Patched AI or native AI: the difference that matters
"AI-native" has become an overused marketing claim. Here is what actually separates AI patched onto a platform from genuinely native AI, and what it changes for your analyses.
Patched AI: a chatbot bolted onto a platform
Patched AI is an MCP server connected to an existing platform, with a chatbot for analyses and suggestions. The AI is grafted on top of the tool. We have seen these solutions in large organisations and their limits show quickly: the result depends on the user (whoever phrases it better gets more), and the answer arrives without you knowing where it came from or how it was built.
Why patched AI accelerates you into the wall
You may get a RAG, but a generic one: it searches your documents without knowing exactly which field you are filling in. You lose time going back and forth between the chatbot and the platform. And nothing is worse than an AI that confidently asserts a wrong, hard-to-verify result. AI should save you time on what is true, not on what merely sounds plausible.
Native AI: the approach designed at Vailor
At Vailor, the AI was built into the platform from day one. It works field by field: for each item of the pre-assessment or the risk assessment, it looks for the excerpts of your documents that concern it and proposes an answer that quotes them, and Vailor checks word for word that each quoted passage is really in the document. Prefilling needs no prompt. On top of that, the "Ask Vailor" assistant, on every page of an assessment, answers from the assessment and its documents, with no internet access, and can launch those prefills. You choose the model, including a self-hosted one, and nothing is validated without a human.
Patched AI vs native AI: four decisive differences
Traceable and verifiable
When the AI relies on your documents, it quotes the passage, and Vailor checks word for word that it is there. No black box: you check before you validate.
No prompting skills required
The AI starts from the field to fill in and its context, not from an instruction typed by hand. Quality no longer rests on each user's writing skills.
One RAG per field, sources attached
The search targets exactly what you are filling in. Quoted passages are checked word for word against your documents, so an error is visible before validation.
The model of your choice
You choose the model, including one self-hosted on your premises. Your data is never used to train a model.
What native AI solves that patched AI can't
Frequently asked questions about AI-native GRC
What does one RAG per field actually mean?
RAG (retrieval augmented generation) means the system searches your documents for relevant passages before it writes anything. A generic RAG does this for a whole conversation: it pulls documents that look close to the topic and lets the model sort them out. One RAG per field narrows the search to the exact item you are filling in, a risk, a measure, a pre-assessment field, and injects only the passages that bear on it. The difference shows when you check the output: each line points back to the passage that justifies it, not to a pile of documents.
Can generative AI really be deterministic?
Not at the model level: a language model remains probabilistic, and two runs can phrase things differently. What matters is that the result can be verified. At Vailor, every proposal starts from the field to fill in and the excerpts of your documents that concern it; when it relies on a passage, it quotes it, and Vailor checks word for word that the passage is in the document. An expert reviews, corrects and validates, and that decision is traced. That is the opposite of a chatbot on its own, where the quality of the answer depends on how the question was phrased and on what the conversation happened to contain.
Do you need to be good at prompting to get usable output?
No, and that makes a useful buying criterion. When the result depends on the wording, the tool shifts the work onto the user: an experienced practitioner gets a sound analysis, a newcomer gets a plausible one, and nothing tells them apart on reading. A native platform starts from the object being filled in and its context, not from an instruction someone typed by hand. The skill expected from the team goes back to being its own, reviewing and deciding, rather than writing instructions to a machine.
Can a native AI still get things wrong?
Yes. Nothing makes generated content infallible, and a vendor who claims otherwise is asking you to take its word for it. What changes between the two approaches is the cost of checking. When every element points back to its source and to the field it belongs to, an error is spotted quickly and corrected where it originated. When the text comes out of a chat window and is pasted into a document, checking means rereading everything with no idea where each sentence came from. Human review remains the condition for validation either way.
What does a model-agnostic approach change in practice?
It keeps your compliance work from being tied to a single model provider's catalogue. A model is retired, its pricing changes, its terms of use move: with an architecture bound to one provider, those decisions become yours to absorb. At Vailor you choose the model, including one self-hosted on your premises. In our SaaS, data is stored in France (AWS Paris region) and the models run on AWS Bedrock in EU regions. Hence two separate questions worth putting to any vendor: where your documents live, and where the models called during processing actually run.
Does using AI in GRC create new obligations?
It depends on the use. The European AI Act, adopted in 2024, grades obligations by level of risk: internal productivity uses carry few, while systems classed as high risk concentrate the requirements, including for the organisation deploying them. The regulation is not a framework an organisation gets certified against: compliance is shown use by use. ISO/IEC 42001, which sets out an artificial intelligence management system, is certifiable. In both cases a maintained inventory of your AI systems is the starting point.
Why does AI add little on top of a spreadsheet?
Because there is nothing structured for it to work with. In a spreadsheet, a risk, the control that treats it and the evidence that supports it are three cells with no declared link, and the reasoning behind a rating stays in the head of whoever typed it. An AI plugged into that can only comment on text: it cannot tell which field its output belongs to, or what needs updating when a decision changes. Structuring the objects and their links first is what makes the work automatable afterwards, and defensible at audit.
Explore AI GRC with Vailor
Our resources on governance, risk and compliance assisted by artificial intelligence.
By role, and to go further
Pages to discover
Recommended articles
ANSSI-labelled EBIOS RM software: the 2026 overview
The EBIOS Risk Manager tools labelled by ANSSI as of 9 October 2026, what the label guarantees, what it does not, and how to check it.
Supply Chain Cyber Risk: How to Manage Your Suppliers
Supply chain cyber risk: what NIS2, DORA and EBIOS RM require, how to map your critical third parties, and what to ask your suppliers before and after signing.
Move from patched AI to native AI
Book 30 minutes to see how Vailor's AI reads your documents and prepares your risk assessments, under your experts' control.