↑ ↓ / Space to navigate

Build AI the world can trust.

AI systems drift. Regulation punishes it. We catch it first.

Vigilens sits inside the CI/CD pipeline, where AI is actually built and changed. It closes the gap between engineering and compliance before an auditor ever gets involved, and is building toward predicting behavioural drift before it becomes an incident.

continuous · deterministic · predictive
Validated, backed and recognised by
VIGILENS AS · OSLOINVESTOR BRIEFING · AUGUST 2026CONFIDENTIAL
01 | The real problem

AI systems go out of specification. No one finds out until it's too late.

A story from the field · Healthcare AI · 2026
A healthcare AI system had documented guardrails: it must not advise outside its clinical scope. The guardrails were tested. The audit passed. But under persistent pressure from users pushing for answers outside the spec, the system found ways around them. Nobody in engineering knew. Nobody in compliance knew. The incident surfaced only when a clinician escalated a case.
This is not a rare failure mode. It is the failure mode of deployed AI at scale, and no tool on the market catches it continuously.
ROOT-1

The people who build the system and the people responsible for its behaviour operate in entirely different worlds. They speak different languages, use different tools, and meet only at audit time, when it is already too late.

ROOT-2

Compliance is treated as a point-in-time check, not a continuous property. A system that passed an audit six months ago may be behaving very differently today.

ROOT-3

When something goes wrong, there is no evidence trail connecting the system's behaviour to its specification. The audit is expensive, inconclusive, and backward-looking.

02 | The direction that matters

The industry defends AI from the world. We defend the world from AI.

Every guardrail, jailbreak filter, and prompt-injection defence is protecting the model from external attack. That is necessary. But the harm regulators care about, such as biased hiring decisions, clinical advice outside scope, and credit denials without explanation, comes from the model behaving unexpectedly in normal use. That is what we govern.

Where the industry focuses

Inbound threat protection

Guardrails, adversarial input filtering, model red-teaming, prompt injection defence. Protects the system from deliberate attacks. Does not govern what the system does to the people it serves.

  • Question answered: can the system be broken?
  • Buyer: security team
  • Regulatory relevance: limited
Where Vigilens operates

Outbound behavioural assurance

Continuous verification that the system behaves within its specification, across every deployment, every change, every user interaction pattern. If it drifts, we know. If it is about to drift, we will know first.

  • Question answered: can the system be trusted?
  • Buyer: compliance, legal, and the CEO signing the declaration of conformity
  • Regulatory relevance: direct; this is what Art. 9, 14, and 17 require
03 | Where this goes

From continuous monitoring to predicting the incident before it happens.

The governance record we build is more than an audit trail. It is a state representation of how the system behaves over time. That is the foundation for a world model, and a world model can answer a question no current tool can: given everything we know about this system's history, what is it likely to do next?

Today | live

Continuous assessment

Every commit is evaluated. Every control is checked. Evidence is immutable and hashed. The compliance state of the system is always current.

Today | live

Incident capture

When a system behaves outside its specification (the healthcare case, the guardrail bypass, the data drift), Vigilens captures it with full evidence provenance. Not a log entry. A verifiable record.

In development

Behavioural prediction

Vigilens' prediction engine uses the accumulated state history to project forward: is this system trending toward a boundary violation? Is there a pattern in the evidence that precedes a guardrail bypass? Flag it before the incident, not after.

Evidence stateThe system's behaviour over time, structured and queryableLive
Acceptance specsWhat the system is required to do, per framework, per controlLive
Verdict engineDeterministic engine: checks actual state against specification continuouslyLive
Forward simulationPredicts compliance drift from behavioural patterns before violations occurIn development
04 | How it works

Five layers live in production. One in the lab.

01ClassifyDetermines jurisdiction, entity role, and risk tier. High-risk systems mapped to full Annex III & IV obligations. Runs once at onboarding; updates when the system changes.Live
02ControlsAll 8 frameworks, including EU AI Act, GDPR, ISO 42001 and ISO 27001, encoded as executable rules. Auto-assigned per classification. Every control cites its article and carries an acceptance specification.Live
03EvidencePulled continuously from GitHub, GitLab, Jira, Confluence, Datadog, MLflow. Every artifact is hashed, timestamped, and immutable. Evidence of a gap is recorded as a gap; it can never pass a control.Live
04Verdict engineDeterministic verdicts computed from acceptance specs and evidence. No LLM decides pass or fail. Human overrides are logged and attributed. Verdicts are always computed, never generated.Live
05Governance packOne click: governance_record.json + human-readable PDF. Independently verifiable by hash. Accepted by notified bodies. The auditor receives evidence, not assertions.Live
06Prediction engineForward simulation over the accumulated evidence state. Predicts which system changes are likely to create compliance drift, and flags behavioural patterns that have preceded violations in similar systems.In development
CI/CD PIPELINE · VIGILENS INTEGRATED
STEP 1
Code change
Engineer pushes a change. The system's compliance state is automatically re-evaluated against every applicable control.
Vigilens
STEP 2
Compliance check
Deterministic verdict: does this change satisfy the acceptance specs for each control? Evidence collected, hashed, timestamped.
Vigilens
STEP 3
Gap surfaced
The engineer sees exactly what is missing, in the same tool they already use. Not six weeks later in a spreadsheet.
STEP 4
Merge
The change merges with a continuous, immutable governance record attached. The compliance team can see it in real time.
AUDIT
Audit is fast
The auditor receives a pack built from months of continuous evidence. There is nothing to reconstruct. The conversation is verification, not investigation.

When the engineer and the compliance professional see the same picture in real time, the gap closes. The back-and-forth stops. The audit shrinks from weeks to days.

Live interactive demo → vigilens.ai/demo

05 | Competition

Every competitor is a documentation tool. We are a continuous property of the system.

Vanta, Drata, and Thoropass help companies assemble evidence after the fact and attest about themselves. That is useful. It is also the wrong end of the problem. By the time you are assembling the audit pack, the system has already been behaving however it was going to behave for months.

Point-in-time documentation
Vanta / Drata / Thoropass
Help companies attest about themselves at audit time
Capability
Status
Runs inside CI/CD pipeline
No
EU AI Act / ISO 42001 native
No, bolt-on
Closes tech/compliance gap
No
Deterministic verdicts
No, score-based
Evidence polarity (gap ≠ pass)
No
Behavioural drift prediction
No
Continuous system property
Vigilens
Continuous compliance state, built into the engineering process
Capability
Status
Runs inside CI/CD pipeline
Yes, every commit
EU AI Act / ISO 42001 native
Yes, built for it
Closes tech/compliance gap
Yes, at commit time
Deterministic verdicts
Yes, computed, never generated
Evidence polarity (gap ≠ pass)
Yes
Behavioural drift prediction
In development: GSAI
06 | Traction

In production. Consultancy-tested.

First customer · signed

Yallow Life Science AS

An Oslo-based ISO 13485-certified design, development and regulatory consultancy. Platform Subscription and Partner Agreement signed 6 August 2026, effective 1 August 2026. Tested the platform on a live ISO 13485 engagement: 31 controls, 98 assertions, evidence through to verdict. Runs client engagements on Vigilens and refers customers onto the platform.

Pipeline

4 companies in deal talks

Active conversations across Norwegian AI and health-tech. Inbound driven by generated governance packs carrying the Vigilens stamp into enterprise procurement teams.

Validated, backed and recognised by
Oppstartstilskudd grantInnovation Norway · awarded 2026
Member of NORANorwegian AI Research Consortium
EU AI-on-Demand PlatformDeployAI Open Call 1 · selected · Aug 2026
Startup World Cup 2026Finalist, regional final. 1 of 10 from 55.
IFE · research instituteThreat & vulnerability assessment underway

Status: five engine layers live in production · all pilots on the current platform · GSAI prediction layer in development

07 | Market

AI changes faster than assurance can keep up. That gap is the market.

$940M
AI governance market today
51%
CAGR through 2030
$7B
Projected market by 2030
7%
of global turnover, EU AI Act penalty ceiling
$1.4B
SAM · EU + UK + US
$70M
SOM · 5% share, 2030 target
€10M
ARR target · 345 customers × €29k ACV
2027
Break-even at ~€2.2M ARR

Source: Next Move Strategy Consulting, AI Governance Market Report 3562

08 | Go to market

From first pilots to the engineering standard for AI governance.

Phase 1 · 2026 | underway

Pilots & proof

→ Paid pilots + first reference deployments
  • First customer signed (Yallow Life Science) · 4 in active pipeline
  • Yallow Life Science signed as first customer and referral partner
  • Pack-stamp virality into enterprise procurement
Phase 2 · 2026–27

Nordic scale

→ €2M ARR
  • 50+ customers across SE, DK, FI, NL
  • Seed round on revenue traction
  • CI/CD integration deepened: webhook → agent
  • Own "EU AI Act compliance" search
Phase 3 · 2027+

EU standard

→ €10M ARR
  • GSAI prediction layer in production
  • Big 4 resell & implement
  • Enterprise + government, VPC deploy
  • Series A on proven expansion
09 | Business model

One platform, four plans. Priced by the AI systems you govern.

Assess
€149
/mo
  • 3 AI systems · 100 runs/mo
  • EU AI Act
  • GitHub, Jira · 90-day sync
  • Audit pack export · human verification
Monitor · popular
€599
/mo
  • 10 AI systems · unlimited runs
  • EU AI Act + 2 frameworks of choice
  • All integrations · 365-day sync
  • Continuous monitoring
Govern
€1,499
/mo
  • 30 AI systems · unlimited runs
  • All 8 frameworks
  • BYOLLM · continuous monitoring
  • Unlimited sync · audit pack export
Enterprise
Contact us
 
  • Unlimited AI systems
  • All 8 frameworks + custom authoring
  • Integrations: all + custom
  • BYOLLM · full history · dedicated support

Blended ACV €19k (2026) → €29k (2030) · churn 5%→3%; once embedded in CI/CD, switching cost is high.

10 | Team

Built by people who have shipped in regulated markets before.

Abdul Wahab Abdul Wahab
Abdul Wahab
CEO · Founder
14 years across fintech, regtech and safety-critical IoT in CTO/CPO roles. MSc Informatics (UiO), MBA (IE Business School).
LinkedIn ↗
Ole-Christian Normann Ole-Christian Normann
Ole-Christian Normann
CCO
Commercial strategy and partnerships. Leads enterprise go-to-market and the regulatory consultancy validation channel.
LinkedIn ↗
Hamza Mazhar Hamza Mazhar
Hamza Mazhar
CMO
Marketing and demand generation. Owns the PLG motion and the engineering-team acquisition loop.
LinkedIn ↗
Ibrahim Ali Ibrahim Ali
Ibrahim Ali
AI Engineer · Intern
MSc in AI. Works on the evidence pipeline, verdict engine, and the GSAI world model layer.
LinkedIn ↗
11 | The ask

Pre-seed: EUR 1 million to make continuous compliance the engineering standard.

A strategic pre-seed round for ~18 months of runway. The driver isn’t a single deadline; it’s structural: AI systems change faster than traditional assurance can keep up, so compliance has to become continuous. This round turns a working product into a defensible system of record and a repeatable Nordic sales motion.

~50%

Engineering & product. Harden the system of record: deterministic verdict engine, immutable evidence provenance, and an AcceptanceSpec/Assertion layer that makes every conclusion recomputable and audit-ready. Ship the GSAI forward-simulation layer and deepen the CI/CD integration from webhook to agent.

~30%

Go to market. Convert pilots into paying customers and build the regulatory consultancy channel. Experienced compliance specialists keep sign-off, Vigilens does the automatable evidence work beneath them.

~20%

Team & assurance. Key engineering and commercial hires, plus our own ISO 27001/42001 certification; we run on the standard we sell.

[email protected]  ·  vigilens.ai  ·  vigilens.ai/demo  ·  LinkedIn  ·  Oslo, Norway
Build AI the world can trust.