← News

Archer Evolv AI Compliance graphic showing regulation mapped to AWS Bedrock guardrails awaiting approval

15 Sep 2026

Archer

Archer ships Evolv AI Compliance so Bedrock guardrails enforce policy before the model answers

Archer announced Archer Evolv AI Compliance, a product that turns regulations and company policies into policy-as-code Amazon Bedrock Guardrails, deployed natively in the customer’s AWS account and enforced before a model responds — whether the prompt came from an employee or an AI agent. The company says it is available today from Archer and on AWS Marketplace.

SAFETY desk — same-day company primary that a major GRC vendor put runtime AI policy enforcement (not just policy documents) into market for agents and employees on Bedrock.

Product, as the same wire has it: it turns the regulations and company policies that already govern an enterprise into policy as code — approved Amazon Bedrock Guardrails, deployed natively inside the customer’s own AWS account and enforced before a model responds, whether the prompt came from an employee or an AI agent. A guardrail here is a rule that blocks or allows a prompt before the AI model runs. Amazon Bedrock is Amazon’s managed service for running foundation models. Every control traces back to the obligation that required it, the company says, and every violation is recorded in the GRC system of record. File that regulation-to-guardrail / before-the-model-answers picture as Archer’s. This desk did not submit a prompt.

Design, still company: no Archer proxy sits in the inference path — the path a prompt takes to the model. Archer connects through a scoped, least-privilege AWS IAM role and reads guardrail configuration and events, not customer AI traffic. IAM is identity and access management — who is allowed to sign in. Prompt content, model responses, documents, embeddings, PII, model weights, and training data do not reach Archer. Only the violation event does: which control fired, who and when, the confidence score, and version history. PII is personally identifiable information, such as a name or ID number. If connectivity to Archer is interrupted, the native Amazon Bedrock Guardrails continue enforcing as last deployed. File that no-proxy / customer-account / only-violation-events picture as Archer’s. This desk did not inspect an AWS account.

Loop, company: Listen → Decide → Act → Assure → Learn. Listen turns regulations, privacy sources, and a company’s own policies into tracked controls, drawing on Archer’s 22 million regulatory documents. Decide turns those controls into draft Amazon Bedrock Guardrails, deployed only after a named owner approves them. Act checks applicable prompts from employees or AI agents before inference, blocking and logging violations. Inference is the model-compute that produces the next answer. Assure tests guardrails on a set cycle against the approved control so drift or tampering can be flagged. Learn routes findings into Archer issue management, tracked to closure on the same system of record. File that five-stage loop as Archer’s. This desk did not watch a control cycle.

Dial, still company: customers choose Observe (log what a guardrail would block), Advise (route a finding and evidence to a named owner), or Enforce (block violations before inference). Nothing moves up that dial without approval, and versions can be rolled back. File that observe / advise / enforce picture as Archer’s. This desk did not flip the dial.

Scope, company: organizational obligations — credentials and secrets such as API keys and tokens; source code and proprietary technical assets; confidential business information such as contracts, pricing, and M&A activity; and company-defined usage rules — plus regulatory obligations, including personal data under GDPR, CCPA, and state privacy law; protected health information under HIPAA; payment and cardholder data under PCI DSS; and regulated categories such as export-controlled data, securities information, and biometric data. Models outside Bedrock can apply the same approved control through the Amazon Bedrock Apply Guardrail API. GDPR is the EU’s data-privacy law. CCPA is California’s. HIPAA is the U.S. health-privacy law. PCI DSS is the card-data security standard. An API is an application programming interface — the machine-to-machine doors a service exposes. File that two-class scope and the Apply Guardrail API line as Archer’s. This desk did not test a model outside Bedrock.

Named voice on the release: Kayvan Alikhani, chief product and technology officer at Archer. He says a guardrail is only as good as the obligation behind it, and that Archer’s customers do not have to build that chain themselves. File the name, title, and that obligation-behind-the-guardrail line as his, via Archer. His other quotes are color only and stay in Sources.

Availability, company: Archer Evolv AI Compliance is available today, directly from Archer and in the AWS Marketplace. File that available-today / Marketplace line as Archer’s. This desk did not open a Marketplace listing. The release does not print a price. This desk is not inventing one.

About-box context, optional and company-attributed: Archer says more than 1,300 organizations run on it, including half the Fortune 500 and 37 of the top 50 global banks. It cites 22 million regulatory documents, 250 million GRC records, and 492 purpose-built models trained since 2017. File those about-box figures as Archer’s. This desk did not count customers or audit the document library. This desk is not inventing named new customers, annual recurring revenue, or examiner-win claims.

Plain English for the rest of the card: guardrail = a rule that blocks or allows a prompt before the AI model runs. GRC = governance, risk, and compliance — the system of record for rules and proof. GA = generally available, offered to buy or use now. Amazon Bedrock = Amazon’s managed service for running foundation models. IAM = identity and access management, who is allowed to sign in. PII = personally identifiable information. inference = the model-compute that produces the next answer. GDPR = the EU’s data-privacy law. HIPAA = the U.S. health-privacy law. PCI DSS = the card-data security standard.

PRIMARY here: Archer’s 15 Sep 2026 Business Wire company release — Tier A PRIMARY company source, the original record. The same-day company blog is company explainer context, not a second originating newsroom. The product page is product-home context, not a second originating newsroom. The Evolv AI Compliance launch, the regulation-and-policy-to-approved-Bedrock-Guardrails picture, native deployment in the customer AWS account, no Archer proxy in the inference path, prompts / responses / documents / embeddings / PII / weights staying off Archer, violation-event-only telemetry, the Listen → Decide → Act → Assure → Learn loop, the Observe / Advise / Enforce dial with named-owner approval, organizational and regulatory obligation scope, the Apply Guardrail API line for models outside Bedrock, the Alikhani title, the available-today / AWS Marketplace line, and the 1,300 / Fortune 500 / 37-banks / 22-million-documents / 492-models about-box are company-attributed. Architecture and capability claims stay company-attributed — not independently audited here. NOT claimed: pricing, named new customers, ARR, independently verified examiner-win results, that this desk tested Evolv AI Compliance, a stock tip, or investment advice. Distinct from the already-filed postman-passport-ga, digicert-ai-trust-manager, wso2-agent-manager-ga, cloneguard-private-ai, stackhawk-wingman, and phrase-atlas-ga.

RELATED

ONLINE

article thread

guidelines

warming…

warming…

On 15 Sep 2026 Archer announced the launch of Archer Evolv AI Compliance. The company PRIMARY is Archer’s Business Wire release “Archer® Launches Archer Evolv™ AI Compliance, Bringing Runtime Guardrails to AI Governance,” dated September 15, 2026, 10:07 ET, SOURCE Archer (newsitem 20260915268837). This desk read the originating company text via a same-day Business Wire reprint after businesswire.com did not return the page from this environment — used to read the company text, not as a second originating newsroom. GRC means governance, risk, and compliance — the system that keeps a company’s rules and the proof that those rules were followed in one place. That company wire is the filing event. These are company claims. This desk did not run Archer Evolv AI Compliance.

Sources