Framework · Education · Assessment · Assurance

Use AI without surrendering control.

A complete program — courses, workshops, assessment and assurance — for organizations that need to decide where AI belongs, how it should be governed, and how to implement it safely, securely and measurably. Own your data, identity, model, action, evidence and exit — not a vendor dashboard.


We do not sell AI. We help organizations decide where AI belongs, where it does not, how it should be governed, and how it can be implemented safely, securely and measurably. Only then do we build.

Sovereignty is not where the server sits

It is who controls the data, identity, model, action, evidence and exit. Local hosting alone is not sovereignty. A policy is not a control until it changes system behavior, and a control is not operating until it is measured. Every FairByDesign product is built on one operating framework:

Agent → Action → Control → Oversight → Evidence

  • Agent — the model, application or agent doing the work.
  • Action — what it may read, recommend, alter or execute.
  • Control — the measures that constrain that action.
  • Oversight — who intervenes, approves, and can shut it down.
  • Evidence — what lets you reconstruct exactly what happened.

Every control connects to a measurement. The same measurements used to govern AI become the measurements used to monitor whether control is being maintained.


What makes this different

  • An AI agent should never have more authority than the evidence and oversight around it.
  • The client should own the infrastructure and evidence — not rent visibility from a vendor dashboard.
  • No black box. No governance theater. Show the action, control, oversight and evidence.
  • Sometimes the correct AI decision is not to automate.
  • Only after the decision, control and evidence are clear should implementation begin.

The program

All five Sovereign AI courses are available to enrol below. Workshops, assessment and assurance are scoped by engagement. To arrange a private organizational cohort, or to ask about team and organizational licensing, book a briefing call.

Courses

Sovereign AI Foundations

SAF-101 · leaders, governance, security, data & ops · no coding

US$499

Decide where AI belongs, retain the control it requires, measure it, and build a defensible 90-day control roadmap.

Leadership, Procurement & Vendor Control

SAP-201 · executives, procurement, legal, risk · no coding

US$599

Challenge provider claims, set ownership and control requirements, and design the exit before the dependency gets expensive.

Toolsets & Control Stack for Builders

SAT-301 · architects, DevSecOps, engineers · coding + Docker

US$995

Assemble an AI stack you can control, monitor, test and replace — with guided, vendor-neutral labs.

Sensitive Data & Regulated Operations

SAR-401 · privacy, security, compliance · Healthcare/PII edition · no coding

US$795

Put AI to work on sensitive, regulated data without letting it leave its boundary — and prove it.

Continuous Sovereign AI Control Assurance

SAC-501 · control owners, security, ops, governance · annual subscription

US$1,495/yr

Keep your controls provably holding: quarterly control-test packs, an updated measurement catalog, and an annual reassessment.

Workshops

Facilitated, separately priced private engagements that turn one real AI use case into explicit decision authority, data boundaries, controls, oversight and measurements. Priced by scope.

  • Sovereign AI Control Design Workshop — for cross-functional organizational teams.
  • Sovereign AI Toolset Review Workshop — for technical teams.
  • Architecture & Data Boundary Workshop — for architecture, security, data and privacy teams.
  • Measurement, Monitoring & Exit Workshop — for security operations, audit and governance.

Assessment, advanced training & assurance

  • AI Risk & Sovereignty Assessment — an evidence-based baseline across AI security, sensitive data, operational authority, provider dependency and measurements, with a prioritized plan. Scoped by architecture and consequence.
  • Enterprise AI Cybersecurity Deep Dive — a role-based program (executive, security architecture, builder/DevSecOps, security operations, red-team orientation).
  • Offensive AI Security Course — advanced, lab-based, for authorized testers only, in an isolated environment.
  • Managed AI Security & Control Assurance — a managed service for production AI environments.

Free & open

The full public edition of the FairByDesign Sovereign AI Control Framework — scope and intended users, governing principles, roles and accountability, the seven control domains and Measurement Catalog, the decision process, evidence requirements, an assessment and maturity method, and a mapping to external standards — is published in full and free to use with attribution (CC BY 4.0), with a companion Sovereign AI Starter Toolkit and a downloadable PDF.


Who it is for

Executives and boards; security, privacy, data and technology leaders; governance, risk, audit and compliance; procurement and legal; enterprise architects, builders and DevSecOps teams; and organizations in regulated or sensitive-data sectors — healthcare, finance, legal, HR, education and the public sector.

How we work

  1. Decide first — where AI belongs, where it does not, and where it need not be used at all.
  2. Define the control, oversight and evidence the use case actually requires.
  3. Choose measurements, and monitor whether control is being maintained.
  4. Only then implement — internally, with another qualified provider, or with SmartAutomate.

Client ownership of production accounts, keys, data, logs, registries, dashboards and exports is non-negotiable. Our tooling reviews are vendor-neutral, with no undisclosed referral compensation.


Frequently asked questions

Does “sovereign AI” just mean hosting models locally?

No. Local hosting is one option, not the definition. Sovereignty is about who controls the data, identity, model, action, evidence and exit. Sometimes local deployment is justified; sometimes it is theater. We help you tell the difference.

Do you certify that our organization is secure or compliant?

No. Courses issue a certificate of completion only. We do not issue accredited certification, do not claim your organization is “certified,” “fully compliant” or “secure,” and do not replace your legal, security, audit, governance or risk functions. Assessments report evidence — observed, evidenced, partially evidenced, not evidenced or not tested.

Are you endorsed by OWASP, NIST, MITRE, ENISA, CSA or ISO?

No. We cite authoritative primary sources and open standards accurately, but no standards body endorses FairByDesign, and we do not imply otherwise.

Can we implement with our own team or another provider?

Yes. Clients may implement internally or use another qualified provider. SmartAutomate offers separately scoped technical implementation, but it is never required.

When can we start?

All five Sovereign AI courses — Foundations, Leadership & Procurement, Toolsets & Control Stack, Sensitive Data & Regulated Operations, and Continuous Control Assurance — are available to enrol now. Workshops and assessments release in sequence. To arrange a private organizational cohort, or to ask about team and organizational licensing, book a briefing call.


Prices shown are indicative individual launch pricing. Team and organizational licensing, private workshops, assessments and managed assurance are quoted by scope. Prices are in US dollars. Your local currency — for example, euros in the EU — and any applicable taxes are shown at checkout or on your quote.

Questions? Contact info@fairbydesign.org — we reply within one business day.