EU AI Act Annex III enforcement · 47 days to 2 Aug 2026
Aegis Guard Gateway · Adesanya AI Advisory

Compliance enforced at the moment AI executes.

Aegis Guard Gateway sits in your live AI data path and validates legal consent before personal data leaves your enterprise boundary — resolving the GDPR–AI Act compliance conflict at the architectural level.

EU AI Act Article 12 logging·Article 26(6) audit trails·GDPR Article 5 & 17 compatibility·No extensions to 2 Aug 2026
Built from practice experience with
Google · Meta · IONA Technologies · Progress Software · Orcawise
01 · The Problem

Two regulations. One collision.

The AI governance market has split into two camps — and left a dangerous gap between them. Most enterprises are sitting in that gap right now.

Camp 1

GRC Policy Platforms

OneTrust, Credo AI, and similar tools are built for policy documentation, AI system inventorying, and impact assessments. They operate outside the live data path. If personal data is sent to an unapproved model at 3:00 AM, a GRC platform cannot block it. It records that a policy existed. Compliance is retrospective, not preventive.

Camp 2

Technical API Gateways

Portkey, Langfuse, and standard reverse proxies are built for engineers. They manage load balancing, caching, and API token consumption. They have no mechanism to verify whether a specific user revoked their GDPR data processing consent five minutes ago before routing a prompt to an external model. Security gateways like Lakera Guard address data loss prevention — not legal consent status.

Neither camp can answer the question that kills deals and triggers DPC investigations: "Did this person have valid GDPR consent at the moment AI processed their data?"

That is the gap Aegis Guard Gateway closes — real-time legal consent enforcement at the point of AI execution, inside your enterprise boundary.

02 · How It Works

In the live path. Before the data moves.

Aegis Guard Gateway intercepts every AI execution request and validates the legal position before a single byte of personal data leaves your network boundary.

Request path →
Enterprise App
User Request
+ Personal Data
Aegis — Request
PII Redaction
Injection Defence
Consent Platform
OneTrust
Token Valid?
Decision
✓ Valid → AI Model
✗ No consent → Block
Response path ←
Enterprise App
Safe, Compliant
Output
Aegis — Response
Leakage Filter
Article 26 Logging
Audit Store
Cryptographic
Tamper-Resistant Log
AI Model
Response
Payload
STEP 01

Intercept at the Boundary

Every AI execution request — regardless of the model, vendor, or application — is intercepted by Aegis Guard Gateway before data exits the enterprise network. Nothing passes through uninspected.

STEP 02

Validate Consent in Real Time

Aegis queries your consent platform — including OneTrust — for the current, live consent status of the data subjects whose data is being processed. Not cached. Not assumed. Live, at the moment of execution.

STEP 03

Log, Anonymise, Enforce

Approved requests proceed to the AI model with full Article 12 audit logging. Denied requests are blocked and logged with the reason. All logs are anonymised at the point of capture — GDPR data minimisation preserved, AI Act audit trail maintained.

02b · Technical Benchmarks

Infrastructure built for enterprise load.

< 15ms p99
Gateway Latency Overhead

Hard-capped total gateway overhead per request — consent validation, PII redaction, heuristic analysis, and cryptographic logging — verified under representative enterprise load during Week 4 of the pilot.

Fail-Closed
Fault Protocol

Non-configurable circuit breaker. On any gateway fault — runtime exception, memory ceiling breach, consent platform timeout — active packet transit is cut immediately and HTTP 503 returned. Cannot be overridden by Client configuration.

SHA-256 · ECDSA P-256
Cryptographic Log Signing

Every transaction hashed and signed with Client-generated ECDSA P-256 keys and pushed to Client WORM storage or SIEM via TLS 1.3. Satisfies the Article 26(6) log-integrity floor with a minimum six-month retention period.

04 · Engagement Tiers

Three ways to begin.

Every engagement starts with a written scope and a fixed fee. No meters running. Most clients begin with the Architecture Review.

TIER 01

Architecture Review

€750

Fixed fee · 5–7 working days

A structured review of your current AI data-flow, consent mechanisms, and logging architecture against EU AI Act Article 12 and GDPR obligations. Written report with findings and a prioritised remediation roadmap.

  • Mapping of all AI execution paths and data flows
  • Gap assessment against Article 12 logging requirements
  • Consent mechanism review and validity analysis
  • GDPR–AI Act conflict identification and remediation options
  • Written report with prioritised recommendations
  • 60-minute debrief call included
Request Architecture Review
TIER 03

Ongoing Retainer

Pricing on
enquiry

Monthly · minimum 3 months

Continuous governance monitoring after a completed pilot. For organisations that need ongoing compliance assurance as AI systems evolve and the regulatory landscape develops around AI Act enforcement.

  • Monthly AI system risk review against current obligations
  • Ongoing consent architecture monitoring
  • Regulatory update briefings as guidance issues
  • 4 hours of advisory time per month
  • Quarterly gap assessment refresh
  • Priority response on DPC or supervisory authority queries
Discuss the Retainer

ARCHITECTURE REVIEW → PILOT → RETAINER · Each tier stands alone or builds on the last

05 · Who It's For

The people who carry the accountability.

Aegis Guard Gateway is built for the individuals named on compliance documentation — the people who cannot afford a DPC investigation.

Data Protection Officer

You need evidence, not assurance.

Regulators do not accept policy documents as proof of compliance. Aegis produces timestamped, tamper-resistant logs that demonstrate GDPR consent was validated before each AI execution — the kind of evidence that closes a DPC inquiry before it escalates.

Chief Information Security Officer

The control gap is in the legal layer.

Your security stack monitors data in transit. It does not check whether the person whose data is in transit consented to AI processing it. Aegis closes that legal blind spot without requiring changes to your existing security architecture.

General Counsel / Head of Legal

The GDPR–AI Act conflict needs a legal answer.

You have advised the business on GDPR for years. The AI Act creates new logging obligations that appear to conflict with data minimisation. Aegis provides the legal and technical architecture that resolves this conflict — documented, auditable, and defensible to a supervisory authority.

Chief Compliance Officer

The August 2 deadline is fixed.

Annex III obligations under the EU AI Act are not aspirational targets. They apply from 2 August 2026. For financial services, insurance, and essential services — sectors that typically deploy Annex III AI — the operational window to implement compliant architecture is closing.

Founder / Managing Director

Someone just asked if you're compliant. You need an answer.

Your enterprise customer, your investor, your insurer, or your board has asked whether your AI systems comply with the EU AI Act. You don't have a dedicated legal or compliance team — you are the team. Aegis Guard Gateway gives you the architecture, the documentation, and the audit trail to answer that question credibly — before the next meeting, not after an incident.

06 · Contact

Begin the Architecture Review.

Write briefly. Describe the AI system or data-flow you are concerned about, and any deadline you are working to. A response usually follows within one business day.

  1. Architecture Review€750 fixed fee. Written scope confirmed within 24 hours of enquiry.
  2. Findings call60-minute debrief. Gap report and remediation priorities delivered in writing.
  3. Pilot or retainerYour decision, with no obligation. Either engagement is scoped and fixed before work begins.