AI Governance Discovery

AI governance, decided in minutes

The operating system for trustworthy AI.

Describe one AI use case through a guided discovery. Get its binding obligations across 10 jurisdictions, mapped to 23 controls, as an auditable dossier your legal, risk and product teams can actually file.

No account · no data leaves the browser · results in under five minutes

10

Jurisdictions covered

23

Governance controls

8

Control domains

9

With binding law today

Platform

A compliance instrument, not a questionnaire.

Form builders collect answers. This resolves them — against a maintained regulatory dataset, with the reasoning attached to every cell.

Deterministic rules engine

No model guesswork. Every obligation is derived by explicit, versioned rules over a maintained regulatory dataset — the same input always produces the same dossier.

Coherence layer

Contradictions, unsupported assumptions and missing facts in your intake are surfaced inline before they become an audit finding.

Solve once, satisfy many

Obligations are consolidated into a unified control checklist so one implementation closes the same requirement across every jurisdiction in scope.

Filing-grade output

A stamped dossier with verdict, per-jurisdiction rationale, obligation matrix, roadmap and assumptions ledger. Print to PDF, export Markdown or JSON.

Runs entirely client-side

Use-case descriptions never leave the browser. Nothing is stored on a server, which makes pilot approval a conversation instead of a procurement cycle.

Cited and dated

Each cell carries the instrument behind it and each milestone the date it bites, so counsel can verify the reasoning rather than trust it.

How it works

Three steps, one dossier.

01

Describe the use case

Seven guided steps: purpose, geography, role in the value chain, system type, decision impact, data and a prohibited-practice screen.

02

See obligations form live

A running preview shows obligations appear and disappear as answers change, with a change feed explaining what each answer triggered.

03

File the dossier

Get a verdict, a jurisdiction-by-jurisdiction classification, a 23 × 10 obligation matrix and a NOW / NEXT / LATER roadmap with statutory dates.

Coverage

Every jurisdiction that matters, with the instruments behind it.

EU

binding

EU AI Act (2024/1689, as amended by Digital Omnibus 2026) · GDPR Art 22

US states

patchwork

Colorado SB 24-205 · Texas TRAIGA · NYC Local Law 144 · California SB 53 / SB 942 / AB 2013 · Illinois HB 3773 · Federal soft law (OMB, NIST AI RMF)

UK

soft law

Pro-innovation framework (regulator guidance) · UK GDPR Art 22

China

binding

GenAI Interim Measures · Algorithm Recommendation Provisions · Deep Synthesis Provisions · AI Content Labeling Measures

S. Korea

binding

AI Framework Act (live Jan 2026) · Enforcement Decree

Japan

soft law

AI Promotion Act 2025 · METI / MIC AI Guidelines

Canada

soft law

Voluntary GenAI Code of Conduct · Directive on Automated Decision-Making · Quebec Law 25

Brazil

draft

PL 2338/2023 (pending) · LGPD Art 20 (binding)

India

advisory

MeitY advisories · IT Rules synthetic-media amendment · DPDP Act (adjacent)

Singapore

voluntary

Model AI Governance Framework (+ GenAI) · AI Verify

Built for the whole governance function

One shared frame across legal, risk and product.

Legal & regulatory counsel

Triage inbound AI use cases without re-reading six statutes each time. Every conclusion is traceable to the instrument that produced it.

Risk, audit & compliance

Consistent classification across business units, an assumptions ledger for every judgement call, and evidence you can hand to an auditor.

Product & engineering

Know at design time whether a feature is prohibited, high-risk or transparency-only — before the build, not after the launch review.

Procurement & vendor management

Assess third-party AI in the same frame as your own, including deployer duties that do not transfer with the contract.

Enterprise

Deployable inside the perimeter, defensible in front of a regulator.

Zero data egress

The engine runs client-side; no use-case content is transmitted or retained.

Identity ready

SSO/SAML, SCIM provisioning and role separation for reviewers and approvers.

Reproducible

Versioned dataset and deterministic rules mean any dossier can be re-derived exactly.

Pricing

Start free. Scale when governance does.

Evaluation

For individual assessors

Free
  • Unlimited discoveries
  • Full 10-jurisdiction matrix
  • Markdown, JSON and PDF export
  • Client-side only — no account
Start a discovery

Team

For governance functions

Contact us
  • Shared use-case register
  • Reviewer sign-off and versioning
  • Company control library mapping
  • Quarterly regulatory dataset updates
Talk to sales

Enterprise

For regulated groups

Contact us
  • SSO/SAML and SCIM provisioning
  • Private or on-premise deployment
  • Custom jurisdictions and controls
  • Named counsel liaison and SLA
Talk to sales

FAQ

Questions procurement always asks.

Is this legal advice?

No. It is a structured discovery instrument that maps a described use case to published regulatory obligations. It is designed to make counsel faster, not to replace them.

Where is our data processed?

In your browser. The rules engine and the obligation dataset ship with the application, so use-case descriptions are never transmitted or stored.

How is the dataset kept current?

The obligation dataset is versioned and dated. Every dossier records the dataset version it was produced under so past assessments remain reproducible.

Can we add our own controls or jurisdictions?

Yes, on Enterprise. The control set and jurisdiction list are data, not code, and can be extended to your internal framework.

Your next AI use case is already in scope somewhere.

Find out where in five minutes.