Newsroom
News

Compliance by design: built against six EU frameworks from day one

INSTRAT3601 min read

For AI that operates across an organization, compliance cannot be a module you bolt on at the end. We build one shared, compliance-ready foundation, with stricter controls activated by customer, data, and intended use.

Designed against six EU frameworks

  • GDPR — data protection & DPIA
  • EU AI Act — transparency obligations from August 2026
  • NIS2 — cybersecurity baseline
  • DORA — financial-services overlay
  • EU Data Act — switching & portability
  • Cyber Resilience Act — scope assessment

In the product, not a separate module

Governance, provenance, approvals, and an audit view appear through the interface you already use — a Trust & Governance area in administration, inline classification and approval warnings, visible source and AI provenance in outputs, an audit and activity view, and downloadable compliance evidence for auditors.

An honest boundary

We build a compliance-ready foundation and require a formal DPO, legal, and security verification before deployment with real executive or customer data. Full compliance depends on the application, deployment, contracts, and each use case being aligned. We would rather state that plainly than overclaim.

Share

Related posts

News

INSTRAT360 opens the Newsroom

One place for product news, answers, and field notes across Virtual Organization, Nora, and Saga — built to be reshared.

Jul 28, 20261 min.