Prompt injection
Untrusted instructions can try to steer an agent toward actions its operator never intended.
AI is moving from answering questions to remembering, using tools, accessing credentials, executing code and taking actions across real systems. GCF is being built as the governed control layer between AI intelligence and real-world authority.
GCF separates intelligence from authority, so persistent AI can become more capable without automatically gaining unrestricted access or control.
// this timeline is honest, not curated. It shows what was true at each point, including the rebuilds, dead ends and changes in direction.
Long-term idea for an AI assistant that persists and stays local.
Memory, tools, credentials, authority - governance architecture emerges.
Governance, memory, routing, tools, authority separation become core.
GCF architecture reaches a stable baseline for forward dev.
GCF FrameWorks Ltd formed. Move to formal company, raise, validation.
Runtime, governance, model config, internal test evidence.
Stability, regression, closeout - before the next stage.
Controlled evaluators, adversarial testing, security assessment.
Limited cohort after hardening to test reliability and demand.
The risk changes when a model is no longer only generating text. A manipulated, compromised or simply incorrect model should not automatically inherit control over the systems around it.
Untrusted instructions can try to steer an agent toward actions its operator never intended.
A model error should not become permission to access sensitive systems, credentials or data.
Code execution, APIs, files and deployment tools turn bad decisions into real system changes.
Capability can grow faster than the controls governing what the system is actually allowed to do.
GCF places a governed control layer between the model and the real world. The model can think. It cannot act on its own.
The AI can reason. The wider system owns persistence, permissions and authority.
// Public website language avoids internal version labels. Detailed engineering stages remain in technical documentation.
The project has working internal evidence, including a technical evidence pack capturing the runtime, governance block, model configuration and internal test evidence from prior runs.
ISAC is the first product built on GCF. It demonstrates the architecture working on a single realistic user: a persistent assistant with controlled authority.
Read about ISACShow ambition without making unverifiable commercial commitments.
Technical teams and organisations deploying persistent AI with organisational data, software, tools and internal systems, where permission boundaries, audit and controlled authority matter.
Personal assistants with continuity and user-controlled memory, permissions and connected services.
Longer-term deployments across robotics and other private-sector physical systems, where AI actions can affect the real world and governed authority, human override and independent hardware safety controls become critical.
Explore greater capability per unit of compute, while preserving the same principle: more intelligence does not automatically mean more authority.
The round is intended to accelerate engineering, independent security work, compute, external validation and productisation. The aim is not to "finish an assistant". It is to test the architecture seriously against the problem it was built to address.
Investor briefThe research-log personality is part of the site's strength. Historical posts can stay historical while the main company pages carry the updated story.
Proposed new founder essay explaining why GCF separates intelligence from authority.
A technical walkthrough of memory, tools, credentials, policy and high-authority actions.
A product-facing piece connecting ISAC's continuity to GCF's provider-independent architecture.