Policy enforcement. Audit evidence. Human approval. One commercial licence, one SLA, one escalation path. Deploy on-premise, in your VPC, or air-gapped.
EU AI Act fine ceiling: €15 million or 3% of global annual turnover under Article 99. High-risk obligations enforce December 2027 (Omnibus deferral). GPAI and transparency rules enforce August 2026. Deployed on-premise, in your VPC, or air-gapped.
AgentProtect sits on the HookBus event layer and gates every consequential action before execution. All features are included under one commercial licence. No module pick-and-mix.
L1 rules run in under 10ms, no LLM, no API call. L2 uses your approved model for intent reasoning when L1 needs escalation. Returns allow, block, or ask on every tool call. The AI cannot bypass it.
Every lifecycle event, policy decision, and approval is SHA-256 chained into a tamper-evident log. CSV export per date range. Built to satisfy SOC 2 Type II, ISO/IEC 42001, and EU AI Act record-keeping obligations.
Route approval requests to Slack, Teams, or ServiceNow. Reviewer gets a link, approves or denies, the audit trail records who decided what and when. Escalation, delegation, and two-person verification available for high-risk lanes.
High-risk obligations enforce December 2027 under the Omnibus deferral. GPAI and transparency rules enforce 2 August 2026. AgentProtect covers every article listed below.
| Regulation | Obligation | Covered by |
|---|---|---|
| EU AI Act Art 12 | Automatic record-keeping over system lifetime | Covered |
| Art 14(1)-(3) | Human oversight design | Covered |
| Art 14(4)(d) | Decide not to use, disregard, override AI output | Covered |
| Art 14(4)(e) | Intervene or interrupt | Covered |
| Art 14(5) | Biometric ID two-person verification (publicly accessible spaces) | Covered |
| Art 19 | Provider keeps logs ≥ 6 months | Covered |
| Art 20(2) | Duty to inform authorities of corrective action | Covered |
| Art 26(5) | Deployer monitors operation, suspends if risk | Covered |
| Art 26(6) | Deployer keeps logs ≥ 6 months | Covered |
| Art 50 | Transparency obligations (AI labelling, deepfake watermarks) | Covered |
| Art 72 | Provider operates post-market monitoring system | Covered |
| Art 73 | Serious incident reporting (15 days, 2 days fatal) | Covered |
| Art 79 | Procedure for AI presenting a risk | Covered |
| DORA Art 19 | ICT incident reporting (financial services, 4-hour initial) | Covered |
| NIS2 Art 23 | Significant incident notification (24-hour) | Covered |
AgentProtect deploys entirely inside your infrastructure. No outbound calls required for decisions. No telemetry. No vendor-operated control plane.
Runs entirely inside your data centre. No outbound connections required for decisions.
Deploys into your AWS, Azure, or GCP VPC. Private subnets only. No public endpoint required.
Both L1 and L2 decisions run locally. Granite 4 runs on CPU or your own GPU. Works fully offline.
Events, memory, audit chain, policy packs all stay where you put them. No telemetry calls home.
Agentic Thinking Limited does not currently hold third-party compliance certifications. The products are built to the evidence standards that SOC 2 Type II, ISO/IEC 42001, and EU AI Act Article 12 require, so customers can adopt them inside their own compliance programmes today. Full security posture documentation is available under NDA. See the Trust Center.
One demo, 30 minutes. With your CISO, DPO, and Head of AI Governance on the call. You see which workflows trigger Article 14 human-oversight obligations, which carry Article 73 serious-incident reporting exposure, and which features in AgentProtect cover each obligation.