Loading…
Loading…
AI Policy Desk
Ready-to-use templates, risk checklists, and implementation guides built for small teams navigating EU AI Act, GDPR, and US state AI laws — with no dedicated compliance function.
Used by 1,200+ teams. Updated for EU AI Act, GDPR, and 12 US state laws. No account, no paywall.
What applies to my team?
Most downloaded
Start with these templates
Free tools
Interactive tools — get a clear answer in minutes, no consultant required.
4 questions · 2 min
Compliance Quiz
Which AI regulations apply to your team?
Take the quiz →
4 steps · 5 min
Policy Generator
Generate an AI acceptable use policy for your team.
Generate policy →
15 vendors · filterable
Vendor Scorecard
Compare AI vendors on privacy and compliance.
Compare vendors →
3 steps · 5 min
AI Risk Assessment
Rate your AI use cases Low / Medium / High / Critical.
Assess risk →
Explore
Regulations
28 coveredEU AI Act, GDPR, NIST AI RMF, Colorado AI Act, NY Local Law 144, and more — each explained for small teams.
Browse regulations →
Glossary
75 termsPlain-English definitions for AI governance terms: high-risk AI, GPAI models, conformity assessment, shadow AI, and more.
Browse glossary →
Start here
Pillar guides and templates — pick the one most relevant to your situation.
Latest
Templates, checklists, tool comparisons, and implementation guides for small teams adopting AI safely.
How much does AI compliance actually cost? DIY documentation starts at $0. Bias audits run $5,000 to $50,000 per tool. ISO 42001 certification costs $15,000 to $40,000 in year one. Most 1-50 person teams can cover solid compliance for under $5,000 per year if no bias audits are required. Full cost breakdown by team size.
Latest posts
NYC LL144, Illinois AIVEA, FCRA, EEOC guidance, and Colorado SB 26-189 all regulate how small teams use AI in hiring. This guide maps every law to the action it requires, with links to the full cluster.
Italy banned DeepSeek within 72 hours. 13 EU jurisdictions opened investigations. China has no GDPR adequacy decision. Here is what US and EU teams need to know before using DeepSeek or other Chinese AI models, and when the open-source version changes the calculation.
Meta's mandatory MCI program collected employee keystrokes for AI training, then leaked private conversations and medical records company-wide. The legal requirements for AI-powered employee monitoring -- and what the Meta incident means for your policy.
24-hour runbook for leaked AI agent tokens: revoke, rotate, audit blast radius, and restore access before costs spiral. 7 copy-paste steps.
The exact URLs for enterprise privacy policies, DPAs, and trust centers from OpenAI, Anthropic, Google, and Microsoft, organized by vendor and updated for 2026.
The EU Digital Omnibus provisional agreement (May 7, 2026) would delay most high-risk AI obligations from August 2, 2026 to December 2, 2027. But formal adoption is not guaranteed before the August deadline. What deployers must do now regardless of which path the Omnibus takes.
Newsletter
Stay current on AI compliance
Weekly digest of new templates, regulation updates, and deadline alerts. Free, unsubscribe anytime.
Subscribe free →No spam · No vendor ads · Unsubscribe anytime
Templates
Get the complete policy kit
Acceptable use policies, vendor evaluation checklists, risk assessments, and more — all in one place.
View template kits →