Three reports, one incident
GDPR, NIS2, and AI Act Article 73 can all fire on the same agent failure. Separate spreadsheets produce inconsistent facts.
Platform
The AI Act does not replace GDPR. DynasAI is the front layer that logs, redacts, and gates agents so EU and US teams can prove control — while compute and data stay on the cloud you choose.
Enterprises now face stacked EU duties plus a US state-privacy patchwork. Buyers want continuous evidence, not a one-time policy PDF.
European Commission AI Act timeline
GDPR Art. 33
NIS2 incident-reporting duties
EU AI Act penalty framework
Today: any personal data in training, prompts, retrieval, or monitoring still needs a GDPR legal basis, minimization, purpose limits, and data-subject rights. DPIAs (Art. 35) sit alongside AI Act fundamental-rights assessments where those apply. Article 22 protections against solely automated decisions still require a human path. Transparency duties under AI Act Article 50 — chatbot disclosure, synthetic-content marking — apply from 2 August 2026.
Next: high-risk obligations (logging, human oversight, data governance, technical documentation) are the operating system for credit, insurance, employment, and essential services. Annex III high-risk duties are widely expected toward December 2027, with product-embedded systems later — but insurance and financial deployers should not pause FRIA and logging work. In the US, CCPA/CPRA plus 20+ state laws, plus SOC 2 Type II as a procurement default, demand encryption, access logs, and proof that customer data is not used to train public models.
Policy binders and three separate incident templates do not survive a real event. Technical controls have to produce one evidence trail.
GDPR, NIS2, and AI Act Article 73 can all fire on the same agent failure. Separate spreadsheets produce inconsistent facts.
The AI Act does not create a GDPR legal basis. Training and monitoring still need Art. 6 — and a record of processing.
Subject access, deletion, and CCPA “right to know” fail when prompts, retrieval, and tool calls are not queryable.
High-risk and Art. 22 workflows need named reviewers with authority — not a checkbox after the agent already acted.
EU customers need EU residency options; US customers need SOC-aligned tenants. One vendor region is not a strategy.
SOC 2 Type II and ongoing GDPR duties expect continuous evidence: policy versions, redactions, and tool-call history.
You keep data in AWS, Azure, or GCP. We make the agent surface governable: identity, policy, logs, and eval gates.
SSO, RBAC/ABAC, and environment-scoped agent permissions so retrieval inherits the user’s rights — not a shared service account.
Block, redact, or escalate PII and sensitive categories before prompts and tool calls leave your tenant.
Log prompts, retrieved sources, tool calls, policy version, and human overrides. Retention aligned to six-month+ AI Act logging and SOC evidence windows.
Pause for review on automated decisions, conflicts, or policy hits. Named approvers with authority — required for Art. 22 and high-risk oversight.
EU or US regions, your VPC, or a managed template. Customer-managed keys where the cloud allows. No forced training on your corpus.
Map the same traces to GDPR 72h, NIS2 24h/72h, and AI Act serious-incident fields so legal, security, and ops tell one story.
Legal basis, DPIA support, minimization, DPA language, SAR/deletion workflows, and EU residency options.
Learn more →Art. 50 transparency now; logging, human oversight, and documentation patterns for high-risk and insurance/credit deployers.
Incident records and early-warning evidence when agents sit in essential or important entity supply chains.
CCPA/CPRA-style access and deletion, encryption in transit/at rest, access logs, and procurement-ready control descriptions.
Map Govern, Map, Measure, Manage to eval gates, drift monitors, and policy versions — useful for US buyers and insurers.
Quality, lineage, and permission-aware retrieval so governance is not bolted onto a dirty index.
Learn more →A focused engagement that leaves you with a control map, evidence pack, and cloud residency plan — not a slide deck.
Classify agents, personal data, high-risk use (credit, insurance, HR), and subprocessors.
GDPR legal basis, DPIA/FRIA need, Art. 50 disclosures, logging gaps, and US state-privacy overlap.
RBAC, redaction, eval gates, human approval paths, and residency on AWS, Azure, or GCP.
Unified incident template, retention schedule, and security-review artifacts for procurement and DPO review.
Request a security review or start a governance sprint. Data stays in your cloud; DynasAI is the governed front layer.