top of page
Icebreaker · product · patent pending

Runtime AI governance.

Icebreaker is the runtime governance layer for agentic AI.

Every existing control tells you who can act and what they can access. None ask whether what the agent is about to do is right for this session, right now. Icebreaker answers that question before the action executes. It works with any IAM platform, with no replatforming and no IAM replacement, though some integration work may be required. Every other layer asks what. Icebreaker asks why.

Any IAM platform

Keycloak and Ping ready

MCP compatible

Zero Trust aligned

Audit by default

The governance gaps it closes

Autonomous workflow generation breaks problems that static systems never had. A workflow generated at runtime has no pre existing specification to audit. Identity frameworks assume predefined roles, yet an agent decides at runtime which tools to invoke, so its effective permissions are dynamic. Accountability diffuses when a novel sequence of individually sanctioned tools causes harm in combination. A dynamically generated plan cannot be red teamed before it runs, and a plan can be harmful even when every step in it is individually safe. And every responsible AI framework, from the EU AI Act to the NIST AI Risk Management Framework, requires meaningful human control that machine speed autonomy makes hard to define.

Icebreaker is built for exactly these gaps. It evaluates the plan an agent generates against an approved business purpose before any action executes, allowing, blocking, modifying or escalating in real time, and records a tamper evident chain from purpose to action. It turns a runtime generated workflow into something an enterprise can authorise, prove and answer for.

Where Icebreaker sits

It sits inside both analyst maps of this space.

Gartner defines AI Trust, Risk and Security Management as four layers. Icebreaker is squarely in Layer 4, runtime inspection and enforcement. It does not compete with authorisation platforms, identity providers or AI security tools. It integrates with them and adds the purpose and intent envelope they do not have. It sits above authorisation and below the agent.

Forrester AEGIS
Domains addressed
Principles

Control intent at scale

Least agency

Continuous assurance

Explainable outcomes

Gartner AI TRiSM

Layer 1

Layer 2

Layer 3

Layer 4 · Icebreaker · runtime inspection and enforcement

Aligned to Forrester AEGIS

AEGIS, the Agentic AI Enterprise Guardrails for Information Security, is Forrester's framework for governing autonomous AI. Its central argument is a shift from infrastructure centric control to intent centric control, which is exactly the layer Icebreaker provides.

Icebreaker delivers runtime enforcement across three of the AEGIS domains: governance, identity, and threat management. It does not claim to cover every AEGIS domain. It provides the runtime intent and enforcement layer the other domains depend on, and it sits above your identity controls rather than replacing them.

It is built around the four AEGIS principles. Control intent at scale, by evaluating every action against an approved business purpose. Least agency, by issuing no execution token for anything outside the validated intent set. Continuous assurance, through a tamper evident chain recorded from purpose to action. Explainable outcomes, because every decision, including the refusals, is logged and reconstructable.

The result is one control that operationalises what AEGIS, ISO 42001, the NIST AI Risk Management Framework and the EU AI Act independently converge on: documented policy turned into evidenced behaviour at runtime.

The governance hierarchy

Authority flows from purpose to action, and cannot be bypassed.

Each layer issues a cryptographic attestation the next layer must present.

04

Runtime Action

Enforced at the policy enforcement point.

03

Intent Set

Planned actions validated.

02

Objective

Session goal versus purpose.

01

System Purpose

Validated mandate, registered.

attestation
attestation
attestation
TAMPER EVIDENT AUDIT CHAIN

Every decision recorded from purpose to action. No valid execution token, no execution.

System Purpose. A validated, persistent declaration of what the AI system is authorised to do, stored in a registry with a unique identifier. The root of every governance chain.

Objective. The specific goal for this execution run, evaluated by an LLM for semantic alignment with the registered purpose. It proceeds only on approval.

Intent Set. The agent declares its planned operations before any execution begins. The full set is validated for consistency with the approved objective. No token is issued for actions outside it.

Runtime Action. Every action is assessed against the validated intent set, session context and policy, and enforced through your existing policy enforcement point before it executes downstream. Allow, block, modify or escalate. No valid execution token, no execution. Governance is mandatory, not advisory.

The governance gap it fills

Identity tells you who can act. Role and attribute controls tell you what they may access. Security monitoring detects threats. Guardrails filter model output. None of them evaluate whether a permitted action is the right action for this session. Without a purpose boundary, scope creep is invisible until it causes an incident. Without runtime enforcement, actions ride on static permissions. Without a tamper evident chain, there is no evidence when a regulator asks. Icebreaker closes each of these.

Regulation is already here

The EU AI Act establishes binding obligations for high risk AI systems, and its enforcement timeline is being actively revised through the EU legislative process. We deliberately do not anchor to a single date, because the dates are still moving. What is not moving is the direction. The obligations are coming, and the preparation they demand, the ability to show what your AI does, control it, and prove it, takes far longer than any notice period.

Penalties are significant and tiered. Prohibited AI practices carry fines up to 35 million euro or 7 percent of global turnover. Other infringements, including high risk non compliance, carry up to 15 million euro or 3 percent. MAS TRM, DORA, ISO 42001 and the NIST AI Risk Management Framework converge on the same three requirements. Icebreaker provides human oversight, a runtime risk control, and a regulator ready evidence pack by default.

Whatever the final timeline, readiness is the correct posture. Governance that can be stood up in weeks cannot be retrofitted in the days before a deadline.

When Icebreaker gets it wrong

Icebreaker can be wrong. An ungoverned agent can be wrong and untraceable. Those are not the same problem. The engine evaluates four bounded inputs, so its exposure surface is a fraction of the agent it governs. Every decision is logged, including the wrong ones. On low confidence it escalates rather than approves. The worst case with Icebreaker is a traceable, reviewable error. The worst case without it is an unattributable one.

Defensible by design

The four layer mechanism, System Purpose, Objective and Intent Set plus runtime enforcement, is a novel architecture for controlled execution of autonomous software agents. The invention covers the system, the method and the computer readable medium. This is not a configuration of existing tools. It is purpose built IP, patent pending. Technical documentation is available under NDA.

Where Icebreaker is today

Icebreaker is a new product built on patent pending IP, and we are deliberate about how it enters production. The architecture is proven in the identity controls Midships already operates for tier one banks, and Icebreaker is now in two confirmed pilots, one with a tier one bank and one with a telecommunications operator. It is offered through a controlled pilot and design partner programme, so you can prove it against your own workflows, in a bounded scope, with evidence, before it governs anything that matters. We would rather earn your confidence on a contained pilot than overstate a maturity we have not yet demonstrated in your environment.

How to engage

Available as a licensed product or as part of a Midships managed programme. It works with all IAM platforms. Keycloak, Ping AIC, Ping AIS and Ping Authorize are supported, and integration may require new APIs in some environments.

Common Questions

Icebreaker – FAQs

What is Icebreaker?

Icebreaker is the runtime governance layer for agentic AI. It evaluates every agent action against an approved business purpose before it executes, and allows, blocks, modifies or escalates in real time, with a tamper evident audit trail. Every other control asks who can act and what they can access. Icebreaker asks why, and whether this action is right for this session.

Which IAM platforms does Icebreaker work with?

Icebreaker is platform independent and works with all identity and access management platforms. It enforces through whatever policy enforcement point you already run, including Keycloak, Ping and others, and it is MCP compatible. Some integration work may be required, including new APIs in some environments.

How is Icebreaker different from guardrails or an AI firewall?

Guardrails filter model output and security tools detect threats. Neither evaluates whether a permitted action is the right action for the session against an approved purpose. Icebreaker sits above authorisation and below the agent.

Is Icebreaker patent pending?

Yes. The four layer mechanism, System Purpose, Objective and Intent Set plus runtime enforcement, is a novel architecture for the controlled execution of autonomous software agents. Technical documentation is available under NDA.

What happens when Icebreaker gets a decision wrong?

Icebreaker can be wrong, but an ungoverned agent can be wrong and untraceable, which is not the same problem. Every decision is logged, including the refusals, and on low confidence it escalates rather than approves.

bottom of page