Know Which AI LawsApply to YouIn 15 Minutes
Free self-audit tool for EU AI Act, Colorado AI Act, NYC LL144, and more.No legal expertise required. No AI testing AI. Just deterministic results you can trust.
We don't certify. We don't audit.
We help you decide what applies and what doesn't.
Most compliance failures start with misunderstanding scope. We fix that first.
Stop Testing AI with AI
Most compliance tools use AI to audit AI. That's like asking a student to grade their own exam.
Not knowing which regulations actually apply
67% of companiesTeams waste months preparing for laws that don't affect them
Over-engineering controls they don't need
$50K+ wastedBuilding expensive systems for non-applicable requirements
Under-preparing for the ones they do
3-6 month delaysMissing critical deadlines because scope wasn't clear
Paying consultants just to "figure it out"
$10K-$50K spent$500/hour to answer questions you could answer yourself
HAIEC Uses Deterministic Python Engines
Every compliance check runs on deterministic code with 91 rule patterns. No hallucinations. No randomness. Just facts designed for regulatory review.
Why Teams Choose Self-Audit
Get clarity before you spend money, panic, or over-engineer compliance
15 Minutes to Clarity
Get your complete regulatory snapshot faster than scheduling a consultant call
fully traceable Results
Deterministic Python engines - same input = same output, every time
Audit-Ready Evidence
Cryptographic audit trails designed for regulatory and audit review
Instant Downloadable Reports
PDF reports ready to share with stakeholders, investors, or auditors
Four steps to compliance clarity
From confusion to actionable roadmap in 15 minutes
Deterministic Qualification
We determine your size, industry, data types, AI use, and risk profile through targeted questions.
Guided Questions
Each question includes plain-language explanations, real-world examples, and regulatory context.
Conditional Logic
You only see questions relevant to your situation. No wading through irrelevant requirements.
Clear Output
Leave knowing exactly which laws apply, where you're exposed, and what to do next.
Recent AI Compliance Violations
Real penalties from companies that didn't comply. Don't let this be you.
Regulations We Cover
Security, privacy, and AI governance in one place
Why This Is Different
Traditional compliance vs. the modern approach
| Feature | Traditional Tools | HAIEC Self-Audit |
|---|---|---|
| Cost | $10,000+ consultants | Free to start |
| Time to Results | 2-4 weeks | 15 minutes |
| Expertise Required | Legal/compliance background | None - plain English |
| Approach | AI testing AI (probabilistic) | Deterministic Python engines |
| Reproducibility | Different results each time | fully traceable |
| Audit Trail | Black box explanations | Cryptographic evidence |
Frequently Asked Questions
Everything you need to know about AI compliance self-audits
How is this different from other compliance tools?
Most compliance tools use AI to audit AI - that's like asking a student to grade their own exam. HAIEC uses deterministic Python engines with 91 rule patterns. Same input = same output, every time. This produces audit-ready evidence designed for regulatory review.
How long does the self-audit take?
Most assessments take 10-15 minutes. Our TurboTax-style interface adapts to your answers, so you only see relevant questions. Complex organizations with multiple AI systems may take 20-30 minutes.
Do I need any compliance or legal expertise?
No. Every question includes plain-English explanations, real-world examples, and context about why it matters. We built this specifically for founders, developers, and teams without dedicated compliance staff.
Which AI regulations do you cover?
We cover EU AI Act, Colorado AI Act (SB24-205), NYC Local Law 144, ISO 42001, GDPR (for AI), HIPAA (for healthcare AI), ISO 27001, and SOC 2. We're continuously adding new frameworks based on enforcement priorities.
Is this a certification or audit?
No. We help you understand what applies and where you have gaps BEFORE you engage auditors or certification bodies. Think of it as pre-audit clarity that saves you $10K-$50K and months of time.
Can I share results with my auditor or lawyer?
Yes. Every assessment generates an exportable PDF with cryptographic verification. It includes your applicability matrix, gap analysis, and recommended next steps - designed for sharing with auditors, lawyers, or consultants.
Why should I trust HAIEC over other compliance tools?
Because regulators don't accept probabilistic outputs. Our deterministic Python engines produce the same results every time, with full audit trails. We've published research-backed frameworks (DOI: 10.5281/zenodo.18056133) on why reproducibility matters for compliance.
What if I'm already working with a consultant?
Perfect! Use our self-audit to get clarity on scope before your next consultant call. You'll save hours of billable time by arriving with a clear understanding of what applies to you.
Trusted by compliance teams
Building production AI with confidence
“HAIEC's deterministic approach gave us the audit trail regulators demanded. No more explaining probabilistic outputs.”
“The self-audit saved us $25K in consultant fees. We knew exactly what applied before our first legal call.”
“15 minutes to understand Colorado AI Act requirements. Better than 3 weeks of back-and-forth with lawyers.”
More Free Compliance Tools
Complete your compliance toolkit with these free tools from HAIEC
Risk Assessment
Score your AI system's risk level (0-100) with regulatory signals and recommendations
Law Finder
Answer 6 questions to discover which AI regulations apply to your business
Exposure Score
25-question assessment grading your AI governance across 5 domains (A-F letter grade)
Texas AI Law Check
Check if Texas TRAIGA (H.B. 149) applies to your AI system with legal citations
Penalty Calculator
Estimate potential non-compliance fines across NYC LL144, Colorado, EU AI Act, and GDPR
Policy Generator
Generate enterprise-grade compliance policies for SOC 2, ISO 27001, HIPAA, GDPR, and NIST
Ready to know what applies?
Start your free self-audit and get clarity in 15 minutes
Example Assessment Report
See what a completed self-assessment looks like:
Mid-Size Tech Company
200 employees | 5 AI systems in production
1. Inventory Completeness
6/10Significant gaps detected
- Marketing AI tools not tracked in central registry
- 3 vendor-embedded AI systems discovered during audit
- No ownership assigned for 2 legacy systems
2. Risk Assessment Quality
4/10Generic templates only
- Risk assessments use copy-paste boilerplate
- No system-specific mitigation evidence
- Last updated 18 months ago
3. Governance Clarity
7/10Some structure exists
- AI governance committee meets quarterly
- Clear escalation procedures documented
- Gap: Board not regularly briefed on AI risks
4. Technical Controls
5/10Planned but not implemented
- Monitoring dashboards exist but not actively reviewed
- Human review process is rubber-stamping
- Incident response never tested
5. Documentation Audit-Readiness
6/10Some documentation exists
- Core policies documented but stale
- No version control for compliance docs
- Evidence trails incomplete
6. Vendor Management
3/10Critical gaps
- No vendor compliance documentation on file
- No audit rights negotiated in contracts
- Vendor AI assumed to be vendor's responsibility
Recommended Actions (Priority Order)
- P1:Complete AI inventory within 30 days (include vendor-embedded AI)
- P1:Obtain vendor compliance documentation for all AI vendors
- P2:Update risk assessments with system-specific details and evidence
- P2:Test incident response procedures (tabletop exercise)
- P3:Implement version control for compliance documentation
What Auditors Look For in AI Compliance
Documentation Requirements by Audit Type
Internal Compliance Audits
Internal teams evaluate readiness before external audits or regulatory deadlines.
What they check:
- AI System Inventory - Complete list of all AI systems in production, classification by risk level, data flows mapped, vendor vs. internally developed systems identified
- Risk Assessments - Per-system risk analysis completed, mitigation measures documented and implemented, regular review cadence established
- Governance Structure - Clear accountability for AI decisions, escalation procedures defined, board/executive oversight documented
- Technical Controls - Monitoring and logging implemented, human oversight mechanisms functional, incident response procedures tested
External Regulatory Audits
NYC LL144 Audit Focus:
- Independent bias audit on file
- Bias audit published on careers page
- Candidate notice process documented
- 10-day advance notice timeline verified
- Annual audit update schedule
Colorado AI Act Audit Focus (Starting Feb 2026):
- Impact assessments for high-risk systems
- Risk management policy documented
- Consumer disclosure mechanisms
- Meaningful human review process
- Algorithmic discrimination testing
EU AI Act Audit Focus (Phased 2025-2027):
- Technical documentation completeness
- Conformity assessment for high-risk systems
- Post-market monitoring evidence
- Quality management system
- CE marking and registration
Common Compliance Failures That Fail Audits
Failure 1: Incomplete AI Inventory
What happens: Organizations claim "we don't use AI" but auditors discover AI in marketing (content generation), sales (lead scoring), HR (resume screening in ATS), customer service (chatbots), and finance (fraud detection).
Why it's dangerous: Can't comply with laws you don't know apply. Shadow AI lacks documentation, logging, oversight. Discovery during audit reveals systematic governance failure. Penalties apply to all undisclosed systems.
Real example: Company completed self-assessment claiming "no AI use." External audit discovered 12 AI systems across departments. Result: Failed audit + $200K remediation costs + 6-month delay to compliance.
How to fix: Survey all departments about AI tool usage, review vendor contracts for embedded AI, check SaaS subscriptions for AI features, interview department heads, create centralized AI registry.
Failure 2: Generic Risk Assessments
What happens: Risk assessments use copy-paste templates that don't address specific system characteristics.
Red flags auditors spot:
- Same risk ratings for all systems
- Generic mitigation measures ("we monitor")
- No evidence of actual implementation
- Boilerplate language from templates
- No system-specific details
Example of generic assessment:
Risk: Bias in AI decision-making
Likelihood: Medium
Impact: High
Mitigation: Regular monitoring and human oversight
What auditors want to see:
Risk: Gender bias in resume screening AI (System ID: HR-001)
Likelihood: Medium (historical data shows 65% male applicants)
Impact: High (NYC LL144 violation, Title VII exposure)
Mitigation:
- Independent bias audit completed 2024-01-15
- Impact ratios: Male 0.85, Female 1.0 (no disparate impact)
- Quarterly monitoring of selection rates
- Human review of all AI-flagged rejections
- Annual bias audit scheduled 2025-01-15
Evidence: Bias audit report, monitoring dashboard, review logs
Failure 3: Paper Compliance (Policies Without Implementation)
What happens: Beautiful policies exist but aren't actually followed.
How auditors detect this: Request evidence of policy execution, interview employees about actual practices, review system logs for control evidence, test controls to verify functionality, compare policy to reality.
Example disconnect:
- Policy says: "All high-risk AI requires human review before deployment"
- Reality shows: 5 high-risk systems deployed without review
- Evidence: No review meeting minutes, no approval records, no review checklists
What auditors look for: Meeting minutes from AI governance committee, approval records for AI deployments, training completion records, incident response drill results, monitoring dashboard screenshots, access control audit logs.
Failure 4: Stale Documentation
Why auditors reject it:
- Risk assessment from 2023, system changed in 2024
- Bias audit doesn't reflect current model version
- Governance policies reference deprecated systems
- Contact information for AI owners is outdated
- Regulatory references cite superseded laws
How to fix: Add "Last Updated" dates to all documentation, schedule annual compliance reviews, trigger reviews when systems change materially, version control all compliance documents, assign document owners with update responsibility.
Failure 5: Missing Vendor Due Diligence
What auditors discover:
- No vendor contracts reviewed for AI terms
- No vendor compliance documentation on file
- No vendor risk assessments conducted
- No vendor audit rights negotiated
- No vendor incident notification process
What auditors want to see: Vendor AI compliance questionnaire responses, vendor security certifications (SOC 2, ISO 27001), vendor bias audit reports (for hiring AI), vendor data processing agreements (GDPR), vendor SLA with compliance commitments, vendor incident notification procedures.
Gap Analysis Framework
Our self-assessment evaluates gaps across six dimensions:
1. Inventory Completeness
What we check: All AI systems identified and documented, vendor-embedded AI included, shadow AI discovered and catalogued, system ownership assigned, risk classification completed.
Common gaps: Marketing AI tools not tracked, vendor AI assumed to be vendor's responsibility, departmental AI purchases bypass IT, legacy systems forgotten, pilot projects not documented.
Scoring:
- 0-3: Critical gaps (>50% of AI untracked)
- 4-6: Significant gaps (25-50% untracked)
- 7-8: Minor gaps (<25% untracked)
- 9-10: Comprehensive inventory
2. Risk Assessment Quality
What we check: System-specific assessments (not generic), actual controls documented (not aspirational), evidence of implementation provided, regular updates when systems change, mitigation effectiveness measured.
Scoring:
- 0-3: Generic templates only
- 4-6: Some system-specific detail
- 7-8: Detailed assessments with evidence
- 9-10: Comprehensive, evidence-based, regularly updated
3. Governance Clarity
What we check: Clear AI accountability defined, escalation procedures documented, board/executive oversight evidence, AI ethics committee or similar, decision-making authority clear.
Common gaps: No designated AI owner, unclear escalation path, board unaware of AI use, no governance committee, diffuse responsibility.
4. Technical Control Implementation
What we check: Monitoring and logging functional, human oversight mechanisms implemented, incident response procedures tested, access controls enforced, security measures deployed.
Common gaps: Monitoring planned but not implemented, human review is rubber-stamping, incident response never tested, weak access controls, security gaps in AI systems.
5. Documentation Audit-Readiness
What we check: All required documentation exists, documentation is current (not stale), version control implemented, evidence trails maintained, easily retrievable for audits.
6. Vendor Management
What we check: Vendor AI identified and tracked, vendor compliance documentation obtained, vendor risk assessments completed, vendor audit rights negotiated, vendor monitoring ongoing.