Skip to content
Regulation → Engineering

Every regulation
has a landfall.

Regulation in, engineering tickets out — every interpretation documented, every decision defensible.

421
Obligations mapped
18
Regs & standards
7
Jurisdictions
Full
Audit trail
Five use cases

Pick what you are here to do.

You choose one when you create a project. It decides which frameworks are pre-selected, which questions you are asked, and what the guidance says.

AI system pre-scan

Classify an AI system under the EU AI Act, find the algorithms in your code and produce the report before it goes to production.

Privacy / DPIA

Screen personal-data processing for a data-protection impact assessment and the duties that follow it.

Child online safety

Age-appropriate design, parental consent and online-safety duties for a service minors can reach.

Accessibility

Meet WCAG success criteria and evidence them as engineering work, not a one-off audit.

Security & privacy framework

Map a NIST privacy or cybersecurity framework onto the codebase and track the gaps.

Same obligation. Different universe.

EU AI Act Article 27: a public body deploying a high-risk system must assess its impact on fundamental rights before first use. Here is how it lands.

One obligation, from one of the five use cases. Switch the example to trace the other.

Questionnaire answers that trigger it

Deploys or integrates AI systems
Yes
Role under the AI Act
Deployer
Annex III area
Essential public services (pt 5(a), 5(d))
Organisation type
A body governed by public law

Art. 27 fundamental rights impact assessment · EU-AI-ACT-ART-27-FRIA

Verdict flags: friaRequired = yes · publicDeployerRegistrationRequired = yes

Without Landfall

Jira Ticket

Make the benefits model AI Act compliant

Acceptance Criteria

( none )

Audit Trail

Legal sent a memo in March

Auditor verdict: Insufficient evidence.

With Landfall

Jira Ticket

Complete and notify a fundamental rights impact assessment before first use of the eligibility model

Acceptance Criteria

All six Art. 27(1) elements recorded: the processes it is used in, period and frequency of use, affected groups, specific risks to them, human-oversight measures, and response and complaint arrangements. Results notified to the market surveillance authority. IAMA record referenced by id.

Audit Trail

EU AI Act Art. 27(1) → EU-AI-ACT-ART-27-FRIA → applicable, derived from Q26 (Annex III area), Q25 (deployer role) and Q28 (body type) → approved by the compliance lead → ticket COMP-112

Register-entry draft

Risk category (AI Act tier): High-risk AI system (EU AI Act Art. 6(2), Annex III) · Legal basis: TO COMPLETE · Human oversight: required and mapped, describe the arrangement here

Auditor verdict: Full traceability. No findings.

⚠️

The EU AI Act's Annex III duties are in force since 2 August 2026.

If you deploy an AI system in one of the Annex III areas, the deployer duties apply now — Article 26, the Article 27 fundamental rights impact assessment, and registration under Article 49(3). The pre-scan tells you which of them attach to your system, and which do not.

Inside the product

Watch a regulation become a ticket.

Source · UK AADC · Standard 1

“…services likely to be accessed by children should apply age assurance proportionate to risk before personal data is collected…”

Provenance chain
Obligation 1.3 Age assurance before PII collection
Interpreted · J. Smith · Jan 12Approved
COMP-47backlog · ready

Age gate before PII collection

  • Age assurance runs before any PII field renders
  • Verifiable parental consent stored with timestamp
  • Consent withdrawal deletes child data within 48h
The passage

From open ocean to a berth in your backlog.

From “we need to comply” to a defensible plan in under an hour.

01 · Sight

Describe your product

What does your app do? Who uses it? What data do you collect? Takes about 10 minutes. Your answers determine which obligations apply.

02 · Chart

Review obligations

We surface the specific obligations from 12 regulations & 6 standards that apply to your product. You approve, reject, or flag each one. Every decision gets logged.

03 · Steer

Generate implementation tasks

AI translates obligations into engineering tasks with real acceptance criteria. You make the calls — ambiguous interpretations are flagged for your decision, not silently resolved.

04 · Land

Export with full trail

Push to Jira or Linear. Export audit packages. Every ticket traces back through the obligation to the source law. When regulators ask how, you show them.

The chart

421 obligations. 18 regulations and standards. We did the reading.

Sailors navigate different seas by the same stars. Cross-regulation links mean an obligation charted once counts everywhere it applies.

Run your cursor across the chart — the links light the way

EU AI Act · EU GDPR · EU GDPR Art. 8 · EU DSA · UK AADC · UK OSA · COPPA · CA CAADCA · AU OSA · Ireland OSC · Brazil LGPD · Singapore PDPA

Plus NIST CSF 2.0, the NIST Privacy Framework, W3C WCAG 2.2, IEEE 2089, ISO 27566 and AIUC-1 (preview).

Landfall is in pilot. Pilot partners get free access to the full platform, direct support, and input on the roadmap.

On shore

Not another compliance dashboard.

Compliance tools tell you what to do. Landfall gives engineers what they need to actually do it.

Real tickets, not checklists

Outputs actual Jira/Linear issues with acceptance criteria engineers can implement. Not a PDF that gets filed away.

AI assists, you decide

When “age-appropriate” could mean three things, we flag the ambiguity. You choose the interpretation. We document why.

Full citation chain

Code → ticket → task → obligation → regulation text. Traceable in both directions. Auditors love it.

Fits into the tools you already use.

Push work items directly. Verify compliance in your pipeline. No copy-pasting.

JiraPush issues with priority mapping & acceptance criteria
LinearCreate issues with workflow state sync
GitHubPR drift detection & compliance contracts
CI/CDPipeline gate with pass/fail/warn checks
CSVJira-compatible CSV with obligation references
JSONFull audit bundle with SHA-256 integrity

Plus Markdown export, Slack notifications, webhook integrations, and GDPR data export.

Before you board

Questions compliance leads ask.

What does Landfall actually do?

Landfall reads regulatory text (the EU AI Act, the GDPR, the UK AADC, the EU DSA, COPPA and more) and translates it into structured obligations mapped to your specific product context. Those obligations then become prioritised engineering work items your team can build from — with full traceability back to the source regulation.

Who is Landfall built for?

Compliance, policy and engineering teams who have to turn a regulation into engineering work — public bodies deploying an algorithm, financial services teams, and product teams shipping consumer software. You choose a use case when you create a project: an AI system pre-scan under the EU AI Act, a privacy or DPIA screening, child online safety, accessibility, or a NIST security and privacy framework.

What is the EU AI Act pre-scan?

A screening for a team that has to say whether the AI Act applies to a system and whether a data protection impact assessment is needed. Landfall scans the repository for AI components, asks about your role and the Annex III area, and computes a risk tier — the classification is deterministic, not written by a model, so the same answers always produce the same tier. The report carries a numbered rationale with an article citation on every step, an Article 5 prohibited-practice check, a duties table (fundamental rights impact assessment under Art. 27, EU database registration under Art. 49, GDPR Art. 35 DPIA, Art. 36 prior consultation) with the basis printed for each row, the detected AI components as file and line references, and a register-entry draft. It is a screening instrument, not legal advice, and it does not complete your DPIA or approve anything.

Does Landfall replace our legal team?

No. Landfall is a translation tool, not legal advice. It structures the interpretation of regulatory text so your legal and engineering teams can have productive conversations grounded in the same data. Every AI-generated suggestion is flagged for human review.

More questions answered on the full FAQ →

The harbour

Make landfall.

Bring the next regulation ashore with its paper trail intact — and be ready when someone asks how you got here.