Press Relase / News Release Distribution Service [@Press]

Note: This page is a machine translation of the Japanese original and is provided for reference only.
In the event of any discrepancy between this page and the original, the original shall prevail. Click here for the original text.

AI Risks, Costs, and Audit Trails on a Single Platform -- Veranthios Launches AI Governance Platform in the Japanese Market

Manage AI risks—including Shadow AI and data leaks—as well as AI cost management, and provide tamper-evident audit trails—all on a single platform

Veranthios

Japan’s AI governance has shifted from soft-law guidelines to a systematic framework. This shift is reflected in the full implementation of the AI Promotion Act, the Cabinet’s approval of the Basic Plan for AI, Version 1.2 of the Guidelines for AI Businesses, and JIS Q 42001:2025.In the financial sector, the Financial Services Agency went so far as to address the methods for recording and monitoring the use of AI in critical decision-making in Version 1.1 of its AI Discussion Paper.Companies are now being asked to address three key points: whether they can manage AI risks, including “Shadow AI” and data leaks; whether they have a clear understanding of the costs associated with AI; and whether they can provide evidence demonstrating both. Veranthios addresses all three of these areas on a single platform and is launching its service in the Japanese market.



■ Veranthios Launches AI Governance Platform in the Japanese Market

(August 2026, Tokyo) Veranthios PTE Ltd (Headquarters: Singapore) has launched “Veranthios,” an AI governance platform for regulated industries, in the Japanese market.This platform identifies and controls all AI systems operating within an organization—including AI used by employees, SaaS applications, AI coding support tools for developers, and autonomous AI agents integrated into business operations—and maintains an audit trail with tamper-detectable evidence to verify that these controls are functioning properly.

In launching the service in Japan, the company is addressing domestic regulatory trends stemming from the AI Promotion Act (fully enforced on September 1, 2025) and the Basic Plan for AI (approved by the Cabinet on December 23, 2025), as well as Version 1.2 of the “AI Operator Guidelines” issued by the Ministry of Economy, Trade and Industry and the Ministry of Internal Affairs and Communications(published March 31, 2026),the Ministry of Economy, Trade and Industry (METI) and Ministry of Internal Affairs and Communications (MIC) “AI Operator Guidelines,” Version 1.2(published March 31, 2026), JIS Q 42001:2025 (enacted August 20, 2025), and the Financial Services Agency’s “AI Discussion Paper,” Version 1.1 (published March 2026).Deployment options range from on-premises and Kubernetes on a private cloud to fully air-gapped environments, all of which are contained entirely within the customer’s own security perimeter.



■ Market Trends—The Need for AI Governance Is Rapidly Expanding, Particularly in the Financial and IT Sectors

The pace of regulatory development is outpacing the ability of companies to adapt their operational practices.

In the financial sector, the Financial Services Agency (FSA) published Version 1.1 of the “AI Discussion Paper” in March 2026, based on a survey of 130 companies and discussions held during the “Public-Private AI Forum” (June–December 2025).The survey found that over 90% of financial institutions are already using AI, and more than 70% grant broad access to general staff; however, the FSA itself has identified the establishment of governance frameworks, model risk management, third-party oversight, and explainability as unresolved issues.Furthermore, Version 1.1 identified the following as key considerations when using AI for critical decision-making: the nature of the AI, the data used for training, the data referenced via RAG or similar methods, the prompts provided, and whether the recording and monitoring of output results are functioning effectively.In practical terms, this requires financial institutions to maintain “records that allow AI-based decisions to be reproduced retrospectively.”


The situation is equally serious for IT and business companies. In a survey conducted by Free Co., Ltd. of 633 IT and information systems managers in Japan, 66.0% recognized that the use of Shadow AI would increase in 2026, while only 13.6% reported being able to fully visualize the actual state of affairs.Structural constraints have also come to light, with 43% of companies employing one or fewer dedicated IT administrators.In the development field, cyber risks associated with AI use ranked among the top three domestic threats for the first time in the IPA’s “Top 10 Information Security Threats 2026.” Additionally, an industry survey cited in the report indicates that 40–62% of AI-generated code contains exploitable security flaws.

Furthermore, Version 1.2 of the AI Service Provider Guidelines, released in March 2026, introduced new definitions for autonomous AI agents, physical AI, and the chained use of AI systems (collaboration between AI agents).The scope of what needs to be controlled has already expanded from “AI that requires human prompts” to “AI that operates autonomously when given a purpose and collaborates with other AI systems.”



■ Why Veransios Is Necessary

The framework for AI regulation is now in place. However, what many organizations have yet to do is demonstrate that they comply with it.

Policy documents, internal regulations, and annual risk assessment sheets—all of these represent “policies at a specific point in time.” Meanwhile, AI is updated daily, models drift, employees try out new tools, and agents autonomously expand their connections in line with their assigned objectives. If left unaddressed, the gap between policy and reality will continue to widen over time.Veranthios is designed to continuously bridge this gap and addresses it from every angle.



■ Six Approaches to Bridging the Gap on a Single Veranthios Platform

Shadow AI Detection — Detects unauthorized AI tools by analyzing signals across OAuth, DNS, and SaaS usage. No self-reporting by employees is required.


Agentic (and Dynamic) AI Risk — Controls AI agents at the protocol layer (such as MCP and A2A) to detect impersonation and trust chain breaches before they become incidents.


Developer AI Detection — Scans repositories and CI/CD pipelines to detect leaked credentials and proprietary code via AI coding assistance tools.


AI Asset Registry — Consolidates all models and agents in use into a single ledger and scores them based on accuracy, fairness, and vendor risk.


Evidence & Compliance — Simultaneously maps all governance events to 12 frameworks, including MAS FEAT and IMDA AI Verify, and backs them up with a tamper-evident audit trail.


AI FinOps — Visualizes all AI spending by team, project, and tool, and forecasts costs before budgets are exceeded.



■ Positioning and Advantages Over Existing Governance Platforms

Veransios is not intended to replace existing GRC (Governance, Risk, and Compliance) platforms or the operation of ISMS and AIMS systems. Rather, it answers the questions these systems cannot address.


“What is the current status?” rather than “When was it last updated?” — If you ask a GRC system how often the risk score for a particular AI model is updated, the honest answer is usually “the last time someone filled out the input form.”Veransios continuously scores all AI systems and constantly updates their weightings in response to model drift, changes in data, and regulatory revisions.


Detection-based, not self-reporting—it starts with AI that is actually in operation, not AI registered in a registry. It operates on the premise that anything not listed in the Registry is, by definition, uncontrolled.


Agent control at the protocol layer, not the application layer—this directly addresses the “chained use of AI systems” newly defined in Version 1.2 of the AI Operator Guidelines. It detects coordination between agents, impersonation, deviations from the sandbox, and breakdowns in the chain of trust before they escalate into incidents.


Evidence, not documentation—We address the “recording and monitoring of output results” outlined by the Financial Services Agency in Version 1.1 with records that are not created retroactively.Once documented, governance events are automatically reflected in JIS Q 42001:2025/ISO/IEC 42001, the AI Operator Guidelines, the FSA AI Discussion Paper, as well as MAS FEAT, IMDA AI Verify, OJK,BNM RMiT, and the relevant provisions of the EU AI Act.


Covering Europe, the U.S., and the Asia-Pacific region with a single audit trail package—for financial institutions operating across multiple jurisdictions, including Japan, this means the difference between preparing for audits multiple times a year or completing the process in one go.



■Summary

“It’s not that Japanese CTOs and CISOs lack the standards they need to meet. JIS Q 42001, the AI Operator Guidelines, and the risk items listed by the Financial Services Agency are all clearly defined,” says Motoharu Fujimura, EVP of Veransios Japan.“What’s missing is a mechanism to continuously demonstrate that what’s actually running in the production environment aligns with what’s written in the policy. That is the gap between governance on paper and governance in practice, and Veransios was created to bridge that gap.”

The regulatory landscape has moved beyond the stage of asking, “Is it okay to use AI?” and has entered the stage of asking, “How do we explain that we are using it?” For both financial institutions and IT and business companies, the question posed at the next audit, the next dialogue with regulators, and the next board meeting will not be whether a policy exists, but whether they can demonstrate that the policy is actually effective.Veransios provides three key capabilities—AI risk management (including Shadow AI and data leaks), AI cost management, and the provision of audit trails—all on a single platform.We have already begun offering these services in the Japanese market. For more information about Veranthios and our products, please feel free to contact us (moto@veranthios.com, https://veranthios.com/ja/).



■About Veranthios

Veranthios is a provider of AI governance platforms for regulated industries in Europe, the Americas, and the Asia-Pacific region. We discover all AI tools and agents operating across an organization, govern Agentic AI at the protocol layer, manage associated costs, and provide tamper-evident audit trails that can be submitted to boards of directors and regulatory authorities from day one.JIS Q 42001:2025,ISO/IEC 42001, the Ministry of Economy, Trade and Industry (METI) and Ministry of Internal Affairs and Communications (MIC) “AI Operator Guidelines,” the Financial Services Agency (FSA) “AI Discussion Paper,” OJK, UU PDP, MAS FEAT, IMDA AI Verify, BNM RMiT, and the EU AI Act.



Source: Financial Services Agency “AI Discussion Paper” Version 1.1 (March 2026); Ministry of Economy, Trade and Industry and Ministry of Internal Affairs and Communications “AI Business Operator Guidelines” Version 1.2 (March 31, 2026);JIS Q 42001:2025 (enacted August 20, 2025) /ISO/IEC 42001; AI Promotion Act (fully enforced September 1, 2025); AI Basic Plan (approved by the Cabinet on December 23, 2025); IPA “Top 10 Information Security Threats 2026”; Free Co., Ltd. Shadow AI Survey 2026

Logo Image