AI Dispatch
vendor · audit

Holistic AI

Holistic AI markets an end-to-end enterprise AI governance platform. Per the vendor's own homepage, it maps controls to the EU AI Act, NIST AI RMF, ISO/IEC 42001 and NYC Local Law 144, and states it provides a full audit trail for regulators and internal review. It describes deployment gates, approval sign-offs and remediation with human oversight, and says Guardian Agents provide run-time oversight, with Sentinel Agents monitoring risk and Operative Agents able to block, redirect, stop or escalate an action. It lists 40-plus specialised tests covering bias, hallucinations, toxicity, privacy, robustness and performance, plus AI red teaming for prompt injection, jailbreaks and adversarial attacks, and says it connects to AWS, Azure, GitHub, Databricks and 20-plus integrations. The vendor states it was named a Challenger in the 2026 Gartner Magic Quadrant for AI Governance Platforms; the report itself is not published on the page checked and we have not verified the placement independently. Customer claims are unnamed - the page says only that it is trusted by global enterprises running AI at scale. No insurance, indemnity or outcome-based settlement terms appear on the page checked.

www.holisticai.comevidence retrieved Jul 31, 2026 – Sep 23, 2026view as JSONall audit entries1 alternative
ThinFewer than 12 fields evidenced — this vendor discloses little, or we have read little of it

10 fields evidenced · 39 with no public information. Every value below links to the document it came from and the date we checked it.

1 of those is flagged for review: our own check found language in the cited source that may address the field. An editor has not adjudicated it yet.

Runtime governance
2/3

Are scope, spend, and authority enforced while the agent runs?

Re-grounded 2026-10-04 against the current capture (2026-09-23). Vendor describes deployment gates, approval sign-offs and remediation with human oversight, and says Guardian Agents provide run-time oversight with Operative Agents able to block, redirect, stop or escalate an action. Not 3: scope, spend and authority limits are not published as enforced at run time. The prior rationale cited "kill switches" from the 2026-07-31 capture; that term no longer appears on the page, replaced by the intervention wording above.

Our automated recount on Sep 27, 2026 counted enough evidenced fields for 1/3. It never reads what those fields say, so it does not overturn the score above, judged on Oct 4, 2026 — but where the two disagree it is a reason to read this dimension again. Why there are two scores

Audit trail
2/3

Is there a tamper-evident record of what it actually did?

Re-grounded 2026-10-04 against the current capture (2026-09-23). A record exists and is customer-reviewable: the page states a full audit trail for regulators and internal review, and "Build audit-ready evidence. Record decisions, versions and mitigations. Export compliance reports for review." Not 3: nothing published claims the trail is tamper-evident or hash-chained. The prior rationale quoted "continuous audit trails, evidence collection and compliance reporting, audit-ready from day one" from the 2026-07-31 capture; that wording is no longer on the page, though the substance survives in the current one.

Our automated recount on Sep 27, 2026 counted enough evidenced fields for 1/3. It never reads what those fields say, so it does not overturn the score above, judged on Oct 4, 2026 — but where the two disagree it is a reason to read this dimension again. Why there are two scores

Compliance
2/3

Are compliance obligations attached per engagement?

Re-grounded 2026-10-04 against the current capture (2026-09-23). Vendor maps controls to the EU AI Act, NIST AI RMF, ISO/IEC 42001 and NYC Local Law 144 and publishes 40+ specialised tests. Not 3: no certification of Holistic AI itself, and no per-engagement compliance schedule, is published on the page checked. The prior rationale cited "automated control mapping and gap analysis" from the 2026-07-31 capture; "gap analysis" no longer appears on the page, control mapping still does.

Our automated recount on Sep 27, 2026 counted enough evidenced fields for 1/3. It never reads what those fields say, so it does not overturn the score above, judged on Oct 4, 2026 — but where the two disagree it is a reason to read this dimension again. Why there are two scores

This score counts Compliance certifications as undisclosed, and that absence is flagged for review — the cited source may address it. If so, this score is too low. How we check absences

Outcome settlement
0/3

Does payment depend on a verified result?

No public evidence found. The page checked states no outcome-linked payment, fee-at-risk or settlement term.

How this gap gets closed →
Insurance & indemnity
0/3

Can the deployment be insured, and is the customer indemnified?

No public evidence found. The page checked names no carrier, cover, limit or customer indemnity.

How this gap gets closed →

Assurance

Insurance available
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Own liability cover
no public information
www.holisticai.com · checked Aug 19, 2026 · source did not state this
Insurance carriers
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Coverage limits
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Indemnification
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Liability cap
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Audit trail
States it provides a full audit trail for regulators and internal review.
“Full audit trail for regulators and internal review”
www.holisticai.com · checked Sep 23, 2026
Tamper-evident log
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Explainability
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Runtime governance
States Guardian Agents provide run-time oversight: Sentinel Agents monitor risk and Operative Agents can block, redirect, stop or escalate an action.
“Apply Guardian Agents. Monitor risk with Sentinel Agents. Intervene with Operative Agents: block, redirect, stop or escalate.”
www.holisticai.com · checked Sep 23, 2026
Permission scopes
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Compliance certifications
no public information

Flagged for review — the source below contains language that may address this field. Not yet checked by an editor. How we check absences

www.holisticai.com · checked Jul 31, 2026
Regulatory alignment
Maps controls to EU AI Act, NIST AI RMF, ISO/IEC 42001, and NYC Local Law 144.
“Align with EU AI Act, NIST AI RMF, ISO/IEC 42001, NYC Local Law 144 and internal policies.”
www.holisticai.com · checked Sep 23, 2026
Outcome-based pricing
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Settlement mechanism
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Asset custody
no public information
www.holisticai.com · checked Aug 19, 2026 · source did not state this
Dispute process
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
SLA terms
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Evaluation coverage
40+ specialised tests covering bias, hallucinations, toxicity, privacy, robustness and performance
“40+ specialised tests. Assess bias, hallucinations, toxicity, privacy, robustness and performance.”
www.holisticai.com · checked Sep 23, 2026
Self-reported performance
no public information
www.holisticai.com · checked Aug 19, 2026 · source did not state this
Service type
End-to-end AI governance platform (identify, protect, enforce) for enterprise AI systems.
“The end-to-end AI governance platform trusted by global enterprises running AI at scale.”
www.holisticai.com · checked Sep 23, 2026
Regulatory status
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Underwriting backing
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Client types
Global enterprises running AI at scale
“The end-to-end AI governance platform trusted by global enterprises running AI at scale.”
www.holisticai.com · checked Sep 23, 2026

Safety

Safety evaluations
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Red teaming
AI red teaming for prompt injection, jailbreaks and adversarial attacks
“AI red teaming. Test for prompt injection, jailbreaks and adversarial attacks.”
www.holisticai.com · checked Sep 23, 2026
Safety policy
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Usage restrictions
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Model or system card
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Incident reporting
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Third-party evaluations
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Data handling
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this

Practicality

Pricing model
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Price point
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Availability
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Deployment options
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Integrations
Connects to AWS, Azure, GitHub, Databricks, and 20+ other integrations.
“Connects to AWS Azure GitHub Databricks 20+ integrations”
www.holisticai.com · checked Sep 23, 2026
Supported regions
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Support model
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this

Ecosystem

Protocols supported
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
API access
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Open source
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Marketplace presence
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this

Impact

User base
Says it is trusted by global enterprises running AI at scale (no named customers or figures)
“trusted by global enterprises running AI at scale”
www.holisticai.com · checked Jul 31, 2026
Deployment scale
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Target sectors
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
High-risk domains
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Documented incidents
no public information
www.holisticai.com · checked Jul 31, 2026 · source did not state this
Market recognition
Named a Challenger in the 2026 Gartner® Magic Quadrant™ for AI Governance Platforms
“Holistic AI Named a Challenger in the 2026 Gartner® Magic Quadrant™ for AI Governance Platforms”
www.holisticai.com · checked Aug 19, 2026

Compared with

Side-by-side on the fields where Holistic AI and the other entry are both on record and actually differ.

In the wire

Reporting backed by the same source documents as Holistic AI’s own evidenced fields.