The AI Control Assessment™ establishes where an institution's control stands — and where it must be.
It applies the 5×5 Control Matrix™ across all twenty-five intersections, deep within the institution and wide across the chain it depends on, then benchmarks that reading against its sector and the industry, and returns the distance as a defined control program.
Not a policy review.
A control position, established on evidence.

The instrument that measures how much control an institution can demonstrate over the AI it depends on. It reads the five ecosystems of the Institutional AI Stack™ — Power, Compute, Data Centers, Models, Agents — against five pillars of control: Jurisdictional, Logical, Technical, Operational, Contractual.
Twenty-five intersections, each placed on a five-tier scale and read cell by cell, never collapsed into a single score — because an institution can command its models while renting the data centers beneath them, and one number would hide exactly that.
One instrument. Deep and wide. One program.
.png/:/rs=w:1240,cg:true,m)
The 5×5 Control Matrix™ is the instrument. The AI Control Assessment™ is the diagnostic built around it.
The Matrix measures where an institution stands — its demonstrable ability to own, control, and audit the AI behind its decisions, across all twenty-five intersections of five pillars of control by five AI ecosystems. The Assessment applies that instrument in two directions.
The Assessment sets the reading against your peer group, calibrates it to where your obligations require you to be, and returns the distance as a defined control program.
One instrument. Deep and wide. One program.
This assessment begins where AI control actually stands — not where an institution wants it to be.
It reads the institution's position deep and wide, benchmarks it against sector and industry, then defines the direction that closes the gap. Position, urgency, direction — in that order, because a strategy built on anything but an honest baseline is aspiration, not control.
Step 1 · Where does our control stand? The 5×5 Control Matrix™ reads demonstrable control across all twenty-five intersections — deep within the institution, and wide across the chain it depends on.
Step 2 · How do we compare? The reading is benchmarked against sector peers and the broader industry — turning a standing into a position, and a position into urgency.
Step 3 · Where do we need to go? The strategic direction defines what closes the gap — deep, through how much of the stack the institution owns, and wide, through the reach its contracts grant.

The Matrix reads your institution's demonstrated ability to own, control, and audit the AI systems behind its decisions. It applies five dimensions of control — Jurisdictional, Logical, Technical, Operational, and Contractual — independently to each of five AI ecosystems: Power, Compute, Data Centers, Models, and Agents.
The result is twenty-five specific, answerable control questions. Each intersection is placed on a five-tier scale — Sovereign, Governed, Evolving, Reactive, or Not Disclosed — according to what the evidence supports, not what policy asserts. The pattern across the twenty-five cells shows not only how well-controlled your AI is overall, but exactly which intersections are exposed and where investment will change the most.
The Matrix reads the record, not the reputation. A tier above the baseline requires an identifiable, auditable mechanism — control is never inferred from an institution's size, its spending, or the volume of its AI activity.
The finding that recurs. Across institution types, the Models and Agents ecosystems are consistently the least controlled. This is structural, not incidental. External model providers process institutional queries on their own infrastructure, retain interaction logs in their own systems, and operate under terms most institutions have never negotiated against their fiduciary obligations. Enterprise tiers offering zero-retention and confidential inference exist; few institutions have negotiated them, and fewer still have verified that what the contract promises is what the architecture actually enforces. This is not a worst-case scenario. It is the ordinary operational reality of how AI is served today.

A control position means little in isolation. Governed at one intersection, Evolving at another — read alone, the reading is a fact without a verdict. What makes it actionable is context: the same posture that is defensible for one institution is an examination finding waiting to happen for another, and the difference is entirely where its peers and its regulators expect it to stand.
Benchmarking supplies that context in two frames.
Together, the two frames turn a standing into a position, and a position into urgency. A posture that looks acceptable within a sector can still sit behind the industry's trajectory. A posture that leads the industry can still fall short of what a particular sector's regulators require. The board question is not "is our control good?" — it is "is our control keeping pace with the institutions we are measured against, and with where the whole system is heading?"
The benchmark does not grade an institution's control. It tells the institution whether its control is keeping pace — and the moment it sits below where comparable institutions already stand, that is no longer an analytical observation. It is a matter the board must act on.

A gap in control has two possible locations, and each is answered differently. A gap in the AI an institution operates directly is a question of how much of the stack it should own. A gap in a relationship it delegates to is a question of how much reach its contract should grant. The strategic direction addresses both.
When the gap is deep — in your own stack. The evaluation weighs your regulatory obligations, AI dependency, risk tolerance, and operating model, and points to one of four infrastructure strategies:
When the gap is wide — in a relationship. You do not build a data center because an asset manager will not grant audit rights. A gap in a delegated relationship is answered through the contract and the reach it grants — a parallel set of four responses, escalating from acceptance to ownership:
Neither ladder is a judgment that more control is always better. The right response is the one the gap and your obligations require — which, for most institutions, is Rent + Control or Compose deep, and Require or Replace wide, far more often than Build or Internalize.
.png/:/rs=w:1240,cg:true,m)
An assessment that only tells an institution where it stands has done half the work. The value is not the reading itself, but the distance it reveals.
Three measures define that distance.
That distance, read cell by cell and relationship by relationship, becomes the control program: a prioritized sequence of what must be addressed, where accountability sits, which dependencies matter most, and what closes each gap.
Prioritized by impact. Sequenced by dependency. Owned by the institution.
This is where diagnosis becomes control.
The AI Control Assessment™ defines the gap; the Institutional AI Stack™ provides the architecture to close it; OLTAIX™ is the control fabric that sustains it.
The Assessment reveals the gaps — deep and wide. It is where control begins, not where it ends.
The Assessment diagnoses. The Stack builds. OLTAIX operates. One system.
The AI Control Assessment™ and the 5×5 Control Matrix™ are proprietary instruments developed by Institutional AI. Tier placements, benchmarks, and strategic recommendations are produced through Institutional AI's methodology and reflect its analytical interpretation of institutional inputs as of the date of completion. Tiers describe the completeness of demonstrable, evidenced control; they are not assurances about an institution's actual internal controls.
Illustrative examples used on this page are hypothetical scenarios developed to demonstrate the assessment methodology. Any resemblance to specific institutions is incidental. Quoted statements from third-party individuals are attributed to their original sources and reflect those individuals' views, not those of Institutional AI.
Assessment outputs are intended to support institutional decision-making and do not constitute legal, regulatory, investment, tax, or fiduciary advice. Institutions should consult appropriate professional advisors before acting on assessment findings.
Personal information submitted through this form is processed in accordance with our Privacy Policy.
AI is a given. Control is not.™
© 2026 Institutional AI. All Rights Reserved.