Scope

The working documents underneath AI Law. Decoded. Opening October 15.

You get asked whether the AI Act applies to a tool someone already bought. Then whether that makes you the provider or the deployer. Then whether the transparency rules apply. Then what to ask the vendor before legal signs anything.

Four questions. All of them are the same question.

It comes down to scope: which rules actually bind you. That question has an answer. It just isn’t written down anywhere in your company, which is why the same argument keeps arriving at the same meeting and leaving it unresolved.

Scope is where it gets written down.


What it is

A set of working documents for whoever ended up owning AI governance.

Not explainers about the regulation. The documents themselves: the regulation map, the role assignment, the vendor questions. Written to be used, and kept current as the law moves.

The regulation map took me about three months to build the first time, and most of that was not reading. It was working out which legal entity does what, whether a tool touches retail customers, and who owns which system.

It has also never been finished, which is the entire reason Scope is a subscription and not a download.

Everything arrives as a post you can read in your inbox, and as a file you can keep: PDFs, spreadsheets, templates. Download them, print them, put them in the folder where your evidence lives.


A page of it

From the scope method (just a partial excerpt from one of the resources in the stack):

The fixed layer. The regulations that bind every AI use in your organization regardless of what the use is. This layer comes from what the company is: its sector, its legal entities, the jurisdictions it operates in. For an EU bank that layer is the AI Act, DORA, the Capital Requirements Regulation and Directive, and the GDPR. Every AI system in that bank sits on top of those, whether it is a credit scoring model or a chatbot on the careers page.

You build this layer once. It changes rarely, because the company’s identity changes rarely.

The pull-in layer. For each individual AI use case, one question: which additional law does this specific use pull in?

An HR screening tool pulls in employment law. A consumer lending decision pulls in consumer credit rules. Anything customer-facing pulls in consumer protection. The fixed layer tells you the floor. The pull-in question tells you what this particular system drags in on top of it.

You answer this per use case. You do not maintain it centrally, because there is nothing central about it.

Central for what’s common. Per use case for the rest.

If you are not in the EU. The two layers work anywhere. What changes is only what goes in the fixed layer. A US bank builds its floor from its own regulators and whichever state AI laws reach it, then asks the same pull-in question for every use case. The method transfers. The research does not, which is why Scope maps the EU and shows you how to build the rest.


Why not just use the free resources

The free resources are good. artificialintelligenceact.eu is the best public guide to the AI Act and I use it constantly. Law firms publish alerts. A chatbot will summarise Article 25 for you in about four seconds.

None of them can tell you what your company is.

Public guides explain the law. Scope gives you the documents that say which parts of it bind you, what role you are actually in, and what to put in front of procurement. One is a reference to the regulation. The other is a reference to the work.

And the questions that cost the most are the ones a model answers confidently and wrongly. Whether bolting RAG and internal data onto a vendor’s model makes you a provider. Whether a third party fine-tuning on your behalf changes your role. Whether a use the vendor never intended flips your obligations.

I will tell you where the line sits. Where it isn’t settled, I will say that too.


Who this is for

The in-house lawyer, the compliance lead, the product manager, or whoever got handed “the AI thing” because they seemed least busy.

Also: not every company needs the full version. A twenty-person startup running one off-the-shelf tool needs a page and a decision, not a program. If that is you, do not subscribe. The free articles below will get you there, and five of the vendor questions will be published free in September.

If you are outside the EU: find out whether this is your problem before you spend anything. Why the EU AI Act Matters Even If You’re Not in the EU is free and answers it: the three hooks in Article 2(1), five scenarios where you are caught, four where you are not, and the Article 22 requirement to appoint an EU representative before you place anything on the market. Read that first. If none of it lands on you, Scope is not for you yet.

Scope covers the EU AI Act and covers it properly, rather than covering five regimes badly. Colorado, California, Texas, the UK and Singapore get written about on the newsletter. They do not get a document here until I can do them to the same standard.


What’s there on October 15

The scope method and regulation map Two layers, as above. The fixed floor of regulations that bind every AI use in your organization, and the per-use-case question that catches what each system pulls in on top. The method that ends the argument about whether any of this applies to you, with sources attached.

Role assignment: provider or deployer The question I get asked more than any other. Run as sold, tuned to your specification, shipped under your own name, wired into your own data. Which of those changes your role, which doesn’t, and why the size of the behavior change is not the test.

The vendor questions Twenty questions to ask before anyone signs. For each one: why it matters, what a good answer sounds like, what an evasive answer sounds like, and what you need in writing. Built for procurement, not for a seminar. Five of them go out free in September; the full set is here.

The AI inventory spreadsheet A working template with the columns that matter: system, owner, the decision it touches, the vendor, the role, the data. Classification only works once you know what you are classifying, and the inventory is harder than the regulation map.


What you are actually paying for

Maintenance. Every document carries the date it was last checked, and every one gets revisited when the law moves: new guidance, a Commission Q&A, a delegated act, an omnibus amendment that quietly changes a date. The change log is public, so you can see the work whether or not you subscribe.

New documents arrive on top of that, roughly monthly. In order:

  • The AI governance framework checklist. Everything that belongs in a complete framework, listed, so you can see at a glance what you have, what you are missing, and what you can defensibly skip.

  • The AI policy template. The internal policy itself. What has to be in it, what is optional, and what people put in that does nothing except create obligations they then breach.

  • AI literacy documentation. What a defensible Article 4 record looks like, sized three ways: startup, mid-size, large. No certificate is required. Documented measures are.

  • Article 50 transparency. Which disclosures you owe, to whom, and what “clearly and distinguishably” has come to mean in practice.

  • The deployment patterns, one at a time. Run as sold. Fine-tuned. Wrapped. RAG and internal data. Agentic and employee-built tools.

  • Then one more each month, chosen from what subscribers are actually stuck on.


What Scope isn’t

Not legal advice. Not a community. No calls, no forum, no office hours.

You read the documents and you use them. That is the whole arrangement.

These documents are information, not legal advice. Reading them creates no lawyer-client relationship, and you apply your own judgement to your own situation. They are independently authored, written outside my employment and unconnected to any employer’s work product.


If you want to see how I work first

Everything on AI Law Decoded stays free. Three to start with:

If those are useful to you, Scope is the same thinking in a form you can hand to someone else.


What other people say

“In our collaboration on AiValuations, she helped turn complex technical evidence into clear, legally careful materials that governance, risk, and executive audiences can actually use. Her ability to separate technical observations from legal conclusions made the work stronger and more credible.”

— John Holman, engineer, Awakened Intelligence.
(We have collaborated on AiValuations, so read it knowing that.)


The early rate

Pledge before October 15 and you pay the early rate: $15 a month, or $150 a year.

Scope opens on October 15. Pledges convert that day at the rate you locked in. On 16 October the price goes to $30 a month, or $300 a year.

If you came in before October 16 you keep $150 for as long as you stay subscribed. Substack holds that automatically, so there is nothing you need to do.

How pledging works: you enter your card and nothing is charged. No money moves until October 15. If it never launches, you are never billed.

Organization rate: $800 a year. Same documents, different permission. One subscription covers circulating them inside your company: forward the vendor questions to procurement, put the inventory template in a shared drive, attach the regulation map to a board paper. Select the Founding Member option for that.

What you may do with them. On the individual rate, the documents are for you: use them in your own work, quote them, cite them. Circulating them across your organization needs the organization rate. Neither rate permits republishing them publicly or reselling them. If you are unsure whether what you want to do is covered, ask me and the answer will almost certainly be yes.


For expensing it

Most subscribers will put this on a company card. Something along these lines usually helps get an easy sign-off from management:

A maintained regulatory reference for our EU AI Act obligations, covering which regulations apply to us, role classification per system, and vendor due diligence for procurement. Updated as guidance changes. $150 a year (which is roughly one hour of external counsel).


Written by

Silvia Stepitova. AI Regulatory Lawyer. I spent six years at Amazon, where I led a GenAI project that ended up in the Wall Street Journal. I now build the AI governance framework inside a regulated financial institution, which means I am writing these documents because I need them, not because I read about them.


Subscribe to AI Law. Decoded. and then click “Pledge your support”

Someone at your company will have to write all of this down eventually. The only real question is whether it happens before somebody asks, or after.