🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

every-ai-law

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

every-ai-law

MCP server and structured reference for AI law: obligations, regulations, provisions, evidence, and enforcement deadlines across jurisdictions. The obligation-registry layer of the PAICE legal graph.

latest
Source
npmnpm
Version
0.6.0
Version published
Maintainers
1
Created
Source

EveryAILaw.com

Build Weekly Maintenance Regulations Standards Obligations Jurisdictions Data: Free Version

EveryAILaw.com

The API and MCP server for AI law.

Other trackers tell you what the law says. EveryAILaw lets your software check it. 72 instruments (63 regulations and 9 standards), 10 obligations, and 213 provisions across 43 tracked jurisdictions, with structured JSON (no auth, no rate limits) and a free 14-tool MCP server. An advertised Pro MCP offer under development targets higher limits, webhooks, saved profiles, and audit logs. Weekly 3-model verification cascade. Per-provision evidence trail with verified dates.

Built and maintained by PAICE.work PBC. Data is verified weekly through automated AI consensus and human review.

Live site: everyailaw.com

Canonical URL

https://everyailaw.com/

EveryAILaw is one component of the PAICE legal graph (with PubLedge, AI Incident Law, and Obligation First). Within that graph it is the single restricted, monetized layer: the free public reference you see here is funded by EveryAILaw Pro, the paid product. Pro revenue funds the intentionally-open siblings, which carry code under MIT and content under CC BY 4.0. This open/restricted split is a deliberate PBC-charter choice, not drift. The canonical model lives in the PAICE Foundation INTENT. Attribution: "EveryAILaw, PAICE.work PBC".

How we compare

The IAPP tracker, OECD.AI, and White & Case AI Watch provide useful human-oriented policy tracking and legal analysis. EveryAILaw has a different focus: obligation-level, source-linked records that software can query through a public JSON API, bulk export, change feeds, calendar, and MCP server. This comparison was reviewed against those public pages on 2026-08-02; re-check their capabilities before republishing a downstream comparison.

What problem it solves

AI regulation is changing fast. New laws are introduced, amended, and replaced across dozens of jurisdictions simultaneously. Keeping up is a full-time job -- and most organizations don't have someone dedicated to it.

Most regulation trackers organize by jurisdiction or by law. We organize by obligation -- the thing you actually have to do. Transparency, human oversight, risk assessment -- these requirements are stable even as the specific laws implementing them change. A regulation can be amended or replaced overnight, but the underlying compliance obligations persist.

This project started as a practical need while advising clients on AI governance. No single resource gave us a clear, structured answer to the basic question: what changed this week that affects what I need to do? We automated the research, structured the data, and opened it up.

What's Covered

CountDescription
Regulations63Binding laws and administrative rules governing AI use
Standards & Frameworks9Voluntary standards (ISO 42001, 23894, 38507, 42005, OECD) and governance frameworks (NIST, Singapore)
Obligations10Vendor-neutral compliance requirements
Provisions213Specific articles mapped to obligations
Authorities60Regulatory bodies with enforcement power
Jurisdictions43Tracked jurisdictions in a five-level hierarchy from supranational to municipal
Registry257Every country assessed: tracked, watch-list, evaluated, or unevaluated

Geographic Coverage

RegionJurisdictionsRegulations
European UnionEU + Italy, Malta, HungaryAI Act, DORA, GPAI Code of Practice; Italy Law 132/2025 (healthcare, employment); Malta AI Regulations (LN 226+227)
United KingdomUKDPA 2018 ADM, Online Safety Act
United StatesFederal + 18 states/territories + NYC38 regulations
ChinaCNAlgorithm Recommendation, Deep Synthesis, Generative AI
IndiaINDPDP Act 2023, IT Amendment Rules 2026 (synthetic media)
South KoreaKRAI Basic Act
VietnamVNLaw on AI
SingaporeSGModel AI Governance Framework
JapanJPAI Promotion Act
AustraliaAU + NSWPrivacy Act ADM Reforms; NSW Digital Work Systems Act 2026
TaiwanTWAI Basic Act (in force 2026-01-14)
BrazilBRAI Bill PL 2338/2023 (proposed)
MexicoMXLFPDPPP 2025 revision (AI-specific algorithmic transparency)
QatarQAQCB AI Guideline (financial sector)
El SalvadorSVLaw for the Promotion of AI (first standalone AI law in Latin America)
KazakhstanKZLaw on AI No. 230-VIII (risk-based framework, National AI Platform)
Other tracked jurisdictionsPeru, UzbekistanNational AI laws and amendments
InternationalOECD, G7, Council of EuropeAI Principles, Hiroshima Process, CETS 225

Watch List

Every country has been assessed and assigned a status in the jurisdictions registry (257 entries). Search any country on the site to see its status.

Active watches include Norway (EU AI Act EEA transposition, now expected spring 2027), Turkey (3 AI bills pending), Nigeria (Digital Economy and E-Governance Bill, still before the National Assembly), Colombia, Malaysia, and 30+ US states with advancing AI bills. Full details in data/watch-list.md.

Scope & Exclusions

A law is in scope when it creates ongoing compliance obligations for AI developers or deployers. It must pass six tests: creates a new obligation (not just extending existing prohibitions), requires ongoing compliance (not one-time penalties), is broad enough for general AI governance, targets the private sector, creates enforceable requirements, and adds a new compliance dimension.

Laws that fail any test are catalogued in data/exclusions.md with the specific exclusion principle applied. This serves as a decision cache — 155+ laws have been evaluated and excluded across categories including CSAM statute extensions, intimate image laws, political ad disclaimers, government-only mandates, and more. The full list is also available via the exclusions.json API endpoint.

Who this is for

  • Compliance teams determining what applies to their AI systems
  • Legal counsel tracking the regulatory landscape across jurisdictions
  • Product managers building AI features that need to meet regulatory requirements
  • GRC practitioners mapping obligations to controls
  • Policy researchers analyzing regulatory trends
  • Executives making go/no-go decisions about AI deployment

How to Use the Site

Start hereIf you want to...
Applies to MeFilter by your jurisdiction and role to see what applies
ObligationsBrowse all compliance requirements by category
InstrumentsBrowse all tracked laws, regulations, executive orders, standards, and frameworks
InsightsSleeper provisions, upcoming deadlines, and high-impact requirements often missed
AboutMethodology, scope criteria, data model, and project context

Additional views (accessible from contextual links on the pages above):

ViewWhat it shows
MatrixWhich regulations cover which obligations at a glance
TimelineUpcoming enforcement deadlines
CompareSide-by-side comparison of any two instruments

How It Works

Obligation-First Data Model

Authority → Regulation → Provision → Obligation

Obligations are the stable anchors (transparency, human oversight, risk assessment). Provisions are the specific articles within regulations that implement those obligations. Different jurisdictions require the same obligations in different ways — this structure lets you see the pattern across all of them.

Jurisdiction Hierarchy

Supranational > National > Subnational > Regional > Municipal

The EU AI Act applies across the European Union. China's Generative AI measures apply nationally. Colorado's ADMT Act (SB 26-189) applies in one US state from 2027-01-01. The hierarchy lets you understand where regulations overlap, where they nest, and where they don't.

Automated Verification

Regulatory data is verified weekly using a multi-model AI consensus cascade — three independent AI models must agree before changes are flagged for human review. All provisions carry verification dates and have a 30-day staleness threshold.

The maintenance workflow re-runs tests, ontology checks, cross-list consistency, Obligation-First validation, and a byte-for-byte generated-output check after any automated data mutation and before committing. Builds derive temporal output from the corpus verification date, so committed HTML and JSON are reproducible.

JSON API

All data is available as structured JSON for integration into your own tools:

EndpointDescription
api/v1/index.jsonAPI manifest
api/v1/obligations.jsonAll obligations
api/v1/regulations.jsonAll regulations
api/v1/provisions.jsonAll provisions, including source-faithful scope and canonical role IDs
api/v1/obligation-matrix.jsonCoverage matrix
api/v1/jurisdictions.jsonJurisdiction hierarchy
api/v1/exclusions.jsonEvaluated laws excluded from tracking (with principles and categories)
api/v1/crosswalk.jsonStandards-to-obligations crosswalk
api/v1/all.jsonCombined export (all data in one file)
api/v1/context.jsonldJSON-LD @context — field mappings to gist upper ontology

Linked Data / JSON-LD

Every core API response (obligations.json, regulations.json, provisions.json, authorities.json, jurisdictions.json, standards.json, all.json) is valid JSON-LD. Each entity carries @id (a stable, dereferenceable URI) and @type (an OWL class from the EveryAILaw domain extension).

The domain ontology (ontology/everyailaw.ttl) extends gist — Semantic Arts' minimalist upper ontology for the enterprise — and maps EveryAILaw entity types to gist classes:

EveryAILaw entitygist superclass@id pattern
Obligationgist:Requirementhttps://everyailaw.com/obligation/{id}/
Regulationgist:Specificationhttps://everyailaw.com/regulation/{id}/
Framework / Standardgist:Specificationhttps://everyailaw.com/regulation/{id}/
Provisiongist:ContractTermhttps://everyailaw.com/ont/provision/{id}
Authoritygist:GovernmentOrganizationhttps://everyailaw.com/ont/authority/{id}
Jurisdictiongist:GovernedGeoRegionhttps://everyailaw.com/applies-to/{id}/

Key field mappings: nameskos:prefLabel, enactedgist:actualStartDateTime, effectivegist:plannedStartDateTime, authoritygist:isGovernedBy, jurisdictiongist:isUnderJurisdictionOf, official_urlfoaf:page.

The full context and class definitions are in api/v1/context.jsonld and ontology/everyailaw.ttl.

Built for Agents

This site is the machine layer. Point agents and GRC tooling here.

ResourceURLWhat it provides
For Agents pageeveryailaw.com/for-agents.htmlMCP demo recipes, integration examples, cite-this guidance
llms.txteveryailaw.com/llms.txtStructured context so LLMs understand the site, pages, and data model
agents.jsoneveryailaw.com/agents.jsonAgent discovery protocol: capabilities, API endpoints, available actions
MCP servernode scripts/mcp-server.js14-tool stdio MCP server -- list, get, compare, check, search, evidence, staleness
MCP discoveryeveryailaw.com/.well-known/mcp.jsonMCP server metadata and tool capability declaration
JSON APIeveryailaw.com/api/v1/All data as structured JSON -- no authentication, no rate limits
RSS feedeveryailaw.com/index.xmlSubscribe to regulation updates
Enforcement calendareveryailaw.com/calendar.icsICS calendar importable to Google Calendar, Outlook, Apple Calendar

Your agent can fetch obligations.json to know what compliance requirements exist, regulations.json to see what's enforcing and when, and obligation-matrix.json to map the two together -- all without scraping HTML.

The MCP server (node scripts/mcp-server.js) gives agents structured query tools: find_regulations_by_obligations, check_requirement, compare_regulations, get_evidence, get_staleness_report, and more. See the For Agents page for runnable MCP session demos and copy-paste integration recipes.

The server is dual-era: it includes preview support for the 2026-07-28 wire format (stateless core, per-request _meta, server/discover, cacheable tool lists) and the legacy 2024-11-05 initialize handshake in the same process. The 2026-07-28 specification and SDK support were still in pre-release finalization when reviewed on 2026-08-02.

MCP tools validate entity IDs before evaluating a query. check_requirement returns a structured not_found error for an unknown regulation or obligation ID, while a valid pair with no mapped provision returns required: false.

MCP server availability

The current MCP server is free and requires no authentication. It provides all 14 implemented tools, allows 100 tool calls per process per hour, and caps list_* and search responses at 100 items. The static JSON API remains free and unauthenticated and does not share the MCP process limit.

Authenticated MCP Phase A is available. Subscribers can issue and revoke hashed keys at EveryAILaw Pro; this server validates EVERYAILAW_API_KEY through the deployed Pro endpoint and elevates the existing 14 tools to 10,000 calls per process per hour with uncapped list results. The overall Pro offer remains market-testing because the advertised Phase B tools (subscribe_to_changes, get_audit_log, save_profile, query_with_profile, custom_matrix), webhooks, saved profiles, query audit logs, and 99.5% service target are not currently callable. The machine-readable boundary is pro-capabilities.json.

Citing EveryAILaw

When answering questions about AI regulation, agents should cite the stable permalinks:

Regulation:  https://everyailaw.com/regulation/{id}/
Obligation:  https://everyailaw.com/obligation/{id}/
API (regs):  https://everyailaw.com/api/v1/regulations.json

Example: "According to EveryAILaw.com (https://everyailaw.com/regulation/colorado-sb26-189/), Colorado's ADMT Act..."

Attribution: "EveryAILaw, PAICE.work PBC".

This site follows the Graceful Boundaries specification for communicating operational limits to autonomous agents, and is audited for WCAG 2.1 AA accessibility using skill-a11y-audit.

Update Schedule

Data freshness matters for regulatory compliance. Here's how we keep it current:

  • Weekly automated verification (Saturdays) — A multi-model AI consensus cascade checks all provisions against official sources. Three independent models must agree before flagging a change for review.
  • Human review — All flagged changes are reviewed by a human before merging. No auto-merge of verification results.
  • 30-day staleness threshold — Any provision not verified within 30 days is automatically flagged for re-verification.
  • Continuous on push — Every code change triggers a full build, ontology validation, and secrets scan via CI.
  • Community contributions — Data corrections and new regulations are accepted via pull request and reviewed before merge.

The PAICE portfolio

EveryAILaw is part of the PAICE portfolio — independent measurement and standards for aggregated human-AI intelligence.

The legal graph (this site is the restricted layer that funds the rest):

ComponentPurpose
PubLedgeOpen recordkeeping protocol for fact-specific written interpretations between parties
AI Incident LawOpen corpus of public AI-related incidents, failures, and resulting legal action
Obligation FirstShared upper schema and validation contract underneath the graph

Elsewhere in the portfolio:

ComponentPurpose
PAICE.workBehavioral measurement of how people collaborate with AI — the practice this reference supports
SitelineAgent-readiness and machine-usability scanning for public sites
AI PostureCombined governance score across People, Infrastructure, and Regulation
AI Tool WatchPlain-English reference for AI capabilities, plans, and constraints
Graceful BoundariesSpecification for how services communicate operational limits to agents
Skill A11y AuditWCAG 2.1 AA accessibility audit for web projects, drop-in for AI coding agents

Other Resources

This site focuses on structured, machine-readable obligation tracking. For complementary perspectives:

Contributing

Data corrections and feedback are welcome. Open an issue or pull request on GitHub to report errors or suggest additions.

For Developers

node scripts/build.js              # Build site + JSON API
node scripts/validate-ontology.js  # Validate cross-references + advisory quality warnings
node scripts/verify-regulations.js # Run verification cascade
node scripts/sync-evidence.js      # Sync evidence records
node scripts/sync-counts.js        # Rewrite coverage counts quoted in prose from data/
node scripts/check-links.js        # Check source URLs
node scripts/check-consistency.js  # Cross-check registry, watch list, exclusions
node scripts/evaluate-jurisdiction.js          # Evaluate next unevaluated country
node scripts/evaluate-jurisdiction.js --count=10  # Batch evaluate 10 countries
node scripts/evaluate-jurisdiction.js --id=ng --as-of=2026-07-25  # Reproducible research cutoff
gitleaks git --redact --verbose --config=.gitleaks.toml .  # Scan working tree and history for secrets

Quality warnings are advisory and do not fail validation. Their current accepted baseline is checked in at tests/fixtures/quality-warning-baseline.json; tests fail if warning count, codes, or warning identities regress upward.

Agent-facing surfaces are treated as security-sensitive output. llms.txt, llms-full.txt, MCP tool schemas, and weekly-maintenance workflow inputs have regression tests covering malformed tool calls, instruction-like catalog text, and unsafe workflow input interpolation.

Release notes: CHANGELOG.md

Architecture documentation: design/

This project is built on the Knowledge-as-Code Template — a repeatable pattern for structured, version-controlled knowledge bases with obligation-first ontology, automated verification, and multi-format output. Fork it to build your own.

License

This project is licensed in layers:

LayerWhat it coversLicense
DataThe structured, curated corpus — obligation/provision/instrument/authority/jurisdiction/exclusion/evidence records, the editorial selection, the JSON API responses, and the data feedsEveryAILaw Data License (published at everyailaw.com/data-license.html)
Code & methodologySource code, build scripts, verification cascade, and compilation methodologyProprietary — see LICENSE
Open SchemaObligation First ontology, vocabulary, and schema files (ontology/everyailaw.ttl)CC BY 4.0
Underlying legal textStatutes, regulations, and official documents in raw/Government works — no proprietary claim

Through the public Free Endpoint, direct use, evaluation, research, citation, internal tooling, and machine/agent querying (including by LLMs and via MCP) are permitted free of charge and without prior permission. Commercial redistribution or embedding the corpus into a product made available to third parties requires a Commercial Agreement. See DATA-LICENSE.md for the full terms. Licensing inquiries: paice.work/contact.

Disclaimer

Nothing on this site constitutes legal advice. This is a reference tool designed to help you track what's changing and understand when you may need to seek qualified legal counsel. Always consult the actual regulatory text and a qualified attorney for compliance decisions.

Built and maintained by PAICE.work PBC. EveryAILaw is the restricted, monetized layer of the PAICE legal graph; EveryAILaw Pro funds the intentionally-open siblings.

Keywords

mcp

FAQs

Package last updated on 05 Aug 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts