Independent control, explained
What is vendor-neutral AI governance?
Vendor-neutral AI governance means the authority over what AI agents may do sits outside any single model, agent, framework or vendor. The same rules apply to every agent, whoever built it. The component that proposes an action is not the component that decides on it. Changing AI vendors does not change the controls.
AI Acts. Crelis Decides. · Runtime authorization for AI agents

- Principle
- Who proposes does not decide
- Independent of
- Model, agent, framework and vendor
- Scope
- Actions that matter, not every action
- Outcome
- Allow, require human approval, escalate, or block
Why it exists
Proposing an action is not the same as deciding on it
An AI agent proposes actions. That is its job. Whether a consequential action should go ahead is a separate question, and it may need a separate owner.
Many companies begin with one agent and the controls that come with it. Those controls are useful, and they are a sound place to start. As agents from more vendors arrive, each brings its own controls. The rules a company cares about most may then need one home that does not depend on any single vendor.
This page is about where the decision sits. How each action is decided is explained on the runtime authorization page.
Proposing an action and deciding on it are two different jobs.
How it differs
Each component looks at something different
Each component is useful, and they can run side by side. Vendor-neutral governance is about where the final decision on a consequential action sits.
Component
What it looks at
Where it sits
Model safeguards
What a model says
With the model
Platform-native controls
The agents on one platform
With the agent platform
Agent security
How an agent behaves
Around the agent
Orchestration
The next step in the work
With the workflow
Vendor-neutral governance
What any agent tries to do, whoever built it
Independent of all of them
Orchestration decides what an agent does next. Independent authority decides whether it may.
What independence means
What the rules do not depend on
Vendor-neutral governance does not replace the controls a vendor provides. It keeps the final decision on consequential actions in one place, under the company's own rules.

The model
The rules look at what an agent tries to do, not the model inside.

The agent and framework
Agents built in different ways are held to the same rules.

The vendor
Changing an AI vendor does not change the controls.
What regulators point to
Controls at the moment an agent acts
We publish an independent, primary-sourced reference mapping SAFR, NIST AI RMF and EU AI Act requirements to controls at AI-agent execution time. It cites the source documents and implies no endorsement.
If you are evaluating
Questions to ask about independence
These are questions, not answers. They apply to any vendor, any platform and any team that builds its own controls.
- 01Is the component that decides separate from the component that proposes the action?
- 02Does the same control cover agents built on different models and vendors?
- 03If we change our model or agent vendor, do our rules and records stay in place?
- 04Are the rules and thresholds ours to set?
- 05Can a past decision be shown later without relying on the agent that asked?
Read next
Go deeper
Pages and articles that take one part of this further.
- What is runtime authorization for AI agents?the term, explained
- GREENLIGHTthe product page, the execution visa and the FAQ
- What is enterprise agent governance?one rule across every agent and vendor
- Deterministic policy or LLM-as-judgea post on whether fixed rules or a model should hold the final decision
- Shadow mode for AI agentsa post on observing decisions before anything is blocked
FAQ
Vendor-neutral governance, in short answers
The questions people ask about independent authority over AI agents.
What is vendor-neutral AI governance?
Vendor-neutral AI governance means the authority over what AI agents may do sits outside any single model, agent, framework or vendor. The same rules apply to every agent, whoever built it. The component that proposes an action is not the component that decides on it. Changing AI vendors does not change the controls.
Why might authority over AI agent actions need to be independent of the AI vendor?
So that the one proposing an action is not also the one approving it. For consequential actions, that separation may matter more as a company runs agents from several vendors. An independent authority keeps the final decision in one place, outside any single vendor.
Is vendor-neutral AI governance the same as vendor-agnostic agent governance?
Yes. Both mean the rules do not depend on who supplied the agent. Model-agnostic AI agent controls are narrower. They mean the rules do not depend on which model sits behind the agent. All three describe controls that are independent of what they govern.
Does vendor-neutral governance replace the controls built into an AI platform?
No. Platform-native controls and agent security tools are appropriate and complementary, and they stay in place. Vendor-neutral governance adds one independent place where the final decision on a consequential action is made and recorded.
Is vendor-neutral governance the same as orchestration?
No. Orchestration plans the work: it picks the next step and the tool to use. An independent authority does not plan or direct agents. It decides whether a proposed action may happen: allow, require human approval, escalate, or block. The two do different jobs and can sit side by side.
What happens to our controls if we switch AI vendors?
They stay the same. With vendor-neutral governance, the rules look at what an agent tries to do, not at the model or vendor behind it. A new agent is held to the same rules as the one it replaced.
Which AI models and agents does GREENLIGHT work with?
Any agent whose consequential actions you route through Crelis, model- and vendor-neutral by design. Crelis evaluates what an agent tries to do, not how the model works inside, so switching AI vendors doesn’t change your controls. Tested so far with the agents and SDKs running in our hosted pilot environment; no vendor is certified or endorsed.
Give your agents a green light — safely.
Start in shadow mode on non-production traffic. See every decision GREENLIGHT would have made — before you let it make one.
