Twenty tools
The real number is almost always larger than the list you keep. Capabilities a vendor added to software you already licensed count. So does the tool a department adopted without telling anyone.

Regulatory Intelligence for AI Deployments
Twenty tools, two use cases each, three jurisdictions. That is a hundred and twenty determinations — every one a real question of law, and none of them made faster by the hundred and nineteen before it. Expertise is not the constraint. Hours are.
The arithmetic
It is that the work scales with your tool inventory, and your team does not. Every new tool multiplies against every use case and every place a person sits.
The real number is almost always larger than the list you keep. Capabilities a vendor added to software you already licensed count. So does the tool a department adopted without telling anyone.
The same model screening candidates and answering billing questions is two different objects under the law. Regulatory weight follows the decision, not the software.
Obligations attach by where the person is, not where you are. One tool used across twelve states is twelve separate applicability questions.

The gap
You are not uninformed. You are outnumbered. Every hour spent establishing which rules apply is an hour not spent on the judgment only you can supply — whether what you found is acceptable, and what to do about it.
Five axes, one answer
This is the whole company in one object. Name the deployment along five axes and the applicable corpus resolves — including what was assessed and found not to apply.
A demonstration of the shape of a determination, not a determination. Four toggles is the teaching version; the real intake also asks what these axes turn on — human review and how consistent it is, solely-automated decisions, vulnerable populations, entity thresholds — and which controls you already have. A real LegisGate Compass™ Report is built from that, evaluated against the full corpus, and every finding is cited to primary statutory source, including the instruments assessed and found not to attach.
The credential chain
Most tools can tell you a law exists. The value is in the unbroken line from a sentence in your report back to a sentence in a statute.
Every provision in the LegisGate Meridian™ is opened at its official text and pinned to a resolvable URL. No nicknames, no plausible neighbours, no citation that only looks statute-shaped.
Your intake is evaluated against that corpus by the patent-pending Meridian™ Engine — deterministic code, not a model asked to guess which laws feel relevant.
Findings carry the citation they were determined from. Where the corpus cannot support a claim, the document says so rather than filling the space.
They open the cite, read the provision, and see that it says what we said it says. Sufficiency is their call. It was always going to be.
What we will not do. We do not certify compliance, and no document we produce satisfies a legal obligation on its own. We identify, map, document and prepare. Your counsel decides whether what we found is enough.
One determination, three deliveries
Compass answers what applies. Dynamic Assessments fill the regulatory half of the documents those laws require. Govern keeps the record true after the day you filed it.
Name the tool, the use, the jurisdictions, the industry and the data. Receive a cited report of what attaches — and what does not.
The report →
DPIA, FRIA, PRA and DPA scaffolds arriving pre-populated with the regulatory half, in the official format where an official format exists.
The documents →
Obligations with an owner, a date and evidence. When the corpus moves, the record tells you which of your documents just aged.
The workspace →Before the letter arrives
Not one of them is answered by knowing the law. All of them are answered by records that were made before anybody asked.
Which AI systems are actually in production?
Including capabilities a vendor added to software you already licensed, and tools a department adopted without central review. Most organizations find the real list is longer than the one they keep.
What decision does each one make or influence?
Regulatory weight concentrates on consequential decisions — credit, housing, employment, healthcare, education, insurance, access to essential services. A scheduling assistant and an underwriting model are not the same object under the law.
Whose residents does each system touch?
Obligations attach by where the person is, not where you are. One tool used across twelve states is twelve separate applicability questions.
Where is the assessment — or the documented decision that none was required?
Both answers are defensible. Neither is defensible undocumented. An empty file does not read as not required. It reads as not considered.
Who owns each obligation, by name — and when did the review begin?
An owner is a person, not a department. And the date is the one answer on this page that cannot be produced later: a record created after an inquiry arrives is evidence of reaction, not of process.
If assembling these answers would take more than a few days, that is itself the finding. An inquiry rarely allows more time than that.
Writing
Field notes for the person who will be asked whether a deployment is defensible. No product tours, no gated PDFs, no email required.
A confident answer, produced in seconds, with no citation anybody could open. We ran the same deployment through a determination and compared what each one could actually show.
Read →Most of the writing addresses providers. The deployer obligations are shorter, land sooner in practice, and are the ones your organisation is most likely to be holding.
Read →D&O policies were written before deployers carried statutory duties of their own. What the exclusions now say, and the question to put to your broker.
Read →
Start where the exposure is
Pick the deployment that would be hardest to explain in a letter. Run it first. Fifteen minutes of intake will tell you whether the rest of the inventory is a problem.