The control failures that appear when AI starts acting
Four of them stall security reviews in regulated organisations. Each has its own page: what the failure is, when it becomes visible, what it costs, and the record obstruo produces instead.
You deploy AI faster than you capture verifiable proof of the policies, approvals and controls behind every action.
What an agent may do in production stops matching what anyone approved, because permissions live in code and tool configs instead of policy.
The AI policy your organisation approved on paper is not the set of controls actually running in front of each request.
Nobody can say which providers and subprocessors receive your data right now, from which region, under which data classification.
Five more places the same controls apply
The four problems above are where reviews stall. These scenarios run on the same policy engine and produce the same records.
Protect sensitive data
Personal data, credentials and confidential records reach models through prompts, retrieved context and tool responses. Minimisation has to happen in the request path, not in a policy document.
Control models and providers
Approval decisions are made per model and per region, then quietly bypassed the next time a team hardcodes a model name. Logical model names put the decision back in policy.
Govern MCP tools
MCP turned every internal system into something a model can call. The question stops being what the model says and becomes what it is permitted to do.
Extend governance to coding assistants
The largest source of unmanaged AI traffic in most organisations is not an application. It is an IDE assistant and a browser tab, both reading source and customer data.
Control AI spend and usage
Runaway spend is a governance failure with an invoice attached. Budgets and rate limits belong next to the other controls, enforced on the same request.
Consultancies, ISO 42001 implementers and AI Act advisors connect their assessments to obstruo enforcement, so their recommendations end up as active controls instead of a report.
Your AI. Your data. Your control.
Bring the problem that is blocking your security review. We will show the controls and the evidence it produces.