Dashboard
HelpCompliance Architecture › The Four-Layer Compliance Architecture

The Four-Layer Compliance Architecture

Most AI compliance strategies are a policy document and a terms-of-service clause. MAIA's compliance is running code — four independent layers, each operating at a different point in the pipeline, each enforceable without relying on the others.

Layer 1 — Industry Agent Compliance Constraints

Every one of MAIA's 47 specialized agents carries a compliance envelope embedded in its governing rules — a defined scope of what it is authorized to analyze, what language it is prohibited from producing, and what patterns in its own reasoning require escalation before output is delivered. When an agent's rules update, its compliance constraints update with it. This is architecture, not policy.

Layer 2 — Navigator Policy Acknowledgment

Before a rehearsal begins, the Navigator confirms they understand the data handling obligations and prohibited input categories for their detected industry. First-session acknowledgment is comprehensive — covering universal rules and all industry-specific constraints. The acknowledgment is timestamped and written to the session record.

Layer 3 — Data Ingestion Audit Agent (DIAA)

Scans every input — uploaded documents, typed context, connector-sourced data — before it enters the pipeline. DIAA runs before redaction, on raw data, so it sees the full signal before credentials and secrets are masked. It holds prohibited content, notifies the Navigator in plain language, logs only the flag event (never the content itself), and offers resolution paths. Read the full DIAA article.

Layer 4 — Language Audit Agent (LAA)

Reviews every stage output before it reaches the Navigator. The LAA enforces three dimensions: the universal MAIA language standard, your industry's prohibited language patterns, and scope boundary enforcement. Minor violations are rewritten silently. Industry-specific violations surface a brief notice. Outputs that cannot be rewritten compliantly are held and regenerated. Read the full LAA article.

Invisible by Design

The compliance layer is invisible in normal operation. Neither DIAA nor LAA surface to the Navigator unless a flag is triggered. When a flag fires, you receive a brief plain-language notice — no rule citations, no agent names, no technical compliance language. The system is a guardrail, not an interrogation.

Every flag event writes to the session compliance audit log: timestamp, industry, stage, flag category, action taken. content_logged is always false. The flagged content is never recorded. Only the event is.

Was this helpful?

MAIA Decision OS — maiaos.ai

Terms Privacy Contact