Regulations are live, not theoretical
The EU AI Act enforces with fines up to €35M or 7% of global turnover. Malaysia's AI Act 2026, Singapore's Agentic AI framework and ASEAN DEFA are all in force. "We didn't know" is no longer a defence.
// THE GOVERNANCE LAYER FOR AI
OAG is the governance layer that sits between your AI and the models it runs on. It audits your codebase against 24 regulatory frameworks and seals the evidence with a cryptographic root — continuously, not once a year. No binders. No consultant opinions. When the regulator asks, you answer in minutes.
// THE EXPOSURE
Boards are personally exposed. Regulators no longer accept policy PDFs — they want verifiable evidence tied to the code that actually runs.
The EU AI Act enforces with fines up to €35M or 7% of global turnover. Malaysia's AI Act 2026, Singapore's Agentic AI framework and ASEAN DEFA are all in force. "We didn't know" is no longer a defence.
Consultants produce gap analyses. Regulators want proof that the controls exist in the running system — traceable from policy clause to source line. A PDF cannot be cross-examined. A Merkle root can.
A traditional compliance review consumes a quarter of engineering time and is stale the day it ships. Code changes hourly; binders don't.
When a model denies a loan or routes a patient, the question in court is: who governed that decision, and can you prove it? Provenance is now a board-level asset.
// THE INSTRUMENT
OAG Audit is the product your compliance officer can put in front of a board — and a regulator.
Submit a GitHub, GitLab or Bitbucket repository. OAG's digestion engine parses the codebase at the AST level — TypeScript, Python, Java, COBOL, VB6, C++ and more — then executes 24 regulatory frameworks against what it finds.
Awaiting submission. Reports typically complete in ~90 seconds.
Demo routes to the OAG Audit API. Prefer a walkthrough?
// THE PLATFORM
Each capability is an independent, auditable module. Subscribe to what you need today; compose the rest as you scale.
Repository-level compliance audits, sealed as evidence.
Tamper-evident cryptographic proof your evidence is intact.
Deterministic human-in-the-loop control before execution.
Pre-inference interception for the threats models can't see.
Modernise legacy estates without a big-bang rewrite.
Any model, any provider — with automatic failover.
// LIVE PROOF — READ FROM OUR OWN REGISTRY
These figures are read from OAG's own registry. The platform that audits you is itself audited, sealed and versioned.
// TRUST
“The evidence trail is what sold our board. We went from a binder nobody trusted to a report a regulator can verify itself.”
“Ninety seconds from repository to sealed findings. Our last compliance review took a quarter of engineering time.”
// HERITAGE
Controls on paper, audited by humans, stale on arrival.
Structured audits. The gap between documented and actual remained.
Checks at the gate. Governance stopped the moment code deployed.
Governance compiled into every route and every decision. Verifiable at runtime, sealed by Merkle root.
"Humans govern at the constitutional level. Machines execute at the operational level." — THE OAG CONSTITUTION
// ARCHITECTURE
OAG is not an LLM and not an IDE. It is the governance layer between them.
Three free audits a month. No credit card. Ninety seconds to evidence.
ENTERPRISE & SELF-HOSTED: me@jhosen.com