Sample report. Northwind E-commerce LLC is a fictional 75-person Shopify store created to illustrate what Plumbline delivers. Real audits use your actual company data and team interviews.
plumbline

AI Act Compliance Audit — Northwind E-commerce LLC

Audit period: April 2026 · Engagement #PL-2026-0042 · Delivered May 8, 2026

Executive summary

Northwind E-commerce (a 75-person Shopify store doing $14M GMV, US-based with shipping to EU customers) uses 23 distinct AI-powered tools across operations, marketing, and customer support. Of these:

Critical action required by Aug 2, 2026: 3 high-risk systems need full DPIA + human-oversight documentation. Estimated 28 hours of in-house work, or we can complete the documentation as a follow-on engagement.

Section 1 — AI Tool Inventory

This inventory was built from (a) workspace scans of Google Workspace and Slack integrations, (b) 4 async team interviews, and (c) cross-reference against the AICPA-AI Tool Registry.

CategoryToolUsed byPurposeEU risk
MarketingKlaviyo AIMktg (3)Email subject-line generation, send-time predictionMin
MarketingJasperMktg (2)Blog drafts, product descriptionsLim
OperationsNotion AIAll (52)Doc summaries, meeting notesMin
OperationsOtter.aiOps (8)Meeting transcriptionMin
OperationsLoom AIEng (12)Video transcript + summaryMin
PricingPrisyncMktg (1)Algorithmic price-matching for EU + US customersHigh
SupportGorgias AISupport (6)Customer-facing chatbot, ticket triageLim
SupportAdaSupport (4)Pre-purchase chatbot on EU siteLim
PeopleHireVueHR (2)Video-interview scoring for warehouse hires (EU + US)High
PeopleLattice AIHR (2)Performance review summariesHigh
PeopleCalendly AIAll (38)Meeting schedulingMin
EngineeringGitHub CopilotEng (12)Code completionMin
EngineeringCursorEng (5)Code editingMin
EngineeringVercel v0Eng (3)UI component generationMin
FinanceBrex AIFinance (2)Expense categorizationMin
FinanceVenaFinance (1)Financial forecastingLim
LegalSpellbookLegal (1)Contract reviewLim
DataMixpanel AIData (3)Insight generation on customer behaviorLim
DataAnthropic Claude APIEng (4)Custom internal tooling (research assistant, dashboards)Lim
DataOpenAI ChatGPT TeamAll (60)General-purpose assistanceLim
SalesApollo AISales (3)Lead enrichment, outreach draftingMin
SalesGongSales (3)Call recording + analysisLim
SalesClaySales (1)Multi-source lead enrichmentMin

Section 2 — Jurisdiction Risk Classification

EU AI Act (effective Aug 2, 2026)

Three Northwind systems trigger high-risk obligations under EU AI Act Annex III:

Nine systems are limited-risk requiring consumer-facing transparency notices (chatbots, AI-generated content).

Colorado SB 205 (effective Feb 1, 2026)

Same three high-risk systems trigger Colorado SB 205 obligations because Northwind makes consequential decisions about Colorado residents (4.2% of customer base). Requires:

NYC Local Law 144 (AEDT, in effect)

HireVue use for hiring of NYC-resident candidates triggers a bias audit obligation within 12 months prior to use. Northwind's last bias audit was Sept 2024 — out of window. Action: schedule fresh audit before next hiring cycle.

Section 3 — Recommended Actions (priority order)

  1. By Jun 15, 2026: Schedule NYC AEDT bias audit for HireVue (vendor-provided or 3rd-party).
  2. By Jul 1, 2026: Publish consumer-facing AI transparency notice on northwind.com and northwind.eu (template provided in Appendix A).
  3. By Jul 15, 2026: Complete DPIA for HireVue, Lattice AI, and Prisync (template provided in Appendix B).
  4. By Aug 1, 2026: Register the 3 high-risk systems in EU AI System Registry once operational (registry opens Aug 2026).
  5. By Aug 1, 2026: Implement human-oversight protocol for HireVue and Lattice AI hiring/perf decisions (template provided in Appendix C).
  6. Ongoing: Add AI use disclosure to Gorgias and Ada chatbot opening messages.
  7. Ongoing: Adopt the governance policy (Appendix D) and assign an internal AI compliance owner.

Section 4 — Vendor Compliance Verification

Of the 23 tools, 14 vendors have published AI Act compliance statements. The remaining 9 require direct outreach; templates for that outreach are included in Appendix E.

Appendices (in full report)