Skip to content
All services
AI you can governBuild

AI model access and release gates

Give your applications one controlled route to AI models with a keyless fallback, keep model calls in EU regions and hold generative features back until evaluation and data-protection sign-off.

When you need it

Your product teams are adding AI features, and each team wires up its own model API key. Nobody can say which models are called, in which region, or who decided that a feature was ready for customers.

What sets the quote

  • Sized by the AI-enabled apps, model providers and environments in scope.
  • Two weeks: up to 2 AI-enabled apps, 1 model provider and 3 environments (for example development, test and production).
  • Three weeks: up to 5 AI-enabled apps, 2 model providers and 4 environments.
  • Larger scopes are quoted after the call.

What changes

  • Every application calls AI models through one agreed route, with no model keys in code or pipelines.
  • Model calls stay in EU regions, and each AI feature can be switched on or off per environment in infrastructure code.
  • A keyless fallback route is ready if the central AI gateway is unavailable.
  • Generative features reach production only after evaluation and a recorded data-protection sign-off.

What you get

  • Model access design and decision record, reviewed with your team
  • Integration of each app with your central AI gateway as the main route, where you have one
  • Keyless fallback route to the model provider: an IAM role for Amazon Bedrock, a managed identity for Azure model endpoints or a service account for Vertex AI
  • EU region pinning for model calls, set in infrastructure code
  • AI feature switches per environment in infrastructure code
  • Release gate that keeps generative features off in production until the evaluation result and the data-protection sign-off are recorded
  • Runbook for switching routes and turning features off

This package follows a pattern already in production for an AI-enabled application: the app calls a central AI gateway, falls back to keyless model access, keeps model calls in EU regions, switches its AI features in infrastructure code and keeps generative features off in production until evaluation and data-protection sign-off. If you have no central AI gateway yet, the keyless route becomes the main route.

Not included

  • Building or operating an AI gateway (we integrate your apps with yours, or design the pattern with your platform team)
  • Running model evaluations; your team evaluates, and the gate records the result
  • Data protection impact assessments or legal advice
  • Building the AI features themselves
  • Model hosting, fine-tuning or GPU capacity

What we need from you

  • Write access to the application and infrastructure repositories in scope; every change arrives as a pull request.
  • The gateway's endpoint, authentication method and quotas from the team that runs it.
  • A pipeline or platform engineer that can apply infrastructure code in each environment.
  • Named sign-off owners for product, security and data protection.

How it works

  1. Free 30-minute call to count the AI-enabled apps, model providers and environments, then a written fixed quote.

  2. Map the AI features, the models they call and the data they send, then agree the design and the sign-off rules.

  3. Build the routes, switches and gate as code; you review every change as a pull request.

  4. Test a switch to the fallback route and a feature shutdown, then hand over.

At a glance

Duration
2–3 weeks
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect
Assess

AI risk quick scan

In 1–2 weeks, a read-only review of the AI tools, model keys, agents and data flows in your organisation, with the risks ranked and a 30/60/90-day plan to fix them.

Duration:1–2 weeks
Build Popular

Governed AI coding agents

Let your engineers use AI coding agents on real repositories, with written working agreements, grounded answers, read-only cloud access and human consent before every production change.

Duration:1–2 weeks
Build Popular

AI platform landing zone

A governed place in your cloud for AI agents and AI-enabled apps, built as code in four to six weeks: inherited guardrails, approved models and regions only, and a keyless identity for every agent.

Duration:4–6 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.