Archer

Type: company (GRC platform vendor; “Archer Technologies”) Sector: governance, risk and compliance software — regulatory change management, AI governance, third-party risk, IT/security risk, audit First seen: 2026-09-10 (S-2026-09-10-archer-accelerate-tour) Last updated: 2026-09-16

Created 2026-09-16 from S-2026-09-15-archer-evolv-ai-compliance and S-2026-09-14-archer-evolv-foundation-workplace (daily AI-governance vendor-intelligence scan; both Archer Summit-week launch releases fetched in full after search surfaced the press index), adding to S-2026-09-10-archer-accelerate-tour — schema 2+-source trigger met (three sources). All three are Archer’s own releases; every capability, customer-count and accuracy figure on this page is vendor-asserted and not independently verified. Scope note: this page tracks Archer’s AI-governance-relevant moves, not the company generally.

Snapshot

Archer is a long-established GRC system-of-record vendor (“25 years”; “more than 1,300 organizations … including half the Fortune 500 and 37 of the top 50 global banks” — vendor figures, banks unnamed) that in September 2026 repositioned around purpose-built GRC AI: “492 purpose-built models trained since 2017”, “22 million regulatory documents” and “250 million GRC records”, with the models, data and experts described as having “came with Compliance.ai” [S-2026-09-14-archer-evolv-foundation-workplace][S-2026-09-15-archer-evolv-ai-compliance]. At Archer Summit (Orlando, 14–17 Sep 2026) it launched two things that matter to this wiki: Evolv Foundation / Evolv Workplace — a “harnessed digital workforce” of scoped, supervised “AI Operators” working inside audit, third-party-risk, IT-risk and operational-risk processes [S-2026-09-14-archer-evolv-foundation-workplace] — and Evolv AI Compliance — regulations and policies compiled into obligation-traced Amazon Bedrock Guardrails enforced in the customer’s AWS account on every employee or agent prompt, with violations flowing back to the GRC record [S-2026-09-15-archer-evolv-ai-compliance]. Archer therefore appears on AI Governance Platforms twice over: as a GRC incumbent selling the “connection between repository and guardrail”, and as a vendor whose own agents now sit inside the second and third lines of defence [inference].

Positions / Claims they advance

  • Runtime guardrails govern intent, not identity. “IAM governs identity. Runtime guardrails govern intent. An employee or agent can be correctly scoped, authenticated and logged and still submit a prompt that breaks a regulation no one translated into a control” [S-2026-09-15-archer-evolv-ai-compliance].
  • The governance market’s gap is the link between repository and guardrail. “Much of the market delivers the repository or the guardrail, rarely the connection between them. Archer Evolv AI Compliance is that connection” [S-2026-09-15-archer-evolv-ai-compliance].
  • Evidence should be the control, not the policy. Source, obligation, control, guardrail and violation event “form one audit trail a customer can hand to an examiner on demand”; “the exam question has changed from ‘show us your policy’ to ‘show us the control’” [S-2026-09-15-archer-evolv-ai-compliance].
  • Enforcement mechanics (AI Compliance): five-step loop Listen → Decide (draft Bedrock Guardrail deployed only after a named owner approves) → Act (every prompt checked before inference) → Assure (guardrails “tested on a set cycle”, drift/tampering flagged) → Learn (findings tracked to closure in Archer issue management); no proxy in the inference path; non-Bedrock models via the Bedrock Apply Guardrail API; Observe / Advise / Enforce rollout dial with per-version rollback; Archer reads guardrail configuration and events through one least-privilege IAM role and never prompt content, responses, PII, weights or training data; local enforcement continues if connectivity drops [S-2026-09-15-archer-evolv-ai-compliance].
  • Obligation scope (AI Compliance): organisational (secrets/credentials, source code, confidential business information, customer-defined usage rules) and regulatory — GDPR/CCPA/state privacy, HIPAA, PCI DSS, export-controlled, securities and biometric data. No AI-specific regulation or standard is named [S-2026-09-15-archer-evolv-ai-compliance].
  • Agents belong inside the GRC harness. Three-system architecture — System of Record (Archer GRC), System of Intelligence (Evolv Foundation: 492 models, plain-language prompt layer honouring existing Archer roles and citing the source record, and “the harness” that persists state, “confines every action to a defined scope, and reports progress to the supervisor who owns the result”), System of Outcomes (Evolv Workplace: a marketplace of AI Operators, “each hired for a specific job, granted a specific scope, supervised by a named person and accountable through the same audit trail as everyone else”) [S-2026-09-14-archer-evolv-foundation-workplace].
  • Scale claims for Operators: “dozens” live “in production with customers today” across Foundation, Audit, Third-Party Risk, IT Risk and Operational Risk; “more than 200 by the end of 2026 and more than 500 by the end of 2027” (forward-looking) [S-2026-09-14-archer-evolv-foundation-workplace].
  • Accuracy positioning: “95% confidence, 100% accurate on the calls it’s confident about, and the remaining 5% routed to a human expert” versus unnamed general-purpose LLMs (vendor-run June 2026 benchmark) [S-2026-09-10-archer-accelerate-tour]; “Archer Evolv resolved 100% of the same set, because low-confidence work routes to an expert rather than shipping with no flag” [S-2026-09-14-archer-evolv-foundation-workplace]. “For productivity, an agent is sufficient. For control, only an Operator is defensible” [S-2026-09-14-archer-evolv-foundation-workplace].
  • Risk, compliance and security are converging on one AI action (“a risk event, an obligation and a security exposure in the same instant”) landing on CRO, CCO and CISO together [S-2026-09-14-archer-evolv-foundation-workplace][S-2026-09-15-archer-evolv-ai-compliance].

Relationships

  • relates-to → AI Governance Platforms — GRC-incumbent entrant supplying obligation-traced runtime guardrails and agentic Operators; competes for the AI-governance system-of-record role [S-2026-09-15-archer-evolv-ai-compliance][S-2026-09-14-archer-evolv-foundation-workplace].
  • relates-to → Three Lines of Defence for AI — Operators work inside second- and third-line processes (audit, operational risk, third-party risk), making the vendor’s own AI part of the lines it serves [S-2026-09-14-archer-evolv-foundation-workplace][inference].
  • relates-to → Model Risk Management and Agentic AI — a GRC vendor’s 492 models and Operators are candidate in-scope models for SS1/23 / SR 11-7 inventories and validation [inference].
  • partners-with → AWS — Evolv AI Compliance is built on Amazon Bedrock Guardrails, deployed in the customer’s AWS account and sold via AWS Marketplace [S-2026-09-15-archer-evolv-ai-compliance].
  • competes-with → IBM — IBM OpenPages/watsonx.governance is the other GRC-backbone route to AI governance in the vault [S-2026-07-16-aigi-ibm-openpages-techvest][inference].
  • competes-with → Monitaur — both sell governance evidence to regulated enterprises, from opposite starting points (GRC record vs AI-validation) [inference].

Tracked changes

  • 2026-06-29 — Summit announcement promising “a different category of GRC software: AI that is designed for second-line risk and compliance workflows and proves who did what, why, and at what confidence” (release referenced in S-2026-09-10-archer-accelerate-tour; not separately ingested).
  • 2026-06-30 — Vendor benchmark release claiming 95% verified accuracy on regulatory change management vs general-purpose LLMs (referenced, not ingested) [S-2026-09-10-archer-accelerate-tour].
  • 2026-09-10 — Accelerate six-city tour announced (São Paulo, Santiago, Rome, Tokyo, Sydney, Singapore; 6–23 Oct 2026); “governed AI Operator” first mentioned [S-2026-09-10-archer-accelerate-tour].
  • 2026-09-14 — Archer Evolv Foundation and Evolv Workplace launched at Summit; AI Operators and harness architecture described; Compliance.ai models/data referenced as running “across all of Archer” [S-2026-09-14-archer-evolv-foundation-workplace].
  • 2026-09-15 — Archer Evolv AI Compliance launched: obligation-traced Amazon Bedrock Guardrails with Observe/Advise/Enforce dial; available direct and on AWS Marketplace [S-2026-09-15-archer-evolv-ai-compliance].

Open Questions

  • No EU AI Act, ISO/IEC 42001, NIST AI RMF, SS1/23, SR 11-7 or DORA mapping is claimed in any of the three releases; the regulatory obligations shipped as guardrails are content-category privacy/security rules. Is AI-specific obligation content on the roadmap? [S-2026-09-15-archer-evolv-ai-compliance]
  • Who validates the 492 models and the Operators? A bank whose second line runs on Archer Operators inherits the vendor’s models into its model inventory; the only evidence offered is Archer’s own evaluation [S-2026-09-14-archer-evolv-foundation-workplace][S-2026-09-10-archer-accelerate-tour].
  • Is the “audit trail a customer can hand to an examiner” immutable and exportable, and how does it reconcile with AWS’s own Bedrock/AgentCore logs? [S-2026-09-15-archer-evolv-ai-compliance]
  • AWS-only enforcement: what does DORA ICT-concentration look like for a firm whose model estate spans Azure/GCP and whose GRC guardrails live in one hyperscaler’s guardrail service? [inference]
  • Does the “harness” map to any open agent-control specification (OWASP ACS, MCP governance) or is it proprietary? [S-2026-09-14-archer-evolv-foundation-workplace]
  • “37 of the top 50 global banks” — none named; no EU/UK regulated reference in any source.
  • What is Compliance.ai and when did Archer acquire it? (Referenced, not in vault.)
  • Internal inconsistency carried from the 15 Sep scan: Archer site event card shows Summit “September 13, 2026” while releases say 14–17 Sep ⚠️ (minor; not a source contradiction).

Sources