Onboard existing agents
Bring OpenClaw, OpenCode, Claude Code, Codex CLI, Gemini CLI, and MCP-compatible automations into one operating model.
Preloop helps organisations bring existing AI agents under policy, approval, gateway, and observability controls without rebuilding their stack.
Use one control plane to onboard agents, route model traffic, govern tools, and keep every important action observable.
Bring OpenClaw, OpenCode, Claude Code, Codex CLI, Gemini CLI, and MCP-compatible automations into one operating model.
Allow safe operations, block risky ones, and require human review when a tool call deserves oversight or explanation.
Route model traffic through the Preloop Gateway for allowed-model enforcement, attribution, and budget visibility.
Track what each runtime attempted, which policy matched, who approved it, and what happened next across sessions and workflows.
Preloop sits between your agents, models, and sensitive actions so you can move fast without losing control.
Use manual MCP setup or the preloop agents discover flow to bring existing agents into one control plane.
Set policies, approval paths, allowed models, and governance rules around tools, environments, and business actions.
Let trusted work continue, send risky actions to humans, and keep model traffic on governed paths.
Use visibility into runtime activity, approvals, spend, and audit history to keep improving your AI operations.
Whether you are just starting with AI or formalising governance across multiple teams, the same platform can adapt.
Launch AI-assisted workflows quickly, with policy guardrails that keep small teams safe while they scale.
Standardise secure automation across departments and make AI adoption operational instead of experimental.
Coordinate governance, approvals, and monitoring across multiple stakeholders, environments, and business processes.
Preloop is designed for organisations that need safe automation, human accountability, budget awareness, and operational clarity.
The EU AI Act, the Cyber Resilience Act, DORA and NIS2 each leave part of the work to Member States: which authority supervises, what penalties apply, how incidents are notified. Each Preloop country domain keeps that national layer. The EU-level detail lives on preloop.ai.
Most obligations apply from 2 August 2026 (Art. 113). Each Member State designates at least one market surveillance authority and one notifying authority (Art. 70) and sets its own penalty rules within the limits of Art. 99. Preloop records tool calls, policy decisions, approvals and outcomes per runtime session. That is session evidence for the Art. 12 logging and Art. 14 human oversight discussion. Preloop does not classify your system.
Reporting of actively exploited vulnerabilities and severe incidents (Art. 14) applies from 11 September 2026; the remaining obligations from 11 December 2027 (Art. 71). Notifications go to the national CSIRT designated as coordinator and to ENISA (Art. 14, Art. 16). Market surveillance is national (Art. 52). Preloop verifies an SBOM you already produced and writes a versioned result.json. It does not file reports.
Applies since 17 January 2025 (Art. 64). Supervision sits with the existing national financial supervisors (Art. 46). Preloop keeps allow, deny and require-approval decisions on tool calls, with approver and timestamp, as operational evidence inside a DORA programme you already run.
A directive, so it applies through national transposition laws; the deadline was 17 October 2024 (Art. 41). Risk-management measures, including supply-chain security, are in Art. 21(2). Preloop can require approval when agents pull packages, call MCP servers or deploy from CI, and keep the trail.
EU-level pages on preloop.ai
Country layer
Evidence, not compliance, and not legal advice. Preloop is not a law firm. Every reference above names the instrument and the article or date so you can check it on EUR-Lex yourself.
Most AI Act obligations apply from 2 August 2026 (Regulation (EU) 2024/1689, Art. 113). Preloop is part of readiness work, not a compliance guarantee: human approval before consequential actions, policy enforcement on tools, runtime visibility, and audit evidence per session.
What you can show an assessor: which actions agents may take on their own, which need a named approver, which models and tools ran in production, and who approved what, when.