
While more companies are using AI as an offensive move, there are no shortage of cases where the "defense" that supports it behind the scenes is not sufficiently in place. To use AI safely and connect it to sustainable growth, you need to establish, at the same time, three pillars that cannot function if even one is missing.
This article explains the roles of the three safeguards that support AI use — AI Safety (technical safety), AI governance (organizational control), and certification programs (external proof) — along with concrete examples of related initiatives.

Why the three safeguards each play a different role
The three safeguards all share the same goal of "using AI safely," yet they approach it at completely different layers.
| Safeguard | Role | Target |
|---|---|---|
| AI Safety | Technical safety | A system-level defensive wall that blocks cyberattacks and prevents AI "lies" (hallucinations) |
| AI governance | Organizational control | Internal rules and management structure that define "who operates AI safely, and how" |
| Certification programs | External proof | Undergoing review by a third-party body to objectively prove that a company's AI operations are safe |
Even if you shore up the technology alone, it won't be thoroughly followed in the field without operating rules. Even if you put the rules in place alone, without a means to objectively prove them, it won't lead to external trust. Only when all three are in place together do they form the foundation that supports "offense-oriented AI use."
1. AI Safety: Protecting through technology
AI Safety is the domain of making AI itself technically safe. This includes system-level defensive walls that block cyberattacks and prevent "hallucination," where AI generates incorrect information.
A representative product in this domain is the AI safety platform "GENFLUX," developed and provided by Elith. GENFLUX is offered as an integrated platform that broadly supports companies' safe and secure use of AI, spanning adoption, operation, security, quality evaluation, and custom development.
The main features GENFLUX provides are structured so companies can choose them according to the challenges they face.
- Shadow AI countermeasures: Visualizing AI usage within the company, detecting and blocking input content, DLP (data exfiltration prevention), and audit log/report output
- Agent evaluation: Automated evaluation of AI response quality, compliance with standards such as OWASP, and benchmark comparisons
- High-performance RAG: RAG chat, knowledge management, continuous improvement operations (RAG Ops), and department-specific access control
- On-premises delivery (Local): A closed environment on a dedicated GPU server that keeps sensitive data from leaving the company
- Custom AI development: End-to-end support from building AI tailored to your operations, to UI, integration, and workflow design, through to ongoing operation
Elith, the company behind GENFLUX, is an AI startup with strengths in the AI Safety and AI Security domains. It has built up a track record of research presentations and papers at international conferences such as ICLR, CVPR, IEEE ITSC, and ICCV, and is characterized by its continued development of defense technologies based on research into attack methods themselves. It has also been selected for the fourth round of "GENIAC," a national project to strengthen domestic generative AI development projects, and is working on developing "FinGuard," an AI guardrail model for the financial sector.
Based on the idea that "understanding AI more deeply than attackers do leads to genuine defense," combining research with implementation forms the foundation underpinning the AI Safety safeguard.
2. AI governance: Protecting through rules
AI governance is a management structure that formulates internal rules and guidelines, defining "who operates AI safely, and how." Even with a technical defensive wall in place, if the rules for who uses it and how remain vague, risks such as shadow AI and information leaks will build up in the field.
- Understanding the AI in use (visualization through an AI inventory)
- Organizational structure for risk assessment and response
- Establishing internal approval and enforcement processes for rules
Initiatives like these fall within this domain. Technology (AI Safety) and organization (AI governance) are a paired relationship that cannot function with only one side in place.
3. Certification programs: Protecting through proof
Certification programs are a mechanism for undergoing review by a third-party body to objectively prove that a company's AI operations are safe. No matter how much structure a company builds internally, if outsiders cannot judge whether it is "really safe," it will not lead to trust from business partners and customers.
A prime example is the "AI Governance C Certification" (AI Governance Core Certification) established by JDLA (Japan Deep Learning Association). It is drawing attention as a means of externally proving an AI governance structure, and as a program that can be obtained in a relatively short period.
As a certified consulting firm for C Certification, Elith supports companies in building AI governance structures and obtaining C Certification. If you are struggling with formulating rules and guidelines for using AI in your organization, or with building internal structures, please feel free to reach out to us.
We also welcome inquiries at the stage of "I don't know where to start" or "I want to get a clear picture of where we currently stand." Even if the specifics haven't been decided yet, we will work with you to figure out an approach suited to your current situation.

The perspective of building all three safeguards at the same time
AI Safety, AI governance, and certification programs may look like independent efforts, but in practice they complement one another.
- Technology (AI Safety) alone is not thoroughly followed in the field without rules
- Rules (AI governance) alone lack real effectiveness without a technical defensive wall
- Even with technology and rules in place, without proof (certification programs) it does not lead to external trust
The more a company advances "offense-oriented AI use," the more it needs a perspective of building all three at once, step by step. The first step is to identify which safeguard is weakest at your own company.
