Technical evaluation

vCISO Lite versus Holistic AI

Holistic AI is the sole Challenger in the June 2026 Gartner MQ — #1 in Critical Capabilities for AI Risk & Compliance, with genuine bias-audit rigor and ~20% of published NYC LL144 reports. vCISO Lite ships Trustworthy Autonomy + Evidence Graph + APRI + services bundled at $8,500/mo flat Enterprise MSRP, with the broader compliance program on the same SKU.

Prepared
Method
Capability walk against Holistic AI’s published product surface (holisticai.com, holisticai.com/ai-governance-platform, holisticai.com/learn/what-are-guardian-agents), press releases, and case studies. vCISO Lite’s live platform. Both vendors’ Gartner MQ pages consulted for 2026 placement.
Sources
holisticai.com, holisticai.com/ai-governance-platform, holisticai.com/case-study, holisticai.com/holistic-ai-recognized-gartner-magic-quadrant-2026, vcisolite.com product surfaces, and Regulation (EU) 2024/1689 (Articles 12, 99). See §10.
Corrections
Both vendors invited to review. Send corrections to /contact; the “Prepared” date above is bumped on any material update.
On this page · 10 sections

TL;DR

Findings§1

Where Holistic AI leads

  • Sole Gartner MQ Challenger + #1 Critical Capabilities. Sole Challenger in the June 16, 2026 MQ; ranked #1 for the AI Risk & Compliance use case at 3.90/5.0.[8]
  • Bias / fairness / algorithmic-auditing rigor. Automated bias/robustness/efficacy/privacy/transparency testing in the Protect module. NYC LL144 pipeline automates impact-ratio calculation with schema reformatting. ~20% of published LL144 bias-audit reports market-wide.[3] If {company}’s primary problem is LL144 in HR-tech, Holistic AI is the stronger fit.
  • Independent-auditor operating model today. Platform vendor AND audit firm — Wikipedia DSA audit December 16, 2024.[7] Works today because AI-audit independence rules are nascent (PCAOB / AICPA / ISO 17021 all out of scope; NYC DCWP LL144 definition targets AEDT-developer conflicts, not platform-vendor side-lines).[11] §10 walks the regulatory framework.
  • UCL academic anchor. Co-CEO Koshiyama is a UCL Research Fellow.[9] Credo AI and OneTrust don’t have a comparable academic anchor.
  • Guardian Agents runtime marketing. Sentinel + Operative agents.[4] Deployment mechanics (SDK vs gateway vs sidecar) not publicly documented.
  • Fortune-500 customer logos. Unilever, GSK, GE Healthcare, Siemens, Aon, UKG, JCI, PMI, Publicis, Allegis, Manpower, MindBridge, Starling Bank, and more.[10]

Where vCISO Lite leads

  • A knowable Enterprise-tier number. $8,500/mo flat MSRP bundles Trustworthy Autonomy + Evidence Graph + APRI. Holistic AI is contact-sales; no public band.[2]
  • 250+ SCF-cross-mapped frameworks on the same SKU. One vendor for AI-Gov + SOC 2/ISO 27001/HIPAA/PCI DSS/DORA/NYDFS/CMMC/FedRAMP. Holistic AI is a pure-play AI-Gov specialist; broader program requires a second platform.[6]
  • APRI vs their workflow-embedded AI — same category, more shipped, with governance guarantees. APRI (our MCP tool graph + evidence-backed answer surface) adds end-to-end vendor questionnaires with cited evidence, board packs, Linear-ticket remediation plans, SOC 2 readiness PDFs, vendor risk re-scoring, M&A data rooms. Caller-entitlement scoped, complete tool-call audit trail, observe-first with confirmation gates. Live MCP endpoint at mcp.vcisolite.com for Claude + Cursor.
  • Trustworthy Autonomy has a published evaluation harness. Public beta 2026-07-07; grades the agent by task category with pass rates + failure cases visible pre-purchase. Guardian Agents mechanics live behind a demo wall.
  • Evidence Graph — externally-anchored. Per-event Ed25519 signing + RFC-3161 external anchor + transparency log live prod 2026-08-20. Auditor re-derives without trusting the platform. Holistic AI’s "continuous audit trails" are platform-internal.
  • Evidence Graph SDK is licensable. Embed the same integrity in a partner product, internal system, or insurance pipeline. Optionality Holistic AI doesn’t offer.
  • vCISO Lite for Auditors — sales-audit severance designed in from day one. Structural rule the hybrid model doesn’t have: the platform sales team can’t sell the platform to an auditor’s audit clients. Copies the discipline financial-audit regulators arrived at over decades (SOX §201, PCAOB Rule 3520, Big-4 consulting-arm severance). Future-proofs against the direction AI-audit rules are heading.
  • Founder-direct. [email protected] reaches the founder, not an enterprise SDR queue.

Scope & evaluation criteria

Boundaries§2

In scope

Buyer profile
SMB and mid-market operators (25–1,500 employees) evaluating a purpose-built AI governance platform to cover agent inventory, policy enforcement, framework-mapped evidence, and runtime autonomous operations — where AI-Gov work sits inside a broader compliance program. Fortune-500 CIO evaluations with a pure-play AI-Gov specialist mandate (or an HR-tech NYC LL144 primary use case) are Holistic AI’s home turf and are noted where relevant; they are not the buyer this page is written for.
Evaluation frame
Ten capability categories the SMB and mid-market buyer is evaluating BOTH tools for. Not: everything each product does.
Comparison basis
Published product documentation, live product surfaces, vendor recognition pages, press releases, and Gartner primary press notice. Not: analyst reports behind Gartner’s paywall, vendor-sponsored bakeoffs, or internal-only NDA material.

Out of scope

NYC LL144 bias-audit specialist market
Holistic AI’s NYC Local Law 144 pipeline, automated impact-ratio calculation, and ~20% share of published LL144 audits are earned and defensible. This page does not litigate whether Holistic AI is the right choice for HR-tech buyers whose primary problem is LL144 compliance; it is. That is a specialist market where cede-the-ground is the honest posture.
Independent-audit services engagement
Holistic AI operates an independent-audit services line (Wikipedia DSA audit December 2024, various NYC LL144 audits). vCISO Lite is a platform vendor, not an audit firm. Buyers who require independent-auditor sign-off engage a separate audit firm alongside vCISO Lite; the comparison here is platform-vs-platform, not platform-vs-hybrid-audit-firm.
Roadmap
Only shipped, generally-available or public-beta capability is compared. Private-preview capabilities are footnoted where public.

Capability coverage

Ten capabilities§3

Amber = Holistic AI ships it. Teal = vCISO Lite ships it. Split = both ship it (weighted when one is materially stronger). Hover a hex for the mechanism detail.

Capability deep-dives

How each side implements it§4

Five capabilities, one spec-card per side. Same slots on both cards so the reader can eye-compare row by row. Framework decomposition lives in §5.

Guardian Agents · runtime overlaySentinel: monitor prod output (prompt injection, jailbreak, hallucination) · Operative: step in inline when threshold crossedIDENTIFY“Full visibility into every AI system”Shadow AI DiscoveryCentralised AI InventoryClassification & Mappingmetadata · ownership trackingPROTECT“Test & manage risk across your portfolio”Automated Testingbias / robustness / efficacy / privacyAgentic Red TeamingAgent Graphagents · tools · tasks · data flowsENFORCE“Apply policy & prove compliance”Risk & Compliance WorkflowsFramework AssessmentsContinuous audit trailsplatform-internal · exportableAWS · Azure · GCP · Databricks · MLflow · OpenAI · Anthropic · LangGraph · CrewAI · AutoGen · MCP · REST · WebhooksAlongside the platform: Holistic AI operates independent third-party audit services (Wikipedia DSA audit December 2024) — hybrid platform-plus-audit-firm operating model.
Three-module architecture: Identify → Protect → Enforce, with Guardian Agents as the runtime overlay.Identify discovers AI assets and populates the inventory; Protect runs automated testing (bias, robustness, red-teaming) and maps agent graphs; Enforce applies policy and generates continuous audit trails. Guardian Agents (Sentinel + Operative) sits on top as the runtime governance layer. Alongside the platform, Holistic AI operates an independent-audit services line — a hybrid model Credo AI and OneTrust do not offer.
§4.1

AI Registry & agent discovery

Both platforms ship model + agent inventory with shadow-AI detection. The difference is what the inventory is evidence-anchored to.

Holistic AI

Identify module: Shadow AI Discovery, Centralised AI Inventory, Classification & Mapping. Continuous discovery across cloud, code, and SaaS environments with metadata auto-population and ownership tracking.

Inputs
Cloud-account scanning (AWS, Azure, GCP), code repositories (GitHub, GitLab, Bitbucket), data/ML platforms (Databricks, MLflow, W&B), agent frameworks (LangGraph, CrewAI, AutoGen), SaaS (ServiceNow, Jira, Confluence, SharePoint).
Outputs
Live AI inventory · classification · ownership tracking · dependency mapping · Agent Graph (agents, tools, tasks, data flows end-to-end).
Evidence
Platform-internal record; Holistic AI proprietary logging.
Fails when
Auditor asks to independently verify the discovery record without trusting Holistic AI's logs.
vCISO Lite

Model + agent inventory with policy binding and every registered asset bound to the Evidence Graph.

Inputs
Integration events, discovery scans, policy state, framework mappings.
Outputs
Live inventory · policy binding · framework-control mapping · signed record per registered asset.
Evidence
Hash-chained record anchored to RFC-3161 external timestamp authority; re-derivable by an auditor who does not trust vCISO Lite.
Fails when
Native agent-framework discovery depth (LangGraph, CrewAI, AutoGen) doesn't match Holistic AI's for buyers running production agents on those stacks natively.
§4.2

Bias / fairness / algorithmic-auditing depth

This is Holistic AI's specialty and vCISO Lite does not compete on this axis. Naming this honestly is what makes the rest of the page credible.

Holistic AI

Protect module: Automated Testing across bias, robustness, efficacy, privacy, transparency. Agentic Red Teaming for jailbreak, toxicity, hallucination, counterfactual bias. Third-party summaries report 100+ automated tests and a Defense Success Rate metric for model safety.

Inputs
Model configurations, training/testing datasets, agent outputs, demographic parity inputs.
Outputs
Fairness metrics · impact ratios · bias findings · Defense Success Rate · exportable audit report format.
Evidence
Independent auditor for Wikipedia DSA (December 2024). Accounts for ~20% of published NYC LL144 bias-audit reports market-wide per academic analysis.
Fails when
Buyer needs the fairness testing INSIDE a broader compliance program (SOC 2, ISO 27001, HIPAA, PCI DSS) on one SKU — Holistic AI is pure-play AI-Gov.
vCISO Lite

Not currently shipped as a competing library. red-team-service ships MITRE ATT&CK-anchored outside-in security testing (30 seeded techniques, 8 tactics) — LLM-specific bias / fairness / drift probe extensions are roadmap, not shipped.

Inputs
N/A for bias/fairness axis today.
Outputs
N/A for bias/fairness axis today.
Evidence
N/A for bias/fairness axis today.
Fails when
Buyer's primary problem is NYC LL144 bias-audit compliance for HR-tech, or an EU AI Act high-risk fairness use case where independent-auditor credibility matters most. In that case Holistic AI is the stronger fit; this page does not claim otherwise.
§4.3

Runtime enforcement / autonomous operations layer

Both platforms are working the same problem — a governed layer where AI agents run real work. The shipped-transparency gap is what makes them evaluable pre-purchase.

Holistic AI

Guardian Agents. Sentinel Agents: continuously monitor AI output in production (prompt injection, jailbreak, data leakage, hallucination, toxicity). Operative Agents: step in inline when risk threshold crossed — govern which tools an AI can call, what it can access, how much it can spend, in real time.

Inputs
Prompts, responses, agent traces, tool-call metadata.
Outputs
Real-time policy enforcement · inline intervention · alerting on threshold crossing.
Evidence
Marketed prominently across the AI-governance-platform page and dedicated /learn/what-are-guardian-agents page. Deployment mechanics (SDK vs gateway vs sidecar vs proxy) not publicly documented.
Fails when
Buyer needs to see the trace format, pass rates, and failure cases BEFORE signing the contract — Holistic AI's runtime detail lives behind a demo wall.
vCISO Lite

Trustworthy Autonomy — the autonomous operations layer of vCISO Lite, running on the Evidence Graph substrate. Public beta since 2026-07-07.

Inputs
Agent action requests · policy state · framework-control mapping · evidence chain state.
Outputs
Signed authorization decision per action · agent execution · evidence-chain record before AND after the action.
Evidence
Every autonomous action recorded to the Evidence Graph; published evaluation harness grades the agent by task category with pass rates + failure cases visible pre-purchase. Trace format and RFC-3161 anchor mechanism published.
Fails when
Buyer needs GA (not public-beta) autonomous action at trust-ladder rung 2 (scoped autonomy) or rung 3 (goal-oriented) today — those reach GA H1 2027 and H2 2027+ respectively.
§4.4

Evidence chain & audit-trail integrity

The question an auditor / insurer / regulator will ask about the AI agent’s actions after the fact. The chain that answers it has to be re-derivable without trusting the platform that produced it.

Holistic AI

Enforce module ships "continuous audit trails" as an output of the workflow layer. Platform-internal audit trail; exportable.

Inputs
Discovery events, policy violation events, workflow signoff records, Framework Assessment results.
Outputs
Audit dashboards · exportable log · compliance evidence generation · framework mapping.
Evidence
Log entries in a proprietary store; verification requires trusting Holistic AI's reporting.
Fails when
Adversarial auditor asks to verify the chain independently without relying on Holistic AI's attestation.
vCISO Lite

Evidence Graph — hash-chained records anchored to an external RFC-3161 timestamp authority. Per-event Ed25519 signing shipped 2026-08-16; transparency log + receipts live in production since 2026-08-20. Independent verifier cron.

Inputs
Every agent action, evidence artifact, policy decision, and framework mapping.
Outputs
Sealed evidence chain · external timestamp attestation · re-derivable proof.
Evidence
Auditor re-derives the chain against the RFC-3161 attestation record; verification does not depend on trusting vCISO Lite.
Fails when
Buyer's existing audit tooling has not been briefed on RFC-3161 verification; onboarding the audit firm to the RFC-3161 verification pattern takes one call.
HOLISTIC AIAgent action + evidencewriteEnforce module · audit trailHolistic AI proprietary loggingexportAuditor reads logVerification requires trusting Holistic AI.vCISO LITE · EVIDENCE GRAPHAgent action + evidencehash + chainHash-chained recordevery block links to the prior hashRFC-3161 anchorre-deriveAuditor verifies chainagainst external anchor recordVerification does not require trusting vCISO Lite.
Holistic AI stores; the Evidence Graph proves.Same architectural difference as against Credo AI and OneTrust — both platforms record what the agent did, but only one produces a record that a party who distrusts the platform can independently verify. Interesting overlap: Holistic AI operates independent audits as a business, so they understand why external verifiability matters — but their platform product does not currently expose that primitive to buyers.
§4.5

Integrity substrate as licensable SDK

Whether the audit-trail primitive is only usable inside the vendor’s product or can also be embedded elsewhere.

Holistic AI

Not offered. Audit trail is a proprietary Holistic AI capability inside the Enforce module.

Inputs
N/A
Outputs
N/A
Evidence
N/A
Fails when
Buyer wants to embed the same integrity substrate in a partner product, an internal system, or an insurance-carrier reporting pipeline.
vCISO Lite

Evidence Graph SDK — Library / Hosted / Enterprise / Charter tiers. Same primitive vCISO Lite uses internally, packaged for embedding. Licensable since 2026-08-15.

Inputs
Partner platform events, internal-system records, third-party reporting.
Outputs
Signed, externally-anchored, re-derivable evidence chain.
Evidence
The SDK produces the same signed evidence chain the product uses internally; consumers verify against the same RFC-3161 attestation record.
Fails when
Buyer's use case is only vCISO Lite's own product surface; SDK licensing is unnecessary optionality.

Framework & control coverage

Framework depth§5

Holistic AI publishes 4 AI-specific frameworkson its product page (EU AI Act, NIST AI RMF, ISO 42001, NYC LL144). vCISO Lite covers the first three plus the 250+ SCF-cross-mapped frameworks (1,468 universal controls)that most mid-market compliance programs actually touch. Holistic AI’s NYC LL144 depth is a specialist strength this page does not claim to match; the gap-fill frameworks vCISO Lite covers natively (and Holistic AI doesn’t publish on the AI Governance surface) are highlighted below.

Holistic AI[8]

EU AI Act
NIST AI RMF
ISO 42001
NYC LL144

vCISO Lite

EU AI Act
NIST AI RMF
ISO 42001
SOC 2
DORA
NYDFS 500
HIPAA
PCI DSS
GDPR
NIST 800-53
NIST 800-171
FedRAMP
CMMC L1
CMMC L2
CMMC L3
ISO 27001
NIST CSF 2.0
ISO 27002
ISO 27701
ISO 22301
HITRUST
SOC 1
SOC 3
CCPA / CPRA
GLBA
CJIS
StateRAMP
TX-RAMP
CIS Controls
CIS Benchmarks
MITRE ATT&CK
NIST 800-63
NIST 800-172
FFIEC CAT
SWIFT CSCF
NIS 2
LGPD
PIPEDA

Pricing & sales motion

How each is bought§6

Two facing pricing stacks — the way a CFO reads a comparison. Amber column is Holistic AI; teal column is vCISO Lite.

Holistic AI

Contact sales

No public tier or dollar figure surfaced today[2]

Sales channel
Direct enterprise sales + independent-audit services line
Direct end-buyer access
Yes, at enterprise scale · self-serve tier not offered
Product SKUs
Platform (Identify + Protect + Enforce + Guardian Agents) + optional independent-audit engagements
Pricing model
Custom enterprise per deployment size, AI systems under management, compliance frameworks[2]
Customer segment
Enterprise + Fortune-500 (Unilever, Mapfre, JCI, GSK, Aon, Siemens, GE Healthcare, Publicis Groupe on the logo bar)[10]
Contract length
Annual minimum · enterprise multi-year typical
Specialty strength
Bias / fairness / NYC LL144 · independent-audit services
Broader-compliance coverage on same SKU
No · pure-play AI-Gov specialist
Sales cycle
Book demo → Enterprise procurement → 3–6 weeks to number
vCISO Lite

$0 / mo

Enterprise tier · bundles Trustworthy Autonomy + Evidence Graph + APRI

Sales channel
Direct · founder-accessible
Direct end-buyer access
Yes · Enterprise via /pricing Contact Sales
Product SKUs
Enterprise $8,500/mo bundles Trustworthy Autonomy + Evidence Graph + APRI · lower tiers $299–$1,499/mo do not include AI-governance features
Pricing model
Flat monthly Enterprise number · framework coverage + evaluation harness included · Trustworthy Autonomy per-action pricing pending (expected ~$1.50–$2 per resolved action, not enforced during public beta)
Customer segment
SMB · mid-market · lean security teams
Contract length
Annual or monthly · no multi-year lock required
Specialty strength
Broader compliance program in one platform · Evidence Graph substrate
Broader-compliance coverage on same SKU
250+ SCF-cross-mapped frameworks (1,468 universal controls) · one platform
Sales cycle
Enterprise: one call · flat MSRP on file (no 3–6 week discovery)

Integration surface

Native connectors§7

Holistic AI’s integrations skew toward hyperscaler cloud + LLM providers + agent frameworks (with MCP named as a first- class connection method); vCISO Lite’s toward the compliance / risk / diligence stack a mid-market operator actually runs. See vCISO Lite’s full catalog on /features/integrations.

IntegrationHolistic AIvCISO Lite
AWSNativeNative
AzureNativeNative
GCPNativeNative
DatabricksNative
MLflowNative
Weights & BiasesNative
OpenAINativeNative
AnthropicNativeNative
LangGraph / LangChainNative
CrewAINative
AutoGenNative
GitHubNativeNative
GitLabNativeNative
BitbucketNative
MCP (Model Context Protocol)NativeNative
ServiceNowNativeNative
JiraNativeNative
SharePointNativeNative
OktaNative
Google WorkspaceNative
Microsoft 365Native
Integration count published?Categories named; total count not publishedNo

Deployment, data, extensibility

Platform architecture§8
AttributeHolistic AIvCISO Lite
Service modelSaaS (AWS / Azure / GCP) plus on-premise per learn page; single-tenant vs multi-tenant not publicly disclosedSaaS multitenant · Enterprise-tier options for isolated deployments on request
Data residencyLondon-based; UK/EU residency plausible but not publicly stated on pages fetchedUS (primary)
Tenant isolationNot publicly disclosedLogical (row-level org scoping)
Public APIREST APIs, Webhooks, SDKs, Endpoints, Custom Connectors named; specification not publicly disclosedREST + MCP (Model Context Protocol) tool graph · OpenAPI 3.0
Runtime governanceGuardian Agents (Sentinel + Operative) · deployment mechanics (SDK / gateway / sidecar / proxy) not publicly documented on marketing pagesTrustworthy Autonomy (public beta 2026-07-07) · Evidence Graph anchor · published evaluation harness · graduated trust ladder
Audit-trail modelEnforce module · “continuous audit trails” · platform-internal · exportable · Holistic AI proprietary loggingEvidence Graph · hash-chained per-event · RFC 3161 external timestamp anchor · SDK-licensable
Bias / fairness testing libraryProtect module · automated bias / robustness / efficacy / privacy / transparency testing · NYC LL144 impact-ratio automation · Agentic Red TeamingNot currently shipped as a competing library — cede this ground honestly. red-team-service (MITRE ATT&CK-anchored) covers outside-in security testing; LLM-specific bias/fairness extension is roadmap.
Conversational LLM surfaceNot the primary axis; workflow-embedded UIAPRI (AI-Powered Risk Intelligence) · MCP tool graph · answers cite evidence chain · caller-entitlement scoped
Independent audit servicesYes — Holistic AI operates as an audit firm (Wikipedia DSA audit December 2024, NYC LL144 audits)No — vCISO Lite is a platform vendor, not an audit firm
Own complianceNot publicly disclosed on pages fetchedSOC 2 Type II · ISO 27001 (in progress) · runs on itself

Business-case briefing

For a budget request§9

Personalized briefing

Make the case for vCISO Lite alongside Holistic AI

A PDF business case, personalized to your company, that lays out the three options, the cost math, and the honest tradeoffs — the argument you need to attach to a budget request or take into a vendor-selection meeting. Written to be credible with a buyer who knows Holistic AI is a Gartner Challenger and won't tolerate shallow dismissal.

View pricing

Notes & sources

Provenance§10
  1. [1] Holistic AI product surface (Identify + Protect + Enforce, three modules with named sub-features) from holisticai.com/ai-governance-platform (accessed 2026-09-14). Homepage positioning at holisticai.com/.
  2. [2] Holistic AI does not publish list pricing. The /pricingURL returned 404 to public research today. Third-party summaries (SoftwareFinder, AppSec Santa) describe “custom enterprise pricing based on deployment size, the number of AI systems under management, and compliance frameworks.” No leaked band surfaced from public sources.
  3. [3] Holistic AI bias / fairness testing depth from holisticai.com/ai-governance-platform(Protect module description). NYC LL144 impact-ratio automation, schema handling, and market share (~20% of published bias-audit reports market-wide) per academic analysis of nycbiasaudit.com filings and public third-party summaries. Third-party review reports 100+ automated tests across red-teaming, bias, hallucination, security, and privacy, plus a “Defense Success Rate” metric for model safety.
  4. [4] Guardian Agents (Sentinel + Operative) from holisticai.com/learn/what-are-guardian-agents (accessed 2026-09-14) and homepage marketing at holisticai.com/. Verbatim Sentinel language: continuously monitor AI output in production; catch prompt injection, jailbreaks, data leakage, hallucination, toxicity “without interrupting workflows.” Verbatim Operative language: when a risk threshold is crossed, “step in inline — governing what AI can do: which tools it calls, what it can access, and how much it can spend, in real time.” Deployment mechanics (SDK vs gateway vs sidecar vs proxy) not publicly documented on the pages fetched.
  5. [5] Holistic AI Enforce module “continuous audit trails” language from holisticai.com/ai-governance-platform. vCISO Lite Evidence Graph: per-event Ed25519 signing shipped 2026-08-16; transparency log + receipts live in production since 2026-08-20 per project changelog.
  6. [6] Holistic AI framework coverage (EU AI Act, NIST AI RMF, ISO 42001, NYC LL144) from holisticai.com/ai-governance-platform and dedicated /nyc-bias-audit product page (accessed 2026-09-14). vCISO Lite’s 250+ SCF-cross-mapped frameworks (1,468 universal controls) from the Secure Controls Framework crosswalk on /features/compliance.
  7. [7] Wikipedia DSA audit case study from holisticai.com/case-study/wikimedia. Customer quote from Jacob Rogers, Associate General Counsel, Wikimedia Foundation. Independent audit published December 16, 2024 — the world’s first independent DSA audit of Wikipedia. Additional case studies for Allegis Group, Bryq, MindBridge, Starling Bank, and Hired live on holisticai.com/case-study.
  8. [8] Inaugural 2026 Gartner Magic Quadrant for AI Governance Platforms, published June 16, 2026; Holistic AI placed as sole Challenger. Companion Critical Capabilities report: ranked #1 for AI Risk & Compliance use case at 3.90/5.0. Source: holisticai.com/holistic-ai-recognized-gartner-magic-quadrant-2026. Prior recognition: Gartner Cool Vendor for AI Security (2024-11-07 per holisticai.com/press-release).
  9. [9] Holistic AI founded 2020 in London by Emre Kazim (Co-CEO) and Adriano Koshiyama (Co-CEO). Koshiyama holds a Research Fellow post at University College London per Alan Turing Institute profile. Great Agent Hack 2025 at UCL East Campus co-hosted with UCL Centre for Digital Innovation and UCL Centre for Sustainability & RealTech Innovation per holisticai.com/press-release/holistic-ai-university-college-london-great-agent-hack-2025. Note: Do not conflate with the separate Paris company “H (formerly Holistic AI)” which raised $200M+ and is unrelated to the London-based Holistic AI.
  10. [10] Customer logo bar from holisticai.com/ homepage (accessed 2026-09-14). Named enterprises: Unilever, Mapfre, Johnson Controls, PMI, eBay, GE Healthcare, SLB, Allegis, ManpowerGroup, GSK, MindBridge, Starling Bank, Siemens, Publicis Groupe, Aon, UKG. Board addition Vahé Torossian (ex-President Microsoft Western Europe) added 2026-06-25 per holisticai.com/press-release.
  11. EU AI Act citations to Regulation (EU) 2024/1689 — Article 12 (automatic-logging mandate for high-risk AI systems, 6-month minimum audit-log retention) and Article 99 (max fines of €35M or 7% of global turnover). NYC Local Law 144 requires an annual independent bias audit for automated employment decision tools serving NYC residents, published on the employer’s website.
  12. [11]AI-audit independence regulatory framework references. PCAOB / SEC independence rules (SEC Rule 2-01 of Regulation S-X, PCAOB Rule 3520) govern financial-statement audits by PCAOB-registered auditors; AI audits are out of scope. AICPA independence rules (Rule 101 of the AICPA Code of Professional Conduct) govern CPAs doing attest engagements; not applicable to non-CPA AI-audit vendors. ISO/IEC 17021-1 §5.2 prohibits accredited certification bodies from providing management-system consultancy; Holistic AI is not currently listed as an accredited ISO 42001 certification body (UKAS / ANAB accredited-body status for 42001 is still being stood up as of 2026-09-14; readiness engagements are not certifications). NYC DCWP Rules Chapter 5, Subchapter T defines “independent auditor” for NYC Local Law 144 bias audits as one who does not have an interest in the AEDT’s deployment or development that would impair impartial judgment; the definition targets AEDT-developer and employer conflicts rather than the auditor’s platform-vendor side-line business. EU DSA Article 37(3) prohibits DSA auditors from providing “non-audit services related to the matters being audited” for a 12-month cooling-off window; whether platform sales into a DSA-audited entity meet that bar is a live legal question that has not been publicly enforced. Historical financial-audit precedent (SOX §201, PCAOB Rule 3520, Arthur Andersen / Accenture divestiture, EY’s 2023 attempted Consulting split) suggests these regimes tighten as categories mature; the hybrid platform-plus-audit-firm model works in the current gap and may not survive it.
  13. All product capability claims for both platforms are current as of the “Prepared” date at the top of this page. Holistic AI’s product surface is evolving; capabilities may have shipped since. Corrections: /contact.
  14. This page does not compare against IBM watsonx.governance, ServiceNow AI Control Tower, Credo AI, OneTrust AI Governance, or the other 2026 Gartner MQ vendors on their own merits — each has its own head-to-head brief under /compare. For the broader category framing and where vCISO Lite sits, see /blog/best-ai-governance-platforms-2026; for the underlying Evidence Graph, see /evidence-graph.