Laws, Jurisdictions & Applications

What's covered today.

Defensibility.ai operationalizes recurring legal tests across cybersecurity, data protection, privacy, AI governance, and executive accountability — with jurisdiction-specific obligations configured on top of a common decision methodology.

Mapped out of the box.

Coverage is not just a list of laws. The platform maps the legal obligation, accountable role, decision threshold, required reasoning, and evidence expected under each regime.

European Union

GDPR · EU AI Act · DORA · NIS2 · DSA · DMA · Data Act · Data Governance Act, with related jurisdictional overlays.

United Kingdom & Ireland

UK GDPR · UK Online Safety Act · Ireland online-safety regimes and related accountability requirements.

United States — Federal

SEC Cyber Rules · SOX · FTC GLBA · HIPAA · COPPA · Executive Order 14117 and other relevant federal obligations.

United States — State

CCPA/CPRA and a growing set of state privacy, AI, child-safety, design-code, and digital-governance laws.

Canada

PIPEDA · Quebec Law 25 and related privacy/accountability requirements.

Australia

Australia Privacy Act · APP 11 and related security, privacy, and online-safety obligations.

Frameworks & Standards

ISO 27001 / 27701 / 42001 / 31000 · NIST AI RMF · CIS · CMMC · DoCRA and related governance frameworks.

Additional jurisdictions

Reasonableness and adequacy regimes can be added by configuration with their actual jurisdictional distinctions preserved.

Coverage evolves. Exact applicability depends on the organization, activity, jurisdiction, and facts; the platform provides legal intelligence, not legal advice.

One decision methodology. Jurisdiction-specific overlays.

Different regimes use different terms, but many repeatedly test whether measures were reasonable, adequate, proportionate, risk-based, appropriate to foreseeable harm, and supported by evidence. The OS separates the common decision logic from the specific obligations and thresholds of each regime.

Adding a jurisdiction is a configuration and legal-mapping exercise, not a rebuild of the operating model.

Current Vertical Application

Minors Safety & Child Welfare: privacy plus psychological welfare.

The OS also supports a dedicated application for organizations serving minors. It treats child privacy and psychological-welfare / harmful-design obligations as distinct governance disciplines and connects both to pre-release accountability and evidence.

Privacy & age assurance

Child-data collection, consent, default settings, age assurance, minimization, and related privacy obligations.

Psychological welfare & design

Dark patterns, addictive engagement loops, curfews, notification mechanics, amplification, and other design-related duties where applicable.

Pre-release defensibility

Maps applicable obligations to accountable leaders, requires the decision record before launch, and preserves evidence of the safeguards implemented.

Minors Safety Defensibility Dashboard

Minors Safety Defensibility Dashboard — governance posture and evidence by applicable obligation.

Built for expansion without blurring what exists today.

The long-term OS architecture can support additional domains where executive legal obligations, decision standards, and evidentiary requirements follow the same pattern. The site keeps that expansion thesis separate from the coverage customers can evaluate now.