Every regulation
has a landfall.
Regulation in, engineering tickets out — every interpretation documented, every decision defensible.
Pick what you are here to do.
You choose one when you create a project. It decides which frameworks are pre-selected, which questions you are asked, and what the guidance says.
AI system pre-scan
Classify an AI system under the EU AI Act, find the algorithms in your code and produce the report before it goes to production.
Privacy / DPIA
Screen personal-data processing for a data-protection impact assessment and the duties that follow it.
Child online safety
Age-appropriate design, parental consent and online-safety duties for a service minors can reach.
Accessibility
Meet WCAG success criteria and evidence them as engineering work, not a one-off audit.
Security & privacy framework
Map a NIST privacy or cybersecurity framework onto the codebase and track the gaps.
Same obligation. Different universe.
EU AI Act Article 27: a public body deploying a high-risk system must assess its impact on fundamental rights before first use. Here is how it lands.
One obligation, from one of the five use cases. Switch the example to trace the other.
Questionnaire answers that trigger it
- Deploys or integrates AI systems
- Yes
- Role under the AI Act
- Deployer
- Annex III area
- Essential public services (pt 5(a), 5(d))
- Organisation type
- A body governed by public law
Art. 27 fundamental rights impact assessment · EU-AI-ACT-ART-27-FRIA
Verdict flags: friaRequired = yes · publicDeployerRegistrationRequired = yes
Without Landfall
Jira Ticket
“Make the benefits model AI Act compliant”
Acceptance Criteria
( none )
Audit Trail
“Legal sent a memo in March”
Auditor verdict: Insufficient evidence.
With Landfall
Jira Ticket
“Complete and notify a fundamental rights impact assessment before first use of the eligibility model”
Acceptance Criteria
All six Art. 27(1) elements recorded: the processes it is used in, period and frequency of use, affected groups, specific risks to them, human-oversight measures, and response and complaint arrangements. Results notified to the market surveillance authority. IAMA record referenced by id.
Audit Trail
EU AI Act Art. 27(1) → EU-AI-ACT-ART-27-FRIA → applicable, derived from Q26 (Annex III area), Q25 (deployer role) and Q28 (body type) → approved by the compliance lead → ticket COMP-112
Register-entry draft
Risk category (AI Act tier): High-risk AI system (EU AI Act Art. 6(2), Annex III) · Legal basis: TO COMPLETE · Human oversight: required and mapped, describe the arrangement here
Auditor verdict: Full traceability. No findings.
The EU AI Act's Annex III duties are in force since 2 August 2026.
If you deploy an AI system in one of the Annex III areas, the deployer duties apply now — Article 26, the Article 27 fundamental rights impact assessment, and registration under Article 49(3). The pre-scan tells you which of them attach to your system, and which do not.
Watch a regulation become a ticket.
“…services likely to be accessed by children should apply age assurance proportionate to risk before personal data is collected…”
Age gate before PII collection
- Age assurance runs before any PII field renders
- Verifiable parental consent stored with timestamp
- Consent withdrawal deletes child data within 48h
From open ocean to a berth in your backlog.
From “we need to comply” to a defensible plan in under an hour.
Describe your product
What does your app do? Who uses it? What data do you collect? Takes about 10 minutes. Your answers determine which obligations apply.
Review obligations
We surface the specific obligations from 12 regulations & 6 standards that apply to your product. You approve, reject, or flag each one. Every decision gets logged.
Generate implementation tasks
AI translates obligations into engineering tasks with real acceptance criteria. You make the calls — ambiguous interpretations are flagged for your decision, not silently resolved.
Export with full trail
Push to Jira or Linear. Export audit packages. Every ticket traces back through the obligation to the source law. When regulators ask how, you show them.
421 obligations. 18 regulations and standards. We did the reading.
Sailors navigate different seas by the same stars. Cross-regulation links mean an obligation charted once counts everywhere it applies.
Run your cursor across the chart — the links light the way
EU AI Act · EU GDPR · EU GDPR Art. 8 · EU DSA · UK AADC · UK OSA · COPPA · CA CAADCA · AU OSA · Ireland OSC · Brazil LGPD · Singapore PDPA
Plus NIST CSF 2.0, the NIST Privacy Framework, W3C WCAG 2.2, IEEE 2089, ISO 27566 and AIUC-1 (preview).
Landfall is in pilot. Pilot partners get free access to the full platform, direct support, and input on the roadmap.
Not another compliance dashboard.
Compliance tools tell you what to do. Landfall gives engineers what they need to actually do it.
Real tickets, not checklists
Outputs actual Jira/Linear issues with acceptance criteria engineers can implement. Not a PDF that gets filed away.
AI assists, you decide
When “age-appropriate” could mean three things, we flag the ambiguity. You choose the interpretation. We document why.
Full citation chain
Code → ticket → task → obligation → regulation text. Traceable in both directions. Auditors love it.
Fits into the tools you already use.
Push work items directly. Verify compliance in your pipeline. No copy-pasting.
Plus Markdown export, Slack notifications, webhook integrations, and GDPR data export.
Questions compliance leads ask.
What does Landfall actually do?
Landfall reads regulatory text (the EU AI Act, the GDPR, the UK AADC, the EU DSA, COPPA and more) and translates it into structured obligations mapped to your specific product context. Those obligations then become prioritised engineering work items your team can build from — with full traceability back to the source regulation.
Who is Landfall built for?
Compliance, policy and engineering teams who have to turn a regulation into engineering work — public bodies deploying an algorithm, financial services teams, and product teams shipping consumer software. You choose a use case when you create a project: an AI system pre-scan under the EU AI Act, a privacy or DPIA screening, child online safety, accessibility, or a NIST security and privacy framework.
What is the EU AI Act pre-scan?
A screening for a team that has to say whether the AI Act applies to a system and whether a data protection impact assessment is needed. Landfall scans the repository for AI components, asks about your role and the Annex III area, and computes a risk tier — the classification is deterministic, not written by a model, so the same answers always produce the same tier. The report carries a numbered rationale with an article citation on every step, an Article 5 prohibited-practice check, a duties table (fundamental rights impact assessment under Art. 27, EU database registration under Art. 49, GDPR Art. 35 DPIA, Art. 36 prior consultation) with the basis printed for each row, the detected AI components as file and line references, and a register-entry draft. It is a screening instrument, not legal advice, and it does not complete your DPIA or approve anything.
Does Landfall replace our legal team?
No. Landfall is a translation tool, not legal advice. It structures the interpretation of regulatory text so your legal and engineering teams can have productive conversations grounded in the same data. Every AI-generated suggestion is flagged for human review.
More questions answered on the full FAQ →
Make landfall.
Bring the next regulation ashore with its paper trail intact — and be ready when someone asks how you got here.