Glacis vs Isara: AI Runtime Security vs Conversation Verification
Glacis Vs Isara
Firms running AI support agents in financial services and iGaming keep meeting the same comparison in 2026: Glacis or Isara. The two names get shortlisted together, but they solve different halves of the same problem. Glacis secures what an AI system does at the infrastructure layer and signs cryptographic proof that a control fired. Isara verifies what your customer facing AI agent actually said, promised and did inside the conversation. Isara exists because the evidence that a customer was treated fairly has to be captured in the conversation itself, not inferred from a system log after the fact.
This guide sets out what each platform is built to prove, why securing the agent and verifying the conversation are not the same job, and a practical framework for deciding which one you need and how the two fit together.
The short version
When you compare Glacis and Isara, hold on to six points:
- Glacis verifies the system. It enforces controls at the inference boundary and proves a technical action was allowed or blocked.
- Isara verifies the conversation. It scores every interaction and proves what the agent said, promised, and did.
- The most costly AI agent failures in regulated customer experience are unauthorised commitments, not blocked transactions, and only the conversation layer catches those.
- Keep the two layers independent, so the checker does not fail the same way the agent does.
- Choose Glacis for infrastructure assurance and Isara for independent, audit ready proof of customer outcomes. Many regulated firms need both.
- Start capturing conversation evidence now, because the record is cumulative and cannot be backdated once a regulator or an underwriter asks for it.
The rest of this article unpacks each point.
Why the Glacis and Isara question is really two questions
Glacis and Isara get compared because both promise to help you trust AI agents. The moment you look at what each one actually inspects, the overlap narrows. Glacis asks whether the system stayed inside its technical boundaries. Isara asks whether the agent treated the customer correctly. A firm can pass the first test and fail the second on the same conversation.
Picture a support agent that never triggers a single blocked action, yet tells a player their account will be reopened tomorrow when policy says it cannot be. Nothing at the infrastructure layer fired, because a spoken promise is words rather than a transaction. The failure lives entirely in the conversation, which is the layer Isara is built to verify.
What Glacis does well
Glacis is a strong runtime security and governance platform, and it is worth being precise about its strengths. It sits inline at the inference boundary, enforces which actions are allowed to run, and emits signed receipts built on its open OVERT standard, which reached version 1.1 on 11 June 2026. Those receipts are witnessed and portable, so an auditor, a customer, or an insurer can verify them independently without trusting Glacis itself.
Its centre of gravity is regulated, high stakes automation such as clinical AI, ambient medical scribes, and hiring decisions, where the core question is whether a technical control executed as intended. For teams whose main risk is an AI system taking an action it should have been stopped from taking, that runtime enforcement layer is genuinely valuable.
What Glacis does not verify, and Isara does
What a runtime security layer cannot tell you is what the agent said to the customer and whether it was allowed to say it. That is a different measurement, and it is the one support and success leaders in regulated verticals are held to. Isara is purpose built for it.
- What was actually said. Isara scores 100% of conversations across every channel, human and AI, rather than sampling a fraction.
- Unauthorised commitments. AI Agents Focus flags unauthorised refunds, discounts, and unsafe data handling inside live conversations.
- Explainable risk signals. Agent Intelligence tracks override rates, correction rates, inconsistencies, and predicted CSAT, so a person can read and defend why a conversation was flagged.
- Regulator ready output. Compliance Audits scan conversations against frameworks such as GDPR and PCI DSS and produce evidence built for a compliance officer, not for an engineer.
- Independence. Isara never builds or sells the agents it checks and connects to Gorgias, HubSpot, Intercom, Zendesk, and Freshdesk without a rebuild, so it verifies the agents you already run.
Why runtime security alone is not enough for regulated customer experience
The market data points the same way. Gartner published its first Market Guide for Guardian Agents on 25 February 2026, defining a category of AI systems whose job is to monitor, govern, and constrain other AI agents. Two of its findings matter for this comparison. Through 2028, Gartner expects at least 80% of unauthorised AI agent transactions to come from internal violations of enterprise policy, such as oversharing or misguided behaviour, rather than from external attacks. By 2029, it expects independent guardian agents to remove the need for almost half of the incumbent risk and security systems protecting AI agents in more than 70% of organisations.
Read those together and the gap is clear. Most agent failures are not break ins that a security layer blocks. They are agents behaving inside the system while doing the wrong thing for the customer, and independence is the property that catches them.
Regulation is moving on the same axis. Under the EU AI Act, the transparency obligations in Article 50 take effect on 2 August 2026, requiring firms to disclose when a customer is interacting with a machine. In the United States, the Texas Responsible Artificial Intelligence Governance Act came into force in January 2026. The UK Financial Conduct Authority expanded its AI Live Testing programme to a second cohort in April 2026, including Barclays, Experian, Lloyds Banking Group, UBS, and GoCardless, working alongside the assurance firm Advai, and it continues to supervise AI through existing principles such as Consumer Duty. In every case the expectation is the same: produce the record of what the agent did, not the policy that says what it should have done.
How to choose between and combine Glacis and Isara: a framework
1. Name the risk you are actually managing
If your exposure is an AI system executing a technical action it should have been blocked from taking, that is a runtime security problem and Glacis speaks to it directly. If your exposure is what the agent tells customers and promises them, that is a conversation verification problem and it is Isara's core focus.
2. Verify the conversation, not just the container
A secure runtime does not prove a fair conversation. Capture and score every interaction your support and success teams handle, including those run entirely by AI agents, so the thing a regulator or a customer will actually ask about is on the record.
3. Keep oversight independent of the agent
An oversight layer that shares the same data, assumptions, and failure modes as the agent it checks tends to miss the same things. Isara positions its judging as decorrelated oversight for this reason, and it verifies agents it did not build, so its checks do not inherit the agent's blind spots.
4. Insist that every signal is explainable
A score with no explanation is not evidence. When Isara flags a conversation, the reason is legible to a compliance officer or an underwriter, which is what turns a signal into something you can defend.
5. Combine the layers where the stakes justify it
The two platforms are complementary rather than competing. Glacis proves the system was secure and a control held. Isara proves the agent made no unauthorised commitment and handled the customer correctly. In high stakes igaming and fintech workflows, running infrastructure assurance and conversation verification together closes both halves of the gap.
6. Start the record now
Conversation evidence compounds because it cannot be backdated. A firm that starts capturing and scoring conversations today will, by the time a regulator or an insurer asks, hold a record spanning years. A firm that starts the week it is asked will hold a record spanning days.
Glacis vs Isara at a glance
| The question the buyer is really asking | Glacis, runtime security | Isara, conversation verification |
|---|---|---|
| Did the system stay inside its technical boundaries? | Yes. Blocks out of scope actions inline and signs an OVERT receipt | Not its focus |
| Did the agent say the right thing to the customer? | Not its focus | Yes. Scores 100% of conversations for what was said and promised |
| Did the agent make an unauthorised commitment? | Only if it triggered a blocked action | Yes. AI Agents Focus flags unauthorised refunds, discounts, and unsafe data handling |
| Is the oversight independent of the agent vendor? | Independent witness countersigns the receipts | Never builds or sells the agents it checks, and connects without a rebuild |
| Who is the output built for? | Auditors, insurers, and security teams | Compliance and customer experience leaders |
Glacis vs Isara by vertical
Financial services. The FCA's principles based approach means firms are judged against existing obligations such as Consumer Duty using whatever evidence they can produce. Glacis can prove an automated payment action was stopped when it breached a control. Isara adds the evidence that speaks to Consumer Duty's outcome focused test: when vulnerability was identified in a conversation, what the agent said next, and whether any commitment made was one the agent was authorised to make.
iGaming. Operators cannot treat AI models as black boxes, and the Gambling Commission expects a documented path from identifying a harm indicator to acting on it. A runtime layer proves an action was blocked. Isara proves what the agent actually told the player, whether a self exclusion request was handled correctly, and whether an unauthorised bonus or reopening was ever promised, which is the part of the record that lives in the conversation.
In both verticals the principle holds. Securing the agent and verifying the conversation are complementary, and regulators increasingly want the second on the record as well as the first.
Frequently asked questions
What is the difference between Glacis and Isara?
Glacis is an AI runtime security and governance platform that enforces controls at the inference boundary and signs cryptographic proof that a control ran. Isara is an independent AI agent verification platform that scores every customer conversation and proves what the agent said, promised, and did. Glacis verifies the system. Isara verifies the conversation.
Do Glacis and Isara compete, or can I use both?
They are complementary. Glacis covers infrastructure assurance and Isara covers conversation verification, and many regulated firms run both so they can prove the system was secure and that the customer was treated fairly.
What can Isara detect that a runtime security layer like Glacis cannot?
Unauthorised commitments and unsafe handling inside the conversation itself. Isara's AI Agents Focus catches unauthorised refunds, discounts, and unsafe data handling in live conversations, and Agent Intelligence tracks override rates, correction rates, inconsistencies, and predicted CSAT across 100% of conversations. These are outcomes an infrastructure control, which watches actions rather than words, will not surface.
How does Isara stay independent of the AI agent vendor?
Isara never builds or sells the agents it checks, which keeps its oversight decorrelated from the agent's own assumptions. It connects to Gorgias, HubSpot, Intercom, Zendesk, and Freshdesk without a rebuild, so it can verify AI support agents you already run rather than requiring you to migrate.
Which one do I need for igaming or fintech compliance?
If your risk is a system executing a blocked action, Glacis addresses it. If your risk is what the agent tells customers and whether it made a commitment it had no authority to make, that is Isara's focus, and it maps to frameworks such as Consumer Duty and the Gambling Commission's expectations. Firms with high stakes automation often use both.
Can Isara verify conversations handled by AI agents as well as human ones?
Yes. Isara monitors and scores conversations across both, tagging areas of concern so a human can read and defend every signal.
Bringing it together
Glacis and Isara are not really rivals. Glacis secures the agent at the infrastructure layer and proves a control held. Isara verifies the conversation and proves the agent made no unauthorised commitment and treated the customer fairly. In regulated customer experience, where the most expensive failures are promises rather than blocked transactions, the conversation layer is the one support and success leaders personally own, and it is the record a regulator or an insurer is most likely to ask for.
If you want to see what that record would show for your own support and success conversations, you can connect a stream in minutes, read only, and see what surfaces by the end of the week.