The problem
The EU AI Act, GDPR, NIS2, and ISO 27001 all expect the same underlying thing: you can say what AI you run, who used it, what data went through it, and what controls applied. If your AI calls go straight to a provider, none of that exists, and assembling it after the fact is a project.
How it works
Because every call passes through aigw, every call leaves a record: the identity behind it, the model, the policy outcome, the cost, and the data categories it touched. The audit trail is checkpointed so tampering shows. Content retention is opt-in and redacted on ingest, so you can keep evidence without keeping the sensitive data inside it.
What you get
- A per-call governance record: who, which model, which policy, allowed or blocked, and what was detected.
- A tamper-evident audit trail you can export for a review.
- Governed content logging, off by default, redacted when on, with its own retention window.
- A live inventory of the models in use and the traffic against them, so an AI register is a report rather than a spreadsheet.
This supports your AI Act, GDPR, NIS2, and ISO 27001 evidence; it does not replace your own assessment. See governance.