The AI in your GRC tool is only as smart as the vendor who built it¶
Every compliance platform that added an AI assistant this year made the same decision, and it rarely comes up in the sales call: whose model is it?
Nearly always, the vendor's. Either something they trained, or a frontier model they license and wrap, tuned when they have the budget and metered against their margin. It lives inside their product. You did not pick it, you cannot swap it, and you will never see its invoice because it is folded into yours.
That one decision caps what the assistant will ever do for you.
What a model you don't own costs you¶
A GRC vendor that supplies the AI is now competing with the labs that build frontier models, and that is a race they will not win. So the assistant gets scoped to what the vendor can afford to run across every customer at once. When a materially better model ships, which now happens every few months, you get it after the vendor has re-tuned and re-priced around it. Often that means the next annual release.
You also can't see inside it. Which model wrote the control narrative that went into your audit pack, and which version, with what instructions? On a hosted assistant those answers live behind a support ticket, if they exist at all. An auditor who asks how a document was produced and hears "the platform's AI suggested it" has just found the end of your evidence trail.
And it is priced for their business, not your workload. Inference is a cost line. A vendor bundling it into a per-seat fee has every reason to cap tokens and shorten context. You never see that happen. You see an assistant that is fine at summaries and thin on the hard parts, like a risk register grounded in your actual estate or a Statement of Applicability with justifications an auditor will accept.
The connector library is the same problem in a different box¶
A vendor-hosted assistant can only see what the vendor's connectors feed it. So the same platforms advertise hundreds of them, and the number is presented as a strength.
Look at what each one is. A connector is a standing credential into one of your systems, stored in the vendor's cloud. It is an integration someone has to keep working every time the upstream API changes. It is a piece of code with its own vulnerabilities, sitting inside a product you did not write, with access to your AWS account, your identity provider, your source control. Multiply by a hundred and you have a large, permanent copy of your keys held by a third party, plus a maintenance treadmill you are paying for whether you use the connector or not.
There is no need for it anymore. You already have an agent that can read your environment with the access your team already holds. Claude Code is one example; any client that speaks the Model Context Protocol will do. It can query your cloud accounts, your ticketing system, your identity provider and your repositories through its own tools, under your own credentials, and nothing about that access ever leaves your side.
What it needs is governance. An agent that can read everything and write anywhere is a risk, not a compliance program. That is the job Kanonik does: it is the AI governance layer the agent works inside. The agent gathers the evidence and proposes the records. Kanonik checks each proposal, waits for a person to approve it, and keeps the result in a record an auditor can verify. Kanonik holds no credentials to your systems at all. It never needs them, because the reading happens on your side.
Bring your own model means exactly that¶
The model that does your compliance work is the one you already use and pay for: Claude, GPT, Gemini, Bedrock or Azure OpenAI, through any client that speaks MCP. It connects to Kanonik over MCP, loads our signed skill library, and does the work in your environment, with your context, at whatever quality the frontier offers that day.
What Kanonik supplies is the part a frontier model cannot supply on its own.
It keeps the record. Controls, requirements, mappings, risks, policies and evidence references live in one typed model, and framework content loads onto it as a package. Five ship today: ISO 27001:2022, SOC 2, GDPR, NIST CSF 2.0 and HIPAA. Adding one is a package, not a rebuild.
It checks every change independently. Before anything lands, a server-side Verifier grades the proposed change against a rule pack and, for the kinds that need it, a second model reading. That check runs on its own credentials, separate from the model that wrote the draft. Your model does the work. It does not mark its own work.
It waits for a person. Every change sits behind a single-use, signed approval that someone on your team clicks. The AI never writes to the record on its own say-so.
And it gives you a record you can verify without us. Every event is hash-chained and the chain root is signed. We ship a verifier that runs in a browser with no install, no upload and no internet connection, so your auditor can check the record on their own laptop, offline, without asking us anything.
We do not host the model. We do not hold your keys. We do not sit between you and the provider you chose. When the frontier moves, you move with it, and nobody at Kanonik has to ship a release for that to happen.
"So it's less automated than a platform with a built-in agent?"¶
We get this question a lot. No. It is better automated, because the ceiling is the frontier rather than a vendor's cost model, and because the agent doing the gathering already has real access instead of whatever a connector was written to fetch.
An in-house assistant is a fixed quantity: the model the vendor could afford, tuned once, upgraded on their calendar, fed by connectors that break when an API changes. Your own frontier model is a rising one. What it can do in your compliance program this year is more than last year, and next year it will be more again, with no change on our side. Our effort goes into the skills, the check and the record. The intelligence is yours to bring, and it improves whether we do anything or not.
What it costs you¶
You need a model subscription and a client that speaks MCP. Most teams already have both. You also take on choosing the model, which is the point: you can pick the strongest one available, switch when something better arrives, and answer an auditor's "which model, which version" from your own logs.
What you stop carrying is a dependency on a compliance vendor's AI roadmap, and a pile of your credentials in their cloud. Next time you are in a sales call, ask whose model it is and where the connector keys live. The answers tell you where the ceiling is and where the risk sits.
Kanonik is new-gen GRC for teams that can't afford the GRC monsters and shouldn't have to. Try Kanonik free for 14 days at kanonik.ai.