SOSX®, AI-enabled systems thinking, for any sector.
For heads of AI governance and compliance
Head of AI Governance / Compliance
SOSX is AI-enabled systems thinking: an agentic AI platform for defining, researching and analysing systems-of-systems problems in any sector, with governance built in that makes it safe for enterprise.
If you lead AI governance or compliance, your desk looks something like this: overlapping obligations (EU AI Act deadlines, ISO 42001 certification, NIST AI RMF adoption) across systems no single team fully maps. Compliance documentation is manual, perpetually stale and framework-by-framework. Nobody holds an accurate picture of the system estate. Audits consume months of effort.
The discipline: what AI governance actually involves
This is well-trodden ground for anyone already doing the job, and it is worth setting out plainly, because what follows only makes sense against it. Good AI governance is roughly six habits. Keep an inventory of what you actually run, at the level of the system rather than the model. Classify by use and by consequence, so obligations attach to risk rather than to whoever shouted loudest. Map controls once and express them many ways, because the frameworks overlap far more than they differ and maintaining five parallel narratives is how documentation goes stale. Keep evidence with lineage, an artefact that says where it came from and when, not a screenshot in a folder. Record human oversight as it happened rather than reconstructing it before the audit. And monitor: an obligation met at go-live and never revisited is an obligation you will meet again, unluckily.
There is a reason the evidence habit matters more than the analysis habit. Legge, in Evaluating Planned Organizational Change (1984), observed that evaluation findings tend to be acted on when they confirm what decision makers already intended, and quietly shelved when they disconfirm it. The governance job, then, is not only to produce good findings; it is to make the inconvenient ones hard to discard without anyone noticing. That is a property of the record, not of the analysis.
All six habits can be run with a register, a document set and a great deal of discipline, and plenty of teams do exactly that. The cost is that the estate moves and the documentation does not.
The estate picture first, the compliance story from it
The first thing SOSX builds is the thing this desk has never had: an accurate, connected picture of the estate. It maps systems and their interactions as one typed, parameterised model, and then the compliance story follows from the model instead of being assembled beside it. SOSX is built against ISO 42001, ISO 27001, the EU AI Act, NIST AI RMF and the OWASP agentic top-10: the frameworks your own review will hold an AI system to, so audit-ready outputs stay current with the systems they describe.
The model carries its own evidence: every claim cites a catalogued source; every AI interaction is audit-logged; every high-stakes output is red-teamed by adversary agents; and decision provenance keeps the rationale chain replayable. Documentation assembled by hand over months becomes documentation generated from a live model.
And the standards claim is made the only honest way: SOSX aligns with and produces evidence for these frameworks. Nobody certifies you but your auditor, and we say that plainly, because you have heard the other version before.
Why we think it holds up
- In our live enterprise trials with a large global aerospace manufacturer, engineers interrogated the audit trail, source grounding and approval gates before the analyses: the governance substrate is what makes AI-generated analysis discussable in an engineering review at all.
- An OWL-EL symbolic reasoner derives structural facts with the entailing axioms attached, kept visibly separate from LLM judgement and from simulation: a reader always knows whether a statement is judgement, proof or computation.
- The full framework-by-framework picture is on the compliance page; the engineering practice it grew up in is SOSX Engineering.
The question you are actually asking
The EU AI Act deadline is fixed — which of our AI-containing systems does it touch, and what can I hand the auditor? With SOSX the answer is an artefact, not an assurance: the model, its sources, the approval trail, the audit log, documentation generated in hours rather than assembled over months.
Go deeper
This sector has no companion book of its own: the central book is where the argument it rests on is made in full.

Bring us a real obligation
Bring us a real obligation (the framework you're behind on, the audit that's coming) and let's have a chat about what the evidence trail looks like on one of your actual systems. We would rather work your live question than show you a canned walkthrough.
