---
title: "Control AI Systems by Firevault - Control Blueprint CP-08"
description: "Bound what an AI system can reach, and keep a stop that the model cannot argue with."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/control-blueprints/cp-08#webpage",
      "url": "https://fire-vault.com/control-blueprints/cp-08",
      "name": "Control AI Systems by Firevault - Control Blueprint CP-08",
      "description": "Bound what an AI system can reach, and keep a stop that the model cannot argue with.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/e0f0866b-dd9e-43f5-bd25-b979b70be970/og-blueprint-cp-08.webp"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/control-blueprints/cp-08#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/control-blueprints/cp-08#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Control Blueprints",
          "item": "https://fire-vault.com/control-blueprints"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Control AI Systems by Firevault - Control Blueprint CP-08",
          "item": "https://fire-vault.com/control-blueprints/cp-08"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "TechArticle",
      "headline": "Control AI Systems - Control Blueprint CP-08",
      "description": "Bound what an AI system can reach, and keep a stop that the model cannot argue with.",
      "author": {
        "@type": "Organization",
        "name": "Firevault"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Firevault",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png"
        }
      },
      "mainEntityOfPage": "https://fire-vault.com/control-blueprints/cp-08",
      "about": {
        "@type": "Thing",
        "name": "Control Blueprint CP-08"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

FIRE + VAULT · CP-08 

# Control AI Systems

Bound what an AI system can reach, and keep a stop that the model cannot argue with.

-   CP-08
-   Path and asset together

Discuss this Blueprint [Read the AI briefing](/ai-kill-switch) [All Blueprints](/control-blueprints)

![Control Blueprint CP-08, Control AI Systems: an isometric diagram of an AI agent whose route to production systems is physically severed, beside a sealed offline vault of model weights](/__l5e/assets-v1/c42048fd-81fa-49e6-9448-fef407daf3c2/blueprint-cp-08-hero.webp)

01 At a glance 

## What this Blueprint does.

Agent, model and tooling access with a physical hard stop

What it does

Bound what an AI system can reach, and keep a stop that the model cannot argue with.

Where it fits

Agent, model and tooling access with a physical hard stop

Who uses it

Financial services, Defence, Critical infrastructure, Healthcare, Public sector, Technology

CP-08 topology 

## How CP-08 controls AI systems.

A FIRE+VAULT pattern. The AI runtime holds no standing route to production data or tooling. Reach exists only as a validated, time-bound window, and a single Execute signal severs it at the physical layer regardless of how the model or its orchestration behaves.

Grounded in the EU AI Act Art. 14-15, NIST AI RMF MANAGE-2.3, ISO/IEC 42001 A.6 and IEC 62443-3-3 SR 5.1.

Z0 

AI runtime and agents

Models, orchestration

AI runtime and agents zone 

Models, orchestration and autonomous agents acting at machine speed

![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)Firebreak ![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate ![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)Relay 

Severed by default. Opens as a validated, time-bound window for a named purpose.

Z1 

Tooling and action layer

APIs, automation

Tooling and action layer zone 

APIs, automation and the systems an agent is allowed to change

![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)Isolate ![FV-Execute module icon](/assets/execute-icon-kJl5Gtmk.png)Execute ![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock 

Separated at hardware level. One Execute signal is the hard stop, enforced physically.

Z2 

Production data and systems

Records, shares

Production data and systems zone 

Records, shares and operational systems the work depends on

OSS 

Crown jewels · detail callout

Model and training asset vault

Weights, curated training sets and the record of every window held offline, outside anything an agent or its operator can reach.

Modules & symbols

![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)Firebreak Physical sever 

![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate Integrity check 

![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)Relay Time-bound path 

![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)Isolate Zone boundary 

![FV-Execute module icon](/assets/execute-icon-kJl5Gtmk.png)Execute Approved action 

![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock Named access 

Conduit Enforced module path 

┄┄┄ 

Crown jewels Offline · detail callout 

02 Modules in this Blueprint 

## How the CP-08 pattern composes.

How the primary modules compose

1.  [1 ![Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)
    
    Firebreak FIRE 
    
    Physically breaks the connection path so the attack cannot continue.
    
    
    
    ](/control/modules/firebreak)
2.  [2 ![Validate module icon](/assets/vault-icon-CD3Pv4ri.png)
    
    Validate VAULT 
    
    Checks the request, command or approval before anything proceeds.
    
    
    
    ](/control/modules/validate)
3.  [3 ![Execute module icon](/assets/execute-icon-kJl5Gtmk.png)
    
    Execute FIRE 
    
    Fires the control action the moment a signal demands it.
    
    
    
    ](/control/modules/execute)
4.  [4 ![Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)
    
    Isolate FIRE 
    
    Separates the affected environment into a controlled zone.
    
    
    
    ](/control/modules/isolate)
5.  [5 ![Relay module icon](/assets/relay-icon-CVhJDRO7.png)
    
    Relay FIRE 
    
    Opens a temporary, time-bound window for an approved purpose.
    
    
    
    ](/control/modules/relay)

Supporting modules

-   [![Lock module icon](/assets/lock-icon-UU3vOaKE.png)
    
    Lock VAULT 
    
    Holds the asset behind identity, role and policy controls.
    
    
    
    ](/control/modules/lock)
-   [![Archive module icon](/assets/archive-icon-B3rc85NY.png)
    
    Archive VAULT 
    
    Preserves the records, logs and evidence the control produced.
    
    
    
    ](/control/modules/archive)
-   [![Unlink module icon](/assets/unlink-icon-B8GFAVW1.png)
    
    Unlink VAULT 
    
    Removes the persistent dependencies that quietly bypass the control.
    
    
    
    ](/control/modules/unlink)
-   [![Transfer module icon](/assets/transfer-icon-DqGa0PQI.png)
    
    Transfer VAULT 
    
    Governs what moves between protected environments.
    
    
    
    ](/control/modules/transfer)

03 How it reads end to end 

## The Blueprint in full.

Firebreak holds the route between the AI system and production systems severed by default, so an agent inherits no standing path. Validate checks each request against identity, purpose and authority before anything opens. Relay grants the reach as a time-bound window rather than a permanent credential. Isolate keeps the model runtime, the data it processes and the tooling it can act on in separate zones. Execute is the hard stop: one signal severs the path at the physical layer, whether or not the software responds. Lock, Archive, Unlink and Transfer hold the models and training material behind identity controls, preserve the record of every window, remove always-on dependencies and govern what data moves in or out.

04 Sector relevance 

## Where CP-08 applies.

Financial services Defence Critical infrastructure Healthcare Public sector Technology 

05 Related Blueprints 

## Compose alongside.

[See all](/control-blueprints)

[

CP-03 FIRE + VAULT 

### Control Third-Party Access

Give third parties access without giving them a permanent doorway.

View Blueprint ](/control-blueprints/cp-03)[

CP-05 FIRE + VAULT 

### Protect Critical Infrastructure

Keep critical systems available, controlled and disconnected from unnecessary exposure.

View Blueprint ](/control-blueprints/cp-05)[

CP-01 FIRE-led 

### Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

View Blueprint ](/control-blueprints/cp-01)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Build control around your environment

Talk to our team about composing this Blueprint for your estate.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up