Free, no gate
Three tools that answer a question you have to answer anyway
None of them asks for an email address before showing you the result. Each one returns something specific enough to forward to whoever actually owns the problem.
In short
Cloudgap publishes three free tools: a scope checker that works out which EU AI Act obligations reach your organisation and when, a cost model for the fully loaded price of security leadership, and a regulatory horizon tracking every UK and EU deadline with its source. None gates its result behind a form.
Does this apply to us?
01
EU AI Act scope checker
The Act reaches you if your system's output is used in the EU, even with no EU entity. Six questions establish whether it does, which obligations follow, and when each one bites.
- You get
- A dated obligation list, plus a calendar file
- Takes
- About three minutes
- Scope
- 6 obligations modelled
What will this cost?
02
Security leadership cost model
Base salary is the part everyone knows. This adds employer NI, pension, recruitment fee and the months the role is funded but empty, then divides by the months actually covered.
- You get
- A year-one figure you can paste into an email
- Takes
- Under a minute
- Scope
- 5 statutory rates, each cited
What is coming?
03
Regulatory horizon
Every obligation we track across the UK and EU, with the date it takes effect, who it applies to, what has moved, and a link to the primary source behind each one.
- You get
- A reference you can cite in a board paper
- Takes
- Nothing to fill in
- Scope
- 11 obligations, verified 25 August 2026
Platform
And one that is not free
On-premise governance, risk and compliance. Map a control once, reuse it everywhere. Deployed inside your own environment, so compliance evidence never leaves it.
- Policy management
- Risk management
- Compliance mapping
- Audit automation
- Vendor management
Why they are not gated
A form in front of the answer is a tell
Every one of these shows its result before it asks you for anything, because a firm that gates a compliance checklist behind a lead capture form is telling you what it thinks the checklist is for. The email step comes after, it is optional, and it asks for consent in plain language rather than a pre-ticked box.
The same applies to the sources. Every regulatory date carries the primary source it came from and the date it was last checked, so you can verify us rather than trust us. Where we do not have a figure, the page says so instead of estimating one.
FAQ