UK DUAA right to complain enforces in -- days · 19 June 2026 EU AI Act high-risk enforces in -- days · 2 August 2026

For Chief Information Security Officer

The AI you do not know is running.

AI exists in scripts, vendor tools, internal automations, and local inference systems. These operate outside governance. Before OBEXGATE enforces anything, it identifies what is actually there.

If you cannot see it before it happens, you cannot prevent it.

Not visibility. Prevention.

Observer Mode shows how your system behaves

Enforce Mode blocks actions before execution

If an action violates policy, it does not run

The visibility problem

Most security tooling assumes it knows what is running.

That assumption is false. Embedded AI, shadow integrations, unmanaged inference endpoints, and vendor-side automations can sit outside the registered surface. A control that does not see them does not govern them.

Hungary: Fined an electronic communications provider €288,000 Art. 5 (1) b), e) GDPR, Art. 32 (1), (2) GDPR Insufficient technical and organisational measures to ensure information security.

Issued by: Hungarian National Authority for Data Protection and the Freedom of Information (NAIH)

Bulgaria: Fined a national revenue agency €2,600,000 Art. 32 GDPR Insufficient technical and organisational measures to ensure information security. A breach affecting millions of records from an agency whose controls did not cover the actual systems in operation.

Issued by: Commission for Personal Data Protection of Bulgaria (KZLD)

OBEXGATE identifies what exists before enforcing it. Discovery feeds the same evaluation engine that runs at execution.

Operational difference. Without discovery: unknown systems run without governance. With discovery: hidden systems are surfaced, classified, and brought into the same control surface as registered agents.

Detail on Shadow AI Discovery.

Policy authority

What is allowed, and who decides.

Governance policy in OBEXGATE is set by the organisation, not the platform. The platform enforces whatever the organisation's governance posture requires.

Policy is expressed across six governance dimensions: Assess, Enforce, Witness, Own, Explain, Sovereign.

Rules are configurable per system, per deployment topology, and per regulatory framework.

Observer Mode lets the security team validate the rule set before enforcement activates.

What it produces for your SOC

Tamper-evident evidence, on the channels you already monitor.

Every governed decision produces a structured record. Verdicts, audit lineage, and incident artefacts route to the SIEM you already operate.

Surface What it does
Decision trace Per-action record: what was evaluated, which frameworks applied, why the decision was made
Audit lineage Tamper-evident chain across every governed event. Cryptographically verifiable.
SIEM egress Splunk, Datadog, Elastic, SentinelOne, plus custom HTTP endpoints
Drift detection Continuous, async monitoring of behavioural shift across agent population. Alerts route to your incident pipeline.
Contestation workflow Right-to-challenge process with review and resolution record.
Incident evidence Structured artefacts available when escalation is required.

Adoption pattern

Observer Mode first. Enforcement when verified.

Observer Mode runs the same evaluation engine, but verdicts surface as alerts rather than blocks. This gives security teams the data needed to validate rules before enforcement is enabled.

When verification is complete, enforcement activates without redeploy.

Core invariants

Properties the system enforces, not policies you configure.

→ No execution without evaluation

Every governed action passes through the verification gate. No bypass path exists in the topology.

→ Unknown agents surfaced

Discovery runs continuously. Newly observed agents are classified before they are permitted to operate.

→ Enforcement cannot be bypassed

The commit authority is runtime-owned. There is no path to mutate state outside the gate.

→ Every decision traceable

Decision provenance is produced as a side effect of operation. Not assembled later.

→ Drift is detected

Behavioural shift across governed systems is surfaced for security review.

→ Audit evidence is sealed

Governed events produce tamper-evident evidence for escalation and audit.

See what is running that you have not registered.

Six questions. Personalised regulatory map, cost basis, statutory exposure. Or 30 minutes with the team to walk through what discovery would find in your environment.