Laws, Jurisdictions & Applications
Defensibility.ai operationalizes recurring legal tests across cybersecurity, data protection, privacy, AI governance, and executive accountability — with jurisdiction-specific obligations configured on top of a common decision methodology.
Coverage is not just a list of laws. The platform maps the legal obligation, accountable role, decision threshold, required reasoning, and evidence expected under each regime.
GDPR · EU AI Act · DORA · NIS2 · DSA · DMA · Data Act · Data Governance Act, with related jurisdictional overlays.
UK GDPR · UK Online Safety Act · Ireland online-safety regimes and related accountability requirements.
SEC Cyber Rules · SOX · FTC GLBA · HIPAA · COPPA · Executive Order 14117 and other relevant federal obligations.
CCPA/CPRA and a growing set of state privacy, AI, child-safety, design-code, and digital-governance laws.
PIPEDA · Quebec Law 25 and related privacy/accountability requirements.
Australia Privacy Act · APP 11 and related security, privacy, and online-safety obligations.
ISO 27001 / 27701 / 42001 / 31000 · NIST AI RMF · CIS · CMMC · DoCRA and related governance frameworks.
Reasonableness and adequacy regimes can be added by configuration with their actual jurisdictional distinctions preserved.
Coverage evolves. Exact applicability depends on the organization, activity, jurisdiction, and facts; the platform provides legal intelligence, not legal advice.
Different regimes use different terms, but many repeatedly test whether measures were reasonable, adequate, proportionate, risk-based, appropriate to foreseeable harm, and supported by evidence. The OS separates the common decision logic from the specific obligations and thresholds of each regime.
Adding a jurisdiction is a configuration and legal-mapping exercise, not a rebuild of the operating model.
Current Vertical Application
The OS also supports a dedicated application for organizations serving minors. It treats child privacy and psychological-welfare / harmful-design obligations as distinct governance disciplines and connects both to pre-release accountability and evidence.
Child-data collection, consent, default settings, age assurance, minimization, and related privacy obligations.
Dark patterns, addictive engagement loops, curfews, notification mechanics, amplification, and other design-related duties where applicable.
Maps applicable obligations to accountable leaders, requires the decision record before launch, and preserves evidence of the safeguards implemented.

Minors Safety Defensibility Dashboard — governance posture and evidence by applicable obligation.
The long-term OS architecture can support additional domains where executive legal obligations, decision standards, and evidentiary requirements follow the same pattern. The site keeps that expansion thesis separate from the coverage customers can evaluate now.