
Dutch governance for AI platform Deeploy works within highly regulated industries to ensure their agents and models are running on safe guard rails. Data Management Insight spoke to Maarten Stolk, Co-Founder and Chief Executive at Deeploy, about the company and why governance is so crucial in the AI age.
Data Management Insight: When was Deeploy created and how does it serve financial institutions?
Maarten Stolk: We started Deeploy in 2020, at a point when most of the conversation about responsible AI was still happening in policy documents and ethical forums rather than through investment in the systems themselves. Our view then, and now, is that you cannot govern a model by writing about it. Governance to be installed where it runs.
That is how we work with regulated organisations such as financial institutions, which are balancing on a tightrope. Their licence to operate is based on trust but the adoption of AI is also crucial, which must be done safely. Deeploy sits alongside the models a bank has in production so that risk and compliance teams can see what those models are deciding, why, and whether that is drifting from what was approved. Customers like bunq (a leading EU neobank) and Novo Nordisk (the biggest pharmaceutical company in Europe) use it to give regulators, auditors and senior management a live answer rather than a retrospective one.DMI: What is the driving mission behind the company?
MS: We believe in and see the huge potential of AI, mostly for high-risk and high-impact use cases across healthcare, financial services and critical infrastructure. It can be used to cure diseases, discover new drugs or personalise treatments, better detect crime or optimise the energy grid. However, in order to apply AI to these use cases, it must be used safely and deployed in a controlled way. This necessitates regulation and governance.
Our mission is to provide that governance, closing the gap between how organisations say their AI behaves and how it actually behaves. Most governance today lives in a manual – a policy, a register, an annual assessment – all of which describes intent.
The model in production does not read it. We have all seen what happens when that gap widens. For instance, the Dutch childcare benefits scandal, which involved false allegations of welfare fraud, costing the Dutch government billions of euros and leading to the resignation of the administration at the time. This was not caused by an absence of rules but by nobody watching what the system was doing to real people. Our mission is to make that kind of blindness impossible. Every AI decision should be observable, explainable and traceable back to a control that somebody signed off. If a regulator, a customer or a court asks why a decision was made, the answer should already exist, not be reconstructed afterwards.DMI: What are the most common pain points that it solves for clients?
MS: There are a few that come up in almost every conversation and the first is risk. A lack of compliance can come with the risk of heavy fines, let alone the operational and commercial risk of losing the trust of your customers.
Next is a lack of control. Costs and use cases can rapidly spiral without adequate oversight and governance.
Then comes efficiency. Businesses want to be able to adopt AI governance thoroughly and effectively but doing this can, in some cases, come with heavy demands on people’s time. Deeploy helps streamline this process.
Finally comes ensuring a licence to operate. Without ISO42001 and compliance with the EU AI Act, regulated vendors simply aren’t able to sell. Deeploy addresses these pain points, giving businesses assurance that their AI deployments are governed, safe and ethical.
DMI: What are the newest challenges that Deeploy is helping clients overcome?
MS: In short, agents. Until recently an AI system took an input and produced an output, and you could reason about it. Agents take actions – they call tools, trigger workflows, hand tasks to other agents. The number of decisions multiplies and the audit trail fragments. Financial institutions are now piloting agents in operations, onboarding and customer service, and their governance frameworks were not designed for software that acts on its own initiative. This is happening at a volume and frequency we have never before experienced. Businesses are moving from 10 AI systems to 1,000 agents, and the models behind them are evolving at pace.
The questions are therefore new: which agent made this decision, what did it have access to, who approved the boundary it was working within? We are helping clients answer those questions and manage workloads with the same principle we have always applied which is to govern at runtime, not using a manual. An agent needs guardrails, logging and explainability built into where it operates, otherwise you are trusting a system you cannot see.
DMI: How are governance expectations changing in the age of AI?
MS: They are shifting from periodic to continuous. Ten years ago, a model validation every 12 months was acceptable. Regulators now expect organisations to know what their AI is doing today.
The EU AI Act has accelerated that and the organisations that struggled with it did not struggle because the rules were unreasonable, they struggled because they had never documented their AI properly in the first place, and discovered that when the obligations arrived. The UK is heading the same way, whatever form its legislation eventually takes.
The other change is who is asking. It used to be the regulator, but now it is customers, boards, insurers and increasingly the courts. Governance is becoming an operating discipline rather than a compliance deadline, and the firms that treat it that way will cope far better.
DMI: What does Deeploy see as the next big thing in data management?
MS: The line between data governance and AI governance is disappearing. For years they were separate disciplines with separate teams with one worried about lineage and quality, the other about model risk. I don’t think that holds any longer, because a model is only as governable as the data feeding it, and a decision is only as explainable as the data that shaped it. I think the next phase is decision-level lineage. Not just where did this data come from, but which data, which model version and which control produced this specific outcome for this specific customer. That is what a regulator will ask for, and it is what most organisations cannot yet produce.
The data management teams that get ahead of this will stop being seen as plumbing and start being seen as the foundation of trustworthy AI. That is a significant shift in how the function is valued.
DMI: What’s in the pipeline for the next 12 months?
MS: Over the next year, we’ll be working to enhance various aspects of our product to ensure the best outcomes and greatest business impact for our users. This includes investing in runtime control to make policies binding at the moment the model or agent acts; advancing our intelligence layer to create governance signals without manual work; and expanding the breadth of our platform to meet AI governance where our customers already work with support for local models and ecosystem integrations.
Subscribe to our newsletter


