UK DUAA right to complain enforces in -- days · 19 June 2026 EU AI Act high-risk enforces in -- days · 2 August 2026

Governance lifecycle

Discover, Assess, Enforce, Remediate, Prove.

The AI governance lifecycle is the operating model for controlling AI risk from unmanaged use through audit evidence.

Read the OBEXGATE Difference →

01

Discover

Identify Shadow AI, AI systems, decision points, data flows, coverage gaps, and unmanaged governance exposure.

02

Assess

Use EVF to evaluate execution viability, governance readiness, AI failure modes, adversarial sufficiency, evidence quality, drift, gate integrity, legal exposure, and regulatory readiness.

03

Enforce

Apply organisation-configurable governance controls at runtime. Return Allow, Warn, Hold, Block, or Stop before an AI-enabled action proceeds.

04

Remediate

Use PRISM reports to convert risk findings into governance, auditor, regulatory, and executive remediation outputs.

05

Prove

Generate sealed audit evidence so the organisation can demonstrate what happened, why it happened, which controls applied, and who was accountable.

On-prem | Sovereign cloud | Partner cloud | Federated

Why the lifecycle matters.

AI risk does not start at model launch and it does not end with a dashboard. It starts when unmanaged systems appear, grows when failure modes are not assessed, becomes exposure when actions run without controls, and becomes expensive when evidence has to be reconstructed after the fact.