European-ready AI safety and control platform

Onboard, control, and observe your AI agents

Preloop helps organisations bring existing AI agents under policy, approval, gateway, and observability controls without rebuilding their stack.

  • Onboard existing agents with the Preloop CLI discovery flow
  • Route risky actions to human approval and governed tool access
  • Keep runtime activity, spend, and audit trails visible
Built for teams moving AI into production
Bring existing agent workflows under control without rewrites
Add human-in-the-loop approvals only where risk warrants it
Choose managed or self-hosted deployment paths

Core capabilities for modern AI operations

Use one control plane to onboard agents, route model traffic, govern tools, and keep every important action observable.

Onboard existing agents

Bring OpenClaw, OpenCode, Claude Code, Codex CLI, Gemini CLI, and MCP-compatible automations into one operating model.

Apply policies, justification, and approvals

Allow safe operations, block risky ones, and require human review when a tool call deserves oversight or explanation.

Control model traffic and spend

Route model traffic through the Preloop Gateway for allowed-model enforcement, attribution, and budget visibility.

Observe runtime sessions and audit trails

Track what each runtime attempted, which policy matched, who approved it, and what happened next across sessions and workflows.

Preloop Tools page showing deny, require approval and allow rules on a payment tool
Per-tool rules: deny above 2000, require approval from 100, allow below 100.

How Preloop keeps automation productive and controlled

Preloop sits between your agents, models, and sensitive actions so you can move fast without losing control.

1. Discover or connect your AI systems

Use manual MCP setup or the preloop agents discover flow to bring existing agents into one control plane.

2. Define guardrails

Set policies, approval paths, allowed models, and governance rules around tools, environments, and business actions.

3. Route critical activity safely

Let trusted work continue, send risky actions to humans, and keep model traffic on governed paths.

4. Monitor and improve

Use visibility into runtime activity, approvals, spend, and audit history to keep improving your AI operations.

A platform for every stage of growth

Whether you are just starting with AI or formalising governance across multiple teams, the same platform can adapt.

Startups

Launch AI-assisted workflows quickly, with policy guardrails that keep small teams safe while they scale.

SMEs

Standardise secure automation across departments and make AI adoption operational instead of experimental.

Enterprise

Coordinate governance, approvals, and monitoring across multiple stakeholders, environments, and business processes.

Security and oversight without slowing teams down

Preloop is designed for organisations that need safe automation, human accountability, budget awareness, and operational clarity.

Human-in-the-loop approvals for critical operations

Policy-based access control for tools and actions

Model gateway controls for approved models, attribution, and budgets

Runtime visibility for usage, sessions, and decision history

Audit-friendly traces of actions, policies, and outcomes

Deployment options that fit managed or self-hosted environments

Preloop Approval Requests page with pending, approved and declined counts and one pending payment approval
The approval queue: one pending request with an expiry, and the resolved history behind it.
EU regulation and national implementation

Four EU instruments, one evidence trail

The EU AI Act, the Cyber Resilience Act, DORA and NIS2 each leave part of the work to Member States: which authority supervises, what penalties apply, how incidents are notified. Each Preloop country domain keeps that national layer. The EU-level detail lives on preloop.ai.

EU AI Act, Regulation (EU) 2024/1689

Most obligations apply from 2 August 2026 (Art. 113). Each Member State designates at least one market surveillance authority and one notifying authority (Art. 70) and sets its own penalty rules within the limits of Art. 99. Preloop records tool calls, policy decisions, approvals and outcomes per runtime session. That is session evidence for the Art. 12 logging and Art. 14 human oversight discussion. Preloop does not classify your system.

Cyber Resilience Act, Regulation (EU) 2024/2847

Reporting of actively exploited vulnerabilities and severe incidents (Art. 14) applies from 11 September 2026; the remaining obligations from 11 December 2027 (Art. 71). Notifications go to the national CSIRT designated as coordinator and to ENISA (Art. 14, Art. 16). Market surveillance is national (Art. 52). Preloop verifies an SBOM you already produced and writes a versioned result.json. It does not file reports.

DORA, Regulation (EU) 2022/2554

Applies since 17 January 2025 (Art. 64). Supervision sits with the existing national financial supervisors (Art. 46). Preloop keeps allow, deny and require-approval decisions on tool calls, with approver and timestamp, as operational evidence inside a DORA programme you already run.

NIS2, Directive (EU) 2022/2555

A directive, so it applies through national transposition laws; the deadline was 17 October 2024 (Art. 41). Risk-management measures, including supply-chain security, are in Art. 21(2). Preloop can require approval when agents pull packages, call MCP servers or deploy from CI, and keep the trail.

EU-level pages on preloop.ai

Country layer

Evidence, not compliance, and not legal advice. Preloop is not a law firm. Every reference above names the instrument and the article or date so you can check it on EUR-Lex yourself.

Preloop Audit Timeline listing model requests and runtime sessions with outcome and time
The audit timeline: every model request and runtime session, filterable by tool, event type, outcome and date.
August 2026

EU AI Act readiness without overclaiming compliance

Most AI Act obligations apply from 2 August 2026 (Regulation (EU) 2024/1689, Art. 113). Preloop is part of readiness work, not a compliance guarantee: human approval before consequential actions, policy enforcement on tools, runtime visibility, and audit evidence per session.

What you can show an assessor: which actions agents may take on their own, which need a named approver, which models and tools ran in production, and who approved what, when.

  • Human oversight machinery for Art. 14 discussions, not a determination that Art. 14 is met
  • Session logs of tool calls, decisions, approvals and outcomes as material for Art. 12 discussions
  • Legal detail and article mapping on the preloop.ai readiness page