UK DUAA right to complain enforces in -- days · 19 June 2026 EU AI Act high-risk enforces in -- days · 2 August 2026

For General Counsel

The proof a regulator asks for, before they ask.

Article-mapped evidence. Decision provenance produced continuously. Contestation workflow that supports right-to-challenge obligations emerging across jurisdictions. The artefacts a regulator actually wants, in the format the statutory framework requires.

If the system verifies itself, the evidence will not hold.

Not documentation. Evidence that holds.

Observer Mode shows how your system behaves

Enforce Mode blocks actions before execution

If an action violates policy, it does not run

Regulatory inquiry

What happens when a regulator asks.

An incident occurs. Legal is notified. What follows is reconstruction: relevant staff are interviewed, logs are retrieved from multiple systems, decisions are mapped to regulatory articles, a timeline is assembled, accountability is established. Each step is contested. Each step takes time that is not available. The evidence that emerges was built after the fact. Its integrity is contestable.

France: Fined a real estate firm €400,000 Art. 5 (1) e) GDPR Insufficient technical and organisational measures to ensure information security.

Issued by: Commission Nationale de l'Informatique et des Libertés (CNIL)

United Kingdom: Fined an international hotel group €20,450,000 Art. 32 GDPR Insufficient technical and organisational measures to ensure information security. The group could not produce adequate evidence of the controls that were in place at the time of the incident.

Issued by: Information Commissioner's Office (ICO)

OBEXGATE produces this record as a continuous side effect of operation. It is not assembled after inquiry begins. It exists before the regulator asks.

The legal problem

Documented intent does not satisfy enforcement requirements.

Most AI governance produces declared posture: policies, attestations, and periodic audits. Regulators are increasingly asking for something different: evidence that the control was active when the decision was made, that the decision is traceable, and that the affected individual can challenge it.

OBEXGATE produces those artefacts as a side effect of operation. Not assembled later. Not reconstructed from logs.

What it produces

Three classes of artefact, every governed decision.

→ Decision provenance

Per-action record of what was evaluated, which frameworks applied, which rule was determinative, and why the decision was made.

→ Article-mapped evidence packs

Evidence mapped to article, principle, or control reference inside the source regulation.

→ Audit lineage

Continuous, verifiable chain across governed events.

→ Contestation record

Challenge, human review, resolution, and supporting evidence.

→ Decommissioning evidence

Structured retirement, access removal, data handling, and sealed closure record.

→ Cross-framework mapping

One event mapped across multiple applicable frameworks.

Evidence flow

How a governed decision becomes a legal record.

Decision Governed action evaluated at runtime
Evidence Decision provenance produced as side effect of operation
Challenge Contestation workflow initiated by the affected individual
Review Human review conducted, record produced
Resolution Resolution recorded, audit lineage sealed

Frameworks covered

Eighty-eight enforcement engines across eight jurisdictions.

Each engine maps to specific articles inside its source regulation. Cross-mapping handles the case where a single decision is governed by multiple frameworks simultaneously.

Jurisdiction Frameworks (selection)
European Union EU AI Act, GDPR, DORA, eIDAS, NIS2
United Kingdom UK GDPR, Data Protection Act 2018, UK DUAA, FCA, PRA
United States HIPAA, FDA, CCPA, NIST AI RMF, FedRAMP, CMMC, SOC 2, ISO 27001
Brazil LGPD
Australia Privacy Act 1988
New Zealand Privacy Act 2020
Canada PIPEDA, AIDA, Ontario Bill 194
Singapore PDPA, Model AI Governance Framework, MAS FEAT, MAS TRM

Complete article-level coverage detail.

Contestation

Right to challenge an automated decision.

OBEXGATE includes a structured contestation workflow that produces the record of the challenge, the human review, the resolution, and the supporting audit lineage.

This is the artefact that demonstrates substantive compliance, not declared compliance, in regulatory inquiry.

Decommissioning

Structured system retirement, not deletion.

When a governed system is retired, OBEXGATE executes a sequenced teardown: credentials revoked, access removed, retained data purged where required, audit trail closed and sealed, identity record decommissioned. Every phase is recorded as part of the audit lineage.

See the evidence your governance would produce.

Six questions. Personalised regulatory map across the frameworks you are exposed to, statutory exposure detail, three-year operational governance cost basis. Or 30 minutes with the team.