About Regmap
Most mid-market companies now deploy AI in hiring, customer service, and operations — often faster than anyone can say which laws attach. Regmap is the inventory and the map: a plain record of every AI system, and beside each one, the regimes that reach it, the obligations that follow, and the artifacts still missing.
Regmap answers three questions, per AI system, over and over:
The work begins with a short intake wizard — about four minutes per system. You describe the system in plain language; the model offers suggested answers, clearly labelled, and you confirm or correct each field. From your confirmed intake, Regmap produces a print-ready AI Compliance Snapshot, an obligation tracker with deadlines, and a set of draft artifacts: an AI-use policy, a risk-assessment worksheet, an inventory register, disclosure notices, and a vendor due-diligence questionnaire.
It is built for the person who has been handed AI governance without being handed a legal department — the ops lead, the general counsel of one, the compliance manager who needs a defensible record before the next audit or customer questionnaire lands.
The first release carries ten mini-regimes across the EU and the United States. Each was drafted from its primary source — the statute or regulation itself — cited to the article or section, and dated so you can see how current it is.
Regulation (EU) 2024/1689, as amended. Risk-tiered obligations for providers and deployers, including the phased timeline for prohibited practices, general-purpose models, and high-risk systems.
Duties of developers and deployers of high-risk AI systems making consequential decisions — reasonable care against algorithmic discrimination, impact assessments, and consumer notices. Effective dates have moved with amendment; Regmap tracks the current one.
The Texas Responsible Artificial Intelligence Governance Act: prohibited uses, disclosure duties, and government-use rules.
Four separate California statutes, each treated as its own regime: AB 2013 (generative-AI training-data transparency), SB 942 (the AI Transparency Act, as amended by AB 853), SB 243 (companion chatbots), and AB 3030 (a health-care generative-AI disclaimer). They carry different operative dates, and Regmap keeps them distinct.
820 ILCS 42 — consent, disclosure, and handling duties when AI analyzes recorded video interviews of applicants.
Amendments to the Illinois Human Rights Act (775 ILCS 5) governing AI use in employment decisions and notice to employees.
New York City's rule on automated employment decision tools — the bias-audit, published-results, and candidate-notice regime. Regmap treats it at city scope, so a New-York-state-only deployment is flagged for analysis rather than wrongly cleared.
The method
This is the discipline the whole product is built around, so it is worth being precise about.
The rules are data, not memory. Applicability is decided by a deterministic engine reading versioned rule tables. Each row carries an identifier, a citation to the primary source, an effective date, a plain-English summary, and a machine-checkable predicate. Change the law and you change a data file — reviewed, dated, and diffable — not a prompt.
The AI never authors a legal conclusion. The model's only job is to suggest answers to the intake — to read your description of a system and propose, say, that it is used for hiring. Its output schema has no field for a regime, an obligation, or a status. It is structurally unable to tell you the law. You confirm the intake; the engine does the rest.
Ambiguity is answered honestly. The predicates use three-valued logic: true, false, and unknown. Where a statute genuinely doesn't resolve your case, the result is needs analysis, naming the open question — never a confident wrong answer dressed up as certainty.
Everything is dated and traceable. Each result records which version of which rule produced it, so a snapshot stays intelligible months later, after the rules have moved on.
Every rule in Regmap ships marked draft, and every result you see wears that mark until a qualified attorney has verified the underlying rule against its source. This is deliberate, and it is not a soft launch flourish — it is the safety property.
The corpus was drafted from primary legal sources with care, and the engine around it is tested rule-by-rule. But drafted-with-care is not the same as counsel-verified, and AI law in 2026 is moving quickly: effective dates slip, statutes are amended, and new cohorts arrive. Until a lawyer signs off on a given rule, Regmap will not present it as settled.
So, plainly: Regmap is not legal advice and is not a substitute for a lawyer. It is an instrument for finding, organizing, and evidencing the compliance work in front of you — and for walking into a conversation with counsel already knowing the questions. Use it that way and it earns its keep.
No. Regmap organizes and evidences compliance work; it is not legal advice and not a substitute for a lawyer. Its rule corpus is draft pending review by qualified counsel, and every result is labelled accordingly.
No — and this is the point of the design. A deterministic engine reading versioned rule tables decides what applies. The AI only proposes intake answers, which you confirm. Its output has no field capable of holding a legal conclusion, so it cannot invent one.
The engine returns needs analysis instead of guessing, and tells you which specific open question it could not resolve from your intake — so you know exactly what to take to counsel.
Each regime file records the date it was last verified against its source, and the app shows that date wherever results appear. Where an effective date is still moving — as several are — the note travels with the result.
The EU AI Act; Colorado SB 24-205; Texas TRAIGA; the California 2026 cohort (AB 2013, SB 942, SB 243, AB 3030); the Illinois AI Video Interview Act; Illinois HB 3773; and NYC Local Law 144. More are planned; the architecture is one-file-per-regime, so adding a jurisdiction is additive work.
Yes. Each organization's data is separated at the database level with row-level security enforced from day one and tested for cross-tenant isolation, not merely asserted in application code.
The plan is a free tier for a single AI system, a Starter tier that adds more systems and the artifact generator, and a Growth tier with unlimited systems, the obligation tracker, and a weekly digest. During the invite-only beta, pricing is being set with early users.
Access is by invitation while the rules are under counsel review. Request access and tell us what you deploy and where you operate.
Private beta
The free tier maps a single AI system end to end. Ask for an invitation and see your first Snapshot.