UK DUAA right to complain enforces in -- days · 19 June 2026 EU AI Act high-risk enforces in -- days · 2 August 2026

OBEXGATE Difference

The OBEXGATE difference is where governance happens.

Model governance governs the model. Agent governance governs the agent. Enterprise governance documents the programme. OBEXGATE governs the organisational execution boundary where AI action becomes consequence.

AI governance is not one layer.

Frontier model governance, agent governance, enterprise governance, and runtime governance solve different problems. OBEXGATE operates at the runtime governance lifecycle layer: where unmanaged AI is discovered, risk is assessed, controls are enforced, remediation is generated, and evidence is preserved.

Governance systems operate at different layers.

Model Governance

Frontier model risk

Focuses on frontier model safety, capability assessment, training controls, release thresholds, systemic risk, and model-level reporting.

Agent Governance

Agent actions and tools

Focuses on agent actions, tool permissions, identity, sandboxing, agent runtime controls, and developer implementation.

Enterprise Governance

Policy and reporting

Focuses on policies, inventories, assessments, risk registers, governance documentation, and compliance reporting.

OBEXGATE Runtime Governance

Execution boundary governance

Focuses on Shadow AI discovery, EVF assessment, failure-mode analysis, organisation-configurable runtime enforcement, PRISM remediation, accountability, data sovereignty, and Witness Audit Evidence.

Comprehensive category comparison by governance layer.

The short version is simple: each governance layer solves a different problem. The detailed comparison below shows why runtime governance is not interchangeable with model governance, agent governance, or enterprise GRC.

CapabilityOBEXGATE Runtime Governance LifecycleFrontier Model GovernanceAgent Governance ToolkitsEnterprise AI Governance
Frontier model safetyNot primaryPrimary focusNot primaryUsually documentation-oriented
Agent tool permissionsIntegrated where actions enter governanceNot primaryPrimary focusDepends on implementation
Shadow AI discoveryCore design focusNot primaryDepends on implementationInventory-oriented
Risk assessmentEVF and PRISMPrimary focusDepends on implementationPrimary focus
Failure-mode assessmentCore EVF surfacePrimary focus at model levelPartialDepends on implementation
Mitigation planningPRISM remediationPrimary focusDepends on implementationPrimary focus
Governance documentationGenerated from runtime evidencePrimary focusDepends on implementationPrimary focus
Runtime enforcementCore design focusNot primaryPrimary focus for agent actionsDepends on implementation
Regulatory article enforcementCore design focusNot primaryPartialUsually documentation-oriented
GDPR and UK GDPR operationalisationCore design focusNot primaryDepends on implementationPrimary focus
EU AI Act operationalisationCore design focusEmergingDepends on implementationPrimary focus
LGPD operationalisationCore design focusNot primaryDepends on implementationDepends on implementation
Data sovereignty controlsCore design focusNot primaryDepends on implementationDepends on implementation
Organisational authority modelsOrganisation-configurable controlsNot primaryPartialUsually policy-oriented
Decision-level accountabilityCore design focusPartialPartialDepends on implementation
Audit evidenceCryptographically sealed. Audit ready.Limited or unclearDepends on implementationCompliance records
Cross-model governanceModel-agnosticInternal or provider focusedToolkit and framework dependentDepends on platform
Deployment across on-prem, sovereign cloud, partner cloud, and federated architecturesDeployment-agnosticNot primaryDepends on implementationDepends on vendor
Remediation reportingPRISM remediationPartialDepends on implementationPrimary focus

Agent governance is not the same as organisational runtime governance.

Agent governance toolkits can be valuable. They help control agent actions, tool permissions, identity, sandboxing, policy enforcement, and developer workflows.

OBEXGATE addresses the organisational layer: jurisdiction, data rights, internal authority, escalation, accountability, regulatory exposure, remediation, and evidence.

Where OBEXGATE sits.

OBEXGATE is not trying to replace frontier model governance, agent governance, enterprise GRC, or legal review.

It addresses the execution boundary: the point where AI-enabled actions interact with legal obligations, internal policy, authority structures, data rights, risk controls, and accountability.

Discover. Assess. Enforce. Remediate. Prove.

Start with your AI governance exposure.

Use the free assessment to identify whether your organisation may need deeper governance review, EVF assessment, or runtime governance deployment.

Sources and accuracy note.

This category comparison is based on public documentation and OBEXGATE product materials. Capabilities may change. Readers should verify current product documentation before making procurement or compliance decisions.

OpenAI Frontier Governance Framework

Microsoft Agent Governance Toolkit GitHub repository

Microsoft Open Source Blog announcement