Loading…
Loading…
AI Policy Desk
Ready-to-use templates, risk checklists, and implementation guides built for small teams with no dedicated compliance function.
Built for startups and lean teams who need AI policy, risk assessments, vendor due diligence, and lightweight governance—without a compliance department.
Free tools
Interactive tools — get a clear answer in minutes, no consultant required.
4 questions · 2 min
Compliance Quiz
Which AI regulations apply to your team?
Take the quiz →
4 steps · 5 min
Policy Generator
Generate an AI acceptable use policy for your team.
Generate policy →
15 vendors · filterable
Vendor Scorecard
Compare AI vendors on privacy and compliance.
Compare vendors →
3 steps · 5 min
AI Risk Assessment
Rate your AI use cases Low / Medium / High / Critical.
Assess risk →
Explore
Regulations
28 coveredEU AI Act, GDPR, NIST AI RMF, Colorado AI Act, NY Local Law 144, and more — each explained for small teams.
Browse regulations →
Glossary
75 termsPlain-English definitions for AI governance terms: high-risk AI, GPAI models, conformity assessment, shadow AI, and more.
Browse glossary →
Start here
Pillar guides and templates—jump in, then subscribe for the monthly checklist.
Latest
Templates, checklists, tool comparisons, and implementation guides for small teams adopting AI safely.
·6 min read·Guides
Year-by-year breakdown of Amazon KDP AI content policies: what the 2024 disclosure rules said, what changed in 2025, and where the policy stands in 2026. Includes the current disclosure requirements and what KDP still does not address.
Latest posts
·8 min read·Guides
California AB 2013 took effect January 1, 2026. GenAI developers must publish a training data disclosure page before offering their system to Californians. Checklist, required fields, enforcement via UCL, and what small teams must do now.
·9 min read·Guides
Copy-paste TypeScript patterns for AI agent logging and audit trails: structured span logging with OpenTelemetry, PII-safe trace storage, compliance-ready audit records, token usage tracking, and decision trail for human review. Working code.
·5 min read·Guides
The TAKE IT DOWN Act (signed May 2025) targets AI-generated NCII and deepfakes. One year after signing, many platforms still lack the 48-hour removal process the law requires. Compliance checklist and what FTC enforcement looks like now.
·8 min read·Guides
TAKE IT DOWN Act compliance checklist for platforms and AI tool operators. Signed May 19, 2025: 48-hour removal window for non-consensual intimate images including AI-generated deepfakes. Who must comply, what to build, and penalties.
·5 min read·Guides
Colorado SB 189 replaces the 2024 Colorado AI Act. Risk assessments dropped, disclosure requirements kept, effective date pushed to January 2027. What the new law requires and what changed.
·6 min read·Guides
EU AI Act GPAI enforcement powers activate August 2, 2026. The obligations already applied from August 2025. What changes in August 2026, who is affected, and what to have ready before the deadline.