An approved policy that nothing enforces is a document, not a control.
The policy your board signed becomes the rules running in front of every request: versioned, enforced in path, and changed without waiting for a release.
The policy deployment gap is the distance between the AI policy your organisation approved and the controls actually enforced in front of every request.
Nobody discovers this problem in a planning meeting
It runs ungoverned until someone remembers to onboard it.
The document changes in a day, production takes a quarter.
It lives in an email thread with no scope and no expiry.
And ship two different controls.
The sample shows local settings that never matched the policy.
The answer is a document, and a promise.
The bill arrives as delay, not as an incident
You can show intent, not enforcement.
Governance scales with headcount instead of traffic.
Temporary permission becomes permanent posture.
Between approval and enforcement, the gap is the risk.
The same finding returns every cycle.
The gap
The control
A policy version is a deployable object with an owner and a propagation time.
This is the shape of the record obstruo produces. It is the same artefact a reviewer, an auditor and an enterprise buyer each ask for, and it exists before they ask.
They arrive together, and the same controls answer them
Your AI. Your data. Your control.
Send us one clause from your AI policy. We will show it as a locked control, with the record it produces.