Bodaty LLC, a Naperville, Illinois-based company, has launched AICtrlNet, an open source platform for Governed AI Orchestration that requires named human approval for consequential AI actions and maintains tamper-evident audit records. The platform has been in production since June and arrives as regulators and insurers tighten the rules around who answers for an AI system's mistakes.
The Liability Question Stops Being Hypothetical
This year, the question of who pays when an AI agent misbehaves stopped being hypothetical. California's AB 316 bars companies that developed, modified, or used an AI system from arguing it acted autonomously. The European Union's revised Product Liability Directive treats firms that modify or brand an AI system as its manufacturer. Insurers, meanwhile, are using Verisk's generative-AI exclusion forms to write AI incidents out of general-liability renewals.
Haran Segram, writing this week in The Wall Street Journal, said the exposure "sits on nobody's books." The gap between AI's actions and human accountability is now a legal and financial reality.
A 1979 Rule Returns
Bodaty's founder and CEO, Bobby Koritala, frames the product as a return to an old principle. "The 1979 IBM training rule said a computer must never make a management decision, because it can never be held accountable," he said.
That rule, he argues, is no longer a historical footnote. "That rule is becoming case law and insurance policy. Businesses don't need braver AI. They need to answer 'who approved that?' in one query. We built software that makes that the default."
Koritala previously served as chief product officer at Infogix, a data-integrity company acquired by Precisely. Infogix's products served many of the country's largest banks and insurers.
How AICtrlNet Works
Stay ahead of the AI curve
The most important updates, news, and content — delivered weekly.
No spam. Unsubscribe anytime.
AICtrlNet is open source at the core. Every consequential action, such as a customer email, invoice, or payment instruction, can be gated behind a named person's approval. Every approval lands in a timestamped, tamper-evident audit record. The platform never moves money on its own.
The person of record is not a contract clause in AICtrlNet. It is how the software runs. Businesses can answer "who approved that?" in one query, with the audit trail as proof.
The platform deploys anywhere: sovereign, air-gapped, or managed cloud. It is model-independent, supporting Claude, OpenAI, Gemini, and local open-weight runtimes.
Open Source and Commercial Tiers
The Community Edition is MIT-licensed and freely available at github.com/bodaty/aictrlnet-community. Business and Enterprise tiers are commercially available, giving organizations three options: free community access, mid-tier business features, and full enterprise controls.
Bodaty also offers HitLai, a small-business product that brings the same governance to SMB operations. In HitLai, the AI does the work, and the team approves the outcomes.
The Bottom Line
The 1979 IBM training rule is becoming case law and insurance policy. Bodaty's answer has been in production since June, and it makes human approval the default, not an optional feature. For companies facing AB 316, the EU directive, and insurers' new exclusions, the software offers a direct answer to a question that now has real financial weight.

