Frameworks

Proprietary frameworks for AI agent safety, AI governance, and AI-assisted development. Published by Dipankar Sarkar. Each framework is a battle-tested pattern from production work — not a thought experiment.

All four came out of specific production problems rather than being designed on a whiteboard first. The Substrate Pattern and Defence in Depth were developed at Neul Labs for the agent runtime and have since been applied at a regulated UK financial-services firm, including presenting the guardrail and kill-switch design to the FCA's regulatory sandbox. The Tiered Governance Model was developed for the same engagement, mapping AI risk to NIST AI RMF, ISO/IEC 42001, and the EU AI Act. Vibes Inside Guardrails formalizes the audit and guardrail discipline used across AI-assisted development work more broadly.

Substrate Pattern

A safety architecture for LLM-powered AI agents. The layer below the model that decides what the agent is allowed to do, and what it is not.

Decomposes agent safety into four independent substrates — memory (what the agent can remember, scoped per user/session/tenant), tool (what the agent can call, with scope, rate limit, and audit), action (what the agent can do, with pre/post-conditions and rollback), and identity (who the agent acts on behalf of, with a chain of custody). Built on four principles: make the wrong thing impossible, default deny, layered safety, and observable by design.

Defence in Depth

Kill-switch architecture and circuit breakers for AI agents. Multiple independent layers of safety, each one tested against the others.

Five layers, each one a backstop for the last: application logic (treated as untrusted), tool execution (sandboxed and rate-limited), action policy (the Substrate layer’s pre/post-condition gate), a circuit breaker, and a manual kill switch reachable in under 30 seconds from any production incident.

Tiered Governance Model

A 4-tier AI governance model (T0-T3) for banks, insurers, and asset managers. Aligned to NIST AI RMF, ISO/IEC 42001, and the EU AI Act.

T0 is read-only AI (summarisation, classification, search — no write access). T1 is advise-only, with a human reviewing every draft. T2 is act-under-supervision, with every action logged, attributed, and reversible. T3 is act-autonomously, the EU AI Act’s “high-risk” tier, with the full conformity-assessment and human-oversight burden that implies.

Vibes Inside Guardrails

A framework for production-ready AI-assisted development. The vibe-coding pattern, with the guardrails that make it safe to ship in regulated environments.

Vibe the prototype fast, then run it through a structured audit before it reaches main: security review, performance audit, accessibility check, error handling, observability, and a kill switch reachable in under 30 seconds. The guardrails are what turn a fast prototype into a production system instead of maintenance debt.

FAQ

Are these frameworks used in production, or just published as theory?

All four are in production use. The Substrate Pattern is the foundational safety pattern for the Neul Labs agent runtime. The Tiered Governance Model and Defence in Depth were applied at Aveni, a regulated UK fintech whose Agent Assure product completed a pilot in the FCA's inaugural Supercharged Sandbox.

How do the Substrate Pattern and Defence in Depth relate to each other?

Defence in Depth's third layer, the action policy gate, is the Substrate Pattern's action substrate. Defence in Depth is the five-layer runtime architecture; the Substrate Pattern is the deeper decomposition of what one of those layers actually enforces.

Which framework applies to AI-assisted coding rather than AI agents in production?

Vibes Inside Guardrails. It targets the vibe-coding workflow specifically — fast AI-generated prototypes — and defines the audit and guardrail steps needed before that code reaches production.