The more precisely you answer, the sharper your snapshot. "Not sure" is always an acceptable answer; that's what the scan is for.
A · You and your organization
Headcount range *
Select…
Under 100
100–250
251–500
501–1,000
1,001–2,000
2,000+
A few capacities switch on whole lanes of obligations. They're additive: each one turns a lane on without turning any others off, and most organizations answer "No" to the three government questions (a private company is carried by the questions below). If a grant, subcontract, or flow-down might make you a contractor and you're not certain, "Not sure" keeps that lane visible as conditional so it's never dropped.
Are you a US federal agency?
Yes
No
Not sure
Are you a state or local government body?
Yes
No
Not sure
Are you a vendor or contractor to a government?
Yes
No
Not sure
A US federal agency usually isn't also a vendor to government or a state/local body; those describe different organizations. An agency is part of the government; a vendor sells to it. If you're a government corporation (e.g. USPS, TVA) or a contractor-operated entity, check the capacities that truly apply; if you're unsure, "Not sure" is the right answer.
If you contract with a government: are you specifically a contractor to the US Department of Defense?
Skip if you answered "No" to the contractor question above. The FY2026 NDAA covered-AI ban (DeepSeek / High Flyer) binds DoD contractors specifically.
Yes
No
Not sure
Are you a regulated insurer or health-benefit plan?
Insurance-department AI rules and guidance (Colorado's regulation and New York's DFS guidance) apply specifically to licensed insurers and health plans. A company that merely touches insurance data usually isn't covered. If your insurance role is unusual and you're not certain it counts, "Not sure" keeps it visible as conditional so it's never dropped.
Yes
No
Not sure
Are you a supervised banking organization (a bank, thrift, or their holding company)?
Federal model-risk guidance (SR 26-2) sets supervisory expectations for supervised banking organizations, most directly those over $30B in assets. A fintech or retailer that merely offers credit is generally not one, but if you're unsure, "Not sure" keeps it visible as conditional.
Yes
No
Not sure
Where do decisions made with AI reach people? (select every one that applies)
Colorado — consumers
California — consumers, job applicants, or employees
New York State — insurance customers
NYC — job applicants or employees
Texas — any operations
Illinois — job applicants or employees
Connecticut — job applicants or employees
New Jersey — consumers, job applicants, or employees
Utah — consumers
Other states only
Select every area where AI helps make or inform decisions about individuals.
"Essential / government services" means AI that helps decide a person's access to public benefits (like Medicaid, unemployment, or housing assistance), essential utilities, emergency services, or services from public-service providers such as hospitals and schools.
Employment / promotion
Education
Lending / credit
Housing
Insurance
Healthcare
Essential / government services
None of these
Do you provide healthcare services or treatment?
Yes
No
Not sure
Does your business meet a CCPA threshold?
You likely qualify if you're a for-profit business doing business in or selling to California, and any one of these is true:
Over $25M in total annual revenue (all sources, including revenue earned outside California)
You buy, sell, or share the personal information of 100,000+ California residents or households in a year
50% or more of your revenue comes from selling or sharing personal information
This is about doing business in or selling to California; being headquartered elsewhere doesn't get you out of it. A company based anywhere can qualify if it reaches California residents. If you're not certain, "Not sure" is the right answer, and we'll show you how to confirm it.
Yes
No
Not sure
Which compliance programs do you already run? (shapes how we'd build on what you have)
HIPAA
SOC 2
ISO 27001
ISO 9001
NIST 800-53
NIST 800-171 / CMMC
FedRAMP
PCI DSS
HITRUST
Privacy program
No formal program yet
The scan is an informational applicability screen based on our verified obligation registry. It is not legal advice and not a substitute for per-system legal review.