Loading…
Loading…
AI Policy Desk
Ready-to-use templates, risk checklists, and implementation guides built for small teams navigating EU AI Act, GDPR, and US state AI laws — with no dedicated compliance function.
Updated for EU AI Act, GDPR, and 9 US state laws. No account, no paywall.
What applies to my team?
Featured
Start with these templates
Free tools
Interactive tools — get a clear answer in minutes, no consultant required.
4 questions · 2 min
Compliance Quiz
Which AI regulations apply to your team?
Take the quiz →
4 steps · 5 min
Policy Generator
Generate an AI acceptable use policy for your team.
Generate policy →
15 vendors · filterable
Vendor Scorecard
Compare AI vendors on privacy and compliance.
Compare vendors →
3 steps · 5 min
AI Risk Assessment
Rate your AI use cases Low / Medium / High / Critical.
Assess risk →
Explore
Regulations
28 coveredEU AI Act, GDPR, NIST AI RMF, Colorado AI Act, NY Local Law 144, and more — each explained for small teams.
Browse regulations →
Glossary
75 termsPlain-English definitions for AI governance terms: high-risk AI, GPAI models, conformity assessment, shadow AI, and more.
Browse glossary →
Start here
Pillar guides and templates — pick the one most relevant to your situation.
Latest
Templates, checklists, tool comparisons, and implementation guides for small teams adopting AI safely.
FTC's July 1 statement claims Colorado's AI Act conflicts with federal law. Public comment closes July 31. What this means for teams already complying.
Latest posts
Google must defend Robby Starbuck's AI defamation suit. Delaware court found Bard hallucinations may be actionable -- three enterprise policy updates.
Which AI governance framework fits your team in 2026? Compare ISO 42001, EU AI Act, and NIST AI RMF on cost, legal obligation, and certification.
France's CNIL and CIANum flagged persistent memory, multi-service data flows, and accountability gaps as the three key GDPR risks in agentic AI.
France's competition authority found three companies control 84% of AI agents. Opinion 26-A-05 explains what enterprise vendor lock-in looks like now.
What does an EU AI Act Article 9 risk management system need? 4 elements, run continuously, documented in a format auditors can inspect.
The OpenAI API has meaningfully different data handling than ChatGPT. API inputs are not used for training by default, zero data retention is available, and a DPA is accessible without an enterprise contract. Here is what that means for your team's governance.
Newsletter
Stay current on AI compliance
Weekly digest of new templates, regulation updates, and deadline alerts. Free, unsubscribe anytime.
Subscribe free →No spam · No vendor ads · Unsubscribe anytime
Templates
Get the complete policy kit
Acceptable use policies, vendor evaluation checklists, risk assessments, and more — all in one place.
View template kits →