EU AI Act · GDPR

EU AI Act-Ready. Audit-Ready.

Compliance built into every agent run. Not added later.

  • €5 welcome credit
  • EU AI Act & GDPR by design
  • No credit card

Audit coverage

100% of high-risk actions logged

Compliance is not a report you assemble after the fact. Every high-risk agent action is classified, checked against five live controls, and written to an immutable audit trail as it runs.

Audit coverage

100%High-risk actions logged
  • PII detection & anonymization - Active
  • Forbidden use blocking (Art. 5) - Active
  • Immutable audit logging - Active
  • AI transparency labels - Active
  • Agent risk classification - Active

Controls

Six controls, built into every agent run

PII detection & anonymization

Automatically surface Dutch BSNs, IBANs, person names, and work emails before they reach a model. Operators can anonymize in one step so downstream prompts stay useful without leaking identifiers.

Forbidden use blocking

Guardrails aligned with Article 5: social scoring, subliminal manipulation, and exploitative biometric surveillance patterns are blocked at submission time with a clear, logged reason code for reviewers.

Immutable audit logging

Every AI interaction - inputs, model choice, tool calls, approvals, and outputs - is retained in an append-only log. Filter by agent, user, severity, and time window; export CSV or JSON for regulators.

AI transparency labels

End users see explicit “You are communicating with an AI system” messaging wherever agents generate content, matching EU transparency expectations for human-facing automation.

Agent risk classification

Tag agents as minimal, limited, or high-risk under your internal AI Act mapping. Attach assessment notes, owners, and review dates so procurement and legal can trace decisions.

GDPR-compliant data handling

Customer data stays in EU regions by default, encrypted in transit and at rest. Retention windows, access logging, and processor agreements align with GDPR accountability requirements.

See it in the product

Dashboard, audit log, and PII preview

Controls

Your compliance posture, at a glance

One view for the AI Act module, chat PII redaction and every governance rule — so operators and legal see exactly what is enforced before an agent ships.

Audit log

Every interaction, append-only

Inputs, model choice, tool calls, approvals, and outputs are retained in an append-only log. Filter by agent, user, severity, and time window; export CSV or JSON for regulators.

PII preview

See sensitive fields before they leave

Dutch BSNs, IBANs, person names, and work emails are surfaced and highlighted before they reach a model — anonymize in one step without breaking downstream prompts.

app.agent-works.ai
SS-14

PII detection preview - highlighted sensitive fields

1200 × 800px

Need the full regulatory walkthrough, definitions, and checklists?

Read EU AI Act Guide

Ship AI agents that pass audit

EU AI Act risk classification, Article 12 audit logs, and an optional PII-detection layer — built into every run.

FAQ

Frequently asked questions

Is AgentWorks GDPR compliant?
Yes. AgentWorks is GDPR-compliant by design: access and portability (a data export) and account erasure — immediate, not scheduled — are self-service from Settings, no ticket required, with anything else handled per-request, plus infrastructure fully hosted in the EU and a Data Processing Agreement available on request.
Does AgentWorks mask PII before sending data to LLMs?
An optional PII-detection layer can mask email addresses, phone numbers, names, IDs, and configurable custom patterns before content reaches a model, then unmask them in the response. It is per-tenant opt-in and reduces exposure — free-text personal-data detection can never be 100% complete, so we do not market it as a guarantee. The guarantee we rely on is architectural: EU hosting plus model providers engaged on a no-training, zero-retention basis.
Where is my data stored?
AgentWorks is fully hosted in the EU on our own infrastructure, in Germany — no third-party cloud region to configure, it is the default and only option.
Does AgentWorks support human-in-the-loop oversight?
Yes. Per-agent and per-pipeline approval flows let a human reviewer accept, reject, or edit AI output before it executes a side-effect (sending email, modifying a record, posting to Slack). High-risk steps can be required to wait on approval per the EU AI Act.
Can I export an audit log of every agent interaction?
Yes. Every chat turn, agent run, and pipeline step is recorded with timestamp, user, model, input, output, applied tools, and approval state. The log is exportable as JSON or CSV for legal review and retained per your data-residency configuration.

See how other platform capabilities work together.

Last updated: July 2026