Obquan flags AI regulatory violations the moment your agents act.
And there's no AI watching AI.
Obquan flags AI regulatory violations the moment your agents act.
And there's no AI watching AI.
Obquan flags AI regulatory violations the moment your agents act.
And there's no AI watching AI.
Obquan flags AI regulatory violations the moment your agents act.
And there's no AI watching AI.
Obquan flags AI regulatory violations the moment your agents act.
And there's no AI watching AI.
Obquan flags AI regulatory violations the moment your agents act.
And there's no AI watching AI.
One source of audit-ready truth, checking your AI against every framework you answer to: GDPR, FCA, the EU AI Act and beyond.
One source of audit-ready truth, checking your AI against every framework you answer to: GDPR, FCA, the EU AI Act and beyond.
One source of audit-ready truth, checking your AI against every framework you answer to: GDPR, FCA, the EU AI Act and beyond.
One source of audit-ready truth, checking your AI against every framework you answer to: GDPR, FCA, the EU AI Act and beyond.
One source of audit-ready truth, checking your AI against every framework you answer to: GDPR, FCA, the EU AI Act and beyond.
One source of audit-ready truth, checking your AI against every framework you answer to: GDPR, FCA, the EU AI Act and beyond.

We do one thing.
We do one thing.
We do one thing.
We do one thing.
We do one thing.
We do one thing.
Obquan monitors what your AI agents actually do as they do it. The Guardian Proxy sits between your agents and your systems, checking every API call against GDPR Article 9, FCA SYSC 3.2.6 and the EU AI Act. Everything runs on fixed rules, so the same action always gives the same result and you get a clear record of where your AI crossed the boundary.
Obquan monitors what your AI agents actually do as they do it. The Guardian Proxy sits between your agents and your systems, checking every API call against GDPR Article 9, FCA SYSC 3.2.6 and the EU AI Act. Everything runs on fixed rules, so the same action always gives the same result and you get a clear record of where your AI crossed the boundary.
Obquan monitors what your AI agents actually do as they do it. The Guardian Proxy sits between your agents and your systems, checking every API call against GDPR Article 9, FCA SYSC 3.2.6 and the EU AI Act. Everything runs on fixed rules, so the same action always gives the same result and you get a clear record of where your AI crossed the boundary.
Obquan monitors what your AI agents actually do as they do it. The Guardian Proxy sits between your agents and your systems, checking every API call against GDPR Article 9, FCA SYSC 3.2.6 and the EU AI Act. Everything runs on fixed rules, so the same action always gives the same result and you get a clear record of where your AI crossed the boundary.
Obquan monitors what your AI agents actually do as they do it. The Guardian Proxy sits between your agents and your systems, checking every API call against GDPR Article 9, FCA SYSC 3.2.6 and the EU AI Act. Everything runs on fixed rules, so the same action always gives the same result and you get a clear record of where your AI crossed the boundary.



See every AI agent action as it happens.
See every AI agent action as it happens.
See every AI agent action as it happens.
See every AI agent action as it happens.
See every AI agent action as it happens.
Every API call your AI agents make is captured in real time, checked against your compliance rules, and logged with full behavioural context. You won't have AI blind spots and you won't discover a breach three months after it happened.
Every API call your AI agents make is captured in real time, checked against your compliance rules, and logged with full behavioural context. You won't have AI blind spots and you won't discover a breach three months after it happened.
Every API call your AI agents make is captured in real time, checked against your compliance rules, and logged with full behavioural context. You won't have AI blind spots and you won't discover a breach three months after it happened.
Every API call your AI agents make is captured in real time, checked against your compliance rules, and logged with full behavioural context. You won't have AI blind spots and you won't discover a breach three months after it happened.
Every API call your AI agents make is captured in real time, checked against your compliance rules, and logged with full behavioural context. You won't have AI blind spots and you won't discover a breach three months after it happened.
Audit-ready evidence.
At the article level.
Audit-ready evidence.
At the article level.
Audit-ready evidence.
At the article level.
Audit-ready evidence.
At the article level.
When regulators ask questions you need answers. Obquan generates compliance evidence mapped directly to GDPR Article 9, FCA SYSC 3.2.6, and EU AI Act articles. A single export will give you everything an auditor needs.
When regulators ask questions you need answers. Obquan generates compliance evidence mapped directly to GDPR Article 9, FCA SYSC 3.2.6, and EU AI Act articles. A single export will give you everything an auditor needs.
When regulators ask questions you need answers. Obquan generates compliance evidence mapped directly to GDPR Article 9, FCA SYSC 3.2.6, and EU AI Act articles. A single export will give you everything an auditor needs.
When regulators ask questions you need answers. Obquan generates compliance evidence mapped directly to GDPR Article 9, FCA SYSC 3.2.6, and EU AI Act articles. A single export will give you everything an auditor needs.
When regulators ask questions you need answers. Obquan generates compliance evidence mapped directly to GDPR Article 9, FCA SYSC 3.2.6, and EU AI Act articles. A single export will give you everything an auditor needs.






Deploys in hours.
Minimal integration.
Deploys in hours.
Minimal integration.
Deploys in hours.
Minimal integration.
Deploys in hours.
Minimal integration.
The Guardian Proxy sits inline between your agents and your infrastructure. Around a dozen lines of SDK code, plus some lightweight backend metadata configuration, is all it takes. No architectural changes or changes to your existing AI stack, and and it works whatever tools your engineers built it on.
The Guardian Proxy sits inline between your agents and your infrastructure. Around a dozen lines of SDK code, plus some lightweight backend metadata configuration, is all it takes. No architectural changes or changes to your existing AI stack, and and it works whatever tools your engineers built it on.
The Guardian Proxy sits inline between your agents and your infrastructure. Around a dozen lines of SDK code, plus some lightweight backend metadata configuration, is all it takes. No architectural changes or changes to your existing AI stack, and and it works whatever tools your engineers built it on.
The Guardian Proxy sits inline between your agents and your infrastructure. Around a dozen lines of SDK code, plus some lightweight backend metadata configuration, is all it takes. No architectural changes or changes to your existing AI stack, and and it works whatever tools your engineers built it on.
The Guardian Proxy sits inline between your agents and your infrastructure. Around a dozen lines of SDK code, plus some lightweight backend metadata configuration, is all it takes. No architectural changes or changes to your existing AI stack, and and it works whatever tools your engineers built it on.
FCA SYSC 3.2.6:
FCA SYSC 3.2.6:
FCA SYSC 3.2.6:
FCA SYSC 3.2.6:
FCA SYSC 3.2.6:
FCA SYSC 3.2.6:
the clock is already running
the clock is already running
the clock is already running
the clock is already running
the clock is already running
In force now
In force now
In force now
In force now
In force now
FCA SYSC 3.2.6 requires effective and ongoing risk monitoring for AI systems. Quarterly assessments are not continuous monitoring. This is enforceable today.
FCA SYSC 3.2.6 requires effective and ongoing risk monitoring for AI systems. Quarterly assessments are not continuous monitoring. This is enforceable today.
FCA SYSC 3.2.6 requires effective and ongoing risk monitoring for AI systems. Quarterly assessments are not continuous monitoring. This is enforceable today.
FCA SYSC 3.2.6 requires effective and ongoing risk monitoring for AI systems. Quarterly assessments are not continuous monitoring. This is enforceable today.
FCA SYSC 3.2.6 requires effective and ongoing risk monitoring for AI systems. Quarterly assessments are not continuous monitoring. This is enforceable today.
Supervision increasing
Supervision increasing
Supervision increasing
Supervision increasing
Supervision increasing
FCA supervisory focus on AI governance is intensifying through 2026. Firms without documented continuous monitoring are exposed in any review.
FCA supervisory focus on AI governance is intensifying through 2026. Firms without documented continuous monitoring are exposed in any review.
FCA supervisory focus on AI governance is intensifying through 2026. Firms without documented continuous monitoring are exposed in any review.
FCA supervisory focus on AI governance is intensifying through 2026. Firms without documented continuous monitoring are exposed in any review.
FCA supervisory focus on AI governance is intensifying through 2026. Firms without documented continuous monitoring are exposed in any review.
Year-end exposure
Year-end exposure
Year-end exposure
Year-end exposure
Year-end exposure
Firms without real-time oversight and audit-ready evidence face material risk at year-end supervisory reviews. Manual audits will not be sufficient.
Firms without real-time oversight and audit-ready evidence face material risk at year-end supervisory reviews. Manual audits will not be sufficient.
Firms without real-time oversight and audit-ready evidence face material risk at year-end supervisory reviews. Manual audits will not be sufficient.
Firms without real-time oversight and audit-ready evidence face material risk at year-end supervisory reviews. Manual audits will not be sufficient.
Firms without real-time oversight and audit-ready evidence face material risk at year-end supervisory reviews. Manual audits will not be sufficient.
Your AI agents are already regulated:
Your AI agents are already regulated:
Your AI agents are already regulated:
Your AI agents are already regulated:
Your AI agents are already regulated:
Your AI agents are already regulated:
four obligations, three of them live today
four obligations, three of them live today
four obligations, three of them live today
four obligations, three of them live today
four obligations, three of them live today
LIVE NOW
LIVE NOW
FCA SYSC 3.2.6
FCA SYSC 3.2.6
FCA SYSC 3.2.6
FCA SYSC 3.2.6
FCA SYSC 3.2.6
FCA SYSC 3.2.6
Firms must maintain adequate systems and controls, monitored on an ongoing basis. An AI agent acting on customer data with valid credentials sits inside that obligation. There is no deadline because there is no grace period.
Firms must maintain adequate systems and controls, monitored on an ongoing basis. An AI agent acting on customer data with valid credentials sits inside that obligation. There is no deadline because there is no grace period.
Firms must maintain adequate systems and controls, monitored on an ongoing basis. An AI agent acting on customer data with valid credentials sits inside that obligation. There is no deadline because there is no grace period.
Firms must maintain adequate systems and controls, monitored on an ongoing basis. An AI agent acting on customer data with valid credentials sits inside that obligation. There is no deadline because there is no grace period.
Firms must maintain adequate systems and controls, monitored on an ongoing basis. An AI agent acting on customer data with valid credentials sits inside that obligation. There is no deadline because there is no grace period.
Firms must maintain adequate systems and controls, monitored on an ongoing basis. An AI agent acting on customer data with valid credentials sits inside that obligation. There is no deadline because there is no grace period.
LIVE NOW
LIVE NOW
SM&CR
SM&CR
SM&CR
SM&CR
SM&CR
SM&CR
A named senior manager is personally accountable for those controls. When the FCA asks how AI agent activity was monitored, the answer belongs to an individual, not a department. Evidence has to exist before the question is asked.
A named senior manager is personally accountable for those controls. When the FCA asks how AI agent activity was monitored, the answer belongs to an individual, not a department. Evidence has to exist before the question is asked.
A named senior manager is personally accountable for those controls. When the FCA asks how AI agent activity was monitored, the answer belongs to an individual, not a department. Evidence has to exist before the question is asked.
A named senior manager is personally accountable for those controls. When the FCA asks how AI agent activity was monitored, the answer belongs to an individual, not a department. Evidence has to exist before the question is asked.
A named senior manager is personally accountable for those controls. When the FCA asks how AI agent activity was monitored, the answer belongs to an individual, not a department. Evidence has to exist before the question is asked.
A named senior manager is personally accountable for those controls. When the FCA asks how AI agent activity was monitored, the answer belongs to an individual, not a department. Evidence has to exist before the question is asked.
LIVE NOW
LIVE NOW
UK GDPR Article 9
UK GDPR Article 9
UK GDPR Article 9
UK GDPR Article 9
UK GDPR Article 9
UK GDPR Article 9
Special category data carries a higher bar. Every access by an autonomous agent needs a lawful basis and a record. Discovering the access months later in a breach investigation is not oversight, it is archaeology.
Special category data carries a higher bar. Every access by an autonomous agent needs a lawful basis and a record. Discovering the access months later in a breach investigation is not oversight, it is archaeology.
Special category data carries a higher bar. Every access by an autonomous agent needs a lawful basis and a record. Discovering the access months later in a breach investigation is not oversight, it is archaeology.
Special category data carries a higher bar. Every access by an autonomous agent needs a lawful basis and a record. Discovering the access months later in a breach investigation is not oversight, it is archaeology.
Special category data carries a higher bar. Every access by an autonomous agent needs a lawful basis and a record. Discovering the access months later in a breach investigation is not oversight, it is archaeology.
Special category data carries a higher bar. Every access by an autonomous agent needs a lawful basis and a record. Discovering the access months later in a breach investigation is not oversight, it is archaeology.
2 DECEMBER 2027
2 DECEMBER 2027
EU AI Act, Annex III
EU AI Act, Annex III
EU AI Act, Annex III
EU AI Act, Annex III
EU AI Act, Annex III
EU AI Act, Annex III
Deployers of high-risk AI must monitor operation and retain automatically generated logs, under Articles 26(5) and 26(6). Biometrics, employment, credit scoring. Fines up to €15M or 3% of global turnover.
Deployers of high-risk AI must monitor operation and retain automatically generated logs, under Articles 26(5) and 26(6). Biometrics, employment, credit scoring. Fines up to €15M or 3% of global turnover.
Deployers of high-risk AI must monitor operation and retain automatically generated logs, under Articles 26(5) and 26(6). Biometrics, employment, credit scoring. Fines up to €15M or 3% of global turnover.
Deployers of high-risk AI must monitor operation and retain automatically generated logs, under Articles 26(5) and 26(6). Biometrics, employment, credit scoring. Fines up to €15M or 3% of global turnover.
Deployers of high-risk AI must monitor operation and retain automatically generated logs, under Articles 26(5) and 26(6). Biometrics, employment, credit scoring. Fines up to €15M or 3% of global turnover.
Deployers of high-risk AI must monitor operation and retain automatically generated logs, under Articles 26(5) and 26(6). Biometrics, employment, credit scoring. Fines up to €15M or 3% of global turnover.
Your AI agents have the keys.
Your AI agents have the keys.
Your AI agents have the keys.
Your AI agents have the keys.
Your AI agents have the keys.
Do you know what they're doing with them?
Do you know what they're doing with them?
Do you know what they're doing with them?
Do you know what they're doing with them?
Do you know what they're doing with them?
Do you know what they're doing with them?
Your AI agents authenticate once, then act on their own across your systems. Tools like IAM and SIEM weren't built to watch what an authorised agent does next, so problems often only come to light weeks later in an audit. Obquan fixes that by checking every agent action as it happens and keeping an audit record you can hand straight to a regulator.
Your AI agents authenticate once, then act on their own across your systems. Tools like IAM and SIEM weren't built to watch what an authorised agent does next, so problems often only come to light weeks later in an audit. Obquan fixes that by checking every agent action as it happens and keeping an audit record you can hand straight to a regulator.
Your AI agents authenticate once, then act on their own across your systems. Tools like IAM and SIEM weren't built to watch what an authorised agent does next, so problems often only come to light weeks later in an audit. Obquan fixes that by checking every agent action as it happens and keeping an audit record you can hand straight to a regulator.
Your AI agents authenticate once, then act on their own across your systems. Tools like IAM and SIEM weren't built to watch what an authorised agent does next, so problems often only come to light weeks later in an audit. Obquan fixes that by checking every agent action as it happens and keeping an audit record you can hand straight to a regulator.
Your AI agents authenticate once, then act on their own across your systems. Tools like IAM and SIEM weren't built to watch what an authorised agent does next, so problems often only come to light weeks later in an audit. Obquan fixes that by checking every agent action as it happens and keeping an audit record you can hand straight to a regulator.
FinTech
Law Firm
Retail

A financial services firm.
AI agents with access to everything.
Your credit decisioning agent has a valid token for your core banking system. It also has access to HR payroll data and customer Personal Data that it has no business touching. Nobody knows because nobody's watching.
Obquan intercepts every call, checks it against FCA SYSC 3.2.6 and GDPR Article 9, and flags the violation in seconds. Your compliance team has the audit trail before the regulator asks.
FinTech
Law Firm
Retail

A financial services firm.
AI agents with access to everything.
Your credit decisioning agent has a valid token for your core banking system. It also has access to HR payroll data and customer Personal Data that it has no business touching. Nobody knows because nobody's watching.
Obquan intercepts every call, checks it against FCA SYSC 3.2.6 and GDPR Article 9, and flags the violation in seconds. Your compliance team has the audit trail before the regulator asks.
FinTech
Law Firm
Retail

A financial services firm.
AI agents with access to everything.
Your credit decisioning agent has a valid token for your core banking system. It also has access to HR payroll data and customer Personal Data that it has no business touching. Nobody knows because nobody's watching.
Obquan intercepts every call, checks it against FCA SYSC 3.2.6 and GDPR Article 9, and flags the violation in seconds. Your compliance team has the audit trail before the regulator asks.
FinTech
Law Firm
Retail

A financial services firm.
AI agents with access to everything.
Your credit decisioning agent has a valid token for your core banking system. It also has access to HR payroll data and customer Personal Data that it has no business touching. Nobody knows because nobody's watching.
Obquan intercepts every call, checks it against FCA SYSC 3.2.6 and GDPR Article 9, and flags the violation in seconds. Your compliance team has the audit trail before the regulator asks.
FinTech
Law Firm
Retail

A financial services firm.
AI agents with access to everything.
Your credit decisioning agent has a valid token for your core banking system. It also has access to HR payroll data and customer Personal Data that it has no business touching. Nobody knows because nobody's watching.
Obquan intercepts every call, checks it against FCA SYSC 3.2.6 and GDPR Article 9, and flags the violation in seconds. Your compliance team has the audit trail before the regulator asks.
See Obquan in your environment.
See Obquan in your environment.
See Obquan in your environment.
See Obquan in your environment.
We connect to a representative agent setup in your sandbox and you see what we see live.
We connect to a representative agent setup in your sandbox and you see what we see live.
We connect to a representative agent setup in your sandbox and you see what we see live.
We connect to a representative agent setup in your sandbox and you see what we see live.
See Obquan in your environment.
We connect to a representative agent setup in your sandbox and you see what we see live.
See Obquan in your environment.
We connect to a representative agent setup in your sandbox and you see what we see live.

Sheraz Yousaf
Sheraz Yousaf
Sheraz Yousaf
Founder & CEO
Founder & CEO
Founder & CEO
15 years in release engineering and systems delivery across financial services, media, and enterprise technology.
15 years in release engineering and systems delivery across financial services, media, and enterprise technology.
15 years in release engineering and systems delivery across financial services, media, and enterprise technology.
15 years in release engineering and systems delivery across financial services, media, and enterprise technology.
“
“
“
“
“
When I looked at what was out there - Credo AI, OneTrust, Datadog - good products all doing pieces of the puzzle. Governance documentation, infrastructure monitoring, risk assessments. But none of them were doing the one thing that actually matters to a regulator: showing what the AI agent did and whether it broke the rules. My background is in systems and infrastructure, you think in terms of what fails at scale and who carries the liability. AI agents operating inside regulated systems with no real-time oversight is exactly that kind of risk. So we built the thing that was missing.
When I looked at what was out there - Credo AI, OneTrust, Datadog - good products all doing pieces of the puzzle. Governance documentation, infrastructure monitoring, risk assessments. But none of them were doing the one thing that actually matters to a regulator: showing what the AI agent did and whether it broke the rules. My background is in systems and infrastructure, you think in terms of what fails at scale and who carries the liability. AI agents operating inside regulated systems with no real-time oversight is exactly that kind of risk. So we built the thing that was missing.
When I looked at what was out there - Credo AI, OneTrust, Datadog - good products all doing pieces of the puzzle. Governance documentation, infrastructure monitoring, risk assessments. But none of them were doing the one thing that actually matters to a regulator: showing what the AI agent did and whether it broke the rules. My background is in systems and infrastructure, you think in terms of what fails at scale and who carries the liability. AI agents operating inside regulated systems with no real-time oversight is exactly that kind of risk. So we built the thing that was missing.
When I looked at what was out there - Credo AI, OneTrust, Datadog - good products all doing pieces of the puzzle. Governance documentation, infrastructure monitoring, risk assessments. But none of them were doing the one thing that actually matters to a regulator: showing what the AI agent did and whether it broke the rules. My background is in systems and infrastructure, you think in terms of what fails at scale and who carries the liability. AI agents operating inside regulated systems with no real-time oversight is exactly that kind of risk. So we built the thing that was missing.
When I looked at what was out there - Credo AI, OneTrust, Datadog - good products all doing pieces of the puzzle. Governance documentation, infrastructure monitoring, risk assessments. But none of them were doing the one thing that actually matters to a regulator: showing what the AI agent did and whether it broke the rules. My background is in systems and infrastructure, you think in terms of what fails at scale and who carries the liability. AI agents operating inside regulated systems with no real-time oversight is exactly that kind of risk. So we built the thing that was missing.
”
”
”
”
”

Lucas D.S
Lucas D.S
Lucas D.S
Lucas D.S
LATAM
LATAM
Head of Engineering
Head of Engineering

Gabriel C
Gabriel C
Gabriel C
Gabriel C
LATAM
LATAM
LATAM
Senior Frontend Engineer
Senior Frontend Engineer
Senior Frontend Engineer

Gabriel B
Gabriel B
Gabriel B
Gabriel B
LATAM
LATAM
LATAM
Senior DevSecOps Engineer
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Subaru W
Subaru W
Subaru W
Subaru W
TOKYO
TOKYO
TOKYO
Head of Branding/UX/UI Design
Head of Branding/UX/UI Design
Head of Branding/UX/UI Design

Carla C
Carla C
Carla C
Carla C
LATAM
LATAM
LATAM
Senior QA Engineer
Senior QA Engineer
Senior QA Engineer

Lucas B
Lucas B
Lucas B
Lucas B
LATAM
LATAM
Principal Engineer
Principal Engineer
Principal Engineer

Lucas D.S
LATAM
Head of Engineering

Gabriel B
LATAM
Senior DevSecOps Engineer

Carla C
LATAM
Senior QA Engineer

Gabriel C
LATAM
Senior Frontend Engineer

Subaru W
TOKYO
Head of Branding/UX/UI Design

Lucas B
LATAM
Principal Engineer
Fractional Advisors
Fractional Advisors
Fractional Advisors
Arman Fallah
Arman Fallah
Arman Fallah
Arman Fallah
Arman Fallah
U.K.
U.K.
U.K.
Chief Risk Officer, Stripe UK
Chief Risk Officer, Stripe UK
Chief Risk Officer, Stripe UK
John Weir
John Weir
John Weir
John Weir
John Weir
U.S.
U.S.
U.S.
Distinguished Engineer formally at Google and Goldman Sachs
Distinguished Engineer formally at Google and Goldman Sachs
Distinguished Engineer formally at Google and Goldman Sachs