# LexLint > A compliance lint for AI, scraping, privacy, cybersecurity, age-gating, and news-aggregation law: get_law reads all six topics and run_lint matches obligations from all six. LexLint reads a declared app profile and reports the obligations that attach to it, jurisdiction by jurisdiction, each one cited to a named instrument with the date the research last read it. Research summaries of published law, not legal advice and not authorization to access any system. ## Start here - [LexLint](https://lexlint.io/): What the lint does and how to run it - [AI, scraping, privacy, cybersecurity, age-gating, and news-aggregation law by jurisdiction](https://lexlint.io/law): Per-jurisdiction research summaries for AI, scraping, privacy, cybersecurity, age-gating and news-aggregation law, and the instruments behind them, each cited to its primary source - [FAQ](https://lexlint.io/faq): What the corpus covers, how fresh it is, and what it deliberately does not answer - [About](https://lexlint.io/about): Who maintains the corpus and how it is researched - [News](https://lexlint.io/news): Developments in AI, scraping, privacy, and cybersecurity law as they land ## For people building and governing agents - [The LexLint Legal Handbook](https://lexlint.io/agents): The section index: what each document holds, who it is for, and which one answers a given question - [Introduction: The 6 parties in AI law](https://lexlint.io/agents/parties): Every piece of user-facing software has a crowd of parties around it, and each one is the hook a different law reaches through. An AI agent sits in the middle of the same crowd and acts on most of them at once. - [Where the parties are, and whose law that makes applicable](https://lexlint.io/agents/jurisdiction): Which jurisdiction's law reaches an AI agent's run, decided from where the parties are: the territorial hook per body of law and per law family, the party whose position triggers scope, the evidence of location available at run time and how far each piece can be trusted, the widening of a declared place to its parents and its union, and what to record when the answer is unknown - [Global AI law: 8 common threads](https://lexlint.io/agents/world-ai-law): What the AI laws in force around the world have in common, the unusual provisions that trip an agent, the older privacy, security and scraping law that already binds one, where the new law restates the old, and why an EU-compliant system still has twenty-seven national layers to read. - [The requirement register](https://lexlint.io/agents/register): Every requirement line the LexLint software-law corpus carries for AI, privacy, scraping and cybersecurity law, typed and dated, with the class of duty it belongs to, the party it binds, the territory it reaches through and what a runtime control can do about it. Tabulated by obligation class, and offered whole as a file. - [Does legal action really happen?](https://lexlint.io/agents/enforcement): Enforcement actions, judgments and settlements, each starting from an ordinary product feature, with the primary source beside every figure: the evidence that these laws constrain software today, at every size of company. - [What the law makes you constrain](https://lexlint.io/agents/controls): What binding law requires an agent's operator to constrain, layer by layer, from the model to the supply chain, with the requirement lines and instruments behind each layer and an alignment note to the Open Secure AI Alliance's SAFE review framework - [What the law makes you able to show](https://lexlint.io/agents/evidence): What binding law requires an agent's operator to be able to show after the fact, in nine classes from prompts and traces to retention periods, each with the requirement lines behind it and an alignment note to the Open Secure AI Alliance's SAFE evidence-preservation list - [What a tamper-proof log still cannot tell you](https://lexlint.io/agents/logs): Why an agent traceability record has to carry the jurisdiction a request was served under, what to record in place of a client IP address, and why a client IP address read at an origin behind a content delivery network names the edge rather than the user - [How a runtime engine takes in legal constraint data](https://lexlint.io/agents/runtime): How a gateway or policy engine on an AI agent's request path takes in legal constraints: the requirement line as a record with a party, a territorial hook and a runtime tier, the measured share of binding law a request path can enforce, detect or evidence, how the engine learns whose jurisdiction decides, what agentgateway and MuleSoft's gateway expose at decision time, four integration shapes with their failure modes, and the ceiling on what any of it may claim - [What an open-source project owes the people who run it](https://lexlint.io/agents/open-source): Every open-source licence disclaims liability and the law binds the operator, so an open-source project carries little legal risk. The exposure it creates for the people who deploy it is another matter, and three questions follow for a project that already knows where that exposure is. - [The clocks an incident starts](https://lexlint.io/clock): The clocks a security incident or a personal-data breach starts, read from every reporting sentence in the corpus, drawn on one time axis beside the SAFE proposal's own timeline - [Incident command: from the facts of an incident to the notices that are due](https://lexlint.io/agents/incident): How to work out which reporting clocks an AI agent incident starts: the facts that engage each clock family, where each family reaches by place, the three states a clock can be in (runs, runs unless, set aside) with nothing hidden, how to read a judgment standard, a bright line or a safe harbour inside a clock sentence, the six moments a clock can count from, and what to record - [When the operator is a public body, the report is a public record](https://lexlint.io/agents/public-record): What public-records (freedom of information) law does to the incident report a public-sector operator of an AI agent holds: which withholding grounds the records acts carry (security, investigations, trade secrets, personal data, deliberations), whether a body must or may withhold, the response deadlines in days, retention, and what follows for the body, its vendor and anyone sending it an alert, read from UnGovr's public-records corpus - [Terminology cheatsheet](https://lexlint.io/agents/cheatsheet): The vocabulary of the section on two pages, the law first and the agent and its words second, every term linked to the page that discusses it or its glossary entry; the same two pages as a PDF at https://lexlint.io/agents/cheatsheet.pdf - [The sixteen themes of the AAIF governance working group, read against binding law](https://lexlint.io/aaif): The AAIF governance working group's sixteen extraction themes read against binding law: the crosswalk from the LexLint corpus's twenty obligation classes, what the distribution says, and an index into the agents handbook by theme and by deliverable. - [The sixteen themes, filled from binding law](https://lexlint.io/aaif/themes): Each of the AAIF working group's sixteen themes filled from binding law: counts, sample requirement lines with type, addressee, hook and runtime tier, and the per-line file in the group's extraction contract. ## Analysis: questions asked across the whole corpus - [Analysis](https://lexlint.io/analysis): Explorations of questions no single jurisdiction's page can answer, with the gaps in our own reading left visible - [What the law requires of logs](https://lexlint.io/analysis/logging): The question, how the five documents fit together, and how much of it the corpus can answer today. - [Why legislators ask for logs](https://lexlint.io/analysis/logging/background): What drafters said they wanted a record for, by family of instrument, and how the expectation moved from paperwork to a running account. - [What the law requires, by geography](https://lexlint.io/analysis/logging/requirements): The eight categories, what share of the people governed by the researched jurisdictions live under each, and the split between a stated duty and an implied one. - [Every jurisdiction, against the eight categories](https://lexlint.io/analysis/logging/jurisdictions): One row per jurisdiction the corpus holds law for, with its population weight and the source of that weight beside it. - [Knowing which law applied, without making the log personal data](https://lexlint.io/analysis/logging/jurisdiction-signals): A log that shows the right law was followed has to show which law was in play, and the moment it does it starts describing a person. - [What a checkable record would have to hold](https://lexlint.io/analysis/logging/recommendations): The eight categories mapped onto the record shapes the standards bodies are converging on, and two configurations that produce one. ## Machine interfaces - [MCP server](https://mcp.lexlint.io): Live tool access: set_profile then run_lint (declare an app, get findings), get_law (AI, scraping, privacy, cybersecurity, age-gating, and news-aggregation law for one jurisdiction), resolve_domain_jurisdiction, check_access - [Corpus JSON Schema](https://data.ungovr.org/v1/schema/ungovr.ai-laws-2.schema.json): Validation contract for the jurisdiction record, coverage index, and bulk-export rows. No API key needed to fetch the schema - [Bulk export manifest](https://data.ungovr.org/v1/ai-laws/export/manifest.json): Row counts and digests for the JSONL export. The corpus itself requires an API key - [App profile schema](https://lexlint.io/schema/lexlint.schema.json): Validation contract for lexlint.yml, the declared app profile the lint reads ## Terms - [Data license](https://www.ungovr.org/open-data/license): The AI and scraping law corpus is licensed non-exclusively by agreement; receipt of a file conveys no license