UK DUAA right to complain enforces in -- days · 19 June 2026 EU AI Act high-risk enforces in -- days · 2 August 2026

AI risk is not always obvious.

Your AI may be creating financial, legal, data, and customer risk right now.

If your app, website, chatbot, workflow, employee tool, or AI agent collects data, answers users, recommends actions, or affects decisions, your business may already have regulatory obligations. OBEXGATE helps you identify the risk, understand which rules may apply, and create evidence before regulators, auditors, customers, or investors ask for it.

If you have already deployed AI in your business, you need to know more than your risk. You need to be able to mitigate it.

The problem

AI does not have to make a final decision to create risk.

AI creates risk when it collects information, gives advice, ranks people, writes records, recommends actions, connects to tools, or changes what a human does next.

That can happen in a chatbot, a form, a website, an internal workflow, a sales tool, a coding agent, a medical assistant, a finance app, or a customer support system.

The issue is simple: if AI affects people, data, money, services, health, employment, insurance, credit, access, or customer trust, someone may ask you to prove it was controlled.

The governance gap

A policy does not stop a bad AI action.

Most organisations have documents: policies, privacy notices, vendor terms, spreadsheets, risk registers, or audit reports. Those matter, but they do not stop an AI tool from giving the wrong answer, using the wrong data, bypassing review, or creating a record no one can explain later.

OBEXGATE is built for the moment before the action happens.

Traditional governanceOBEXGATE
Documents controlsIdentifies AI risk before it becomes formal
Reviews incidentsMaps likely regulatory obligations
Reconstructs evidenceApplies controls before AI-enabled actions proceed
Runs periodic auditsCreates Witness Audit Evidence
Finds issues after executionHelps teams understand what to fix first

How OBEXGATE helps

OBEXGATE helps you control what AI is allowed to do.

OBEXGATE finds where AI is being used, checks the risk, maps the rules that may apply, adds controls before AI-enabled actions proceed, and keeps evidence of what happened.

So when someone asks, "Who approved this?", "What data was used?", "Was this reviewed?", "Why did the system do that?", or "Can you prove compliance?", you are not starting from panic.

Global marketplace risk

Is your app, website, or business in a global marketplace?

If you collect data, serve users, use vendors, or deploy AI across borders, your obligations may not stop at your home country. Click where you do business to see some of the regulations your organisation may need to consider.

The same AI-enabled action can create different obligations depending on the user location, data type, sector, vendor, and decision context.

View regulatory coverage

View AI governance by sector

Five things every AI business needs to answer.

01

Discover

Where are we using AI?

02

Assess

What risk does it create?

03

Enforce

What should be allowed, warned, held, blocked, or stopped?

04

Remediate

What do we need to fix first?

05

Prove

What evidence can we show if questioned?

This is the OBEXGATE lifecycle: Discover. Assess. Enforce. Remediate. Prove.

Different businesses. Same question: can you prove control?

CEOs and founders

You are accountable for AI risk

You are accountable for AI risk even when the tool was added by a team, vendor, or contractor.

CTOs and builders

Your AI stack may be unmapped

Your AI stack may include prompts, models, agents, APIs, logs, data flows, and third-party tools no one has mapped.

Vibe coders and solo developers

Shipping first can create exposure

You may have shipped an app before checking privacy, accessibility, AI regulation, data handling, or customer disclosure obligations.

Fintech teams

Customer treatment needs evidence

AI that affects fraud, onboarding, complaints, credit, risk scoring, or customer treatment can create regulatory and conduct exposure.

Healthcare teams

Care workflows need accountability

AI that touches care, documentation, triage, claims, patient messages, or clinical workflows needs evidence, oversight, and accountability.

Small businesses

Basic data collection may create obligations

Collecting names, emails, uploads, prompts, payments, or customer records may create obligations even if you are not a large company.

Start where you are.

If you are not sure whether AI risk applies to you, start with the free assessment. If you already deployed an app, workflow, chatbot, agent, or AI-assisted business process, use the Pre-Qualification Report or Governance Foundation Report to understand what may apply and what needs attention.

Six dimensions

The six dimensions of OBEXGATE governance

Find out your risk before a regulator that can fine you does.

AI problems become expensive when they turn into customer complaints, investor diligence questions, procurement delays, audits, regulator letters, privacy issues, accessibility complaints, emergency legal review, or public trust problems.

OBEXGATE gives you a way to find the risk early, understand what may apply, mitigate what matters, and build evidence before the question becomes formal.