Independent AI Safety & Assurance

Confidence in the systems you deploy.

Prime Variable advises government and industry on the safe, lawful and accountable use of artificial intelligence — from first risk assessment through to independent assurance of systems already in production.

Public sector Regulated industry Critical infrastructure Technology & product teams

About

A practical discipline,
not a theoretical one.

Most organisations do not have an AI problem in the abstract. They have a specific system, making specific decisions, affecting specific people — and no defensible account of how it behaves, where it fails, or who is answerable when it does.

Prime Variable exists to close that gap. We combine technical evaluation with governance and regulatory expertise, so that the controls we recommend are ones your engineers can implement, your executives can oversee, and your regulators and the public can scrutinise. We work to established standards — the EU AI Act, ISO/IEC 42001, the NIST AI Risk Management Framework, and sector-specific obligations — rather than to a proprietary methodology of our own invention.

We are deliberately independent. We do not resell AI platforms, take vendor commissions, or hold positions in the systems we assess. Our only product is a judgement you can rely on.

Independence

No vendor relationships, no resale margin, no incentive to find a system safer than it is.

Rigour

Findings are evidenced, reproducible and traceable to a stated method — not to opinion.

Practicability

Every recommendation is scoped to something your organisation can actually implement.

Transparency

Plain reporting of limitations, residual risk and what our assessment does not cover.

Services

What we do.

Engagements range from a two-week assessment of a single system to an embedded programme spanning an organisation's entire AI estate.

01

AI Risk Assessment & Assurance

Structured assessment of an AI system across its lifecycle: intended use, data provenance, failure modes, human oversight and downstream impact. Delivered as an evidenced risk register with prioritised, costed remediation.

02

Governance & Policy Advisory

Design of AI governance that functions in practice — policy, acceptable-use standards, approval gateways, model inventories, accountability lines and board-level reporting that reflects real exposure.

03

Regulatory Readiness & Conformity

Gap analysis and remediation planning against the EU AI Act, ISO/IEC 42001, the NIST AI RMF and applicable domestic obligations — including classification, technical documentation and conformity evidence.

04

Model Evaluation & Red-Teaming

Adversarial and capability testing of models and AI-enabled applications: prompt injection, jailbreak resistance, data leakage, tool and agent misuse, bias and robustness — with reproducible test artefacts you retain.

05

Monitoring & Incident Response

Post-deployment controls: drift and performance monitoring, evaluation harnesses in CI, incident classification and escalation, and response playbooks rehearsed before you need them.

06

Training & Capability Uplift

Role-specific education for boards, executives, risk and audit functions, and engineering teams — so that oversight is informed and delivery teams know what safe implementation requires of them.

Industries

Where the stakes are highest.

We work across the public and private sectors. The methods are consistent; the risks, obligations and thresholds of acceptable failure are not.

Government & Public Administration

Automated decision-making that affects entitlements, eligibility and rights — where procedural fairness and reviewability are legal requirements, not preferences.

Defence & National Security

Assurance for systems in high-consequence environments, with meaningful human control and classification-aware handling throughout.

Healthcare

Clinical and administrative AI where safety, evidentiary standards, equity of outcome and patient confidentiality all bind simultaneously.

Financial Services

Credit, fraud, advice and surveillance models under prudential expectations for model risk management, explainability and consumer fairness.

Critical Infrastructure & Energy

Operational technology and forecasting systems where availability, integrity and resilience to adversarial interference are paramount.

Education

Assessment, admissions and student-support tools that must be defensible, age-appropriate and free from opaque profiling.

Legal & Professional Services

Research, drafting and review systems where confidentiality, privilege and the risk of confident fabrication carry professional consequences.

Technology & Product Teams

Pre-release evaluation, safety cases and customer-facing assurance for organisations shipping AI capability to others.

Why Prime Variable

What makes our judgement worth having.

Independent by construction

We hold no vendor partnerships, resale agreements or referral arrangements. Our assessment of a system is not shaped by what we would otherwise have to sell you.

Technical and regulatory in one team

Evaluation engineers and governance specialists work the same engagement, so findings arrive already translated into obligations, controls and board-level consequence.

Aligned to recognised standards

We assess against the EU AI Act, ISO/IEC 42001 and the NIST AI RMF — frameworks your regulators, auditors and customers already recognise and can test our work against.

Scoped to your reality

Engagements run from a rapid assessment of a single system to an embedded assurance programme. We size the work to the decision you need to make, not to a retainer.

Team

Who you work with.

Aryeh Sternberg

Principal Partner

Juna Rice

AI Strategy

Contact

Start a conversation.

Tell us what you are building, buying or already running. An initial discussion is obligation-free, and we will tell you plainly if an engagement is not warranted.

Location
[[Sydney, Australia]] — engagements delivered nationally and remotely
Response time
We typically respond within one business day.

Please enter your name.
Please enter your organisation.
Please enter a valid email address.
Please select a sector.
Please tell us a little about your enquiry.

Thank you — we will be in touch.

Your enquiry has been received. We typically respond within one business day.