Open by Design.
Three Pillars for Public AI Infrastructure.
OCC doesn't build apps. OCC builds infrastructure. Three pillars that together create a complete public AI platform for AI Governance.
Knowledge Companion
The public knowledge base for AI Governance
689 chunks from 26 verified public-domain sources (EU AI Act, GDPR, NIST AI RMF, OECD AI Principles, UNESCO AI Ethics, CoE CETS 225, EC Ethics Guidelines + 15 IIO Framework sources). BM25 retrieval via public API. No API key. No rate limit.
All sources: public domain or Apache-2.0. Complete provenance chain: source → document → chunk. Anti-contamination policy: no copyright-protected content without explicit license review.
Public LLM Core
The first open AI governance language model
compliance-qwen: Qwen2.5-7B (Apache-2.0) with QLoRA finetuning on the OCC corpus (~600 chunks). Reproducible training recipe. Public model card. EU-hosted (IIO AI Hub, RTX PRO 6000, 96GB VRAM).
Goal: the first publicly reproducible, open AI governance language model. No proprietary data. All training steps documented. Safety evaluation before every release (Pillar 3).
Safety, Trust & Governance
Independent security review and open governance framework
No model release without Safety Reviewer sign-off. 94 evaluation questions covering EU AI Act, GDPR, NIST, OECD. 7 red-team scenarios (jailbreak, PII extraction, MCP scope escape, rate limit, CBRN, hallucination, attribution). 8 release gates with clear pass/fail criteria.
No model release without Safety Reviewer sign-off. The red-team playbook defines 7 attack scenarios (jailbreak, PII extraction, MCP scope escape, rate limit, CBRN, hallucination, attribution). All 8 release gates must be green — no emergency override without community vote.
The IIO Governance Framework is the reference implementation for agentic governance. Human-in-the-Loop (HITL) Gates: AI agents pause before irreversible actions. 259 Governance Layers for all business domains. 546 auditable flows with complete evidence trails.
The OCC Governance Framework is available as an MCP server. Claude, Cursor and other MCP-capable agents can directly access 259 layer definitions, HITL gate patterns and all 546 flows — without API keys.
npx -y @occ/mcp-server