EU AI Act Horizon 1 · · Annex III: 2 Dec 2027

Aegis Guard Gateway™ · Adesanya AI Advisory™

Compliance enforced at the moment AI executes.

Aegis Guard Gateway sits in your live AI data path and validates legal consent before personal data leaves your enterprise boundary — resolving the GDPR–AI Act compliance conflict at the architectural level.

Request an Architecture Review See how it works

EU AI Act Article 12 logging · Article 26(6) audit trails · GDPR Article 5 & 17 compatibility · No extensions to 2 Aug 2026

Built by a lawyer. Enforced like one.

Aegis Guard Gateway is built on three pillars: the binding obligations of the EU AI Act, the governance architecture of ISO/IEC 42001, and real-time MCP data-flow runtime security. It is built to a legal specification rather than a security one, for organisations running multi-agent and Model Context Protocol architectures.

Principle 01

Legally Programmed Architecture

Every compliance rule inside Aegis Guard maps directly to a statutory obligation — Article 12, Article 26(6), GDPR Article 7(3). Not software assumptions. Not best-guess policy. Law, expressed as code.

Compliance-supportive architecture. Not legal advice.

Principle 02

Zero-Trust Data Sovereignty

Aegis Guard runs inside your own network. Minimal configuration — redirect your API endpoint, nothing else touches your stack. No cloud connectivity. No external data sharing. Your data never crosses a boundary you don't control.

Principle 03

The Regulatory Imperative

The EU AI Act operates on two enforcement horizons. Transparency and AI literacy obligations are live from 2 August 2026. Annex III high-risk AI full obligations — including Art. 12 logging and Art. 26 deployer requirements — apply from 2 December 2027. CISOs, DPOs, and CROs need architecture that addresses both horizons. Aegis Guard is operational from day one of your Architecture Review.

Two regulations. One collision.

The AI governance market has split into two camps — and left a dangerous gap between them. Most enterprises are sitting in that gap right now.

Camp 1

GRC Policy Platforms

Governance, risk and compliance platforms are built for policy documentation, AI system inventorying, and impact assessments. They operate outside the live data path. If personal data is sent to an unapproved model at 3:00 AM, a GRC platform cannot block it. It records that a policy existed. Compliance is retrospective, not preventive.

Camp 2

Technical API Gateways

AI proxies and standard reverse gateways are built for engineers. They manage load balancing, caching, and API token consumption. They have no mechanism to verify whether a specific user revoked their GDPR data processing consent five minutes ago before routing a prompt to an external model. Security gateways address data loss prevention — not legal consent status.

Neither camp can answer the question that kills deals and triggers DPC investigations: "Did this person have valid GDPR consent at the moment AI processed their data?"

Other tools tell you after a violation has occurred. Aegis Guard Gateway stops the request before it reaches the model — real-time legal enforcement at the point of AI execution, before a single byte of personal data leaves your enterprise boundary.

In the live path. Before the data moves.

Aegis Guard Gateway intercepts every AI execution request and validates the legal position before a single byte of personal data leaves your network boundary.

🏢

Origin

Enterprise App

User request
+ personal data

🛡

Aegis Guard

Gateway

PII redaction
Injection defence
Art. 26(6) logging

Consent Signal

Rule Engine

Payload scanned
Consent language flagged

✓ PASS ✗ BLOCK
🤖

Destination

AI Model

GPT / Gemini
Claude / internal LLM

Response path ←
✓ Compliant output Leakage filter · HMAC-SHA256 audit log written ✗ Blocked & logged
01
02
03
🔒

Intercept at the Boundary

Every AI execution request — regardless of the model, vendor, or application — is intercepted by Aegis Guard Gateway before data exits the enterprise network. Nothing passes through uninspected.

  • Zero bypass — nothing passes uninspected
  • PII redaction at point of entry
  • Prompt injection detection built in

Flag Consent Signals in Real Time

Aegis scans every payload for consent-related signals — opt-in language, lawful-basis markers, GDPR consent phrasing — as part of each classification pass, live at the moment of execution. Direct API integration with named consent platforms, including OneTrust, is planned for a coming release.

  • Consent-language detection built into every classification pass
  • Direct consent-platform integrations planned for a coming release
  • Sub-15ms validation overhead
📋

Log, Anonymise, Enforce

Approved requests proceed to the AI model with full Article 12 audit logging. Denied requests are blocked and logged with the reason. All logs are anonymised at the point of capture — GDPR data minimisation preserved, AI Act audit trail maintained.

  • HMAC-SHA256 tamper-resistant logs
  • GDPR data minimisation preserved
  • Forwarded to your SIEM in real time over HTTPS
v0.2.0 Self-Guided Demo · Available on Request

Two minutes. No installation. The demo drives nine live requests through the gateway — a consent REVOKED block on a financial data query, a prompt injection attempt flagged CRITICAL, bulk extraction stopped, and three clean requests that pass. Every intercept writes a verified HMAC-SHA256 audit entry, displayed on screen. Request the demo package with your Architecture Review enquiry — your technical team can pull it apart before committing to anything.

python3 demo_client.py

Watch the mechanism, end to end.

A tool call enters the AI data path. Aegis Guard Gateway evaluates it against the EU AI Act risk taxonomy — Prohibited, High-Risk, Transparency — before the request reaches the model, applies a fail-closed enforcement decision, and writes the outcome to a tamper-evident audit trail that is anonymised at the point of capture, not after. The diagram and the walkthrough below show the same enforcement path at two levels of depth.

Diagram of the Aegis Guard Gateway real-time AI compliance workflow: request interception, EU AI Act risk-taxonomy evaluation, fail-closed enforcement, and HMAC-SHA256 tamper-evident audit trail

The gateway resolves a specific legal collision: the EU AI Act's Article 26(6) deployer log-retention duty (deferred to 2 December 2027 under the Digital Omnibus, Regulation (EU) 2026/1744, in force 27 July 2026) requires a tamper-evident record kept for at least six months, while GDPR Articles 5 and 17 require personal data to stay minimised and erasable. Aegis Guard resolves it before the log is written — every entry is anonymised at the point of capture, signed with HMAC-SHA256, and stored inside the client's own network boundary.

Infrastructure built for enterprise load.

Sub-15ms

Gateway Latency Target

Consent validation, rule evaluation, and cryptographic logging run inline before each AI tool call. The architecture is designed for sub-15ms total overhead. Precise latency benchmarks are established during the Pilot, scoped to your specific AI execution environment.

Fail-Closed

Circuit-Breaker Protocol

Non-configurable circuit breaker. On any gateway fault — runtime exception, memory ceiling breach, consent platform timeout — active packet transit is cut immediately and HTTP 503 returned. Cannot be overridden by Client configuration.

HMAC-SHA256

Audit-Ready by Default

Every transaction signed with HMAC-SHA256, key held inside your own network boundary — a tamper-evident record your legal team can present to a regulator without a developer in the room. Forwarded to your SIEM over HTTPS in real time, ready for WORM-configured retention on your side. Satisfies the Article 26(6) log-integrity obligation.

MCP-Aware

MCP Runtime Validation

When your AI system calls another AI system via Model Context Protocol, Aegis Guard validates the data flow at each node — logging tamper-evident interaction records, enforcing content boundaries, and mapping accountability to the correct deployer. This is the gap standard compliance middleware does not address.

Three ways to begin.

Every engagement starts with a written scope and a fixed fee. No meters running. The Architecture Review is the usual starting point.

TIER 02

30-Day Sandbox Pilot

Fixed fee · on enquiry
Scoped to your environment · 30 calendar days

Live deployment of Aegis Guard Gateway in a sandboxed environment against one defined AI execution path. Documented compliance outcomes, full audit log review, and a signed compliance report suitable for DPC or internal board reporting.

  • Aegis Guard Gateway configured for your environment
  • One AI execution path fully instrumented
  • 30 days of live consent validation and logging
  • Full audit log review and anomaly report
  • GDPR–AI Act reconciliation documentation
  • Compliance report for board or regulator
  • Architecture Review included (no separate charge)
Start the Pilot

TIER 03

Ongoing Retainer

Monthly retainer · on enquiry
Minimum 3 months · rolling

Continuous governance monitoring after a completed pilot. For organisations that need ongoing compliance assurance as AI systems evolve and the regulatory landscape develops around AI Act enforcement.

  • Monthly AI system risk review against current obligations
  • Ongoing consent architecture monitoring
  • Regulatory update briefings as guidance issues
  • 4 hours of advisory time per month
  • Quarterly gap assessment refresh
  • Priority response on DPC or supervisory authority queries
Discuss the Retainer

ARCHITECTURE REVIEW → PILOT → RETAINER · Each tier stands alone or builds on the last

The people who carry the accountability.

Aegis Guard Gateway is built for the individuals named on compliance documentation — the people who cannot afford a DPC investigation.

Data Protection Officer

You need evidence, not assurance.

Regulators do not accept policy documents as proof of compliance. Aegis produces timestamped, tamper-resistant logs that demonstrate GDPR consent was validated before each AI execution — the kind of evidence that closes a DPC inquiry before it escalates.

Timestamped, tamper-resistant audit logs ready for a DPC inquiry.

Chief Information Security Officer

The control gap is in the legal layer.

Your security stack monitors data in transit. It does not check whether the person whose data is in transit consented to AI processing it. Aegis closes that legal blind spot without requiring changes to your existing security architecture.

Closes the legal blind spot without touching your security stack.

General Counsel / Head of Legal

The GDPR–AI Act conflict needs a legal answer.

You have advised the business on GDPR for years. The AI Act creates new logging obligations that appear to conflict with data minimisation. Aegis provides the legal and technical architecture that resolves this conflict — documented, auditable, and defensible to a supervisory authority.

Documented GDPR–AI Act conflict resolution — auditable and defensible.

Chief Compliance Officer

The Annex III deadline moved. The preparation window just became the compliance window.

High-risk AI obligations — Art. 12 logging and Art. 26 deployer requirements — apply from 2 December 2027 under the EU AI Act Digital Omnibus. For financial services, insurance, and essential services, that is 17 months to build architecture that works. The organisations that start now will not be scrambling in 2027.

Architecture designed for 2 Dec 2027 — 17 months to build it right.

Founder / Managing Director

Someone just asked if you're compliant. You need an answer.

Your enterprise customer, your investor, your insurer, or your board has asked whether your AI systems comply with the EU AI Act. You don't have a dedicated legal or compliance team — you are the team. Aegis Guard Gateway gives you the architecture, the documentation, and the audit trail to answer that question credibly — before the next meeting, not after an incident.

Audit trail and documentation — credible before the next board meeting.

Whitepaper library.

Two practical guides — one for enterprises subject to EU AI Act obligations, one for US AI SaaS providers navigating the EU market. Download free. No spam.

EU Track · High-Risk AI Systems

The Production-Stage Audit Trail for High-Risk AI Systems under the EU AI Act

✓ Received. We'll email you the PDF within one business day.

US / Global Track · Market Entry

The Extraterritorial Blueprint: Selling US AI SaaS into the European Market

✓ Received. We'll email you the PDF within one business day.

Begin the Architecture Review.

Write briefly. Describe the AI system or data-flow you are concerned about, and any deadline you are working to. A response usually follows within one business day.

  1. Architecture Review — fixed fee, confirmed on enquiry. Written scope confirmed within 24 hours of enquiry.
  2. Findings debrief — Written gap report and remediation priorities delivered within the review period.
  3. Pilot or retainer — Your decision, with no obligation. Either engagement is scoped and fixed before work begins.

abdulwahab@adesanyaaiadvisory.com

Dublin · Ireland

I agree to my data being processed to respond to my enquiry, per the privacy policy.