Enterprise AI

Research partnership for secure Agentic AI in regulated organisations

Research partnership for secure Agentic AI in regulated organisations

neuland AI

neuland AI

·

2

Min. Lesezeit

Four people holding signed Memoranda of Understanding at IFA Berlin. From left: Turing Space, Dr Klement Ruey-Sheng Gu (Taipei Representative Office), Yunus Philip Uyargil (neuland.ai), PolyCrypt.

MoU signing at IFA Berlin: neuland.ai, PolyCrypt and Turing Space launch a research partnership for secure Agentic AI.

meldung

Two colleagues ask the same AI the same question and receive different answers.

That is exactly how it should be.

At IFA Berlin, neuland.ai, PolyCrypt and Turing Space signed a Memorandum of Understanding for a joint research partnership. The signing took place in the presence of Dr Klement Ruey-Sheng Gu, representative of the Taipei Representative Office in Germany, and the Taiwanese delegation of the Taiwan Startup Terrace. Yunus Philip Uyargil, CTO of neuland.ai, signed on behalf of the company.

At the heart of the partnership is a question that matters for every deployment of Agentic AI in regulated organisations: in whose name does an AI agent act - and what information is it allowed to see?

In practice, Agentic AI rarely fails because of the model's quality. More often it fails because of identity, authorisation and access control. As long as these questions remain unanswered, compliance officers are left with one safe but unhelpful option: the agent is granted access to the lowest common denominator of information. That keeps it protected - but in many cases barely useful.

An example from everyday business

A project manager and a working student ask the same internal AI about the status of the same project.

The project manager receives the project progress, an assessment of technical risks drawn from a classified document and information on team utilisation. The working student receives the project progress and nothing else.

Not because a filter decides at the end which content still needs to be removed. Rather, because the classified document does not exist for the student's agent at the point of retrieval.

That distinction matters: post-hoc filtering remains a probabilistic statement. Data that cannot be retrieved is a guarantee.

The principle: rights follow the person

No agent receives more rights than the person who authorised it. Every action remains traceable to that person.

The employee signs the permission for their own agent themselves - with a private key that never leaves their wallet. There is no centrally managed shared agent that everyone uses. An escalation of rights is not prevented after the fact; it is structurally excluded.

The roles of the partners

Turing Space contributes its expertise in Verifiable Credentials and digital identity for people and agents. The technology answers questions such as: who is this agent? Who authorised it? And how long does that authorisation last?

PolyCrypt provides cryptographic authorisation and key derivation. It determines which action is permissible and ensures that without the matching key no plaintext is visible.

The neuland.ai HUB brings these building blocks together in a platform that can be EU-hosted or run entirely on-premises. The point is not just security but also usability: an agent that reveals nothing because it cannot answer anything is not a product.

Why Germany and Taiwan?

Germany and Taiwan face similar challenges: both sides develop technologies for organisations that cannot or do not want to hand their data to a third-party cloud.

The partnership therefore relies on open standards such as W3C Verifiable Credentials and OpenID4VP, and on sovereign operation in the organisation's own data centre - down to a fully air-gapped network.

The Memorandum of Understanding is the starting point for a joint technical roadmap. We will show publicly what comes of it.

Two colleagues ask the same AI the same question and receive different answers.

That is exactly how it should be.

At IFA Berlin, neuland.ai, PolyCrypt and Turing Space signed a Memorandum of Understanding for a joint research partnership. The signing took place in the presence of Dr Klement Ruey-Sheng Gu, representative of the Taipei Representative Office in Germany, and the Taiwanese delegation of the Taiwan Startup Terrace. Yunus Philip Uyargil, CTO of neuland.ai, signed on behalf of the company.

At the heart of the partnership is a question that matters for every deployment of Agentic AI in regulated organisations: in whose name does an AI agent act - and what information is it allowed to see?

In practice, Agentic AI rarely fails because of the model's quality. More often it fails because of identity, authorisation and access control. As long as these questions remain unanswered, compliance officers are left with one safe but unhelpful option: the agent is granted access to the lowest common denominator of information. That keeps it protected - but in many cases barely useful.

An example from everyday business

A project manager and a working student ask the same internal AI about the status of the same project.

The project manager receives the project progress, an assessment of technical risks drawn from a classified document and information on team utilisation. The working student receives the project progress and nothing else.

Not because a filter decides at the end which content still needs to be removed. Rather, because the classified document does not exist for the student's agent at the point of retrieval.

That distinction matters: post-hoc filtering remains a probabilistic statement. Data that cannot be retrieved is a guarantee.

The principle: rights follow the person

No agent receives more rights than the person who authorised it. Every action remains traceable to that person.

The employee signs the permission for their own agent themselves - with a private key that never leaves their wallet. There is no centrally managed shared agent that everyone uses. An escalation of rights is not prevented after the fact; it is structurally excluded.

The roles of the partners

Turing Space contributes its expertise in Verifiable Credentials and digital identity for people and agents. The technology answers questions such as: who is this agent? Who authorised it? And how long does that authorisation last?

PolyCrypt provides cryptographic authorisation and key derivation. It determines which action is permissible and ensures that without the matching key no plaintext is visible.

The neuland.ai HUB brings these building blocks together in a platform that can be EU-hosted or run entirely on-premises. The point is not just security but also usability: an agent that reveals nothing because it cannot answer anything is not a product.

Why Germany and Taiwan?

Germany and Taiwan face similar challenges: both sides develop technologies for organisations that cannot or do not want to hand their data to a third-party cloud.

The partnership therefore relies on open standards such as W3C Verifiable Credentials and OpenID4VP, and on sovereign operation in the organisation's own data centre - down to a fully air-gapped network.

The Memorandum of Understanding is the starting point for a joint technical roadmap. We will show publicly what comes of it.