AI Governance · Compliance

AI Compliance Gap Analysis

Which rules apply, where you fall short, and what to fix first — scored against EU AI Act, NIST AI RMF, or ISO 42001.

Last reviewed:

Where does your AI use break rules you don't even know apply to you? Most organisations find out from a regulator, a customer contract, or an audit. A gap analysis is how you find out first, on your own terms.

What a gap analysis gives you

  1. Which rules apply to you
  2. Where you fall short
  3. What to fix firstA prioritised top-5, not all 30 at once.
  4. How far along you already are

Find your biggest compliance gaps in 90 seconds — free, no email required to start.

Run the free gap check

Or go straight to the full analysis — $39, one-time.

Frequently asked

What is an AI compliance gap analysis?
A structured assessment that identifies which regulatory obligations apply to your AI use, where your organisation currently falls short, and what to prioritise fixing first — scored against a framework such as the EU AI Act, NIST AI RMF, or ISO 42001.
Which framework should I run a gap analysis against?
Choose the EU AI Act if you operate in or sell into Europe, the NIST AI Risk Management Framework for a US-recognised risk framework, or ISO/IEC 42001 for an independently certifiable standard. Many organisations run more than one, starting with whichever a customer or regulator asks about.
How many obligations does an AI compliance gap analysis cover?
A full analysis commonly scores around 30 obligations per framework, with a prioritised top-5 list highlighting the highest-risk gaps to close first.

This page and the linked tool produce first-draft, AI-generated documents — not legal advice. Qualified review is required before you rely on any output.

Sources: Regulation (EU) 2024/1689 (EU AI Act) · NIST AI Risk Management Framework · ISO/IEC 42001:2023 · Responsible AI Studio .

← All AI governance resources