AI Governance · Compliance
AI Compliance Gap Analysis
Which rules apply, where you fall short, and what to fix first — scored against EU AI Act, NIST AI RMF, or ISO 42001.
Where does your AI use break rules you don't even know apply to you? Most organisations find out from a regulator, a customer contract, or an audit. A gap analysis is how you find out first, on your own terms.
What a gap analysis gives you
- Which rules apply to you
- Where you fall short
- What to fix firstA prioritised top-5, not all 30 at once.
- How far along you already are
Find your biggest compliance gaps in 90 seconds — free, no email required to start.
Run the free gap checkOr go straight to the full analysis — $39, one-time.
Frequently asked
- What is an AI compliance gap analysis?
- A structured assessment that identifies which regulatory obligations apply to your AI use, where your organisation currently falls short, and what to prioritise fixing first — scored against a framework such as the EU AI Act, NIST AI RMF, or ISO 42001.
- Which framework should I run a gap analysis against?
- Choose the EU AI Act if you operate in or sell into Europe, the NIST AI Risk Management Framework for a US-recognised risk framework, or ISO/IEC 42001 for an independently certifiable standard. Many organisations run more than one, starting with whichever a customer or regulator asks about.
- How many obligations does an AI compliance gap analysis cover?
- A full analysis commonly scores around 30 obligations per framework, with a prioritised top-5 list highlighting the highest-risk gaps to close first.
This page and the linked tool produce first-draft, AI-generated documents — not legal advice. Qualified review is required before you rely on any output.
Sources: Regulation (EU) 2024/1689 (EU AI Act) · NIST AI Risk Management Framework · ISO/IEC 42001:2023 · Responsible AI Studio .