
Navigating AI Compliance
for Teams That Want to Ship
"We're not allowed to use AI" stops more projects than the law does. Dr. Alexa Scheffler builds compliance software for regulated industries – and her read of the EU AI Act is that it doesn't forbid you from using AI. Its first requirement is that your people learn to.
Meet Dr. Alexa Scheffler

Alexa builds the software that answers one question for large companies: are we actually allowed to use AI for this? REGULIGHT is a chat agent that asks only the questions it needs, and a workflow that keeps the evidence tidy for whenever someone comes asking for it.
She studied computer science. She then spent most of a career not writing code.
"In my studies in computer science, I always loved software development, but I always went into the direction of being a business analyst or an architect. I was not the best coder because I was too slow. The other students, they were twice as fast as me coding, because I always had to look up: what kind of method am I using now?"
She was good with people, so she went to the management track, and worked alongside the coders instead of being one. Her own summary of what followed: "I did not have any hands-on coding experience for almost a decade."
That is the person who now ships a compliance product. Which matters, because the thing that eventually got her building was not a course and not a hire. It was a form.
"In corporates there was always this step until talking to compliance. And there were a lot of helpful people, of course — but they had their rules and they had their complicated questionnaires. And this is why I said: why do I have to fill out this complicated questionnaire? I want to make it easier."
The Sentence That Stops the Project
Every company I talk to in Germany has the same ghost in the building. Someone has an idea. Someone else says no. Nobody can quite produce the rule that says no.
"There are so many people who have innovative ideas to do something with data, to do something with AI. But then there are some naysayers — let's say someone from compliance, regulations or other businesses — who say: you cannot do this, because there's some regulation that says you cannot."
I have been on the wrong end of this more times than I can count, and I have never got used to it:
"That's so tough in Germany. I work with bigger companies and it's like — what the hell are they doing? Isn't the job of compliance to enable the company? And then they're just constantly in your way instead of enabling you."
Alexa's answer is more generous than my question deserved, and it is the reason this article exists. The people saying no are not villains. They are doing precisely the job they were trained for.
"There are some of the legals who are really trying to enable the company, but most of the times they're not in the discipline to try out things. They are educated to think about what can go wrong."
Read that carefully, because it changes what you do next. If the person blocking you is trained to imagine failure, then arriving with more enthusiasm is the worst possible move. You are bringing optimism to a risk assessment.
What actually moves them is the thing almost nobody brings: an accurate reading of what the law says.
Read the Act, and You're Mostly Allowed
The EU AI Act is new, which is exactly why it functions so well as a blanket no — nobody in the room has read it, so nobody in the room can contradict the most cautious person present.
Here is what it actually asks you to do first.
"So what you're going to do if you want to use AI as a company: first you have to assess what kind of risk is behind this AI. And for most of the use cases, it's not very critical."
The high-risk category is real, and it is narrow on purpose. Her examples: a health insurance claim processed 100% automatically. A credit decision where an agent alone decides whether you get the money. Those sit under heavy regulation, and Alexa's view is that they should.
Then comes the sentence that most projects never hear.
"But most of the other AI use cases, it's just that you have to have some cornerstones about the usage of AI. So as a company, according to the AI Act, you're allowed to use it."
I wanted to test this against something I had built myself, because abstract reassurance is worth nothing in a meeting. I made an HR funnel tool with candidate scoring, and had long arguments with Claude about where it landed. The answer I got was about where the human sits.
No human in the loop on who gets hired, and you are squarely in the high-risk category. But:
"If you frame it in a way that the AI is supporting the process and giving the human the information on which the human makes the decision, this is low risk. Does this roughly cover it?"
Roughly, she said. With the caveat that it always depends — she has worked with lawyers long enough that she can produce that answer on reflex.
But notice what just happened. The risk level was not a property of the technology. It was a property of how the workflow is designed. The same model, doing the same scoring, is high risk or low risk depending on whether a person is still making the call.
Which means most of the time you are not asking permission. You are choosing a design.
It's Not Yes or No. It's How Much Risk You'll Manage.
We went through all of this once before, with GDPR. I got exactly one genuinely useful frame out of that entire era, and it came from lawyers in the middle of a big case.
"The perfect, only really useful frame I got from legal people at Osborne Clarke — actually in a big case — was the phrasing: is this a manageable risk?"
That question does something the other question cannot. "Are we allowed?" hands the decision to whoever is most afraid. "Is this a manageable risk?" hands it back to the person who owns the outcome.
"As a company, as an entrepreneur, I can make a judgment call and say: this is a manageable risk. And I can get this answer, that this is a manageable risk, from my legal people."
Alexa agreed, and put it in the language of the Act itself:
"It's always a risk based approach. So it's not a yes or no, we can do it or we can do it not, but we can do it with what type of risk. And the higher the risk, the more management you need behind that."
This is the single most portable thing in the episode. It converts a gate into a dial. There is no version of this conversation where the answer is a locked door — there is only a question of how much management sits behind the thing you want to do.
Walk into the next meeting with the dial, not the door.
The First Requirement Is That Your People Learn
So you have classified honestly and you are in the ordinary category with almost everyone else. I asked the obvious follow-up: what does the Act actually demand of us then?
Her answer is the part of this conversation I have not been able to put down.
"First thing is you have to ensure that people in your company are educated with AI. So in the last years there was a huge new business coming out of AI trainings, but there are no cornerstones from regulations how these AI literacy would look like."
Sit with that for a second, because it inverts the whole argument.
The regulation that gets quoted as the reason to stay away from AI opens by requiring that your people learn to use AI. It is not a permission you have to win. It is an obligation you are already behind on.
And because the law never specified what that training should contain, a market appeared to fill the gap. Alexa was blunt about the result — "kind of boring":
"So people were talked about the risk levels of AI. I don't know if this was bringing the business of these companies so much forward."
A legal obligation to make people AI-literate, discharged by sitting them in a room and explaining risk tiers. Everybody complies. Nobody can do anything on Monday.
Then I asked about documentation, expecting the GDPR nightmare — the registers, the records, the consultants. Here is the entire requirement, in her words:
"It's always good to write something down… It's just that: okay, Ben Sufiani and Alexa Scheffler were taking place at the training on August 2026, and it was about that curriculum. Write it down and then you're safe. It's not that difficult."
Two names, a date, a topic. If an audit ever comes, you have evidence that the people using AI in your company were trained, and what they were trained on.
That is the paperwork. Four lines in a text file.
What the "No" Actually Costs
Put the two halves next to each other and the arithmetic stops being close.
On one side: classify the use case, keep a human where the decision matters, write four lines down. On the other side: the months and years a company spends not building, because the most cautious sentence in the room went unchallenged.
Alexa knows the price of that delay from the inside, because she paid it herself. She had the computer science degree the whole time. What she did not have was the belief that the building part was hers to do.
"I remember going to my first Vibe Coding Cologne, and it was completely like a whole new experience for me. Oh my god, I can do things — and it's not that I have to wait for this magical technical co-founder to make my ideas happen, but I can do it on my own."
The magical technical co-founder is the same character as the regulation nobody can produce. Both are stand-ins for permission. Both are somebody else's signature you have decided you need before you are allowed to start. Neither is coming.
What replaced it for her was not a qualification. It was somebody standing next to her while the agent misbehaved:
"Sometimes I need someone to take me by the hand and say: don't worry, you're doing this step. And when your coding agent is doing something completely crazy — keep calm, keep coding, and you will come to a solution."
And the cost is not evenly distributed. Late in the conversation she raised something she had clearly been carrying, and she used a specific word for it.
"What I see is falling behind. At most of the events I go to — vibe coding, or anything like AI engineering — sometimes I'm the only woman in the room."
Falling behind is what the "no" buys you. Not a fine, not a breach, not a headline — just a slow, compounding distance between the people who started and the people who waited to be told they could.
The risk you were avoiding was manageable. The cost of avoiding it wasn't.
Minutes on the Keyboard, Not Hours in a Training
Here is where the two halves of this argument finally close on each other. The Act wants your people AI-literate. The literacy trainings that grew up to serve it mostly teach risk tiers. Alexa's version of what literacy actually is has nothing to do with a classroom.
"To move forward in your AI journey, you have to go to the keyboard. So every minute on the keyboard gives you AI literacy."
Which means the building is not a detour from the compliance work. The building is the compliance work, and it is the only version of it that leaves your team able to do something afterwards.
I asked her for the concrete steps. She gave three.
"You need at least one pro subscription for any intelligent model, may it be OpenAI or Claude. I think this is very good invested money. It's 20 euros a month, but it's very, very well invested money. With the free tier, you do not get that far. And having a fun product to start with: building a website for something. It does not have to be a full software as a service solution, but to have your own website online. Just play around a little. This is an amazing start."
Pay the twenty euros. Build a website you actually want. That is the entire on-ramp, and if it sounds too small to count as corporate AI literacy, that is the point — it produces people who have done the thing, which no slide deck about risk tiers has ever managed.
If you want the version that scales past one person, her other recommendation is the one I'd push hardest on inside a company:
"This is the way I would recommend everyone to start with organizing your life with AI: having this markdown file directory somewhere. You could use Obsidian, but also others. And then connect your Cowork, OpenAI or whatever. This is the way to start, so you can see what AI can do for you."
A folder of plain text your agent can read. It is how we run our own company brain, it is where project rules live, and — usefully for this argument — it is also exactly where four lines saying who was trained, when, and on what would go.
The same markdown file that makes your agent useful is the file that makes you audit-ready.
Go and Find Out What You're Allowed To Do
The whole argument, compressed:
Classify the use case honestly, and accept that high risk is narrower than the room believes. Keep a human where the decision matters, and watch the risk level move. Ask is this a manageable risk? instead of are we allowed?, so the call lands with the person who owns the outcome. Write down who was trained and on what. Then get your people onto the keyboard, because that is the requirement the law actually leads with.
None of that is a fight with your compliance team. It is the conversation they were trained to have, held with someone who has read the thing — which is the dialogue Alexa argued for from her very first answer.
If you want the safety side done properly while you move, Safety First and Zero Trust in the Pirate Codex are the two chapters that keep "we moved fast" from turning into the incident that proves the naysayers right. And if the keyboard part is the bit that feels out of reach, the three levels of AI engagement is the shortest route from chat to actually building.
"If you're interested about our founder story — but as well about how can corporates use AI without having a bad conscience that there are any regulations behind — you can follow me on LinkedIn."
Alexa is at Vibe Coding Cologne on 2 September with the laptop open — a live look at REGULIGHT and how it got built, not slides about it. She came to these as an attendee. That is usually how this starts.
Nobody is going to hand you the permission slip. It turns out it was already in the regulation.
About This Conversation
Alexa is the founder of REGULIGHT, a compliance solution that helps medium-sized and corporate teams work out whether they are allowed to use AI for a given use case – and keep the evidence tidy for when someone asks. She studied computer science, spent most of a decade away from hands-on code, and started building again through vibe coding and the Pirate Forge.
Ready to Go Deeper?
Pirate Lab
·Wed, Sep 9 · 18:00 CESTFree weekly online workshop where we walk through the week's Captain's Insight together. Bring your project, get live feedback.
Vibe Coding Cologne
·Wed, Sep 2 · 18:30 CESTMonthly in-person meetup in Cologne. Talks from Ben and local founders, drinks, building alongside the community.
Vibe Hackathon Cologne
·Fri, Sep 4 · 14:30 CESTIntensive on-site weekend hackathon – build and ship something real in 48 hours with other founders in Cologne.
Pirate Forge
·In 34 days · Wed, Sep 306-week cohort program combining build and grow tracks. Weekly workshops, accountability, the founders you'd want to ship next to.
