Your AI is either an Asset or a Liability. We make sure it isn't a Fine.
The EU AI Act is enforced from August 2026. UK GDPR is already active and the ICO is enforcing. We build your compliance framework in plain English, specific to how your business actually uses AI. Fixed price. Plain English. No lock-in.
Tick what your business actually does.
apply to you
Nothing selected — tick one above and watch.
Which AI laws apply to you?
Tick what your AI and automation actually do. In 30 seconds, see exactly which regulations you've triggered across the UK, EU and US — the deadline and the maximum fine for each. No account needed to see your result.
Check your AI risk — free →Global. Straightforward. No nonsense.
"I started Ops Intel because I watched too many good businesses use AI tools without any compliance framework — and assume that because nothing had gone wrong yet, nothing would."
"The ICO doesn't need a new law. UK GDPR already covers AI. Most businesses are non-compliant and don't know it. That's the problem I built Ops Intel to fix."
"We get you compliant first. Then visible. Then running your AI team. In that order — because that's the only order that makes sense."
Most businesses using AI are already non-compliant.
Here's what that costs.
The ICO doesn't need a new AI law. UK GDPR already applies to every AI system that processes personal data. If you have EU customers, the EU AI Act is live. If you use AI in US hiring decisions, state law already applies. Regulators issued their first AI-specific fines in Q1 2026 — and the amounts aren't trivial.
Maximum fine for non-compliance with the EU AI Act for prohibited AI practices. GPAI (general-purpose AI) obligations are already in force. High-risk AI deadlines land December 2027.
Maximum fine under UK GDPR for organisations that fail to protect personal data — including data processed by AI tools. The ICO is actively investigating AI systems right now.
Per violation under Texas and Illinois AI laws. US state AI legislation is accelerating — with consumer protection fines that compound per affected individual.
If you use ChatGPT with client data, you are already non-compliant under UK GDPR without a lawful basis and a Data Processing Agreement.
If you have EU customers and use any AI tool, the EU AI Act already applies to your business — regardless of where you're based.
Most compliance policies online are generic templates that won't protect you. A policy must be specific to how your business actually uses AI.
Fixed price. Plain English. Specific to your business. Not a template.
A policy is a document.
A framework is a system.
Most firms have a policy in a folder somewhere. What a regulator asks for is evidence that it is enforced, reviewed and current — and that is six documents, not one.
The AI Compliance Framework
Six documents. One system. Fixed price.
- Acceptable Use Policy
- Data Classification Matrix
- GDPR Compliance Position
- Employee Training & Acknowledgement
- AI Risk Register
- Incident Response Procedure
Not ready for all six? Start with the policy.
Three to eight pages setting out how AI may be used in your business, in plain English. It does not stop your team using AI. It stops them using it dangerously.
Get your AI policyTrading in more than one country? More than one law applies.
Which ones depends on where your customers are, where your staff are and where your AI has effect — not where the business is registered.
- UK
- EU
- US
- Canada
This is the thing itself.
Not a picture of one.
A genuine UK + EU Combined Compliance Framework, produced by the same system that will produce yours, for a fictional firm of solicitors we invented to test it. Written around what that firm actually does with AI — which is why it is long, and why a template could never have been.
Read it page by page
14 dates that decide whether you are compliant.
8 of them have already passed.
Which of these catch you depends on where your customers are, where your staff are and where your AI has effect. Most businesses are on more than one line.
Europe
- in force Obligations for general-purpose AI models.
- in force Article 50 transparency duties, deployer obligations, and enforcement powers for national regulators.
- coming New prohibitions, and Article 50(2) marking of synthetic content.
- coming Every Member State must have an AI regulatory sandbox running.
- coming High-risk obligations for Annex III systems — including AI used in recruitment, credit scoring, education and essential services.
- coming High-risk obligations for Annex I systems — AI embedded in products already covered by EU product safety law.
United Kingdom
- in force Most Part 5 data protection provisions of the Data (Use and Access) Act 2025, including the wider lawful bases for solely automated decisions and the safeguards that come with them.
- in force The duty on controllers to operate a complaints procedure and respond to data protection complaints within set time limits.
United States
- in force Texas HB 149, the Responsible Artificial Intelligence Governance Act — prohibited uses, government AI disclosure, and Attorney General enforcement.
- in force California SB 942, the AI Transparency Act — free AI detection tool and latent provenance disclosure for large generative AI providers. Delayed from 1 January 2026 by AB 853.
- coming Colorado SB 26-189 — developer and deployer duties for automated decision-making technology used in consequential decisions. It repealed and reenacted SB 24-205, which never took effect.
Canada
- in force Ontario ESA / O. Reg. 476/24 — a publicly advertised job posting must disclose the use of AI to screen, assess or select applicants. Employers of 25 or more, including where a third party screens on their behalf.
Australia
- coming Privacy Act 1988 (Cth), APP 1.7 — a privacy policy must say what kinds of personal information a computer program uses to make decisions that could reasonably be expected to significantly affect a person, and what kinds of decisions those are.
United Arab Emirates
- in force DIFC Data Protection Regulation 10 — a business deploying an autonomous or semi-autonomous system that processes personal data must tell users, on first use, what the system decides for itself, what it was built to do and what it does with the output.
Your customers decide which law
applies to you. Not your address.
Where your customers are, where your staff are and where your AI has effect — those decide, not where the business is registered. We write frameworks to four legal systems, and serve four more on request.
- United Kingdom UK GDPR, in force now. The Data (Use and Access) Act added automated-decision duties from 5 February 2026.
- European Union The EU AI Act. General-purpose AI obligations already apply; enforcement begins 2 August 2026.
- United States State by state, not federal. Texas from 1 January 2026, California from 2 August 2026, Colorado from 1 January 2027.
- Canada PIPEDA plus provincial law. Ontario's AI hiring disclosure rules applied from 1 January 2026.
What it's like to work with us.
Before Scott got involved, our website was embarrassing — it wasn't doing us any favours. He rebuilt it completely, built us a custom property valuation tool that we're now rolling out to clients, and sorted out our AI compliance so we're covered on the data side. He also set up automations that have taken a few of the repetitive jobs off our plate.
What I found different about working with Scott is that he actually explains what he's doing and why it matters — he doesn't just disappear and come back with something. The valuation tool in particular is something clients have already noticed, and that's the kind of thing that helps us stand out in a competitive market.
If you're an estate agent thinking about your digital setup or your AI compliance, I'd go to Scott first.
- AI compliance framework
- Website rebuild
- Custom valuation tool
- Workflow automation
Everything you need to know.
More questions? Read our full FAQ →
Nobody gets a warning first.
They get a complaint, and then an investigation.
The ICO is enforcing now. The EU AI Act deadlines are live. And most businesses using AI have nothing to hand over when someone asks — no policy, no record of which tools their staff are using, nobody named as responsible for any of it.
You can spend the next year learning AI law yourself — or hand it to us for a fraction of the cost of a junior hire. In 30 minutes we'll show you exactly where you're exposed, where you're invisible to AI search, and what your AI team should take on first. No obligation. No hard sell. Just certainty.
Claim Your Free Audit →