Discover
Where are we using AI?
AI risk is not always obvious.
If your app, website, chatbot, workflow, employee tool, or AI agent collects data, answers users, recommends actions, or affects decisions, your business may already have regulatory obligations. OBEXGATE helps you identify the risk, understand which rules may apply, and create evidence before regulators, auditors, customers, or investors ask for it.
If you have already deployed AI in your business, you need to know more than your risk. You need to be able to mitigate it.
The problem
AI creates risk when it collects information, gives advice, ranks people, writes records, recommends actions, connects to tools, or changes what a human does next.
That can happen in a chatbot, a form, a website, an internal workflow, a sales tool, a coding agent, a medical assistant, a finance app, or a customer support system.
The issue is simple: if AI affects people, data, money, services, health, employment, insurance, credit, access, or customer trust, someone may ask you to prove it was controlled.
The governance gap
Most organisations have documents: policies, privacy notices, vendor terms, spreadsheets, risk registers, or audit reports. Those matter, but they do not stop an AI tool from giving the wrong answer, using the wrong data, bypassing review, or creating a record no one can explain later.
OBEXGATE is built for the moment before the action happens.
| Traditional governance | OBEXGATE |
|---|---|
| Documents controls | Identifies AI risk before it becomes formal |
| Reviews incidents | Maps likely regulatory obligations |
| Reconstructs evidence | Applies controls before AI-enabled actions proceed |
| Runs periodic audits | Creates Witness Audit Evidence |
| Finds issues after execution | Helps teams understand what to fix first |
How OBEXGATE helps
OBEXGATE finds where AI is being used, checks the risk, maps the rules that may apply, adds controls before AI-enabled actions proceed, and keeps evidence of what happened.
So when someone asks, "Who approved this?", "What data was used?", "Was this reviewed?", "Why did the system do that?", or "Can you prove compliance?", you are not starting from panic.
Global marketplace risk
If you collect data, serve users, use vendors, or deploy AI across borders, your obligations may not stop at your home country. Click where you do business to see some of the regulations your organisation may need to consider.
The same AI-enabled action can create different obligations depending on the user location, data type, sector, vendor, and decision context.
Where are we using AI?
What risk does it create?
What should be allowed, warned, held, blocked, or stopped?
What do we need to fix first?
What evidence can we show if questioned?
You are accountable for AI risk even when the tool was added by a team, vendor, or contractor.
Your AI stack may include prompts, models, agents, APIs, logs, data flows, and third-party tools no one has mapped.
You may have shipped an app before checking privacy, accessibility, AI regulation, data handling, or customer disclosure obligations.
AI that affects fraud, onboarding, complaints, credit, risk scoring, or customer treatment can create regulatory and conduct exposure.
AI that touches care, documentation, triage, claims, patient messages, or clinical workflows needs evidence, oversight, and accountability.
Collecting names, emails, uploads, prompts, payments, or customer records may create obligations even if you are not a large company.
If you are not sure whether AI risk applies to you, start with the free assessment. If you already deployed an app, workflow, chatbot, agent, or AI-assisted business process, use the Pre-Qualification Report or Governance Foundation Report to understand what may apply and what needs attention.
For a quick exposure snapshot.
For deployed apps, websites, workflows, agents, and small businesses that need an exposure map and initial next-step priorities.
For organisations that need a weighted score, full report, likely regulatory issues, and basic remediation pathways.
For organisations that need audit-grade evaluation, FRIA where applicable, specific remediation planning, and deployment support.
Six dimensions
Maps AI risk, reversibility, governance readiness, behavioural envelope, and failure-mode exposure.
Blocks or holds unauthorised actions before execution.
Captures every action, including refused actions. The author cannot be the final verifier.
Every action carries a named human owner. Delegation does not erase accountability.
Renders the same evidence for governance, audit, regulatory, and executive audiences.
Treats jurisdiction, region, residency, and data sovereignty as first-class platform fields.
AI problems become expensive when they turn into customer complaints, investor diligence questions, procurement delays, audits, regulator letters, privacy issues, accessibility complaints, emergency legal review, or public trust problems.
OBEXGATE gives you a way to find the risk early, understand what may apply, mitigate what matters, and build evidence before the question becomes formal.