Platform

One evidence pack for GDPR, AI Act, and US privacy

The AI Act does not replace GDPR. DynasAI is the front layer that logs, redacts, and gates agents so EU and US teams can prove control — while compute and data stay on the cloud you choose.

The 2026 compliance clock

Enterprises now face stacked EU duties plus a US state-privacy patchwork. Buyers want continuous evidence, not a one-time policy PDF.

EU AI Act general application and Article 50 transparency duties
2 Aug 2026

European Commission AI Act timeline

GDPR Article 33 breach notification window when personal data is involved
72h

GDPR Art. 33

NIS2 early warning and formal incident reporting for essential entities
24h / 72h

NIS2 incident-reporting duties

maximum AI Act fine of global turnover (or €35M) for prohibited practices
7%

EU AI Act penalty framework

GDPR still applies. The AI Act adds more.

Today: any personal data in training, prompts, retrieval, or monitoring still needs a GDPR legal basis, minimization, purpose limits, and data-subject rights. DPIAs (Art. 35) sit alongside AI Act fundamental-rights assessments where those apply. Article 22 protections against solely automated decisions still require a human path. Transparency duties under AI Act Article 50 — chatbot disclosure, synthetic-content marking — apply from 2 August 2026.

Next: high-risk obligations (logging, human oversight, data governance, technical documentation) are the operating system for credit, insurance, employment, and essential services. Annex III high-risk duties are widely expected toward December 2027, with product-embedded systems later — but insurance and financial deployers should not pause FRIA and logging work. In the US, CCPA/CPRA plus 20+ state laws, plus SOC 2 Type II as a procurement default, demand encryption, access logs, and proof that customer data is not used to train public models.

Where governance programs fail

Policy binders and three separate incident templates do not survive a real event. Technical controls have to produce one evidence trail.

Three reports, one incident

GDPR, NIS2, and AI Act Article 73 can all fire on the same agent failure. Separate spreadsheets produce inconsistent facts.

No legal basis for AI data

The AI Act does not create a GDPR legal basis. Training and monitoring still need Art. 6 — and a record of processing.

Logs that cannot answer SAR

Subject access, deletion, and CCPA “right to know” fail when prompts, retrieval, and tool calls are not queryable.

Human oversight on paper

High-risk and Art. 22 workflows need named reviewers with authority — not a checkbox after the agent already acted.

Cloud lock-in vs residency

EU customers need EU residency options; US customers need SOC-aligned tenants. One vendor region is not a strategy.

Point-in-time audits

SOC 2 Type II and ongoing GDPR duties expect continuous evidence: policy versions, redactions, and tool-call history.

Controls DynasAI runs in the front layer

You keep data in AWS, Azure, or GCP. We make the agent surface governable: identity, policy, logs, and eval gates.

  1. Identity & scoped access

    SSO, RBAC/ABAC, and environment-scoped agent permissions so retrieval inherits the user’s rights — not a shared service account.

  2. Minimization & redaction

    Block, redact, or escalate PII and sensitive categories before prompts and tool calls leave your tenant.

  3. Immutable traces

    Log prompts, retrieved sources, tool calls, policy version, and human overrides. Retention aligned to six-month+ AI Act logging and SOC evidence windows.

  4. Human-in-the-loop gates

    Pause for review on automated decisions, conflicts, or policy hits. Named approvers with authority — required for Art. 22 and high-risk oversight.

  5. Residency & customer control

    EU or US regions, your VPC, or a managed template. Customer-managed keys where the cloud allows. No forced training on your corpus.

  6. One incident evidence pack

    Map the same traces to GDPR 72h, NIS2 24h/72h, and AI Act serious-incident fields so legal, security, and ops tell one story.

Frameworks we design for

GDPR

Legal basis, DPIA support, minimization, DPA language, SAR/deletion workflows, and EU residency options.

Learn more →

EU AI Act

Art. 50 transparency now; logging, human oversight, and documentation patterns for high-risk and insurance/credit deployers.

NIS2

Incident records and early-warning evidence when agents sit in essential or important entity supply chains.

US privacy & SOC-aligned

CCPA/CPRA-style access and deletion, encryption in transit/at rest, access logs, and procurement-ready control descriptions.

NIST AI RMF

Map Govern, Map, Measure, Manage to eval gates, drift monitors, and policy versions — useful for US buyers and insurers.

Governance readiness sprint

A focused engagement that leaves you with a control map, evidence pack, and cloud residency plan — not a slide deck.

  1. System & data inventory

    Classify agents, personal data, high-risk use (credit, insurance, HR), and subprocessors.

  2. Gap map

    GDPR legal basis, DPIA/FRIA need, Art. 50 disclosures, logging gaps, and US state-privacy overlap.

  3. Control build

    RBAC, redaction, eval gates, human approval paths, and residency on AWS, Azure, or GCP.

  4. Evidence pack

    Unified incident template, retention schedule, and security-review artifacts for procurement and DPO review.

Put GDPR and AI Act controls in the product, not the binder

Request a security review or start a governance sprint. Data stays in your cloud; DynasAI is the governed front layer.