# Withdrawn consent, refused at the next AI request.

> Runtime consent enforcement in ColossalX checks consent when an AI request is made, not only when a form was signed. When a person withdraws consent for AI inference, the gateway refuses the next AI request made as that person and logs the refusal. Consent is recorded separately for 11 AI purposes, each with its legal basis.

Consent is checked when the AI request is made, not only when the form was signed, and each refusal is logged.

Canonical page: https://colossalx.tech/platform/runtime-consent · Last reviewed: 6 Oct 2026

*Illustration:* Checked at the request: signed-in user to ColossalX (next request); ColossalX refused before provider A (consent withdrawn); ColossalX to enforcement log (logged).

## Definition: Runtime consent

Runtime consent is consent checked at the moment an AI system uses the data of a person, not only when a form was signed. If the person withdraws it, the next AI request carrying their data is refused and the refusal is logged, so the consent record and the behaviour of the system stay the same thing. [AI security glossary](https://colossalx.tech/resources/glossary#runtime-consent)

## The threat and the control

- **The threat:** A person withdraws consent for AI use of their data, and their next request still reaches a model.
- **The control:** ColossalX reads the latest consent when the request is made, refuses it, and logs the refusal.

## How it works: From a withdrawn consent to a refused request.

One person withdraws consent for AI inference. Followed to their next request, refused at the gateway before any model sees it, and to the log that proves it.

### Workflow: consent withdrawn, next request refused (illustrative)

1. **Consent recorded.** Consent is recorded per person, per AI purpose, with its legal basis.
   Person: claims analyst; Purpose: inference context; Basis: consent; Status: active
2. **Withdrawn.** The person withdraws consent for AI inference.
   Claims analyst: Withdraws consent for AI inference | Active -> Withdrawn
3. **Next request refused.** Their next AI request is refused at the gateway, before any model.
   assistant chat · as claims analyst · Sending -> assistant chat · as claims analyst · Refused | Reason: consent withdrawn
4. **Logged.** The refusal is logged with the user, the model and the time.
   User: claims analyst; Model: provider A; Time: 14:06 | Enforcement log | x, held

## What you see: Consent recorded per person and per AI purpose.

Each consent record names the person, the AI purpose, the legal basis and the status, and a withdrawn purpose stays on the record rather than disappearing.

1. **Purposes, not one flag.** 11 AI purposes, from training to automated decisions, recorded per person. Training, fine-tuning, retrieval indexing, inference context, embeddings, cross-border transfer, output disclosure, profiling, agent delegation, prompt retention and automated decisions are each recorded on their own.
2. **Checked at the request.** The gateway reads the latest consent record when the request is made. The inference-context purpose is enforced at the gateway. The other purposes are records for your own processes, and the screen marks which one the gateway checks.
3. **Refused and logged.** A withdrawn person's next AI request is refused, and the refusal logged. The enforcement log lists refused requests with the user, the model and the time. A quick action revokes AI processing for a person in one step.
4. **Jurisdictions as reference.** 14 privacy and AI regulations are kept as reference profiles. Profiles such as GDPR, India DPDP and the EU AI Act describe each consent model. Coverage is drawn from your records; it is reference for your counsel, not a legal assessment.

*Screen, from a demo workspace:* Consent records in a demo workspace: one person's consent recorded per AI purpose with its legal basis, training and fine-tuning withdrawn and still on the record, inference context active. Callouts: 1. One record per purpose 2. Withdrawn, still on record 3. Inference purpose active

## How we know

- Each of the 11 AI purposes is recorded on its own; the one the gateway enforces is marked.
- Refused requests are listed with the user, the model and the time.
- A consent record keeps its legal basis and the text the person agreed to.
- A failed consent check is recorded as degraded, never hidden.

## Where a withdrawal goes next.

A withdrawal is not a note in a form. It changes what the gateway does, and it shows up in the records your governance teams read.

- **AI gateway.** Consent is one of the checks a request meets before it is routed.
- **Data lineage.** Lineage shows which agents send which personal data to which models.
- **ColossalX Trust Engine.** A withdrawal moves the AI governance pillar of the trust score.
- **Compliance.** Consent sits beside privacy assessments, records of processing and retention.

Where an x ends up: x, held.

## Specs: delivery and data

- **Delivery:** SaaS, from one login.
- **Isolation:** Each customer runs in an isolated workspace with its own database.
- **Certifications:** None held. Frameworks are mapped to and assessed against.

## Frameworks

- Mapped to India DPDP: Withdrawal honoured at the next request.
- Mapped to GDPR: Purpose-specific consent, with its legal basis.

## What it does not do

- The gateway enforces the inference-context purpose, for your workspace's signed-in users.
- No consent record means allowed: the gateway acts on a withdrawal.
- If the consent check itself fails, the request is allowed and recorded as degraded.
- A withdrawal takes effect within about a minute, not at the same moment.

*Illustration:* What is checked: Inference context Checked per request; Training Recorded; Profiling Recorded; Agent delegation Recorded; Automated decision Recorded. Each purpose on record.

## Questions

### What is runtime consent enforcement?

Runtime consent enforcement checks a person's consent at the moment an AI request is made, rather than trusting a form signed months ago. If the consent has been withdrawn, the request is refused before it reaches a model. ColossalX does this at its gateway and keeps a log of the requests it refused.

### How does India's DPDP consent apply to AI systems?

The DPDP Act, 2023 lets a person withdraw consent as easily as they gave it, after which their personal data must stop being processed within a reasonable time. For AI, a withdrawal has to reach the systems that send personal data to models. Core obligations start on 13 May 2027. ColossalX is mapped to DPDP; it is not legal advice.

### What happens when a person withdraws consent?

The gateway reads the latest consent record when a request is made, so within about a minute the next AI request made as that person is refused and logged. Enforcement covers the inference-context purpose for your workspace's signed-in users; the other AI purposes are kept as records for your own processes.

### What evidence of refusals is kept?

Each refused request is listed in the enforcement log with the user, the model and the time, and consent records keep the purpose, the legal basis and the text agreed to. If the consent check itself cannot run, the request is allowed and recorded as degraded, so a gap is visible rather than silent.

### How does this relate to GDPR purpose limitation?

GDPR asks that personal data be used only for the purposes it was collected for, and that consent can be withdrawn as easily as it was given. Recording consent per AI purpose, such as training, profiling or inference, and checking it at the request, is one practical way to show that purposes are kept apart.

## Related

- [Data lineage](https://colossalx.tech/platform/data-lineage)
- [AI gateway](https://colossalx.tech/platform/ai-gateway)
- [Runtime guardrails](https://colossalx.tech/platform/runtime-guardrails)

---

ColossalX is an AI security and governance platform from Quantexra Labs LLP, delivered as SaaS. Book a walkthrough: https://colossalx.tech/demo · client.success@quantexra.tech
