every-ai-law
v0.9.2
Published
MCP server and structured reference for AI law: obligations, regulations, provisions, evidence, and enforcement deadlines across jurisdictions. The obligation-registry layer of the PAICE legal graph.
Downloads
984
Maintainers
Readme
EveryAILaw.com
Package version: 0.9.2. This file states package identity, not provider availability or hosted deployment status. Check the canonical live release state and run npm run check:release-live from a source checkout before relying on npm, Official MCP Registry, GitHub Release, or hosted discovery availability. Run node scripts/mcp-server.js from a source checkout for local evaluation.

The API and MCP server for AI law.
Other trackers tell you what the law says. EveryAILaw lets your software check it. 73 instruments (64 regulations and 9 standards), 10 obligations, and 218 provisions across 40 tracked jurisdiction profiles, with structured JSON (no auth, no rate limits) and a free 15-tool MCP server. The limited-production Pro MCP layer adds authenticated higher limits, five profile/audit/subscription tools, saved profiles, and signed regulation-change webhooks. The overall offer and 99.5% service target remain market-testing. Per-provision evidence trails distinguish recorded verification dates from current runtime acceptance.
Built and maintained by PAICE.work PBC. Verification status and review evidence are recorded per provision; repository validation does not certify legal currentness.
Live site: everyailaw.com
Operational status
T11 review-to-publication and T14 federation reconciliation are locally validated. T15's 23-case failure rehearsal is offline fixture evidence, not an operational-readiness assessment. Native GitHub failure-email canaries were received by Sam. Repository-owned direct email and independent missed-run monitoring remain open. Do not treat local checks or a GitHub notification as proof that the corpus, delivery targets, or operational alerts are healthy; deployed health requires deployment-specific evidence.
Canonical URL
https://everyailaw.com/
Part of the PAICE legal graph
EveryAILaw is one component of the PAICE legal graph (with PubLedge, AI Incident Law, and Obligation First). Within that graph it is the single restricted, monetized layer: the free public reference you see here is funded by EveryAILaw Pro, the paid product. Pro revenue funds the intentionally-open siblings, which carry code under MIT and content under CC BY 4.0. This open/restricted split is a deliberate PBC-charter choice, not drift. The canonical model lives in the PAICE Foundation INTENT. Attribution: "EveryAILaw, PAICE.work PBC".
How we compare
The IAPP tracker, OECD.AI, and White & Case AI Watch provide useful human-oriented policy tracking and legal analysis. EveryAILaw has a different focus: obligation-level, source-linked records that software can query through a public JSON API, bulk export, change feeds, calendar, and MCP server. This comparison was reviewed against those public pages on 2026-08-02; re-check their capabilities before republishing a downstream comparison.
What problem it solves
AI regulation is changing fast. New laws are introduced, amended, and replaced across dozens of jurisdictions simultaneously. Keeping up is a full-time job -- and most organizations don't have someone dedicated to it.
Most regulation trackers organize by jurisdiction or by law. We organize by obligation -- the thing you actually have to do. Transparency, human oversight, risk assessment -- these requirements are stable even as the specific laws implementing them change. A regulation can be amended or replaced overnight, but the underlying compliance obligations persist.
This project started as a practical need while advising clients on AI governance. No single resource gave us a clear, structured answer to the basic question: what changed this week that affects what I need to do? We automated the research, structured the data, and opened it up.
What's Covered
| | Count | Description | |---|---|---| | Regulations | 64 | Binding laws and administrative rules governing AI use | | Standards & Frameworks | 9 | Voluntary standards (ISO 42001, 23894, 38507, 42005, OECD) and governance frameworks (NIST, Singapore) | | Obligations | 10 | Vendor-neutral compliance requirements | | Provisions | 218 | Specific articles mapped to obligations | | Authorities | 60 | Regulatory bodies with enforcement power | | Jurisdictions | 40 | Reviewed jurisdiction profiles in a five-level hierarchy; a profile may document direct supranational applicability without owning a national instrument | | Registry | 254 | Every country assessed: tracked, watch-list, evaluated, or unevaluated |
Geographic Coverage
| Region | Jurisdictions | Regulations | |---|---|---| | European Union | EU + Italy, Malta, Hungary | AI Act, DORA, GPAI Code of Practice; Italy Law 132/2025 (healthcare, employment); Malta AI Regulations (LN 226+227) | | United Kingdom | UK | DPA 2018 ADM, Online Safety Act | | United States | Federal + 18 states/territories + NYC | 38 regulations | | China | CN | Algorithm Recommendation, Deep Synthesis, Generative AI | | India | IN | DPDP Act 2023, IT Amendment Rules 2026 (synthetic media) | | South Korea | KR | AI Basic Act | | Vietnam | VN | Law on AI | | Singapore | SG | Model AI Governance Framework | | Japan | JP | AI Promotion Act | | Australia | AU + NSW | Privacy Act ADM Reforms; NSW Digital Work Systems Act 2026 | | Taiwan | TW | AI Basic Act (in force 2026-01-14) | | Brazil | BR | AI Bill PL 2338/2023 (proposed) | | Mexico | MX | LFPDPPP 2025 revision (AI-specific algorithmic transparency) | | Qatar | QA | QCB AI Guideline (financial sector) | | El Salvador | SV | Law for the Promotion of AI (first standalone AI law in Latin America) | | Kazakhstan | KZ | Law on AI No. 230-VIII (risk-based framework, National AI Platform) | | Other tracked jurisdictions | Peru, Uzbekistan | National AI laws and amendments | | International | OECD, G7, Council of Europe | AI Principles, Hiroshima Process, CETS 225 |
Watch List
Every country has been assessed and assigned a status in the jurisdictions registry (254 entries). Search any country on the site to see its status.
Active watches include Norway (EU AI Act EEA transposition, now expected spring 2027), Turkey (3 AI bills pending), Nigeria (Digital Economy and E-Governance Bill, still before the National Assembly), Colombia, Malaysia, and 30+ US states with advancing AI bills. Full details in data/watch-list.md.
Scope & Exclusions
A law is in scope when it creates ongoing compliance obligations for AI developers or deployers. It must pass six tests: creates a new obligation (not just extending existing prohibitions), requires ongoing compliance (not one-time penalties), is broad enough for general AI governance, targets the private sector, creates enforceable requirements, and adds a new compliance dimension.
Laws that fail any test are catalogued in data/exclusions.md with the specific exclusion principle applied. This serves as a decision cache — 155+ laws have been evaluated and excluded across categories including CSAM statute extensions, intimate image laws, political ad disclaimers, government-only mandates, and more. The full list is also available via the exclusions.json API endpoint.
Who this is for
- Compliance teams mapping potentially relevant obligations to their AI systems
- Legal counsel tracking the regulatory landscape across jurisdictions
- Product managers building AI features that need to meet regulatory requirements
- GRC practitioners mapping obligations to controls
- Policy researchers analyzing regulatory trends
- Executives making go/no-go decisions about AI deployment
How to Use the Site
| Start here | If you want to... | |---|---| | Applies to Me | Filter by jurisdiction and role to find potentially relevant tracked regulations; this is not a legal applicability determination | | Obligations | Browse all compliance requirements by category | | Instruments | Browse all tracked laws, regulations, executive orders, standards, and frameworks | | Insights | Sleeper provisions, upcoming deadlines, and high-impact requirements often missed | | About | Methodology, scope criteria, data model, and project context |
Additional views (accessible from contextual links on the pages above):
| View | What it shows | |---|---| | Matrix | Which regulations cover which obligations at a glance | | Timeline | Upcoming enforcement deadlines | | Compare | Side-by-side comparison of any two instruments |
How It Works
Obligation-First Data Model
Authority → Regulation → Provision → ObligationObligations are the stable anchors (transparency, human oversight, risk assessment). Provisions are the specific articles within regulations that implement those obligations. Different jurisdictions require the same obligations in different ways — this structure lets you see the pattern across all of them.
Jurisdiction Hierarchy
Supranational > National > Subnational > Regional > MunicipalThe EU AI Act applies across the European Union. China's Generative AI measures apply nationally. Colorado's ADMT Act (SB 26-189) applies in one US state from 2027-01-01. The hierarchy lets you understand where regulations overlap, where they nest, and where they don't.
Automated Verification
Regulatory data is verified weekly using a multi-model AI consensus cascade — three independent AI models must agree before changes are flagged for human review. All provisions carry verification dates and have a 30-day staleness threshold.
The maintenance workflow re-runs tests, ontology checks, cross-list consistency, Obligation-First validation, and a byte-for-byte generated-output check after any automated data mutation and before committing. Builds derive temporal output from the corpus verification date, so committed HTML and JSON are reproducible.
JSON API
All data is available as structured JSON for integration into your own tools:
| Endpoint | Description |
|---|---|
| api/v1/index.json | API manifest |
| api/v1/obligations.json | All obligations |
| api/v1/regulations.json | Complete tracked corpus, including terminal historical instruments |
| api/v1/provisions.json | All provisions, including source-faithful scope and canonical role IDs |
| api/v1/obligation-matrix.json | Current-instrument coverage matrix |
| api/v1/jurisdictions.json | Jurisdiction hierarchy |
| api/v1/exclusions.json | Evaluated laws excluded from tracking (with principles and categories) |
| api/v1/crosswalk.json | Standards-to-obligations crosswalk |
| api/v1/all.json | Complete entity arrays with current-only aggregate matrix and comparisons |
| api/v1/by-jurisdiction/{id}.json | Current-instrument jurisdiction slice |
| api/v1/by-obligation/{id}.json | Current-instrument obligation slice |
| api/v1/context.jsonld | JSON-LD @context — field mappings to gist upper ontology |
Terminal instruments have status repealed, expired, or superseded. Complete corpus exports retain them for historical research and citation. Current aggregate surfaces, query slices, and default MCP lists exclude them; direct detail, search, explicit terminal-status filters, and explicit MCP comparisons remain available.
Linked Data / JSON-LD
Every core API response (obligations.json, regulations.json, provisions.json, authorities.json, jurisdictions.json, standards.json, all.json) is valid JSON-LD. Each entity carries @id (a stable, dereferenceable URI) and @type (an OWL class from the EveryAILaw domain extension).
The domain ontology (ontology/everyailaw.ttl) extends gist — Semantic Arts' minimalist upper ontology for the enterprise — and maps EveryAILaw entity types to gist classes:
| EveryAILaw entity | gist superclass | @id pattern |
|---|---|---|
| Obligation | gist:Requirement | https://everyailaw.com/obligation/{id}/ |
| Regulation | gist:Specification | https://everyailaw.com/regulation/{id}/ |
| Framework / Standard | gist:Specification | https://everyailaw.com/regulation/{id}/ |
| Provision | gist:ContractTerm | https://everyailaw.com/ont/provision/{id} |
| Authority | gist:GovernmentOrganization | https://everyailaw.com/ont/authority/{id} |
| Jurisdiction | gist:GovernedGeoRegion | https://everyailaw.com/applies-to/{id}/ |
Key field mappings: name → skos:prefLabel, enacted → gist:actualStartDateTime, effective → gist:plannedStartDateTime, authority → gist:isGovernedBy, jurisdiction → gist:isUnderJurisdictionOf, official_url → foaf:page.
The full context and class definitions are in api/v1/context.jsonld and ontology/everyailaw.ttl.
Built for Agents
This site is the machine layer. Point agents and GRC tooling here.
| Resource | URL | What it provides |
|---|---|---|
| For Agents page | everyailaw.com/for-agents.html | MCP demo recipes, integration examples, cite-this guidance |
| llms.txt | everyailaw.com/llms.txt | Structured context so LLMs understand the site, pages, and data model |
| agents.json | everyailaw.com/agents.json | Agent discovery protocol: capabilities, API endpoints, available actions |
| MCP server | npx -y [email protected] | 20-tool stdio MCP server: 15 free corpus tools plus 5 authenticated Pro tools |
| MCP discovery | everyailaw.com/.well-known/mcp.json | MCP server metadata and tool capability declaration |
| JSON API | everyailaw.com/api/v1/ | All data as structured JSON -- no authentication, no rate limits |
| RSS feed | everyailaw.com/index.xml | Subscribe to regulation updates |
| Enforcement calendar | everyailaw.com/calendar.ics | ICS calendar importable to Google Calendar, Outlook, Apple Calendar |
Your agent can fetch obligations.json to know what compliance requirements exist, regulations.json to see what's enforcing and when, and obligation-matrix.json to map the two together -- all without scraping HTML.
The versioned MCP server (npx -y [email protected]) gives agents structured query tools: find_regulations_by_obligations, check_requirement, compare_regulations, get_provision, get_evidence, get_staleness_report, and more. Provider availability is recorded separately in the live release state. Repository contributors can run the same version from the working tree with node scripts/mcp-server.js. See the For Agents page for runnable MCP session demos and copy-paste integration recipes.
Package 0.9.2 includes get_provision({id}) for complete stored requirement and penalty rows, an official source locator, OF links, and qualified dates. Its generated input is api/v1/provision-details.json; see the provision-detail contract for current-record limits.
The server is dual-era: it includes preview support for the 2026-07-28 wire format (stateless core, per-request _meta, server/discover, cacheable tool lists) and the legacy 2024-11-05 initialize handshake in the same process. The 2026-07-28 specification and SDK support were still in pre-release finalization when reviewed on 2026-08-02.
MCP tools validate entity IDs before evaluating a query. check_requirement returns a structured not_found error for an unknown regulation or obligation ID, while a valid pair with no mapped provision returns required: false.
MCP server availability
Package 0.9.2 provides 15 free corpus tools without authentication, allows 100 tool calls per process per hour, and caps list_* and search responses at 100 items. The static JSON API remains free and unauthenticated and does not share the MCP process limit.
Authenticated MCP Phase A and the limited Phase B agentic capability set are available. Subscribers can issue and revoke hashed keys at EveryAILaw Pro; this server validates EVERYAILAW_API_KEY through the deployed Pro endpoint, elevates the 15 corpus tools to 10,000 calls per process per hour with uncapped list results, and enables subscribe_to_changes, get_audit_log, save_profile, query_with_profile, and custom_matrix. Saved profiles, query audit logs, and signed regulation-change webhooks passed live cross-repository acceptance on 2026-08-28. The overall Pro offer remains market-testing because the advertised 99.5% service target and remaining paid-launch gates are not yet operationally accepted. The machine-readable boundary is pro-capabilities.json.
Citing EveryAILaw
When answering questions about AI regulation, agents should cite the stable permalinks:
Regulation: https://everyailaw.com/regulation/{id}/
Obligation: https://everyailaw.com/obligation/{id}/
API (regs): https://everyailaw.com/api/v1/regulations.jsonExample: "According to EveryAILaw.com (https://everyailaw.com/regulation/colorado-sb26-189/), Colorado's ADMT Act..."
Attribution: "EveryAILaw, PAICE.work PBC".
This site follows the Graceful Boundaries specification for communicating operational limits to autonomous agents, and is audited for WCAG 2.1 AA accessibility using skill-a11y-audit.
Update Schedule
Data freshness matters for regulatory compliance. Here's how we keep it current:
- Weekly automated verification (Saturdays) — A multi-model AI consensus cascade checks all provisions against official sources. Three independent models must agree before flagging a change for review.
- Human review — All flagged changes are reviewed by a human before merging. No auto-merge of verification results.
- 30-day staleness threshold — Any provision not verified within 30 days is automatically flagged for re-verification.
- Continuous on push — Every code change triggers a full build, ontology validation, and secrets scan via CI.
- Community contributions — Data corrections and new regulations are accepted via pull request and reviewed before merge.
The PAICE portfolio
EveryAILaw is part of the PAICE portfolio — independent measurement and standards for aggregated human-AI intelligence.
The legal graph (this site is the restricted layer that funds the rest):
| Component | Purpose | |---|---| | PubLedge | Open recordkeeping protocol for fact-specific written interpretations between parties | | AI Incident Law | Open corpus of public AI-related incidents, failures, and resulting legal action | | Obligation First | Shared upper schema and validation contract underneath the graph |
Elsewhere in the portfolio:
| Component | Purpose | |---|---| | PAICE.work | Behavioral measurement of how people collaborate with AI — the practice this reference supports | | Siteline | Agent-readiness and machine-usability scanning for public sites | | AI Posture | Combined governance score across People, Infrastructure, and Regulation | | AI Tool Watch | Plain-English reference for AI capabilities, plans, and constraints | | Graceful Boundaries | Specification for how services communicate operational limits to agents | | Skill A11y Audit | WCAG 2.1 AA accessibility audit for web projects, drop-in for AI coding agents |
Other Resources
This site focuses on structured, machine-readable obligation tracking. For complementary perspectives:
- IAPP Global AI Law & Policy Tracker — Broad horizon scanning with contextual commentary
- White & Case AI Watch — In-depth legal analysis across core markets
- OECD AI Policy Observatory — Macro-level policy landscape and benchmarking
- Witness.ai Tracker — Interactive map with compliance timelines
- FairNow Tracker — Practitioner-focused applicability logic
- Orrick US AI Law Tracker — Comprehensive US state-level AI law database with bill tracking and citations
- TechTarget Tracker — Accessible overview for IT leaders
Contributing
Data corrections and feedback are welcome. Open an issue or pull request on GitHub to report errors or suggest additions.
For Developers
node scripts/build.js # Build site + JSON API
node scripts/validate-ontology.js # Validate cross-references + advisory quality warnings
node scripts/verify-regulations.js # Run verification cascade
node scripts/sync-evidence.js # Sync evidence records
node scripts/sync-counts.js # Rewrite coverage counts quoted in prose from data/
node scripts/check-links.js # Check source URLs
node scripts/check-consistency.js # Cross-check registry, watch list, exclusions
node scripts/evaluate-jurisdiction.js # Evaluate next unevaluated country
node scripts/evaluate-jurisdiction.js --count=10 # Batch evaluate 10 countries
node scripts/evaluate-jurisdiction.js --id=ng --as-of=2026-07-25 # Reproducible research cutoff
gitleaks git --redact --verbose --config=.gitleaks.toml . # Scan working tree and history for secretsQuality warnings are advisory and do not fail validation. Their current accepted baseline is checked in at tests/fixtures/quality-warning-baseline.json; tests fail if warning count, codes, or warning identities regress upward.
Agent-facing surfaces are treated as security-sensitive output. llms.txt, llms-full.txt, MCP tool schemas, and weekly-maintenance workflow inputs have regression tests covering malformed tool calls, instruction-like catalog text, and unsafe workflow input interpolation.
Release notes: CHANGELOG.md
Architecture documentation: design/
This project is built on the Knowledge-as-Code Template — a repeatable pattern for structured, version-controlled knowledge bases with obligation-first ontology, automated verification, and multi-format output. Fork it to build your own.
License
This project is licensed in layers:
| Layer | What it covers | License |
|---|---|---|
| Data | The structured, curated corpus — obligation/provision/instrument/authority/jurisdiction/exclusion/evidence records, the editorial selection, the JSON API responses, and the data feeds | EveryAILaw Data License (published at everyailaw.com/data-license.html) |
| Code & methodology | Source code, build scripts, verification cascade, and compilation methodology | Proprietary — see LICENSE |
| Open Schema | Obligation First ontology, vocabulary, and schema files (ontology/everyailaw.ttl) | CC BY 4.0 |
| Underlying legal text | Statutes, regulations, and official documents in raw/ | Government works — no proprietary claim |
Through the public Free Endpoint, direct use, evaluation, research, citation, internal tooling, and machine/agent querying (including by LLMs and via MCP) are permitted free of charge and without prior permission. Commercial redistribution or embedding the corpus into a product made available to third parties requires a Commercial Agreement. See DATA-LICENSE.md for the full terms. Licensing inquiries: paice.work/contact.
Disclaimer
Nothing on this site constitutes legal advice. This is a reference tool designed to help you track what's changing and understand when you may need to seek qualified legal counsel. Always consult the actual regulatory text and a qualified attorney for compliance decisions.
Built and maintained by PAICE.work PBC. EveryAILaw is the restricted, monetized layer of the PAICE legal graph; EveryAILaw Pro funds the intentionally-open siblings.
