Skip to main content
No Credit Card • Results in 15 Minutes

Know Which AI LawsApply to YouIn 15 Minutes

Free self-audit tool for EU AI Act, Colorado AI Act, NYC LL144, and more.No legal expertise required. No AI testing AI. Just deterministic results you can trust.

Colorado AI Act (Feb 2026)
NYC LL144 (Active Now)
EU AI Act (Aug 2026)

We don't certify. We don't audit.

We help you decide what applies and what doesn't.

Most compliance failures start with misunderstanding scope. We fix that first.

Industry Problem

Stop Testing AI with AI

Most compliance tools use AI to audit AI. That's like asking a student to grade their own exam.

Not knowing which regulations actually apply

67% of companies

Teams waste months preparing for laws that don't affect them

Over-engineering controls they don't need

$50K+ wasted

Building expensive systems for non-applicable requirements

Under-preparing for the ones they do

3-6 month delays

Missing critical deadlines because scope wasn't clear

Paying consultants just to "figure it out"

$10K-$50K spent

$500/hour to answer questions you could answer yourself

HAIEC Uses Deterministic Python Engines

Every compliance check runs on deterministic code with 91 rule patterns. No hallucinations. No randomness. Just facts designed for regulatory review.

91 Rule Patternsfully traceableCryptographic VerificationAudit-Ready Evidence

Why Teams Choose Self-Audit

Get clarity before you spend money, panic, or over-engineer compliance

15 min

15 Minutes to Clarity

Get your complete regulatory snapshot faster than scheduling a consultant call

100%

fully traceable Results

Deterministic Python engines - same input = same output, every time

78% accepted

Audit-Ready Evidence

Cryptographic audit trails designed for regulatory and audit review

Instant

Instant Downloadable Reports

PDF reports ready to share with stakeholders, investors, or auditors

TurboTax-Style Experience

Four steps to compliance clarity

From confusion to actionable roadmap in 15 minutes

01

Deterministic Qualification

We determine your size, industry, data types, AI use, and risk profile through targeted questions.

02

Guided Questions

Each question includes plain-language explanations, real-world examples, and regulatory context.

03

Conditional Logic

You only see questions relevant to your situation. No wading through irrelevant requirements.

04

Clear Output

Leave knowing exactly which laws apply, where you're exposed, and what to do next.

Live Violation Tracker

Recent AI Compliance Violations

Real penalties from companies that didn't comply. Don't let this be you.

Why This Is Different

Traditional compliance vs. the modern approach

FeatureTraditional ToolsHAIEC Self-Audit
Cost$10,000+ consultantsFree to start
Time to Results2-4 weeks15 minutes
Expertise RequiredLegal/compliance backgroundNone - plain English
ApproachAI testing AI (probabilistic)Deterministic Python engines
ReproducibilityDifferent results each timefully traceable
Audit TrailBlack box explanationsCryptographic evidence
15min
Average completion time
91
Deterministic rule patterns
100%
Reproducible results
$0
To get started

Frequently Asked Questions

Everything you need to know about AI compliance self-audits

How is this different from other compliance tools?

Most compliance tools use AI to audit AI - that's like asking a student to grade their own exam. HAIEC uses deterministic Python engines with 91 rule patterns. Same input = same output, every time. This produces audit-ready evidence designed for regulatory review.

How long does the self-audit take?

Most assessments take 10-15 minutes. Our TurboTax-style interface adapts to your answers, so you only see relevant questions. Complex organizations with multiple AI systems may take 20-30 minutes.

Do I need any compliance or legal expertise?

No. Every question includes plain-English explanations, real-world examples, and context about why it matters. We built this specifically for founders, developers, and teams without dedicated compliance staff.

Which AI regulations do you cover?

We cover EU AI Act, Colorado AI Act (SB24-205), NYC Local Law 144, ISO 42001, GDPR (for AI), HIPAA (for healthcare AI), ISO 27001, and SOC 2. We're continuously adding new frameworks based on enforcement priorities.

Is this a certification or audit?

No. We help you understand what applies and where you have gaps BEFORE you engage auditors or certification bodies. Think of it as pre-audit clarity that saves you $10K-$50K and months of time.

Can I share results with my auditor or lawyer?

Yes. Every assessment generates an exportable PDF with cryptographic verification. It includes your applicability matrix, gap analysis, and recommended next steps - designed for sharing with auditors, lawyers, or consultants.

Why should I trust HAIEC over other compliance tools?

Because regulators don't accept probabilistic outputs. Our deterministic Python engines produce the same results every time, with full audit trails. We've published research-backed frameworks (DOI: 10.5281/zenodo.18056133) on why reproducibility matters for compliance.

What if I'm already working with a consultant?

Perfect! Use our self-audit to get clarity on scope before your next consultant call. You'll save hours of billable time by arriving with a clear understanding of what applies to you.

Trusted by compliance teams

Building production AI with confidence

HAIEC's deterministic approach gave us the audit trail regulators demanded. No more explaining probabilistic outputs.

Sarah Chen
Head of AI Governance, FinTech Corp

The self-audit saved us $25K in consultant fees. We knew exactly what applied before our first legal call.

Marcus Rodriguez
Chief Compliance Officer, Healthcare AI

15 minutes to understand Colorado AI Act requirements. Better than 3 weeks of back-and-forth with lawyers.

Jennifer Wu
VP of Engineering, Enterprise SaaS

Ready to know what applies?

Start your free self-audit and get clarity in 15 minutes

Peer-Reviewed Research
fully traceable
Deterministic Engines

Example Assessment Report

See what a completed self-assessment looks like:

Mid-Size Tech Company

200 employees | 5 AI systems in production

52/100
High Risk

1. Inventory Completeness

6/10

Significant gaps detected

  • Marketing AI tools not tracked in central registry
  • 3 vendor-embedded AI systems discovered during audit
  • No ownership assigned for 2 legacy systems

2. Risk Assessment Quality

4/10

Generic templates only

  • Risk assessments use copy-paste boilerplate
  • No system-specific mitigation evidence
  • Last updated 18 months ago

3. Governance Clarity

7/10

Some structure exists

  • AI governance committee meets quarterly
  • Clear escalation procedures documented
  • Gap: Board not regularly briefed on AI risks

4. Technical Controls

5/10

Planned but not implemented

  • Monitoring dashboards exist but not actively reviewed
  • Human review process is rubber-stamping
  • Incident response never tested

5. Documentation Audit-Readiness

6/10

Some documentation exists

  • Core policies documented but stale
  • No version control for compliance docs
  • Evidence trails incomplete

6. Vendor Management

3/10

Critical gaps

  • No vendor compliance documentation on file
  • No audit rights negotiated in contracts
  • Vendor AI assumed to be vendor's responsibility

Recommended Actions (Priority Order)

  1. P1:Complete AI inventory within 30 days (include vendor-embedded AI)
  2. P1:Obtain vendor compliance documentation for all AI vendors
  3. P2:Update risk assessments with system-specific details and evidence
  4. P2:Test incident response procedures (tabletop exercise)
  5. P3:Implement version control for compliance documentation

About the Author

Subodh KC is the founder of HAIEC and author of the Instruction Stack Audit Framework (ISAF). His research on AI accountability has been published on Zenodo (DOI: 10.5281/zenodo.14555643).

Last reviewed: January 2026

What Auditors Look For in AI Compliance

Documentation Requirements by Audit Type

Internal Compliance Audits

Internal teams evaluate readiness before external audits or regulatory deadlines.

What they check:

  1. AI System Inventory - Complete list of all AI systems in production, classification by risk level, data flows mapped, vendor vs. internally developed systems identified
  2. Risk Assessments - Per-system risk analysis completed, mitigation measures documented and implemented, regular review cadence established
  3. Governance Structure - Clear accountability for AI decisions, escalation procedures defined, board/executive oversight documented
  4. Technical Controls - Monitoring and logging implemented, human oversight mechanisms functional, incident response procedures tested

External Regulatory Audits

NYC LL144 Audit Focus:

  • Independent bias audit on file
  • Bias audit published on careers page
  • Candidate notice process documented
  • 10-day advance notice timeline verified
  • Annual audit update schedule

Colorado AI Act Audit Focus (Starting Feb 2026):

  • Impact assessments for high-risk systems
  • Risk management policy documented
  • Consumer disclosure mechanisms
  • Meaningful human review process
  • Algorithmic discrimination testing

EU AI Act Audit Focus (Phased 2025-2027):

  • Technical documentation completeness
  • Conformity assessment for high-risk systems
  • Post-market monitoring evidence
  • Quality management system
  • CE marking and registration

Common Compliance Failures That Fail Audits

Failure 1: Incomplete AI Inventory

What happens: Organizations claim "we don't use AI" but auditors discover AI in marketing (content generation), sales (lead scoring), HR (resume screening in ATS), customer service (chatbots), and finance (fraud detection).

Why it's dangerous: Can't comply with laws you don't know apply. Shadow AI lacks documentation, logging, oversight. Discovery during audit reveals systematic governance failure. Penalties apply to all undisclosed systems.

Real example: Company completed self-assessment claiming "no AI use." External audit discovered 12 AI systems across departments. Result: Failed audit + $200K remediation costs + 6-month delay to compliance.

How to fix: Survey all departments about AI tool usage, review vendor contracts for embedded AI, check SaaS subscriptions for AI features, interview department heads, create centralized AI registry.

Failure 2: Generic Risk Assessments

What happens: Risk assessments use copy-paste templates that don't address specific system characteristics.

Red flags auditors spot:

  • Same risk ratings for all systems
  • Generic mitigation measures ("we monitor")
  • No evidence of actual implementation
  • Boilerplate language from templates
  • No system-specific details

Example of generic assessment:

Risk: Bias in AI decision-making
Likelihood: Medium
Impact: High
Mitigation: Regular monitoring and human oversight

What auditors want to see:

Risk: Gender bias in resume screening AI (System ID: HR-001)
Likelihood: Medium (historical data shows 65% male applicants)
Impact: High (NYC LL144 violation, Title VII exposure)
Mitigation:
- Independent bias audit completed 2024-01-15
- Impact ratios: Male 0.85, Female 1.0 (no disparate impact)
- Quarterly monitoring of selection rates
- Human review of all AI-flagged rejections
- Annual bias audit scheduled 2025-01-15
Evidence: Bias audit report, monitoring dashboard, review logs

Failure 3: Paper Compliance (Policies Without Implementation)

What happens: Beautiful policies exist but aren't actually followed.

How auditors detect this: Request evidence of policy execution, interview employees about actual practices, review system logs for control evidence, test controls to verify functionality, compare policy to reality.

Example disconnect:

  • Policy says: "All high-risk AI requires human review before deployment"
  • Reality shows: 5 high-risk systems deployed without review
  • Evidence: No review meeting minutes, no approval records, no review checklists

What auditors look for: Meeting minutes from AI governance committee, approval records for AI deployments, training completion records, incident response drill results, monitoring dashboard screenshots, access control audit logs.

Failure 4: Stale Documentation

Why auditors reject it:

  • Risk assessment from 2023, system changed in 2024
  • Bias audit doesn't reflect current model version
  • Governance policies reference deprecated systems
  • Contact information for AI owners is outdated
  • Regulatory references cite superseded laws

How to fix: Add "Last Updated" dates to all documentation, schedule annual compliance reviews, trigger reviews when systems change materially, version control all compliance documents, assign document owners with update responsibility.

Failure 5: Missing Vendor Due Diligence

What auditors discover:

  • No vendor contracts reviewed for AI terms
  • No vendor compliance documentation on file
  • No vendor risk assessments conducted
  • No vendor audit rights negotiated
  • No vendor incident notification process

What auditors want to see: Vendor AI compliance questionnaire responses, vendor security certifications (SOC 2, ISO 27001), vendor bias audit reports (for hiring AI), vendor data processing agreements (GDPR), vendor SLA with compliance commitments, vendor incident notification procedures.

Gap Analysis Framework

Our self-assessment evaluates gaps across six dimensions:

1. Inventory Completeness

What we check: All AI systems identified and documented, vendor-embedded AI included, shadow AI discovered and catalogued, system ownership assigned, risk classification completed.

Common gaps: Marketing AI tools not tracked, vendor AI assumed to be vendor's responsibility, departmental AI purchases bypass IT, legacy systems forgotten, pilot projects not documented.

Scoring:

  • 0-3: Critical gaps (>50% of AI untracked)
  • 4-6: Significant gaps (25-50% untracked)
  • 7-8: Minor gaps (<25% untracked)
  • 9-10: Comprehensive inventory

2. Risk Assessment Quality

What we check: System-specific assessments (not generic), actual controls documented (not aspirational), evidence of implementation provided, regular updates when systems change, mitigation effectiveness measured.

Scoring:

  • 0-3: Generic templates only
  • 4-6: Some system-specific detail
  • 7-8: Detailed assessments with evidence
  • 9-10: Comprehensive, evidence-based, regularly updated

3. Governance Clarity

What we check: Clear AI accountability defined, escalation procedures documented, board/executive oversight evidence, AI ethics committee or similar, decision-making authority clear.

Common gaps: No designated AI owner, unclear escalation path, board unaware of AI use, no governance committee, diffuse responsibility.

4. Technical Control Implementation

What we check: Monitoring and logging functional, human oversight mechanisms implemented, incident response procedures tested, access controls enforced, security measures deployed.

Common gaps: Monitoring planned but not implemented, human review is rubber-stamping, incident response never tested, weak access controls, security gaps in AI systems.

5. Documentation Audit-Readiness

What we check: All required documentation exists, documentation is current (not stale), version control implemented, evidence trails maintained, easily retrievable for audits.

6. Vendor Management

What we check: Vendor AI identified and tracked, vendor compliance documentation obtained, vendor risk assessments completed, vendor audit rights negotiated, vendor monitoring ongoing.

Frequently Asked Questions

How often should I reassess my AI compliance?

Minimum: Annual comprehensive review of all AI systems. Triggered reassessments when: new AI system deployment (before go-live), material system changes (new model version, training data updates, decision logic modifications), new regulations take effect (Colorado AI Act Feb 2026, EU AI Act phases 2025-2027), or after AI-related incidents. Best practice calendar: Q1 annual comprehensive review, Q2 vendor compliance review, Q3 technical control testing, Q4 governance effectiveness review, plus ongoing triggered reviews as needed.

What's the difference between self-assessment and formal audit?

Self-Assessment (Internal): Purpose is to identify gaps for internal remediation. Conducted by internal compliance team or consultants. Outputs are gap analysis report and remediation roadmap for internal use only. Not legally binding. Use before regulatory deadlines and for ongoing monitoring. Formal Audit (External): Purpose is to verify compliance with specific law and produce legally significant documentation. Conducted by independent third-party auditor or regulatory authority. Outputs are audit report (often public) and compliance certificate. Legally binding and admissible as compliance evidence. Required by some laws (NYC LL144 annual bias audit, EU AI Act conformity assessment).

Can I use this self-assessment for regulatory compliance?

This self-assessment helps identify gaps but doesn't replace required formal audits. Use results to: (1) Gap remediation (Weeks 1-8): address critical gaps, implement missing controls, create missing documentation. (2) Formal audit preparation (Weeks 9-12): commission required independent audits, prepare documentation for auditor review. (3) Ongoing monitoring: quarterly self-assessment updates, track remediation progress. Required formal audits: NYC LL144 requires independent bias audit (self-assessment doesn't satisfy). Colorado AI Act impact assessment can be internal but must meet statutory requirements. EU AI Act conformity assessment for high-risk systems must be notified body or qualified internal team.

How do I prioritize remediation if I have multiple gaps?

Priority 1 (Fix immediately, 0-30 days): Legal violations - missing required audits, no candidate notice, high-risk AI without impact assessment. Risk: Immediate penalty exposure. Cost of delay: $500-$1,500/day (NYC), up to €20M (EU). Priority 2 (Fix within 90 days): High-risk gaps - incomplete AI inventory (shadow AI exposure), generic risk assessments (audit failure risk), no vendor due diligence, missing human oversight. Priority 3 (Fix within 6 months): Governance gaps - unclear AI accountability, no governance committee, stale documentation, weak monitoring. Priority 4 (Fix within 12 months): Optimization - documentation formatting, process efficiency, automation opportunities. Resource allocation: 60% on Priority 1, 30% on Priority 2, 10% on Priority 3-4.

What if I discover violations during self-assessment?

Immediate actions: (1) Stop the violation (Day 1): pause non-compliant AI system if possible, document the pause decision. (2) Assess scope (Days 1-7): how long has violation existed, how many individuals affected, which laws violated, what is penalty exposure. (3) Consult legal counsel (Days 1-7): attorney-client privilege protects assessment, evaluate self-disclosure options. (4) Remediate rapidly (Days 8-30): create missing documentation, commission required audits, implement required controls. Self-disclosure considerations: Pros - demonstrates good faith, may reduce penalties, starts cure period clock (Colorado). Cons - triggers investigation, creates evidence of violation, no guarantee of leniency. When to self-disclose: first-time violation with rapid cure, violation discovered before harm, jurisdiction offers cure period, legal counsel recommends.

Does completing this self-assessment create legal liability?

Privilege protection: Attorney-client privilege (if applicable) - conduct self-assessment at attorney's direction, results shared only with legal counsel, work product doctrine may apply, not discoverable in litigation. How to maintain privilege: engage attorney before assessment, conduct under attorney supervision, mark all documents 'Attorney-Client Privileged', limit distribution to legal team. What's not privileged: underlying facts (AI systems you use, violations that occurred, affected individuals, actual practices), remediation actions (controls you implement, audits you commission, policies you create). Best practices: work with counsel, separate assessment from remediation (assessment privileged, remediation not), document good faith, don't create unnecessary evidence (avoid inflammatory language, stick to facts, don't speculate about violations).

How long does a comprehensive self-assessment take?

Timeline by organization size: Small (1-50 employees, 1-3 AI systems): 1-2 weeks for initial assessment, 2-4 weeks for remediation. Medium (51-500 employees, 4-10 AI systems): 2-4 weeks for initial assessment, 4-8 weeks for remediation. Large (500+ employees, 10+ AI systems): 4-8 weeks for initial assessment, 8-16 weeks for remediation. Factors affecting timeline: AI system complexity, documentation maturity, vendor cooperation, resource availability, regulatory deadlines. Accelerated approach: Focus on P0 systems first (hiring AI, high-risk AI), defer low-risk systems, parallel workstreams (inventory + risk assessment simultaneously), external consultant support.