Problems

The control failures that appear when AI starts acting

Four of them stall security reviews in regulated organisations. Each has its own page: what the failure is, when it becomes visible, what it costs, and the record obstruo produces instead.

01
AI evidence debt

You deploy AI faster than you capture verifiable proof of the policies, approvals and controls behind every action.

Security review Customer questionnaire Internal audit
Read the problem page
02
Agent authority drift

What an agent may do in production stops matching what anyone approved, because permissions live in code and tool configs instead of policy.

New tool added Irreversible action Incident review
Read the problem page
03
Policy deployment gap

The AI policy your organisation approved on paper is not the set of controls actually running in front of each request.

New project Policy update Audit sample
Read the problem page
04
Live processor blindness

Nobody can say which providers and subprocessors receive your data right now, from which region, under which data classification.

Article 30 record Subprocessor list DPIA update
Read the problem page
Additional control scenarios

Five more places the same controls apply

The four problems above are where reviews stall. These scenarios run on the same policy engine and produce the same records.

Redaction, EU standard in path
PROMPT AS SENT BY THE APPLICATION
Refund Anna Kowalska, IBAN PL61109010140000071219812874, card ending 4471.
PROMPT AS IT LEAVES YOUR NETWORK
Refund {PERSON_18b}, IBAN {IBAN_3d2}, card {PAN_a09}.
Entities detected3 redacted, 0 passed
Re-identificationOn response, inside your boundary
If detection cannot runFail closed
01 Data

Protect sensitive data

Personal data, credentials and confidential records reach models through prompts, retrieved context and tool responses. Minimisation has to happen in the request path, not in a policy document.

Where it breaks today
Redaction is implemented per application, so every team gets it slightly wrong.
Retrieval and tool responses pull data back in after the prompt was cleaned.
A DPIA claims minimisation that nobody can demonstrate per request.
What obstruo does
Detects and tokenizes personal data and secrets before the request leaves your network.
Applies the same standard on the way back, including tool and retrieval responses.
Records what was redacted per request, so GDPR Article 32 has an artefact behind it.
Redaction Secret detection Per-country standards Fail closed
02 Models

Control models and providers

Approval decisions are made per model and per region, then quietly bypassed the next time a team hardcodes a model name. Logical model names put the decision back in policy.

Where it breaks today
Model names are hardcoded, so an approved-model list is advice rather than a control.
A provider deprecates a version and every project has to be patched.
Nobody can prove that EU traffic stayed on EU endpoints last quarter.
What obstruo does
Applications request a logical model name, and policy resolves which provider answers.
Unapproved models and out-of-region endpoints are refused in path.
Swap a provider, add a fallback or pin a jurisdiction without touching application code.
Approved models Routing Residency Fallbacks
Model catalog
obstruo-chat-euAPPROVED
resolves to eu-central, fallback eu-west
obstruo-reasoningAPPROVED
high-risk projects require approval record
obstruo-cheap-batchNON-EU, LIMITED
allowed for anonymised workloads only
provider-x-previewBLOCKED
no DPA on file, 41 attempts refused this week
Applications never name a provider. Policy decides, and the decision is recorded.
Tool permissions, trading-analyst 4 of 11 allowed
market_data.readAllowed
portfolio.readAllowed
research.searchAllowed
crm.contact.readAllowed, redacted
place_orderDenied
payments.transferDenied
unregistered MCP serverRefused
Reads allowed, writes denied, every attempt recorded with its arguments schema.
03 Tools

Govern MCP tools

MCP turned every internal system into something a model can call. The question stops being what the model says and becomes what it is permitted to do.

Where it breaks today
Teams register MCP servers themselves, and security learns about it later.
A single server exposes both harmless reads and irreversible writes.
Tool responses carry personal data straight back into the model context.
What obstruo does
Only registered MCP servers are reachable, and only per agent.
Permissions are set per tool and per action, so reads and writes are separated.
Tool responses pass the same redaction standard as prompts before re-entering context.
MCP registry Action permissions Response redaction
04 Assistants

Extend governance to coding assistants

The largest source of unmanaged AI traffic in most organisations is not an application. It is an IDE assistant and a browser tab, both reading source and customer data.

Where it breaks today
Assistant traffic bypasses obstruo entirely, so no policy applies to it.
Secrets and customer records get pasted into prompts nobody records.
Blocking the tools outright pushes engineers onto personal accounts.
What obstruo does
Any assistant that accepts a custom base URL can be pointed at obstruo today, and inherits the same policy.
Secret detection and redaction apply to pasted context, not only to application prompts.
Dedicated adapters for coding assistants and browser AI are on the roadmap, not shipped. We will say so plainly in a security review.
Base URL onboarding Secret detection Adapters, planned
Coverage, honestly labelled
Assistants with configurable base URLLIVE
Secret and PII detection on pasted contextLIVE
Coding-assistant adaptersPLANNED
Browser adaptersPLANNED
Exposure map for unmanaged AI useIN DEVELOPMENT
Design partners shape this surface. Ask us where your assistants would sit today.
Budgets, this month €38,140 of €52,000
Claims automation€14,900 / €18,000
Support copilot€9,240 / €20,000
Trading research€14,000 / €14,000
Ceiling reached, further calls refused until reset or increase
Budgets act on the request. The refusal is recorded with the policy that caused it.
05 Cost

Control AI spend and usage

Runaway spend is a governance failure with an invoice attached. Budgets and rate limits belong next to the other controls, enforced on the same request.

Where it breaks today
Cost is discovered at the end of the month, on a provider invoice.
One retry loop in one agent consumes a quarter of the quarterly budget.
Spend cannot be attributed to a project, agent or business owner.
What obstruo does
Enforces spend ceilings and rate limits per organisation, project and agent.
Attributes every request to its project, agent and owner, so cost has an address.
Routes eligible workloads to cheaper approved models, without weakening the data rules.
Budgets Rate limits Attribution Routing
Working with an advisor on this?

Consultancies, ISO 42001 implementers and AI Act advisors connect their assessments to obstruo enforcement, so their recommendations end up as active controls instead of a report.

See the partner programme

Your AI. Your data. Your control.

Bring the problem that is blocking your security review. We will show the controls and the evidence it produces.

See obstruo in action See pricing