Cross-border regimes
Most organisations deploying AI answer to several regulators at once, and each asks a version of the same question in different words. AI SENTINEL resolves which regimes reach each system, asks one question set drafted to the strictest of them, and generates the documents each regime expects.
Highest common denominator, plus overlays
The assessment has a common core that is always asked. Each core question is drafted to the strictest formulation among the regimes, so answering it once satisfies every regime that asks a weaker version of the same thing.
On top of that core sit jurisdictional overlays. An overlay question appears only when that regime's rules have put the system in scope, so a European deployer is never asked about Washington health carriers, and a Texas-only business never sees a California section number.
Every question declares which requirement codes its answer evidences. That is what lets one answer stand as evidence in several compliance registers at the same time, and it is what the generated documents cite.
The regimes
EU AI Act
83 requirementsRegulation (EU) 2024/1689. Risk classification, Annex III screening, the Article 27 fundamental rights impact assessment, Article 50 transparency, Annex IV technical documentation and the obligation calendar.
GDPR
26 requirementsThe AI-relevant articles, with Article 22 on solely automated decisions and Article 35 on impact assessments in full, including the CJEU reading that an automatically generated score can itself be the decision.
California CCPA ADMT
92 requirementsThe OAL-approved regulations: the three-prong human-involvement test, significant-decision domains, pre-use notice, opt-out, access, and the risk-assessment regime that has been live since January 2026.
Colorado SB 26-189
10 requirementsThe replacement statute that repealed the original Colorado AI Act. Advance notice, post-decision disclosure, correction and review, and developer documentation. Effective 1 January 2027, subject to pending federal litigation.
Texas TRAIGA
11 requirementsHouse Bill 149, in force since January 2026. Intent-based prohibitions, government and health care disclosure duties, the NIST safe harbour and the regulatory sandbox.
Washington
16 requirementsNo single act, so five instruments: the My Health My Data Act for algorithmic health inference, HB 1170 provenance (2026 c 167, from 1 February 2027), HB 2225 companion chatbots (2026 c 168, from 1 January 2027), the prior-authorisation limits on AI-only denials in RCW 48.43.830 (in force since 11 June 2026), and RCW 43.105 for public agencies.
How scope is decided
Each regime has its own deterministic rules module. It reads the jurisdictions your organisation has declared plus a handful of screening answers, and returns one of three states.
Applies
The regime reaches this system, and its overlay questions and requirements attach.
Does not apply
Someone answered the questions that rule it out. This is an assertion, so it is only ever made from answers a person actually gave.
Undetermined
Nobody has answered yet. Nothing attaches, and the state is shown as an open question rather than being read as a no. An unanswered question is a visible gap, never a silent one.
Answers you already gave
Where two regimes ask the same legal question, the product reuses the answer rather than asking twice. A California ADMT determination that finds the technology is the sole factor in a significant decision also answers the GDPR Article 22 question, and a positive determination with a named decision domain answers the Colorado covered-technology test. The assessment records which answer it inferred from, so the reasoning stays auditable.
What you take away
From one answered assessment the product assembles four documents. Assembly is deterministic: no model is called, so a document that cites statute is reproducible and every sentence traces to an answer. They download as Markdown so they can go straight into your own systems of record.
Unified impact assessment
One record answering the EU AI Act fundamental rights impact assessment, the GDPR data protection impact assessment, the California risk assessment and the state regimes.
Multi-jurisdictional AI notice
A universal core drafted to the strictest regime, plus one addendum for each jurisdiction that adds obligations of its own. The addenda never mix.
Human review and appeal protocol
One review workflow satisfying GDPR Article 22(3), the California human-appeal exception, the Colorado review right and the EU AI Act right to an explanation, with a table of what each jurisdiction words differently.
Agentic addendum
The stress test as a document: where each of the three breaks when the system hands off to an autonomous agent, and the provisions that layer demands.
Gaps are shown, not hidden
An unanswered question does not silently drop the paragraph it would have filled. It becomes a visible gap carrying the obligation it would have evidenced, and every gap is collected into an open-items summary at the top of the document. A generated document that quietly omits an unanswered obligation is worse than no document, because it reads as complete.
The agentic stress test
Every regime in this product was written for a system that produces an output which a person then uses. An autonomous agent that acts on that output breaks that assumption in a different place in each regime.
The stress test runs eleven findings over the system, each naming the document it breaks, the assumption the regime made, what the handoff does to it, and the provision the agentic layer demands. Findings are gated on the regimes that actually apply, so a Texas deployer is not shown a GDPR failure.
The Article 22 boundary moves to the agent
Your analysis said the decision is not solely automated because a person reviews the output. If an agent then acts on it and nobody reviews the action, the decision the person experiences is solely automated after all.
The human-involvement prongs fail at the handoff
The California test requires a reviewer with authority to change the decision. An agent that executes before review completes removes that authority in practice, and the test is conjunctive.
The protocol reviews what cannot be reversed
With an agent in the chain the action is often complete before anyone appeals. Review without reversal is not the human intervention the GDPR requires.
Getting started
Declare your jurisdictions
In Settings, record where the organisation operates. Nothing can resolve until this is done, and the product says so rather than guessing.
Answer the organisation screening
Five questions, each shown only if a jurisdiction you declared turns on it. Whether you are a public agency, a health carrier, a health care provider, a covered generative AI provider, or process Washington consumer health data.
Open a system's Cross-border regimes tab
See which regimes apply and which are still undetermined, then answer the system screening: how automated the decision is, whether special-category data is involved, and whether the output goes to an autonomous agent.
Attach the requirements and create the assessment
The in-scope requirements attach to the system's compliance record, and the unified assessment is created with the question set that system actually needs.
Generate the documents
Download the assessment, the notice, the protocol and the agentic addendum. Answer more questions and regenerate: the gaps close as you go.
The regulatory content in this module was signed off on 8 September 2026 and carries that marker on every generated document, alongside the date it was last reviewed against source. The EU AI Act and California packs are still pending their own sign-off, and a document that cites them says so. Nothing here is legal advice.
What's new