Obquan flags AI regulatory violations the moment your agents act.
And there's no AI watching AI.

Obquan flags AI regulatory violations the moment your agents act.
And there's no AI watching AI.

Obquan flags AI regulatory violations the moment your agents act.
And there's no AI watching AI.

Obquan flags AI regulatory violations the moment your agents act.
And there's no AI watching AI.

Obquan flags AI regulatory violations the moment your agents act.
And there's no AI watching AI.

Obquan flags AI regulatory violations the moment your agents act.
And there's no AI watching AI.

One source of audit-ready truth, checking your AI against every framework you answer to: GDPR, FCA, the EU AI Act and beyond.

One source of audit-ready truth, checking your AI against every framework you answer to: GDPR, FCA, the EU AI Act and beyond.

One source of audit-ready truth, checking your AI against every framework you answer to: GDPR, FCA, the EU AI Act and beyond.

One source of audit-ready truth, checking your AI against every framework you answer to: GDPR, FCA, the EU AI Act and beyond.

One source of audit-ready truth, checking your AI against every framework you answer to: GDPR, FCA, the EU AI Act and beyond.

One source of audit-ready truth, checking your AI against every framework you answer to: GDPR, FCA, the EU AI Act and beyond.

We do one thing.

We do one thing.

We do one thing.

We do one thing.

We do one thing.

We do one thing.

Obquan monitors what your AI agents actually do as they do it. The Guardian Proxy sits between your agents and your systems, checking every API call against GDPR Article 9, FCA SYSC 3.2.6 and the EU AI Act. Everything runs on fixed rules, so the same action always gives the same result and you get a clear record of where your AI crossed the boundary.

Obquan monitors what your AI agents actually do as they do it. The Guardian Proxy sits between your agents and your systems, checking every API call against GDPR Article 9, FCA SYSC 3.2.6 and the EU AI Act. Everything runs on fixed rules, so the same action always gives the same result and you get a clear record of where your AI crossed the boundary.

Obquan monitors what your AI agents actually do as they do it. The Guardian Proxy sits between your agents and your systems, checking every API call against GDPR Article 9, FCA SYSC 3.2.6 and the EU AI Act. Everything runs on fixed rules, so the same action always gives the same result and you get a clear record of where your AI crossed the boundary.

Obquan monitors what your AI agents actually do as they do it. The Guardian Proxy sits between your agents and your systems, checking every API call against GDPR Article 9, FCA SYSC 3.2.6 and the EU AI Act. Everything runs on fixed rules, so the same action always gives the same result and you get a clear record of where your AI crossed the boundary.

Obquan monitors what your AI agents actually do as they do it. The Guardian Proxy sits between your agents and your systems, checking every API call against GDPR Article 9, FCA SYSC 3.2.6 and the EU AI Act. Everything runs on fixed rules, so the same action always gives the same result and you get a clear record of where your AI crossed the boundary.

See every AI agent action as it happens.

See every AI agent action as it happens.

See every AI agent action as it happens.

See every AI agent action as it happens.

See every AI agent action as it happens.

Every API call your AI agents make is captured in real time, checked against your compliance rules, and logged with full behavioural context. You won't have AI blind spots and you won't discover a breach three months after it happened.

Every API call your AI agents make is captured in real time, checked against your compliance rules, and logged with full behavioural context. You won't have AI blind spots and you won't discover a breach three months after it happened.

Every API call your AI agents make is captured in real time, checked against your compliance rules, and logged with full behavioural context. You won't have AI blind spots and you won't discover a breach three months after it happened.

Every API call your AI agents make is captured in real time, checked against your compliance rules, and logged with full behavioural context. You won't have AI blind spots and you won't discover a breach three months after it happened.

Every API call your AI agents make is captured in real time, checked against your compliance rules, and logged with full behavioural context. You won't have AI blind spots and you won't discover a breach three months after it happened.

Audit-ready evidence.
At the article level.

Audit-ready evidence.
At the article level.

Audit-ready evidence.
At the article level.

Audit-ready evidence.
At the article level.

When regulators ask questions you need answers. Obquan generates compliance evidence mapped directly to GDPR Article 9, FCA SYSC 3.2.6, and EU AI Act articles. A single export will give you everything an auditor needs.

When regulators ask questions you need answers. Obquan generates compliance evidence mapped directly to GDPR Article 9, FCA SYSC 3.2.6, and EU AI Act articles. A single export will give you everything an auditor needs.

When regulators ask questions you need answers. Obquan generates compliance evidence mapped directly to GDPR Article 9, FCA SYSC 3.2.6, and EU AI Act articles. A single export will give you everything an auditor needs.

When regulators ask questions you need answers. Obquan generates compliance evidence mapped directly to GDPR Article 9, FCA SYSC 3.2.6, and EU AI Act articles. A single export will give you everything an auditor needs.

When regulators ask questions you need answers. Obquan generates compliance evidence mapped directly to GDPR Article 9, FCA SYSC 3.2.6, and EU AI Act articles. A single export will give you everything an auditor needs.

Deploys in hours.
Minimal integration.

Deploys in hours.
Minimal integration.

Deploys in hours.
Minimal integration.

Deploys in hours.
Minimal integration.

The Guardian Proxy sits inline between your agents and your infrastructure. Around a dozen lines of SDK code, plus some lightweight backend metadata configuration, is all it takes. No architectural changes or changes to your existing AI stack, and and it works whatever tools your engineers built it on.

The Guardian Proxy sits inline between your agents and your infrastructure. Around a dozen lines of SDK code, plus some lightweight backend metadata configuration, is all it takes. No architectural changes or changes to your existing AI stack, and and it works whatever tools your engineers built it on.

The Guardian Proxy sits inline between your agents and your infrastructure. Around a dozen lines of SDK code, plus some lightweight backend metadata configuration, is all it takes. No architectural changes or changes to your existing AI stack, and and it works whatever tools your engineers built it on.

The Guardian Proxy sits inline between your agents and your infrastructure. Around a dozen lines of SDK code, plus some lightweight backend metadata configuration, is all it takes. No architectural changes or changes to your existing AI stack, and and it works whatever tools your engineers built it on.

The Guardian Proxy sits inline between your agents and your infrastructure. Around a dozen lines of SDK code, plus some lightweight backend metadata configuration, is all it takes. No architectural changes or changes to your existing AI stack, and and it works whatever tools your engineers built it on.

FCA SYSC 3.2.6:

FCA SYSC 3.2.6:

FCA SYSC 3.2.6:

FCA SYSC 3.2.6:

FCA SYSC 3.2.6:

FCA SYSC 3.2.6:

the clock is already running

the clock is already running

the clock is already running

the clock is already running

the clock is already running

In force now

In force now

In force now

In force now

In force now

FCA SYSC 3.2.6 requires effective and ongoing risk monitoring for AI systems. Quarterly assessments are not continuous monitoring. This is enforceable today.

FCA SYSC 3.2.6 requires effective and ongoing risk monitoring for AI systems. Quarterly assessments are not continuous monitoring. This is enforceable today.

FCA SYSC 3.2.6 requires effective and ongoing risk monitoring for AI systems. Quarterly assessments are not continuous monitoring. This is enforceable today.

FCA SYSC 3.2.6 requires effective and ongoing risk monitoring for AI systems. Quarterly assessments are not continuous monitoring. This is enforceable today.

FCA SYSC 3.2.6 requires effective and ongoing risk monitoring for AI systems. Quarterly assessments are not continuous monitoring. This is enforceable today.

Supervision increasing

Supervision increasing

Supervision increasing

Supervision increasing

Supervision increasing

FCA supervisory focus on AI governance is intensifying through 2026. Firms without documented continuous monitoring are exposed in any review.

FCA supervisory focus on AI governance is intensifying through 2026. Firms without documented continuous monitoring are exposed in any review.

FCA supervisory focus on AI governance is intensifying through 2026. Firms without documented continuous monitoring are exposed in any review.

FCA supervisory focus on AI governance is intensifying through 2026. Firms without documented continuous monitoring are exposed in any review.

FCA supervisory focus on AI governance is intensifying through 2026. Firms without documented continuous monitoring are exposed in any review.

Year-end exposure

Year-end exposure

Year-end exposure

Year-end exposure

Year-end exposure

Firms without real-time oversight and audit-ready evidence face material risk at year-end supervisory reviews. Manual audits will not be sufficient.

Firms without real-time oversight and audit-ready evidence face material risk at year-end supervisory reviews. Manual audits will not be sufficient.

Firms without real-time oversight and audit-ready evidence face material risk at year-end supervisory reviews. Manual audits will not be sufficient.

Firms without real-time oversight and audit-ready evidence face material risk at year-end supervisory reviews. Manual audits will not be sufficient.

Firms without real-time oversight and audit-ready evidence face material risk at year-end supervisory reviews. Manual audits will not be sufficient.

Your AI agents are already regulated:

Your AI agents are already regulated:

Your AI agents are already regulated:

Your AI agents are already regulated:

Your AI agents are already regulated:

Your AI agents are already regulated:

four obligations, three of them live today

four obligations, three of them live today

four obligations, three of them live today

four obligations, three of them live today

four obligations, three of them live today

LIVE NOW

LIVE NOW

FCA SYSC 3.2.6

FCA SYSC 3.2.6

FCA SYSC 3.2.6

FCA SYSC 3.2.6

FCA SYSC 3.2.6

FCA SYSC 3.2.6

Firms must maintain adequate systems and controls, monitored on an ongoing basis. An AI agent acting on customer data with valid credentials sits inside that obligation. There is no deadline because there is no grace period.

Firms must maintain adequate systems and controls, monitored on an ongoing basis. An AI agent acting on customer data with valid credentials sits inside that obligation. There is no deadline because there is no grace period.

Firms must maintain adequate systems and controls, monitored on an ongoing basis. An AI agent acting on customer data with valid credentials sits inside that obligation. There is no deadline because there is no grace period.

Firms must maintain adequate systems and controls, monitored on an ongoing basis. An AI agent acting on customer data with valid credentials sits inside that obligation. There is no deadline because there is no grace period.

Firms must maintain adequate systems and controls, monitored on an ongoing basis. An AI agent acting on customer data with valid credentials sits inside that obligation. There is no deadline because there is no grace period.

Firms must maintain adequate systems and controls, monitored on an ongoing basis. An AI agent acting on customer data with valid credentials sits inside that obligation. There is no deadline because there is no grace period.

LIVE NOW

LIVE NOW

SM&CR

SM&CR

SM&CR

SM&CR

SM&CR

SM&CR

A named senior manager is personally accountable for those controls. When the FCA asks how AI agent activity was monitored, the answer belongs to an individual, not a department. Evidence has to exist before the question is asked.

A named senior manager is personally accountable for those controls. When the FCA asks how AI agent activity was monitored, the answer belongs to an individual, not a department. Evidence has to exist before the question is asked.

A named senior manager is personally accountable for those controls. When the FCA asks how AI agent activity was monitored, the answer belongs to an individual, not a department. Evidence has to exist before the question is asked.

A named senior manager is personally accountable for those controls. When the FCA asks how AI agent activity was monitored, the answer belongs to an individual, not a department. Evidence has to exist before the question is asked.

A named senior manager is personally accountable for those controls. When the FCA asks how AI agent activity was monitored, the answer belongs to an individual, not a department. Evidence has to exist before the question is asked.

A named senior manager is personally accountable for those controls. When the FCA asks how AI agent activity was monitored, the answer belongs to an individual, not a department. Evidence has to exist before the question is asked.

LIVE NOW

LIVE NOW

UK GDPR Article 9

UK GDPR Article 9

UK GDPR Article 9

UK GDPR Article 9

UK GDPR Article 9

UK GDPR Article 9

Special category data carries a higher bar. Every access by an autonomous agent needs a lawful basis and a record. Discovering the access months later in a breach investigation is not oversight, it is archaeology.

Special category data carries a higher bar. Every access by an autonomous agent needs a lawful basis and a record. Discovering the access months later in a breach investigation is not oversight, it is archaeology.

Special category data carries a higher bar. Every access by an autonomous agent needs a lawful basis and a record. Discovering the access months later in a breach investigation is not oversight, it is archaeology.

Special category data carries a higher bar. Every access by an autonomous agent needs a lawful basis and a record. Discovering the access months later in a breach investigation is not oversight, it is archaeology.

Special category data carries a higher bar. Every access by an autonomous agent needs a lawful basis and a record. Discovering the access months later in a breach investigation is not oversight, it is archaeology.

Special category data carries a higher bar. Every access by an autonomous agent needs a lawful basis and a record. Discovering the access months later in a breach investigation is not oversight, it is archaeology.

2 DECEMBER 2027

2 DECEMBER 2027

EU AI Act, Annex III

EU AI Act, Annex III

EU AI Act, Annex III

EU AI Act, Annex III

EU AI Act, Annex III

EU AI Act, Annex III

Deployers of high-risk AI must monitor operation and retain automatically generated logs, under Articles 26(5) and 26(6). Biometrics, employment, credit scoring. Fines up to €15M or 3% of global turnover.

Deployers of high-risk AI must monitor operation and retain automatically generated logs, under Articles 26(5) and 26(6). Biometrics, employment, credit scoring. Fines up to €15M or 3% of global turnover.

Deployers of high-risk AI must monitor operation and retain automatically generated logs, under Articles 26(5) and 26(6). Biometrics, employment, credit scoring. Fines up to €15M or 3% of global turnover.

Deployers of high-risk AI must monitor operation and retain automatically generated logs, under Articles 26(5) and 26(6). Biometrics, employment, credit scoring. Fines up to €15M or 3% of global turnover.

Deployers of high-risk AI must monitor operation and retain automatically generated logs, under Articles 26(5) and 26(6). Biometrics, employment, credit scoring. Fines up to €15M or 3% of global turnover.

Deployers of high-risk AI must monitor operation and retain automatically generated logs, under Articles 26(5) and 26(6). Biometrics, employment, credit scoring. Fines up to €15M or 3% of global turnover.

Your AI agents have the keys.

Your AI agents have the keys.

Your AI agents have the keys.

Your AI agents have the keys.

Your AI agents have the keys.

Do you know what they're doing with them?

Do you know what they're doing with them?

Do you know what they're doing with them?

Do you know what they're doing with them?

Do you know what they're doing with them?

Do you know what they're doing with them?

Your AI agents authenticate once, then act on their own across your systems. Tools like IAM and SIEM weren't built to watch what an authorised agent does next, so problems often only come to light weeks later in an audit. Obquan fixes that by checking every agent action as it happens and keeping an audit record you can hand straight to a regulator.

Your AI agents authenticate once, then act on their own across your systems. Tools like IAM and SIEM weren't built to watch what an authorised agent does next, so problems often only come to light weeks later in an audit. Obquan fixes that by checking every agent action as it happens and keeping an audit record you can hand straight to a regulator.

Your AI agents authenticate once, then act on their own across your systems. Tools like IAM and SIEM weren't built to watch what an authorised agent does next, so problems often only come to light weeks later in an audit. Obquan fixes that by checking every agent action as it happens and keeping an audit record you can hand straight to a regulator.

Your AI agents authenticate once, then act on their own across your systems. Tools like IAM and SIEM weren't built to watch what an authorised agent does next, so problems often only come to light weeks later in an audit. Obquan fixes that by checking every agent action as it happens and keeping an audit record you can hand straight to a regulator.

Your AI agents authenticate once, then act on their own across your systems. Tools like IAM and SIEM weren't built to watch what an authorised agent does next, so problems often only come to light weeks later in an audit. Obquan fixes that by checking every agent action as it happens and keeping an audit record you can hand straight to a regulator.

FinTech

Law Firm

Retail

A financial services firm.
AI agents with access to everything.

Your credit decisioning agent has a valid token for your core banking system. It also has access to HR payroll data and customer Personal Data that it has no business touching. Nobody knows because nobody's watching.

Obquan intercepts every call, checks it against FCA SYSC 3.2.6 and GDPR Article 9, and flags the violation in seconds. Your compliance team has the audit trail before the regulator asks.

FinTech

Law Firm

Retail

A financial services firm.
AI agents with access to everything.

Your credit decisioning agent has a valid token for your core banking system. It also has access to HR payroll data and customer Personal Data that it has no business touching. Nobody knows because nobody's watching.

Obquan intercepts every call, checks it against FCA SYSC 3.2.6 and GDPR Article 9, and flags the violation in seconds. Your compliance team has the audit trail before the regulator asks.

FinTech

Law Firm

Retail

A financial services firm.
AI agents with access to everything.

Your credit decisioning agent has a valid token for your core banking system. It also has access to HR payroll data and customer Personal Data that it has no business touching. Nobody knows because nobody's watching.

Obquan intercepts every call, checks it against FCA SYSC 3.2.6 and GDPR Article 9, and flags the violation in seconds. Your compliance team has the audit trail before the regulator asks.

FinTech

Law Firm

Retail

A financial services firm.
AI agents with access to everything.

Your credit decisioning agent has a valid token for your core banking system. It also has access to HR payroll data and customer Personal Data that it has no business touching. Nobody knows because nobody's watching.

Obquan intercepts every call, checks it against FCA SYSC 3.2.6 and GDPR Article 9, and flags the violation in seconds. Your compliance team has the audit trail before the regulator asks.

FinTech

Law Firm

Retail

A financial services firm.
AI agents with access to everything.

Your credit decisioning agent has a valid token for your core banking system. It also has access to HR payroll data and customer Personal Data that it has no business touching. Nobody knows because nobody's watching.

Obquan intercepts every call, checks it against FCA SYSC 3.2.6 and GDPR Article 9, and flags the violation in seconds. Your compliance team has the audit trail before the regulator asks.

See Obquan in your environment.

See Obquan in your environment.

See Obquan in your environment.

See Obquan in your environment.

We connect to a representative agent setup in your sandbox and you see what we see live.

We connect to a representative agent setup in your sandbox and you see what we see live.

We connect to a representative agent setup in your sandbox and you see what we see live.

We connect to a representative agent setup in your sandbox and you see what we see live.

See Obquan in your environment.

We connect to a representative agent setup in your sandbox and you see what we see live.

See Obquan in your environment.

We connect to a representative agent setup in your sandbox and you see what we see live.

Sheraz Yousaf

Sheraz Yousaf

Sheraz Yousaf

Founder & CEO

Founder & CEO

Founder & CEO

15 years in release engineering and systems delivery across financial services, media, and enterprise technology.

15 years in release engineering and systems delivery across financial services, media, and enterprise technology.

15 years in release engineering and systems delivery across financial services, media, and enterprise technology.

15 years in release engineering and systems delivery across financial services, media, and enterprise technology.

When I looked at what was out there - Credo AI, OneTrust, Datadog - good products all doing pieces of the puzzle. Governance documentation, infrastructure monitoring, risk assessments. But none of them were doing the one thing that actually matters to a regulator: showing what the AI agent did and whether it broke the rules. My background is in systems and infrastructure, you think in terms of what fails at scale and who carries the liability. AI agents operating inside regulated systems with no real-time oversight is exactly that kind of risk. So we built the thing that was missing.

When I looked at what was out there - Credo AI, OneTrust, Datadog - good products all doing pieces of the puzzle. Governance documentation, infrastructure monitoring, risk assessments. But none of them were doing the one thing that actually matters to a regulator: showing what the AI agent did and whether it broke the rules. My background is in systems and infrastructure, you think in terms of what fails at scale and who carries the liability. AI agents operating inside regulated systems with no real-time oversight is exactly that kind of risk. So we built the thing that was missing.

When I looked at what was out there - Credo AI, OneTrust, Datadog - good products all doing pieces of the puzzle. Governance documentation, infrastructure monitoring, risk assessments. But none of them were doing the one thing that actually matters to a regulator: showing what the AI agent did and whether it broke the rules. My background is in systems and infrastructure, you think in terms of what fails at scale and who carries the liability. AI agents operating inside regulated systems with no real-time oversight is exactly that kind of risk. So we built the thing that was missing.

When I looked at what was out there - Credo AI, OneTrust, Datadog - good products all doing pieces of the puzzle. Governance documentation, infrastructure monitoring, risk assessments. But none of them were doing the one thing that actually matters to a regulator: showing what the AI agent did and whether it broke the rules. My background is in systems and infrastructure, you think in terms of what fails at scale and who carries the liability. AI agents operating inside regulated systems with no real-time oversight is exactly that kind of risk. So we built the thing that was missing.

When I looked at what was out there - Credo AI, OneTrust, Datadog - good products all doing pieces of the puzzle. Governance documentation, infrastructure monitoring, risk assessments. But none of them were doing the one thing that actually matters to a regulator: showing what the AI agent did and whether it broke the rules. My background is in systems and infrastructure, you think in terms of what fails at scale and who carries the liability. AI agents operating inside regulated systems with no real-time oversight is exactly that kind of risk. So we built the thing that was missing.

Lucas D.S

Lucas D.S

Lucas D.S

Lucas D.S

LATAM

LATAM

Head of Engineering

Head of Engineering

Gabriel C

Gabriel C

Gabriel C

Gabriel C

LATAM

LATAM

LATAM

Senior Frontend Engineer

Senior Frontend Engineer

Senior Frontend Engineer

Gabriel B

Gabriel B

Gabriel B

Gabriel B

LATAM

LATAM

LATAM

Senior DevSecOps Engineer

Senior DevSecOps Engineer

Senior DevSecOps Engineer

Subaru W

Subaru W

Subaru W

Subaru W

TOKYO

TOKYO

TOKYO

Head of Branding/UX/UI Design

Head of Branding/UX/UI Design

Head of Branding/UX/UI Design

Carla C

Carla C

Carla C

Carla C

LATAM

LATAM

LATAM

Senior QA Engineer

Senior QA Engineer

Senior QA Engineer

Lucas B

Lucas B

Lucas B

Lucas B

LATAM

LATAM

Principal Engineer

Principal Engineer

Principal Engineer

Lucas D.S

LATAM

Head of Engineering

Gabriel B

LATAM

Senior DevSecOps Engineer

Carla C

LATAM

Senior QA Engineer

Gabriel C

LATAM

Senior Frontend Engineer

Subaru W

TOKYO

Head of Branding/UX/UI Design

Lucas B

LATAM

Principal Engineer

Fractional Advisors

Fractional Advisors

Fractional Advisors

Arman Fallah

Arman Fallah

Arman Fallah

Arman Fallah

Arman Fallah

U.K.

U.K.

U.K.

Chief Risk Officer, Stripe UK

Chief Risk Officer, Stripe UK

Chief Risk Officer, Stripe UK

John Weir

John Weir

John Weir

John Weir

John Weir

U.S.

U.S.

U.S.

Distinguished Engineer formally at Google and Goldman Sachs

Distinguished Engineer formally at Google and Goldman Sachs

Distinguished Engineer formally at Google and Goldman Sachs

© 2026 Obquan.All Rights Reserved. 

© 2026 Obquan.All Rights Reserved. 

© 2026 Obquan.All Rights Reserved. 

© 2026 Obquan.All Rights Reserved. 

© 2026 Obquan.All Rights Reserved.