Resources/Blog

Notes on governing AI in production

What we learn building the control layer: regulation with dates attached, redaction that has to survive a review, and the parts of agent governance nobody enjoys.

Performance28 July 20266 min read
What runtime AI controls cost you, in milliseconds

Every protection Obstruo offers has a price. Here is the whole list, measured on live production traffic, at the median and at the tail.

Read the article
Regulation28 July 20266 min read
Article 50 of the EU AI Act applies from 2 August 2026

Transparency stops being guidance and becomes an obligation. Here is what changes, and why it is a request-path problem rather than a product-copy problem.

Read the article
Evidence14 July 20267 min read
A request log is not evidence

Every gateway writes logs. Almost none of them answer the question an auditor asks eleven months later.

Read the article
Redaction30 June 20266 min read
The same prompt, two definitions of personal data

A support message from Munich and the same message from California are not the same compliance object. Redaction has to know the difference.

Read the article
Agents17 June 20265 min read
Govern MCP tools before your agents get them

Model access is a data question. Tool access is an action question, and it is the one that will wake your on-call.

Read the article
Engineering3 June 20265 min read
Getting provider keys out of your services

Provider keys spread the way secrets always spread. The migration off them is smaller than teams expect.

Read the article

Bring the question your security review is stuck on

We would rather answer it on the first call than in a questionnaire three weeks later.

See obstruo in action Product overview