IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Istari launches AI security managed operations with Cranium

Istari launches AI security managed operations with Cranium

Wed, 5th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

ISTARI has launched an AI security managed operations service with Cranium AI for enterprise clients managing AI systems across their organisations.

Delivered by ISTARI and built on Cranium AI's platform, the service is designed to identify, govern, certify and protect AI systems throughout their working life. Those systems include models, agents, datasets, tools and third-party AI products used within a business.

The launch comes as companies face growing pressure to show that AI governance operates in day-to-day practice rather than existing only in internal policy documents. It also reflects a wider shift as AI adoption moves from limited testing to a board-level issue in large organisations.

Designed as a single managed offering, the service puts one provider in charge of operational work that many companies may struggle to staff internally. That work includes discovery and inventory, governance and compliance operations, adversarial testing and certification, runtime guardrail operations, AI vulnerability management and reporting.

Use case focus

Rather than treating each model or dataset as a separate governance object, the service is organised around what the companies describe as a governed use case. In practice, that means assessing the combination of users, models, agents, memory, datasets, tools and connected systems involved in a specific piece of AI-enabled work.

Each use case is then risk-tiered and moved through what Cranium calls its AI Trust Loop: Discover, Observe, Govern, Secure and Prove. Review and sign-off requirements rise with the level of risk, while certification steps are aligned with frameworks including the EU AI Act, NIST AI RMF and ISO/IEC 42001.

Once an AI use case is operating in production, Cranium's platform monitors prompts, responses and agent actions against configured policy in real time. ISTARI's analysts handle policy tuning, alert triage and other decisions that require human oversight.

The service can be adapted to different levels of delegated authority. Clients can use ISTARI for strategic advice and recommendations, or allow the firm to carry out agreed actions within defined thresholds.

Governance gap

The launch highlights a gap that has emerged across many large organisations as AI tools spread faster than governance and security teams can build oversight processes. While standards and frameworks for AI risk management have multiplied, many remain difficult to translate into routine operating controls across business units, external suppliers and newer forms of AI agents.

Cranium and ISTARI are positioning the service around that problem, arguing that businesses want practical governance embedded in live systems without slowing deployment while they build specialist teams from scratch.

"AI adoption inside enterprises is outpacing the governance processes built to support it," said Jonathan Dambrot, Chief Executive Officer and Co-founder of Cranium. "AI Security Managed Operations is designed to close that gap in practice, bringing Cranium's AI security and governance capabilities together with a delivery team that operates them day to day on the client's behalf."

ISTARI traces its origins to Temasek and was established in 2020 as a cyber advisory business focused on resilience and emerging technology risk. Cranium is based in the New York metropolitan area and sells an AI security and governance platform covering the model lifecycle.

The service is being offered in three editions: Advise, Operate and Autonomous. Onboarding typically takes eight to 12 weeks before reaching steady-state operation, depending on the size of a client's AI estate.

That structure suggests the companies expect varying levels of appetite among customers for handing over operational control in AI governance. Some businesses may want outside help mainly for policy and oversight, while others may prefer a managed model for continuous monitoring, testing and response.

The emphasis on a single accountable provider also reflects a common complaint among corporate buyers that AI risk management is often split between cloud suppliers, software vendors, internal security teams, legal staff and business units. Pulling those strands into one operating model is likely to be part of the sales pitch, especially for multinational companies dealing with overlapping governance frameworks.

"In the exponential age, adoption moves at one speed and governance at another, and that gap is where the real risk lives," said Rossa Shanks, Chief Executive Officer of ISTARI. "This new service exists to close it: to let clients adopt AI at full pace while we make sure every use case stays governed, evidenced and secure in production. This service gives clients a single accountable partner for that work, with a clear model for how much of the day-to-day decision-making they choose to delegate."