ISTARI has launched an AI security managed operations service built on Cranium AI’s platform, giving enterprise clients a single provider for governing and protecting AI systems throughout their working life. The offering arrives as companies face mounting pressure to demonstrate that AI governance operates in practice, not just on paper, and as AI adoption shifts from limited experiments to a board-level priority.
The service covers discovery and inventory, governance and compliance operations, adversarial testing and certification, runtime guardrail operations, AI vulnerability management and reporting. Rather than treating each model or dataset as a separate governance object, it organises work around what the companies call a “governed use case” — the combination of users, models, agents, memory, datasets, tools and connected systems involved in a specific piece of AI-enabled work.
How the service works
Each use case is risk-tiered and moved through Cranium’s AI Trust Loop: Discover, Observe, Govern, Secure and Prove. Review and sign-off requirements increase with the risk level, and certification steps align with frameworks including the EU AI Act, NIST AI RMF and ISO/IEC 42001.
Once a use case is in production, Cranium’s platform monitors prompts, responses and agent actions against configured policy in real time. ISTARI analysts handle policy tuning, alert triage and other decisions that require human oversight. Clients can choose how much authority to delegate — using ISTARI for strategic advice and recommendations, or allowing the firm to carry out agreed actions within defined thresholds.
The service is offered in three editions: Advise, Operate and Autonomous. Onboarding typically takes eight to 12 weeks before reaching steady-state operation, depending on the size of a client’s AI estate.
Closing the governance gap
The launch highlights a gap that has emerged across many large organisations: AI tools are spreading faster than governance and security teams can build oversight processes. Standards and frameworks for AI risk management have multiplied, but many remain difficult to translate into routine operating controls across business units, external suppliers and newer forms of AI agents.
“AI adoption inside enterprises is outpacing the governance processes built to support it,” said Jonathan Dambrot, chief executive officer and co-founder of Cranium. “AI Security Managed Operations is designed to close that gap in practice, bringing Cranium’s AI security and governance capabilities together with a delivery team that operates them day to day on the client’s behalf.”
ISTARI traces its origins to Temasek and was established in 2020 as a cyber advisory business focused on resilience and emerging technology risk. Cranium is based in the New York metropolitan area and sells an AI security and governance platform covering the model lifecycle.
The emphasis on a single accountable provider responds to a common complaint among corporate buyers: AI risk management is often split between cloud suppliers, software vendors, internal security teams, legal staff and business units. Pulling those strands into one operating model is likely to be part of the sales pitch, especially for multinational companies dealing with overlapping governance frameworks.
“In the exponential age, adoption moves at one speed and governance at another, and that gap is where the real risk lives,” said Rossa Shanks, chief executive officer of ISTARI. “This new service exists to close it: to let clients adopt AI at full pace while we make sure every use case stays governed, evidenced and secure in production.”
Why this matters for operations
For operations teams, the service offers a way to embed AI governance into daily workflows without building specialist teams from scratch. Instead of juggling multiple vendors and internal stakeholders for model inventory, compliance checks and monitoring, one partner handles the operational layer — freeing operations staff to focus on deployment speed while staying within regulatory and security boundaries. The ability to delegate day-to-day decisions within defined thresholds also gives operations leaders a clear model for scaling AI for Operations governance without overloading their own teams. For those focused on AI for Cybersecurity Analysts, the service’s runtime monitoring and adversarial testing components directly address the kind of real-time threat detection and incident response that cybersecurity operations need to keep production AI safe.
Your membership also unlocks: