Our AI enforcement outcome SDK
1 Sep 2026
Enjoyed holidays? We did! But also accomplished some great work. Over Summer, our CTO and team developed a SDK (that B/B sets in 3 lines of codes) for chained-proof compliance regarding AI calls.
What AI compliance?
Every call a product makes to OpenAI, Deepseek, Anthropic or Mistral leaves a trace. Today, that trace isn't evidence: it's a log Tech staff wrote (and could easily rewrite). We built ID side to replace that self-made log with an evidence: a cryptographically signed proof, attached to every AI call, stating WHO makes the AI call, WHICH RULES are decided upon, and on what LEGAL BASIS applies.
Our solution is new (patent-protected) because it automatically generates a temper-evident exportable ledger of enforcement outcome, verifiable by a regulator years later without our support.
What does our SDK enable? Why does it provide "AI framing"?
All organizations, and their employees, want to save FTE-equivalent time with AI. Using Copilot "only" (and not the others) just because "it is safe" does not match today's AI market reality. The hiccup is that organizations must demonstrate compliance with their AI obligations.
We designed our SDK to address this compliance gap:
- It is SIMPLE: 3 lines of code, no migration, no new endpoints
client = consent.wrap(OpenAI())
- It is CHEAP: Compliance infrastructure shouldn't cost more than the AI call it rides on (agentic AI is about to make billions of these micro-decisions a day) -starting at €0 for non-profits and micro-enterprises, and the SDK core will be open-source. Consent has to get cheaper as AI gets faster, or it gets skipped.
- 1 OBJECT, 2 READERS: The 3 lines an engineer ships and the legal basis a DPO declares resolve to the same signed proof (no translation loss between the codebase and the compliance file). Our SDK sits on a CTO's roadmap and a DPO's audit file at the same time.
- HUMAN-CENTRIC (where a person is asked) or ORGANISATION-CENTRIC (where they're not). Beyond AdTech B2C consent (with a banner and one person at a time), B2B is where EU AI Act and GDPR accountability actually gets decided at scale: each organization sets its own rules for its own AI use, and those rules get logged and chain-proofed exactly like an individual's consent would be.
Our SDK will be on the market in Q4 2026 (SaaS or self-hosted). Our team remains happy to walk any CTO or DPO through it.
What AI compliance?
Every call a product makes to OpenAI, Deepseek, Anthropic or Mistral leaves a trace. Today, that trace isn't evidence: it's a log Tech staff wrote (and could easily rewrite). We built ID side to replace that self-made log with an evidence: a cryptographically signed proof, attached to every AI call, stating WHO makes the AI call, WHICH RULES are decided upon, and on what LEGAL BASIS applies.
Our solution is new (patent-protected) because it automatically generates a temper-evident exportable ledger of enforcement outcome, verifiable by a regulator years later without our support.
What does our SDK enable? Why does it provide "AI framing"?
All organizations, and their employees, want to save FTE-equivalent time with AI. Using Copilot "only" (and not the others) just because "it is safe" does not match today's AI market reality. The hiccup is that organizations must demonstrate compliance with their AI obligations.
We designed our SDK to address this compliance gap:
- It is SIMPLE: 3 lines of code, no migration, no new endpoints
client = consent.wrap(OpenAI())
- It is CHEAP: Compliance infrastructure shouldn't cost more than the AI call it rides on (agentic AI is about to make billions of these micro-decisions a day) -starting at €0 for non-profits and micro-enterprises, and the SDK core will be open-source. Consent has to get cheaper as AI gets faster, or it gets skipped.
- 1 OBJECT, 2 READERS: The 3 lines an engineer ships and the legal basis a DPO declares resolve to the same signed proof (no translation loss between the codebase and the compliance file). Our SDK sits on a CTO's roadmap and a DPO's audit file at the same time.
- HUMAN-CENTRIC (where a person is asked) or ORGANISATION-CENTRIC (where they're not). Beyond AdTech B2C consent (with a banner and one person at a time), B2B is where EU AI Act and GDPR accountability actually gets decided at scale: each organization sets its own rules for its own AI use, and those rules get logged and chain-proofed exactly like an individual's consent would be.
Our SDK will be on the market in Q4 2026 (SaaS or self-hosted). Our team remains happy to walk any CTO or DPO through it.
