SAT, SEPTEMBER 26, 2026
Independent · In‑Depth · Practitioner‑Tested
Claude Productivity

Six Prompts to Map Your AI Regulatory Exposure

The Ban Artificial Superintelligence Act was introduced on 23 September with 20-year prison terms and a development pause, and it defines superintelligence in prose with no compute threshold. It is unlikely to pass. The point of reading it is that the definitions being drafted now are the ones you will be measured against later, and vague definitions catch more than precise ones. These six prompts map where a deployment actually sits.

⌨️ 6 prompts 🕐 Updated Sep 26, 2026
💡 How to use these prompts: Replace everything in [BRACKETS] with your specific details before sending. Click Copy to copy any prompt to your clipboard instantly.
1
Which Rules Actually Reach Me
Most compliance panic comes from reading proposals as if they were law. Sort them first.
Here is what my product does, where my users are, and where my infrastructure runs.<br/><br/>List every AI-specific regulation or proposed regulation that plausibly applies, and for each state:<br/>1. Whether it is in force, proposed, or speculative<br/>2. The specific provision that reaches my case<br/>3. What it requires me to do<br/><br/>Separate in-force obligations from proposals clearly. Do not blend them into one list - I need to know what I must do now versus what I should watch.<br/><br/>If a regulation probably does not apply to me, say so and say why.<br/><br/>DEPLOYMENT:<br/>[paste]
2
Stress-Test a Vague Definition Against My System
Vague definitions are decided by whoever documented their position first. This produces that document.
A draft bill covers AI that "exceeds human cognitive performance and capabilities across most domains." There is no compute threshold, benchmark, or evaluation standard attached.<br/><br/>Take my system described below and argue BOTH sides:<br/>1. The case a regulator would make that it falls inside this definition<br/>2. The case I would make that it falls outside<br/><br/>Then tell me which specific facts about my system decide it, and which of those facts I could document now to make the second argument easier later.<br/><br/>SYSTEM:<br/>[paste]
3
Find the Documentation Gap
The gaps that matter are the ones you cannot backfill. Find those before you need them.
Given the obligations below that apply to my deployment, audit what I would need to produce if a regulator asked tomorrow.<br/><br/>For each obligation: what evidence satisfies it, whether I appear to have that evidence based on what I have described, and what I would have to reconstruct.<br/><br/>Rank the gaps by how hard they are to fill retroactively. Anything that requires contemporaneous records - training data provenance, evaluation results at time of release, incident logs - goes at the top, because those cannot be recreated after the fact.<br/><br/>OBLIGATIONS AND CURRENT STATE:<br/>[paste]
4
Map Model Provider Risk Into My Stack
Fable 5 was suspended by export directive for 20 days this year. Provider regulatory risk is your outage.
My product depends on the model providers listed below.<br/><br/>For each, identify regulatory events that would disrupt my service, not theirs: export controls on their models, a development pause reaching their release cycle, jurisdiction restrictions, or a forced change to their terms.<br/><br/>For each risk, tell me what my fallback would be and how long switching would take. Be specific about whether my prompts, fine-tunes and evaluation suites would transfer.<br/><br/>PROVIDERS AND DEPENDENCIES:<br/>[paste]
5
Write the Position Statement Before You Need It
Every company writes this eventually. Writing it calmly beats writing it in a news cycle.
Draft a one-page statement of how my system works, what it can and cannot do, and what controls are in place.<br/><br/>Write it for a non-technical regulator or journalist, not an engineer. Requirements:<br/>1. No claims I cannot evidence<br/>2. State limitations plainly rather than burying them<br/>3. Name the specific controls, not "robust safeguards"<br/>4. Flag in brackets any claim where I need to check a fact before publishing<br/><br/>SYSTEM AND CONTROLS:<br/>[paste]
6
Separate Real Obligations From Vendor Marketing
Compliance theatre is sold as compliance. This separates what you must do from what someone wants to sell you.
Below are compliance claims and requirements a vendor has told me apply to my use of their product.<br/><br/>For each, tell me whether it is: an actual legal obligation, a contractual obligation they have imposed, an industry norm with no force, or marketing.<br/><br/>Cite the source of the obligation where one exists. Where a vendor is presenting their own product requirement as a regulatory one, say so plainly.<br/><br/>VENDOR CLAIMS:<br/>[paste]