Verifiable AI Governance Where the Data Lives: Polygraf AI, Intel® TDX, and Intel® Trust Authority
Polygraf AI and Intel – July 29, 2026
Enterprise AI adoption is outpacing the controls that are designed to govern it. Employees paste their customer records into consumer chatbots, agents query production systems, and copilots summarize documents that were never classified for AI use. IDC has labeled unmanaged AI usage as an increasingly dominant enterprise data exfiltration vector and estimates that breaches involving shadow AI carry approximately $670,000 in additional costs. For regulated and mission-sensitive organizations, cloud-based inspection introduces the same exposure it is intended to prevent. The governance layer must therefore operate where the data resides, without external dependencies and with sufficiently low latency to remain inline with live traffic. A defense program operating in an IL5 (Impact Level 5: US Department of Defense data classification for SECRET or TOP SECRET) environment cannot depend on a vendor-controlled inspection API. A hospital can’t solve a PHI (Protected Health Information) exposure problem by adding a third-party solution that also gets to see the PHI. For these enterprises, the control has to run inside their own environment – and it has to be fast enough to sit inline with real user traffic.
Polygraf AI built its control plane around that constraint. Working with Intel, Polygraf AI now runs its enforcement layer inside hardware-isolated Trust Domains using Intel® Trust Domain Extensions (Intel® TDX), with Intel® Trust Authority providing independent attestation – extending on-premises AI governance from something a customer must trust to something a customer can verify.
“Our customers should not have to choose between adopting AI and keeping sensitive data under their control. We designed Polygraf AI to run entirely on CPUs, so governance can operate where the data already resides. With Intel TDX and Intel Trust Authority, customers can also verify that the software governing their data is authentic, unmodified, and operating inside a hardware-isolated environment.” Yagub Rahimov, CEO, Polygraf AI
What Polygraf AI Does
Polygraf AI provides an AI Behavioral Control Plane that operates between users, AI applications, autonomous agents, and enterprise data. It evaluates AI interactions in real time and applies policy before sensitive information is exposed or an unauthorized action is completed.
The control plane follows a View, Control, Enforce model. It discovers AI usage across the organization, identifies and redacts sensitive information in prompts and outputs, applies inline policy actions, and creates a tamper-evident record of each decision.
Polygraf AI operates 17 proprietary, task-specific, energy-efficient SLMs (Small Language Models), each trained for a bounded detection and governance task rather than adapted from a general-purpose foundation model. Together, the models detect more than 80 categories of sensitive information, with reported performance ranging from 93% to 98% across evaluated use cases, which IDC places approximately 17% above hyperscaler alternatives. Each model runs entirely on CPU (1.3Ghz, 8GB RAM), not GPU, making sub-100ms inline enforcement possible. Enforcement reaches users through a governed inference gateway, endpoint-level control covering unsanctioned tools, meeting deepfake governance, document redaction, and a governance dashboard producing continuous compliance evidence across internal policies.
On-Premises as an Architecture, Not a Deployment Option
Many vendors describe themselves as deployment-flexible. Almost any software can be containerized and installed inside a customer’s network, so the question isn’t whether a product can be deployed on-premises – it is what stops working when it is. The dependency that’s hardest to remove is model fidelity. If detection depends on a multi-billion-parameter model, on-premises deployment gets complicated and usually ends with one of two things: a local proxy that escalates the ambiguous cases to a hosted service it can’t reach in a disconnected environment, or a “real” local deployment that requires the customer to buy and operate a much more expensive infrastructure and accept a noticeable latency that removes inline enforcement – where it becomes reactive detection solution rather than a proactive preventative solution.
Polygraf AI set the constraint first and found the accuracy within it, through task decomposition rather than one model that understands everything. Achieving this combination required task-specific model development, data engineering, and optimization rather than simply packaging a general-purpose model for local deployment, which is why the technology is difficult to replicate. The result is a tool that runs at full capability with no external dependency, in IL2-IL6 (Department of Defense security classification spectrum ranging from IL2 for public data to IL6 for classified SECRET-level information)-ready and fully air-gapped environments, on the customer’s existing Intel Xeon estate.
How Polygraf AI’s Architecture Differs
The comparison below highlights how Polygraf AI’s AI Behavioral Control Plane differs from cloud-dependent AI security platforms and traditional data loss prevention tools across deployment, performance, detection, and infrastructure requirements.
| Capability | Polygraf AIBC | Cloud-Based AI Security Solutions | Traditional DLP |
| Energy-efficient inference | ✓ | Limited | Limited |
| CPU-only operation with no GPU required | ✓ | Typically no | ✓ |
| Context-aware sensitive information detection | ✓ | Limited | Limited |
| Fully air-gapped operation | ✓ | No | Limited |
| Sub-100 ms latency for real-time enforcement | ✓ | Varies | Varies |
| Explainable detection with feature attribution | ✓ | Limited | Limited |
| On-premises, task-specific Small Language Models | ✓ | Typically no | No |
Local execution resolves the data-egress and infrastructure-dependency problems. It does not, by itself, prove that the enforcement runtime is authentic or protect sensitive data from privileged infrastructure access. That is the gap that Intel TDX and Intel Trust Authority address.
Closing the Last Gap with Intel TDX
Running inside the customer’s boundary removes egress risk, but it leaves two problems open. The control plane engine is the place where the most sensitive data moves in plain text – it sees prompts before redaction and outputs before filtering, and holds policy configuration. Anyone able to inspect virtual machine memory sits inside that trust boundary. And a customer running enforcement on their own hardware still has to take the vendor’s word that the software in production is the software that was reviewed.
Intel TDX addresses the first. Polygraf AI runs the enforcement runtime – the inference service, policy decision point, redaction pipeline – as a measured Trust Domain on each enforcement node, isolated by hardware from the host operating system, the hypervisor, and other workloads. Management tooling and long-term storage stay outside, keeping the measured surface small. Model weights are delivered encrypted and released only to a Trust Domain whose measurement matches the expected build, so proprietary models are never in plaintext on infrastructure that Polygraf AI doesn’t control.
Intel TDX also fits the architecture rather than constraining it. Because Polygraf AI’s models are CPU-only, and because Intel® Advanced Matrix Extensions accelerate the matrix operations that dominate small language model execution on the same Xeon processors that provide Intel TDX, confidential execution and inference performance come from the same silicon – with no accelerator in the request path. Isolation at the virtual machine level rather than the application enclave level also means one codebase runs identically with TDX, without it, and air-gapped, rather than a confidential-computing fork that drifts from the mainline.
Intel Trust Authority: Verification of the Customer Controls
Intel Trust Authority verifies Trusted Execution Environments independently of whoever operates the infrastructure, which in Polygraf AI’s model means the verifier is neither the infrastructure operator nor Polygraf AI. In practice, this delivers:
- Enforcement that fails is closed. Traffic is not routed to an enforcement instance until it produces a valid attestation quote appraised against customer policy.
- Attestation as audit evidence. Decision records reference the attestation state in force, binding a specific enforcement decision to a specific verified environment.
- One trust model across venues. The same appraisal policy applies in a customer data center, a colocation facility, and a sovereign cloud.
- Protected model IP and policy integrity. Weights, policy configuration, and audit buffers are protected from software outside the Trust Domain.
In those deployments, Intel‘s provisioning model supports offline platform registration, with appraisal running locally against Intel’s certificate chain. The cryptographic root of trust is unchanged; what shifts is that appraisal is performed inside the customer’s environment rather than outside it, which many accreditation regimes prefer, because they do not want an external dependency in the trust path either.
Real-World Applications
- Government, defense, and critical infrastructure. Programs in IL2- IL6-ready environments need enforcement that functions with no external dependency and is evidence-defensible under accreditation. Local CPU-only inference, hardware-rooted isolation, and offline-capable attestation support zero-trust requirements without an internet path.
- Financial services and insurance. Institutions must demonstrate to regulators that customer data never reached an external model provider, and that the control enforcing it was genuine and unmodified at the time of each decision.
- Healthcare. PHI redaction must occur before a prompt reaches a model, which makes the redaction layer itself a HIPAA-relevant system. Hardware isolation removes the infrastructure team from the population with technical access to unredacted PHI.
- Multinational enterprises. Organizations spanning conflicting residency regimes can run one policy model and one enforcement architecture in every jurisdiction, with per-location attestation evidence.
Polygraf AI is deployed across these segments directly and through partners, including system integrators and managed security service providers.
Conclusion
AI governance exists on the requirement that policy be enforced at the point of interaction, on infrastructure the customer controls, with evidence that survives an audit. Polygraf AI meets the first two conditions through an architecture built around small, accurate, CPU-only models. Intel TDX protects that enforcement layer while it runs, Intel AMX keeps it fast enough to stay inline, and Intel Trust Authority makes its integrity independently verifiable, including where there is no network to verify over. For organizations deploying AI under regulatory, sovereign, or classification constraints, the combination turns AI governance from a stated posture into a verifiable one.
1 Source: IDC Market Note, “Polygraf AI: Bringing On-Premises, Air-Gapped Policy Enforcement to Every AI Interaction Across the Enterprise and Defense Data Ecosystem,” Doc. #US54687126, July 2026.