What's new

The releases below are listed newest first. Every regulatory addition carries a law-review date and a pending legal sign-off marker.

One assessment, five regimes

0.3.08 September 2026

Most organisations deploying AI now answer to several regulators at once, and reconciling them by hand is where governance programmes stall. This release makes one impact assessment answer all of them, and generates the documents each regime expects.

Four more regulatory regimes

GDPR, Colorado SB 26-189, Texas TRAIGA and Washington's five domain instruments join the EU AI Act, NIST AI RMF, ISO 42001 and California ADMT. That is 294 requirements across eight frameworks and 115 cross-framework mappings, all bilingual. Each regime resolves its own scope from your declared jurisdictions and a few screening answers, and an unanswered question stays visibly undetermined rather than quietly reading as a no.

The unified impact assessment

One question set with a common core drafted to the strictest formulation among the regimes, plus overlays that appear only where a regime applies. Every question declares the requirement codes its answer evidences, so one answer stands as evidence in several compliance registers at once. Where two regimes ask the same legal question the product reuses the answer: a California ADMT sole-factor finding also answers the GDPR Article 22 question.

Three documents you can take away

The unified impact assessment, a multi-jurisdictional notice built as a universal core plus one addendum per jurisdiction, and a human review and appeal protocol with a table of what each jurisdiction words differently. Assembly is deterministic, so a document that cites statute is reproducible. They download as Markdown, to go straight into your own systems of record.

Gaps are shown, not hidden

An unanswered question becomes a visible gap carrying the obligation it would have evidenced, collected into an open-items summary at the top of every document. Citations are filtered to the regimes that actually apply, so a document never names a state you do not operate in.

The agentic stress test

Eleven findings covering where each document breaks when the system hands its output to an autonomous downstream agent: the Article 22 boundary moving to the agent, the California human-involvement prongs failing at the handoff, a notice that no longer describes the decision, a protocol that reviews what cannot be reversed, records that trace the output rather than the action, and an agent that reaches past the processing contract. Each names the assumption the regime made and the provision the agentic layer demands.

The vendor supply chain

The vendor catalog has carried structured subprocessor lists for 254 vendors, with 604 entries cross-linked to other catalog vendors. They are now rendered: a supply chain on each catalog entry with the reverse view of who depends on it, a supply-chain tab on each of your vendors marking the subprocessors you already govern, and a shared-subprocessors card showing the providers sitting beneath more than one of your vendors. The Annex IV draft receives the list too.

A self-hosting upgrade fix

The migrator's pre-baseline check had never fired, so installs created before the migrations baseline could not upgrade. Both faults are fixed and the upgrade path is now verified against the published image on every release.

California, jurisdictions and the obligation calendar

0.2.xAugust 2026

The releases that made the product multi-jurisdictional in the first place.

California CCPA ADMT

The fourth compliance framework: 92 requirements, the three-prong human-involvement determination, significant-decision domains, opt-out basis, designated reviewer and appeal route, and the risk-assessment deadlines.

Jurisdictions and the regulatory calendar

A jurisdiction model on the organisation and per system, driving a dated obligation timeline bound to your own inventory rather than a generic list of deadlines.

Article 50 transparency

Per-system transparency profiles, the four obligations, marking methods and generated transparency statements.

Legal review status

The GDPR, Colorado, Texas and Washington packs, the unified assessment and the agentic stress test were signed off on 8 September 2026. The two Washington items previously flagged as unconfirmed were verified against the session laws first: HB 1170 is chapter 167, Laws of 2026, effective 1 February 2027, and HB 2225 is chapter 168, effective 1 January 2027. The prior-authorisation limits are in force from 11 June 2026, not 2027, because the January 2027 date shown against RCW 48.43.830 belongs to a later section that reconciles two 2025 amendments rather than to the artificial-intelligence duties. The EU AI Act and California ADMT packs carry their own review dates and are still pending sign-off; any document citing them says so.

See it in the product

Open any AI system and choose the Cross-border regimes tab.

Read the cross-border documentation