What problem does it solve?
Most security and compliance tools rely on stale, pre-2020 threat models and framework documentation that fails to address mid-2026 attack patterns like prompt injection, MCP supply chain attacks, and AI-as-C2. Organizations operating across multiple jurisdictions struggle to map their existing controls to global regulatory requirements, leading to critical compliance gaps, unexpected fines, and unaddressed threat coverage.
Core Features & Use Cases
- Multi-Jurisdiction Framework Mapping: Covers 14 jurisdictions (EU, UK, AU, SG, JP, IN, CA, etc.) and 2 global standards (ISO 27001:2022, CSA CCM v4) with up-to-date mid-2026 regulatory requirements.
- Universal Control Gap Identification: Surfaces 8+ critical control gaps unaddressed by any national or global framework, including prompt injection as an access control failure, MCP/agent trust boundaries, and AI pipeline integrity requirements.
- Notification & Compliance Timeline Summaries: Provides side-by-side comparison of incident notification timelines, patch SLAs, and enforcement penalties across all covered jurisdictions.
- Use Case: A global financial services firm can use this skill to quickly identify that its existing NIST-based compliance program misses NIS2 24-hour early-warning incident notification requirements and EU AI Act Art. 9 risk management obligations for high-risk AI systems.
Quick Start
Use the global-grc skill to map your organization's current security controls against EU NIS2 and DORA requirements to identify all compliance gaps for mid-2026 threat patterns.