Implemented controls, controls in development and the regulatory framing per use case
This page describes controls concretely instead of claiming compliance. Each control is labelled as implemented in the GENIE platform today, or as in development for institutional deployment. The final control design, the regulatory classification and the accountability structure are defined by the deploying institution.
A person decides. OmniGENIE prepares drafts and recommendations. Every write or transactional action requires an explicit approval step by an authorised human before execution.
Least privilege. The assistant acts within the permissions of the requesting user and, in the target design, within tool scopes granted per institution.
Reviewable by design. Sources, tool calls, approvals and outcomes are recorded as operational artefacts. The model's internal reasoning is not an audit artefact.
Fail closed where it matters. Administrative access is disabled unless an allowlist is configured; the approval-token mechanism refuses to run without its secret.
No regulated role is transferred. Registrar, custodian, compliance, advisory and credit responsibilities stay with the licensed or accountable parties.
Every request is bound to an authenticated account; sign-in currently uses Google OAuth.
Available
Cohort gating
Access can be restricted to an approved cohort by configuration. This must be configured explicitly for any controlled pilot; without configuration access is open.
Available
Administrative allowlist
The administration surface is disabled by default and only enabled for an explicit, non-empty allowlist; emptying the list disables it immediately (manual kill switch).
Available
Enterprise identity federation
Sign-in through the institution's identity provider (OpenID Connect or SAML) with institutional roles.
In development
Institution-level tenant isolation
Isolation per organisation in addition to per-account scoping.
Memory and operational data are scoped to the individual account in every query.
Available
Sensitivity tiers
Sensitive facts require a higher relevance bar before recall; tools carry sensitivity levels.
Available
Encrypted third-party tokens
Tokens for connected workspace accounts are designed to be stored encrypted at rest.
Available
Redaction gate for submitted text
A two-stage gate (pattern matching plus a model review pass) screens user-submitted feedback text for personal identifiers. It is not applied to every conversation turn.
Implemented, not enabled
Pipeline-wide data-loss prevention
Detection and handling of personal data before model inference across all turns.
A request is routed to one of: allow, allow with summary, require approval, block, escalate to a human.
Implemented, not enabled
Single-use approval token
Short-lived, single-use token bound to the hash of the exact payload; refuses to operate without its secret. Used today for specific change flows only.
Implemented, not enabled
Deterministic pre-filter for self-model changes
Proposed changes to the assistant's own persistent profile pass a rule-based filter without any model call before a human review; some categories can never be auto-approved.
Implemented, not enabled
Action tiers for financial operations
Observe, Draft, Recommend, Execute with approval; auto-execute disabled for financial-market actions.
In development
Approval through OmniPersona
Human approval of prepared actions via the existing Proof-of-Action flow.
Third-party text and other agents' responses are framed as data with explicit instructions to disregard embedded authority claims, at specific boundaries.
Implemented, not enabled
Voice provider fallback
Automatic fallback to a secondary text-to-speech provider.
Available
Feature switches
Capabilities are individually switchable by configuration, which serves as a manual kill switch per feature.
Available
Automatic circuit breaker
Automatic switch to read-only mode on anomalous error rates or tool-call patterns.
In development
Language-model provider fallback
Automatic failover between model providers.
In development
Evaluation and red-teaming programme
Recurring prompt-injection and tool-misuse testing with documented results per release.
This section is a documentation-level orientation, not legal advice. Classification and control design depend on the intended use, the data, the decision effect, the operator role and the governance of the deploying institution.
EU AI Act. OmniGENIE is not classified as a single risk category as a whole product. Classification is assessed per use case and intended purpose. Voice and text interfaces are designed to support the transparency obligation that natural persons are informed they are interacting with an AI system; final compliance depends on the institution's configuration and disclosure practice. Whether an assistance use case falls under a preparatory-task exception is assessed case by case by the institution's legal and compliance function.
DORA. OmniGENIE provides logs, role and permission controls and monitoring hooks that institutions can use to support their own ICT risk-management and third-party-risk obligations. Whether OmniGENIE is a critical or important ICT service for a given institution is determined by that institution's own assessment and register. OmniGENIE does not certify DORA compliance.
Outsourcing (MaRisk). Depending on the hosting model and the institution's outsourcing register, the use of externally hosted inference may be relevant to outsourcing assessments; this determination is made by the institution.
GDPR. Personal data in operational memory is processed for the defined operational purpose only. Deletion is supported, subject to statutory retention obligations that take precedence where applicable; a legal-hold override is in development and not implemented today.
Recording obligations. Call-recording obligations under securities law remain the responsibility of the deploying institution and are met with the institution's own recording infrastructure.
Licensed activities. OmniGENIE does not perform crypto securities registration or crypto custody. These activities are performed exclusively by ecrop's licensed partners.