AnchorGate v0.1 is open source — self-host the full stack today. Star on GitHub →

AnchorGate

EU AI Act readiness

Article 12 asks for records of operation. Start there.

No tool makes you EU AI Act compliant, and you should distrust any that claims to. What a gateway can honestly do is produce the automatically generated records of operation the Act asks for — signed, tamper-evident, and mapped through a concrete control catalogue. That part, AnchorGate does in the path.

The Act, honestly

What the Act asks — and what a gateway can honestly cover

The Act is mostly organizational: classification, risk management, human oversight, documentation. A slice of it is operational — and that slice is exactly what a gate in the request path can evidence.

Records of operation (Article 12)

High-risk systems need automatically generated logs of their operation, kept traceable over the lifecycle. A signed, append-only ledger of every request, verdict, and policy version is that record — produced automatically because it’s in the path.

Traceability you can hand over

When a market surveillance authority or auditor asks how the system behaved, a Trust Packet is an answer they can verify independently — offline, against the public key, without trusting your tooling or ours.

What AnchorGate does not do

It won’t classify your systems, write your FRIA, or run your risk-management system — those are legal and organizational judgments. The risk register holds your classification; it doesn’t make it. Anyone selling “AI Act compliance in a box” is selling the box.

Governance & evidence

Evidence that survives the question “says who?”

One export: a manifest of scope and thresholds, the signing public key, and every decision event with its exact canonical payload and signature. Your auditor re-verifies each record offline — against the key, not against our word. If a byte changed anywhere, verification fails. Every record maps onto EU AI Act, ISO/IEC 42001, and SOC 2 control catalogues.

  • No dashboard access required — the packet is self-contained.
  • Signatures cover a stored canonical payload, so verification never depends on database round-tripping.
  • Each record carries its DEMM grade: how far up the ladder from “screenshot” to “reconstructable” it stands.

Design partners

No borrowed logos. A standing offer instead.

AnchorGate is v0.1. We don’t have testimonials yet, and we won’t invent them — what we have is a program for the first teams who put real traffic through the gate. We’d rather build with five serious teams than sell to fifty.

Who it’s for

  • Platform and GRC teams facing an EU AI Act, ISO/IEC 42001, or SOC 2 conversation this year
  • Agentic workloads — RAG, copilots, MCP tool use — running in regulated environments
  • Teams that want enforcement and evidence from the same gate their traffic already crosses

The exchange

You get

  • A direct line to the maintainers, not a ticket queue
  • Deployment support in your VPC
  • Your governance requirements shaping the roadmap

We get

  • Your ugliest governance requirements, stated plainly
  • Feedback from a real deployment — not a demo
Email hello@anchorgate.ai

FAQ

EU AI Act questions, answered carefully

Does AnchorGate classify our AI systems under the Act?
No. Risk classification under the EU AI Act is a legal judgment about your systems and their context — it belongs to you and your counsel. AnchorGate’s risk register records the classification you’ve made and computes posture against it; it never pretends to make the call for you.
What can we concretely evidence for Article 12 today?
That your gated LLM and agent traffic produced automatically generated records of operation: every request’s verdict, the policy version that applied, PII redactions, MCP decisions, and quarantines — each signed with ECDSA P-256 and exportable in a Trust Packet an authority can verify offline. Coverage extends exactly as far as the traffic you route through the gate.
Do we need to replace our routing gateway to prepare for the Act?
No. AnchorProxy is OpenAI-compatible on both sides, so it composes with LiteLLM, Portkey, or whatever routes your traffic today — your gateway keeps optimizing, AnchorGate adds the records of operation. One base-URL change puts it in the chain.

Start with the record. The rest of the Act needs it anyway.

Whatever your classification turns out to be, records of operation are the foundation every other obligation leans on. Put a workload through the gate and start accumulating them this week.

Become a design partner

or email hello@anchorgate.ai