Competitive Intelligence — June 2026
VAIG Competitive Analysis
Norway · Europe · Global
AI governance and execution-boundary players across all markets. Full map + top 10 deep dives.
Summary
Three findings that matter
The execution-boundary space is nascent, fast-moving, and wide open for a technically rigorous entrant.
No one owns the execution boundary. Governance platforms audit and report — they don't gate. Security companies detect threats — they don't prove authorization. VAIG's deterministic L1 gate + WORM receipt is architecturally unique.
The market is converging fast. Straiker ($21M, Lightspeed/Bain) and Holistic AI's Guardian Agents both launched 2025–2026. The window for a technically deeper entrant is 12–18 months, not longer.
Norway is a first-mover opportunity. KI-loven enforcement August 2026. Cognite ($2.1B) is the primary domestic customer. Standard Norge's prEN 18229-1 (logging for trustworthy AI) maps directly to VAIG's WORM — submit as reference implementation before August deadline.
Full Map
All players — Norway, Europe, Global
~25 players across AI governance, agentic safety, EU AI Act compliance, and runtime security.
| Company | Country | What | Stage | VAIG angle |
|---|---|---|---|---|
| Boost.ai | Norway | Enterprise conversational AI, regulated industries | ~$30M raised | Potential customer |
| ★Cognite | Norway | Industrial AI/DataOps — Atlas AI, oil & gas | $2.1B (Aker) | Tier-1 customer/channel |
| Altek AI | Norway | Autonomous AI agents for hospitality | Seed | Potential customer |
| ★KI-Norge / Nkom | Norway | National AI hub; KI-loven enforcement Aug 2026 | Government | Creates the market mandate |
| Anch.AI → Asenion | Sweden | EU AI Act research; merged with Fairly AI 2025 | Acquired | European policy competitor |
| ★Standard Norge prEN 18229-1 | Norway | Logging standard for trustworthy AI; Aug 2026 deadline | Standards body | Submit WORM as reference impl. |
| Company | Country | What | Stage | VAIG angle |
|---|---|---|---|---|
| ★Holistic AI | UK | AI governance + Guardian Agents (Operative = real-time intervention) | Series A | Most direct European competitor |
| Asenion | Sweden/CA | First ISO 42001 certified platform; EU AI Act end-to-end | Post-acq. | Policy layer — no execution gate |
| ★Lakera → Check Point | Switzerland | LLM security; acquired $300M Nov 2025 | Acquired | Validates space; exit comp |
| Modulos | Switzerland | AI governance SaaS; ISO 42001; EU AI Act | Seed | Policy layer; no runtime |
| Aleph Alpha | Germany | Sovereign European AI; EUR 500M raised | Scale | Infrastructure — not competing |
| Company | Country | What | Stage | VAIG angle |
|---|---|---|---|---|
| ★Straiker | US | Agentic runtime security — Ascend + Defend + Discover AI | $21M (Lightspeed, Bain) | Most direct global competitor |
| ★Credo AI | US | Enterprise governance — Forrester Wave Leader Q3 2025 | Series B | Policy layer — partner angle |
| HiddenLayer | US | ML model security; runtime defense; AISec 2.0 | $50M (M12/MSFT, IBM) | Adjacent; different threat model |
| NVIDIA NeMo Guardrails | US | LLM guardrails toolkit; 3 NIM microservices | Platform | Probabilistic — VAIG determinism differentiates |
| Guardrails.ai | US | Open-source LLM validation library | Open source | Dev tool; no audit, no gate |
| Monitaur | US | AI governance / ML assurance SaaS | Series A | Policy; no execution boundary |
| Arthur AI | US | AI observability, monitoring, bias detection | Series B | Observability only |
| Trustible | US | AI governance; ISO 42001; EU AI Act | Seed | Policy layer |
| Superagent | US | Open-source agent framework with guardrails | Open source | Dev tool; no formal verification |
Deep Dives
Top 10 — detailed analysis
Ranked by direct relevance to VAIG's execution-boundary positioning, market validation, and strategic importance.
Agentic-first AI security. Three products: Ascend AI (adversarial agent testing), Defend AI (runtime security), Discover AI (agent inventory visibility). Backed by Lightspeed and Bain Capital Ventures. Fastest-growing company in the agentic security space — multiple six-figure and seven-figure enterprise deals within 12 months of launch. Named on CSA Agentic AI Security Innovator Map and Gartner Hype Cycle reports.
- First mover, "agentic-first" framing
- Tier-1 VC signal (Lightspeed + Bain)
- Runtime + discovery + red team combined
- Gartner + CSA recognition already
- Land-and-expand sales motion
- Security framing — not formal governance
- No deterministic L1 gate (43ns Rust)
- No WORM cryptographic audit trail
- No EU AI Act compliance mapping
- US-centric; limited EU/EEA footprint
- Probabilistic anomaly detection, not formal gate
AI governance + real-time intervention. Started as EU AI Act compliance and risk assessment. In 2026 launched Guardian Agents: Sentinel Agents (continuous observation) and Operative Agents (real-time intervention — stopping or modifying AI actions). Deepest EU AI Act feature coverage of any European platform (validated by Forrester and analyst firms). UK base with strong European institutional relationships.
- Deepest EU AI Act + ISO 42001 coverage
- Guardian Agents = runtime intervention (converging on VAIG)
- UK + EU geography for Aug 2026 enforcement
- Compliance-first = low buyer friction
- Analyst-validated positioning
- Operative Agents: probabilistic/rule-based, not formally verified
- No deterministic L1 Rust gate
- No geometric stability / Phi-law coherence
- No WORM cryptographic receipt
- Governance dashboard — looks up (board), not down (runtime)
- Safety bolted onto existing compliance tool
LLM prompt injection security → enterprise AI security platform. Lakera built AI security infrastructure focused on prompt injection and adversarial inputs. Acquired by Check Point Software Technologies for an estimated $300M in November 2025. Now forms Check Point's Global Center of Excellence for AI Security in Zurich. Check Point distributes through 100K+ enterprise customers globally.
- Proven PMF — $300M exit validates the space
- Check Point distribution = instant enterprise channel
- Zurich CoE = European AI security presence
- First-mover on prompt injection (OWASP top risk)
- Prompt injection ≠ execution boundary
- No governance layer, no compliance mapping
- No WORM, no formal verification
- Check Point integration may slow innovation
- Different threat model: external attacker vs. internal authorization
Enterprise AI governance benchmark. Forrester Wave Leader Q3 2025. Fast Company Top 6 Applied AI companies of 2026 (alongside Google, NVIDIA, OpenAI, Anthropic). The "ServiceNow for AI governance" — AI inventory management, risk assessment, EU AI Act mapping, ISO 42001, model cards, audit workflows. Sells to Chief AI Officers and Chief Risk Officers at Fortune 500.
- Best-in-class analyst recognition (Forrester, Gartner)
- Global enterprise customer base
- AI Act + ISO 42001 + NIST AI RMF coverage
- Sets buyer expectations across the market
- Salesforce Ventures = ecosystem access
- Zero runtime execution capability
- No gate, no WORM, no formal verification
- Dashboard + workflow tool — does not touch execution path
- Sells to GRC, not engineering
- US-first; EU presence limited
First ISO/IEC 42001 certified AI governance platform. Formed June 2025 by Canadian Fairly AI acquiring Swedish Anch.AI. Anch.AI brought deep EU AI Act regulatory expertise; Fairly AI brought technical AI assurance. IDC-recognized as having the best EU AI Act + ISO 42001 support. Full AI lifecycle governance with a strong European regulatory focus.
- ISO/IEC 42001 certification (first to achieve)
- Anch.AI EU regulatory depth (Sweden, GDPR-native)
- IDC recognition for EU AI Act coverage
- Conformity assessment workflows built in
- Policy/documentation only — no runtime gate
- No action-level WORM logging
- No formal mathematical verification
- Post-merger integration risk
- Canadian-Swedish cultural mismatch risk
ML model security + runtime defense. Focuses on attack vectors traditional security misses: adversarial inference attacks, backdoors in model weights, supply chain poisoning. AISec Platform 2.0 (April 2025) covers AI discovery, supply chain, runtime defense, and attack simulation. 169 employees as of March 2026. Strong defense/government orientation (Booz Allen, Capital One investors).
- Deepest technical depth on model-weight security
- Microsoft M12 + IBM + Capital One = enterprise channel
- Defense/government contracts = recurring base
- AISec 2.0 converging toward runtime defense
- Different threat model: external attacker vs. authorized agent
- No governance framework, no EU AI Act
- No compliance mapping
- No action-level audit trail (WORM)
- US/defense focus limits EU reach
Production LLM guardrails toolkit — free with NVIDIA AI Enterprise. In January 2025, NVIDIA released three NIM microservices: content safety, topic control, and jailbreak prevention. Probabilistic ML classifiers at the inference layer. Ships as part of the NVIDIA AI Enterprise platform — zero procurement friction for the 80%+ of enterprise ML teams running on NVIDIA infrastructure.
- NVIDIA distribution = in every serious ML stack
- Free with AI Enterprise = no friction
- Composable NIM microservices architecture
- Continuously updated as platform feature
- Probabilistic only — ML classifiers, not formal gates
- No deterministic L1 gate
- No WORM cryptographic audit trail
- No EU AI Act compliance mapping
- Input/output filtering ≠ execution boundary
- Developer tool — not enterprise governance product
Norway's largest AI company — industrial AI for oil & gas, manufacturing, energy. Atlas AI platform liberates, contextualizes, and governs industrial data from OT, IT, engineering, and robotics sources. Claims EU AI Act alignment but has no formal execution-boundary layer. Aker-backed (also partnered with OpenAI on Stargate Norway — Europe's first OpenAI data center). $2.1B valuation; customers include global oil refineries, pipelines, offshore operators.
- Deploys AI agents in industrial contexts (wrong action = physical consequence)
- Claims EU AI Act alignment — gap is the execution gate
- Offshore + energy = VAIG's commercial thesis: "higher control cost, lower consequence cost"
- Aker relationship = natural path to VAIG as certified component
- Cognite EU AI Act compliance team
- Atlas AI platform engineering (VAIG as embedded gate)
- Aker / Equinor energy sector relationship
- Stargate Norway as framing: "AI infrastructure needs a governance layer"
Norwegian AI Act implementation — creates VAIG's mandatory market. KI-Norge is the government national hub for responsible AI. Nkom (Norwegian Communications Authority) is the designated coordinating supervisory body. KI-loven (Norwegian transposition of the EU AI Act) targets enforcement from August 2026. Every Norwegian enterprise deploying high-risk AI will need technical controls, risk documentation, and audit logs — exactly what VAIG provides.
- Technical control documentation for high-risk AI
- Audit log of AI decisions (prEN 18229-1)
- Risk management records (prEN 18228)
- Cybersecurity specifications (prEN 18282)
- Conformity assessment process
- L1 gate decision records = technical control proof
- WORM audit trail = prEN 18229-1 logging framework
- Coherence scores = risk signal per action
- L4 compliance layer = cybersecurity spec coverage
- Full VAIG deployment = conformity assessment artifact
The draft European standard for logging in trustworthy AI — maps directly to VAIG's WORM layer. prEN 18229-1 is developed by CEN/CENELEC TC 21 (Artificial Intelligence). Norway's input coordinated by Standard Norge. The standard specifies requirements for how AI systems must log decisions, actions, and outcomes under the EU AI Act framework. Three companion standards: prEN 18282 (AI cybersecurity), prEN 18228 (AI risk management), prEN 18288 (computer vision taxonomy).
- Timestamped decision records per AI action
- Append-only log integrity (no modification)
- Human-readable + machine-readable output
- Agent identity in each record
- Outcome traceability
- Microsecond-precision timestamp per gate decision
- Append-only by architecture (Write-Once-Read-Many)
- JSON + human-readable structured output
- Agent ID, intent score, gate decision, outcome in every record
- Cryptographic signing of each record
Conclusions
Where VAIG stands — and what to do
Where VAIG is differentiated
- Deterministic L1 gate — 43ns Rust, formal binary pass/fail. No competitor has this.
- WORM cryptographic audit trail — append-only, signed receipt per action. Unique.
- Mathematical coherence scoring — Phi-law geometric stability signal. No competitor.
- prEN 18229-1 alignment — WORM maps to the standard before it's even finalized.
- Norwegian first-mover — KI-loven Aug 2026 with no domestic execution-boundary player.
Where VAIG is exposed
- No sales channel yet. Straiker has Lightspeed/Bain and enterprise deals in <12 months.
- Holistic AI converging fast — Guardian Agents Operative = real-time intervention.
- NVIDIA distribution — NeMo Guardrails ships free with every AI Enterprise deployment.
- Phase One (ρ ≥ 0.30 MedQA) not yet complete — empirical foundation still theoretical.