The HandbookVersion 1.0 · August 2026

The AI Regulatory Obligations Handbook


A practitioner’s manual for building an AI regulatory obligations program. Seven chapters, three handouts, and six worksheets, written for the compliance officer, privacy counsel, data protection officer, or internal auditor who has been handed this work and has no framework for it yet. It is free to read, free to share, and it sells nothing.

  1. What applies to us?
  2. What are we obligated to do?
  3. What documents does the law require us to produce?
  4. How do we keep them current?
How the chapters answer the four questions
1What applies to us?Chapters 3 & 42What are we obligated to do?Chapter 53What documents does the lawrequire?Chapter 64How do we keep them current?Chapter 7

The loop is the point. The program does not finish — it runs.

Why this exists

We have built and run compliance programs inside large regulated companies — HIPAA, SOX, SOC 2, ISO, FMLA. The work in this manual is the work we did, written down in the order it actually happens. It is the manual we would have wanted on the first day someone handed us an AI deployment and asked whether it was allowed.

Chapters

Handouts

Single-page references for the three assessments practitioners are most often asked about. Each one covers what triggers it, what it has to cover, and when it is due.

Worksheets

Meant to be printed and used. Each one prints black-on-white with room to write, one worksheet per deployment.

Download the complete handbook — PDF or markdown.

Free to read, share, and adapt inside your organization. Attribution appreciated, not required. No warranty — verify time-sensitive claims against current sources.

LegisGate is the regulatory intelligence for AI deployments company. What we do.

Version 1.0 · August 2026

Talk to usWe're here to help
The AI Regulatory Obligations Handbook | LegisGate