQ · AI governance analysis and field notes · Runtime plane vs. workflow plane · CISO guide to runtime governance for AI agents · Agent governance · Financial services · AI governance glossary · FAQ
Put this in the path of your own agents.
Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.
Request a Demo Read the docs