Official privacy enforcement envelope addressed to the Chief Privacy Officer at Your Organization, with privacy law volumes and a fountain pen on a dark desk

AI teams: know which rules apply before the letter comes.

For counsel and compliance teams shipping AI tools.

Compliance starts with knowing which AI laws and obligations apply to you. That’s the part we do — and the part most organizations couldn’t do at scale.

You get a report your lawyers can use.

  1. 01 Name the AI tool
  2. 02 Answer ten questions
  3. 03 See the assessments that attach

Free AI Regulatory Requirements Check · No account to see the result · Verified to the Meridian · Citations live in Compass™

For your own AI tools

Identifies which regulations attach to a specific deployment, and which assessments it requires.

Run the free check

The Facts

Three things that are true of every company using AI.

This is not our framing. It is what regulators have already ordered organizations to produce.

  1. You need to know the regulatory obligations that apply to every AI Tool your company uses — including AI a vendor added to software you already license.

  2. You need to complete every assessment triggered in the jurisdictions where that AI Tool is used.

  3. You need to keep current on the changing regulations that apply to your AI Tool Inventory.

Massachusetts · Earnest Operations

AI loan underwriting

$2.5M2025

A written AI governance system. Documented fair-lending testing. Risk assessments. A named oversight team.

Hungary · Budapest Bank

Emotion analysis on calls

HUF 250M2022

A completed impact assessment, a documented legal basis, and demonstrable safeguards — or stop the processing.

Italy · Foodinho

Algorithmic rider scoring

€2.6M2021

Human intervention in algorithmic decisions, and periodic checks on the algorithm's accuracy.

Germany · Berlin bank

Automated credit decision

€300K2023

The specific data, factors and criteria behind a single automated decision. On request.

None of it can be assembled quickly. None of it can be backdated.

Sources

Massachusetts OAG, In re Earnest Operations LLC, Assurance of Discontinuance (Jul. 10, 2025). Hungarian NAIH Decision NAIH-85-3/2022 (Budapest Bank). Italian Garante order no. 234/2021 (Foodinho). Berlin Commissioner for Data Protection (BlnBDI), administrative fine, May 31, 2023 — GDPR Arts. 5(1)(a), 15(1)(h), 22(3). Publicly reported enforcement actions; described for information only and not a prediction of any outcome for any organization.

In their own words

What state enforcers said about the first letter.

An initial letter is not litigation. They can ask for information — and compel it.

They treat inquiry as a chance to start a dialogue and resolve the issue short of a cease-and-desist.

These issues do not stop at state borders. Regulators keep institutional memory of how businesses respond.

— State enforcement officials, speaking on a panel at an IAPP conference, October 2025

Governance vs. Compliance

Governance is voluntary. This isn’t.

Governance

Something you choose to adopt. No one arrives to check it.

Regulatory obligation

Has a counterparty — someone with authority who can compel information and impose consequences.

Most vendors help you build a governance framework. We identify what the law requires.

Where to start

The order a compliance officer actually works in.

  1. What applies to us?

    Compass™
  2. What are we obligated to do?

    Compass™
  3. What documents does the law require us to produce?

    Dynamic Assessments™
  4. How do we keep them current?

    Govern™

The regulatory record for every AI Tool you deploy.

From AI deployment to the foundation for your good-faith effort.

LegisGate turns each AI Tool deployment into a cited obligation report, the assessment documents the law requires, and a living record that stays current as regulations change. Triage isn’t a strategy — it’s what happens when the research takes too long. This is built so your whole inventory gets an answer, not just the tools you had time for.

LegisGate
Compass

IdentifyQ1 · Q2

Identify the obligations.

Online intake & processing ~15 minutes.

  • One cited obligation report per AI Tool deployment and use case
  • Which laws and frameworks attach — and which do not
  • Jurisdiction, division, and role for every obligation
  • Assessment determinations from the deployment’s facts
  • Statute-cited findings linked to Meridian™ sources
  • Action items ready for DPO, counsel, and security
  • The first timestamp in your deployment record

$349 per AI Tool deployment

First report complimentary

15-day money-back guarantee

View sample obligation report →

LegisGate
Dynamic Assessments

DocumentQ3

Document the required analysis.

Online intake & processing ~15 minutes. No waiting on anyone.

  • DPIA, FRIA, PRA, and DPA documents from the obligation record
  • Automatically fills the regulatory half of the assessment. Your counsel completes the organizational sections and determines sufficiency.
  • Statutes, triggered obligations, required structure, and vendor intelligence — pre-populated
  • Clear scope: what each document is prepared to support

From $899 – $1,999

Per assessment / document

15-day money-back guarantee

Outside privacy counsel bills $300–$600/hour. We fill the half that requires knowing the law, not knowing your organization.

View sample assessment →

LegisGate
Govern

MaintainQ4

Maintain the record.

Ongoing monitoring.

  • Owners, evidence, and deadlines on every obligation
  • Assessment status across your AI Tool inventory
  • Meridian™ signals when cited law or guidance moves
  • History of what changed, who owned it, and when
  • One continuous record — not a one-time PDF
  • Volume pricing as inventory complexity grows
  • The living file you open when the regulator asks

$79 per AI Tool / month
$39 per assessment / month

Volume pricing available

15-day money-back guarantee

Price your AI Tool Inventory →

The foundation for your good-faith effort. Ready before the regulator asks.

  • Cited sourcesEvery obligation linked to source.
  • Research completedRegulatory research done.
  • Judgment remains yoursYour counsel completes and decides.
  • Always currentRegulatory changes monitored.

The Problem

The obligations don’t attach to the AI Tool.

Microsoft 365 Copilot, deployed three ways.

DeploymentClassificationRiskAssessment
General productivityDrafting, email, notes — no decisions about peopleLimited-risk · Art. 5012CG-2026-00012
HR performance evaluationRatings feeding promotion decisionsHigh-risk · Annex III, employment85CG-2026-00013
Creditworthiness supportInput to lending decisionsHigh-risk · Annex III 5(b)89CG-2026-00014

Same AI Tool. Same vendor. Three different answers.

In plain terms: “Art. 50” means light-touch disclosure duties — tell people they’re talking to AI. “Annex III” means the EU AI Act’s high-risk tier — mandatory testing, human oversight, and a completed assessment before you can ship that use case, even on the same Copilot license.

The gap between those two numbers is the exposure.

Now do the math on your inventory. Twenty AI Tools, each used two different ways, across three jurisdictions where your people work, is not twenty things to check. It’s a hundred and twenty separate answers — and every one is a deployment the law treats as its own decision.

Every deployment your tool list hides is an obligation nobody has assessed — and it cannot be assessed retroactively once an inquiry arrives. Start with the one deployment you’re least sure about — run it through the free Pre-Check and see which answer it gets.

If you asked which AI Tools you use, you asked the wrong question.

Same tool, three risks — the full demonstration

Powered by

LegisGate Meridian

The verified regulatory intelligence layer under every obligation report, assessment document, and maintained record — mapped across jurisdictions and kept current as the law moves.

Obligations mapped
Jurisdictions
Binding laws & regulations
Supervisory guidance

As of · Snapshot · Counts update as the Meridian is curated · how we count

Regulatory Check API

Check obligations before you ship.

Embed the same Meridian™ determination spine that powers Compass™ and Govern™ into your own product — GRC platforms, privacy tools, procurement portals, and enterprise AI catalogs. Pass a tool, use case, and footprint. Receive structured, cited obligations as JSON.

API response showing cited regulatory obligations returned as structured JSON — obligation_id, regulation_reference, and meridian_ref_key for each finding
API connection · embed Meridian™

What attaches

Deployment-specific obligations with article-level citations — not soft product nicknames.

Secure by design

Scoped keys, TLS, audit-logged calls, versioned schemas under license.

Stays current

Official feeds keep Meridian™ current. Your integration inherits the upkeep.

Sales-led license

We scope datasets, jurisdictions, and volume with you. Test credentials before you go live.

Free Pre-Check · No account for the result

See which assessments attach to this AI deployment.

Every team deploying AI should run this before they argue about DPIAs, FRIAs, or state assessments in the abstract.

ProductAI Regulatory Requirements Check

How it works

Ten questions. Named assessments. Then Compass™ for the cites.

You get likely required and may-apply assessments for one deployment — without statutory citations on the free result. Compass™ is where Meridian™ provisions are cited for counsel.

  1. 01Name the AI tool

    Vendor, use case, and who the decisions affect.

  2. 02Answer ten questions

    Geography, org type, data, and human review — e.g. “HR ratings feed promotion decisions.”

  3. 03See what attaches

    Assessments, EU AI Act tier where EU reaches you, magnitude.

  • Likely required

    Assessments indicated from your answers.

  • May apply

    Named facts still open — not a silent guess.

  • EU AI Act posture

    Risk tier when Europe is in the footprint.

Indicative only — not a legal determination. Continue to a Compass™ report when you need the cited obligation map. Sufficiency stays with your counsel.

The prepared record

The inquiry should not be the day the work begins.

The record is built before the letter, or it is built under it.

Built by compliance and audit officers who spent decades on the other side of that table.

obligations · jurisdictions · binding laws · verified to the Meridian · as of

EDPB-format DPIA converter. Shipped July 27, 2026. Start with the free Pre-Check. Continue to Compass™ when you need the cited obligations.

Twenty or more AI Tools? Price your AI Tool Inventory
Cover of a real LegisGate Compass™ report, named to a deployment with a report ID — the prepared record
The prepared record

Beyond your own deployments

A practice or a product — not only your own tools.

If you advise a book of clients, or you sell an AI product to deployers who carry obligations, the same intelligence layer runs across that work. We bring the regulatory intelligence and the intake. You bring the privacy and legal judgment.

For practices

Run obligation analysis across every client’s AI deployment from one book.

For providers

Hand each deployer the regulatory package that ships with your product.

Commercial terms for channel deployment are provided on request. Sufficiency stays with counsel.

Talk to usWe're here to help
LegisGate - Identify the Regulations for your AI Deployments