Governed autonomy · risk & insurance
When an AI acts at 3 a.m., who’s liable?
Control evidence by design. The autonomous SOC your risk committee can actually sign off on.
How it holds
Read-only investigation
Assembles evidence, takes no action.
Approval-gated actions
Consequential actions pass a governing gate.
One audit trail per incident
The investigation is the record.
In one paragraph
What a governed autonomous SOC actually means
A governed autonomous SOC is one whose every autonomous decision is retraceable and whose every consequential action ran with a human in command.
Morpheus is built for that standard: read-only investigation takes no action on its own; consequential actions run only through risk-tiered approval gates across four autonomy modes, reversible and logged; and the investigation itself becomes a single audit trail per incident. The result is control evidence by design, an organization can demonstrate to a regulator, an auditor, or a board not only what the AI decided, but how, and where a human was in the loop, aligning with human-oversight obligations such as EU AI Act Article 14, DORA, and NIS2.
Who is liable when an AI acts in the SOC?
Liability doesn’t disappear because a machine acted. It sits with the organization that deployed it.
The indefensible answer
“The AI did it.”
A record scattered across logs and reconstructed after an incident, if it can be reconstructed at all.
The defensible position
Show precisely what the AI did, that a human could oversee it, and that consequential actions passed a governing gate.
Morpheus is designed so that record exists by default.
How do you prove what an autonomous system did?
You make the investigation itself the record. One chain of custody per incident.
Because the work and the audit record are the same artifact, there’s nothing to assemble after the fact. The proof is a property of how the system runs.
Regulatory context
What do EU AI Act Article 14, DORA, and NIS2 expect here?
You cannot oversee what you cannot retrace.
These regimes converge on meaningful human oversight of high-stakes systems, the ability for a person to understand, monitor, and intervene. Morpheus aligns through read-only investigation, human-in-command approval gates, and a complete per-incident record. This is oversight framing to discuss with your GRC team, not a certification Morpheus holds.
What does the board actually get?
The board decision log
A record it can stand behind
For any incident, the risk committee can see the full record without a fire drill to reconstruct it, which turns “we deployed autonomy” from an open question in a risk review into a documented, defensible control.
Per-incident decision log
- What the automated system decided
- The evidence behind it
- Where a human approved the action
- Where a human overrode it, reversible and logged
Control mapping
Map your oversight obligations to the mechanism
| Regime | Oversight obligation | Morpheus mechanism |
|---|---|---|
| EU AI Act Article 14 | Understand the system | Read-only investigation record |
| DORA | Intervene in decisions | Approval gates, override at any stage |
| DORA / NIS2 | Reverse a consequential action | Reversible, logged, human-in-command actions |
| NIS2 | Monitor and account afterward | One audit trail per incident |
How Morpheus mechanisms map to human-oversight obligations. Oversight framing to confirm with your GRC team, not a certification.
faqs
Frequently Asked Questions
The questions risk, GRC, and legal ask first about autonomy in the SOC.
Who is liable when an AI takes action in a SOC?
Liability rests with the deploying organization, which is why the ability to prove exactly what the AI did, and that a human could oversee it, is the core control. Morpheus records that by design.
Does autonomous response mean the AI acts without approval?
No. Consequential actions run only through risk-tiered approval gates across four autonomy modes; a human can override at any stage, and every action is reversible and logged.
How does Morpheus support human-oversight obligations like Article 14, DORA, and NIS2?
By making the investigation the audit record and keeping a human in command of consequential actions, so oversight is evidenced rather than asserted. Confirm applicability with your GRC team; this is alignment framing, not a certification.
Does Morpheus lower my cyber-insurance premium?
We don’t make that claim. What Morpheus provides is control evidence by design, read-only investigation, approval gates, and a per-incident audit trail, which is the kind of documentation risk and insurance conversations increasingly ask for. Any premium impact is between you and your broker.
Autonomy your risk committee can actually sign off on.
See the per-incident audit trail on a live investigation, and the obligation-to-mechanism mapping your GRC team can work from.