๐ English | ๐ป๐ณ Tiแบฟng Viแปt ๐ Actionable User Guide | ๐ป๐ณ Hฦฐแปng dแบซn Sแปญ dแปฅng
10 AI-Powered Compliance Skills for Product Managers โ covering 35+ jurisdictions, ISO standards, and flexible compliance depth
Building globally compliant software is traditionally slow, expensive, and legally risky. The SafeAI-Global Compliance Suite acts as your embedded Legal & Security co-pilot, shifting compliance entirely to the leftโstraight into the hands of Product Managers and Engineers.
For Product Leadership (CPO/PM):
- โก Accelerate Time-to-Market (TTM): Generate engineering-ready, legally compliant PRDs in minutes. Never wait weeks for external legal reviews that delay sprint cycles.
- ๐ก๏ธ De-Risk Product Launches: Automatically identify and mitigate regulatory risks (GDPR, CCPA, SEC, DORA) before a single line of code is written. Prevents expensive post-launch fines.
- ๐ฏ Immediate Quality Control: Instantly gauge your PRD's compliance readiness with the SafeAI-Global Score (Privacy, Security, and Transparency pillars).
- ๐ Prevent "Compliance Overkill": Ensure you only apply the regulations necessary for your specific target market and product tier, avoiding unnecessary development bloat.
For Engineering Leadership (CTO/DevSecOps):
- ๐ Zero-Friction Handover: Use
/safeai export jirato instantly transform PRDs into Epics and Gherkin BDD Acceptance Criteria. Legal constraints become code constraints. - ๐๏ธ DevSecOps Ready: Generate Terraform/OPA policies direct from PRDs. Validate implementation automatically in CI/CD using locally run
safeai-lint. - ๐ Secure Vibe Coding: Audit AI-generated code (
/safeai scan) for secrets, hallucinated dependencies, and compliance gaps instantly within your IDE.
Not every PRD needs full compliance. To prevent over-engineering simple features, the agent asks you to choose your depth at the start of every chat:
| Level | Mode Name | Best For | What Happens |
|---|---|---|---|
| ๐ข | ๐ Standard PRD | MVPs, internal tools, fast iteration | Generates a clean, standard PRD โ no compliance scanning. |
| ๐ก | ๐ก๏ธ Smart Compliance (Default) | Products going to production | Auto-detects region and applies only the relevant local laws. |
| ๐ด | ๐ Full Compliance Audit | Enterprise, strictly regulated industries | Full audit: All jurisdictions + ISO 27001/42001 + SOC 2 + WCAG. |
Tip: You don't have to wait for the bot to ask. Just say "Standard PRD" or "Full compliance for EU" in your very first prompt to skip Step 0.
Type /template [industry] [region] to instantly grab a tailored PRD skeleton for your specific market:
| Command | Industry | Region | Applied Regulations |
|---|---|---|---|
/template fintech eu |
FinTech | ๐ช๐บ EU | PSD2, GDPR, DORA |
/template healthcare us |
HealthTech | ๐บ๐ธ USA | HIPAA, FDA SaMD |
/template banking vn |
Banking/Payment | ๐ป๐ณ Vietnam | SBV Decision 2345, Circulars 45 & 77, PDPL |
/template ecommerce vn |
E-Commerce | ๐ป๐ณ Vietnam | Law on E-Commerce 2025, PDPL, VNeID verification |
/template ai vn |
AI/ML Product | ๐ป๐ณ Vietnam | Law on AI 2025, Qฤ 33/2026, PDPL |
/template social vn |
Social Media | ๐ป๐ณ Vietnam | PDPL (2026), Decree 356, Law on Cybersecurity 2025 |
/template ai eu |
AI/ML | ๐ช๐บ EU | EU AI Act, GDPR Art. 22 |
See the full list of templates in SKILL.md.
| # | Skill | Focus | For Who |
|---|---|---|---|
| ๐ | SafeAI-Global PRD Agent | 35+ jurisdictions, cross-border transfers, AI governance | All Product Managers |
| ๐ป๐ณ | SafeAI Vietnam Compliance | Deep-dive Vietnam local compliance, SBV, Law on AI 2025 | VN market PMs |
| ๐ช๐บ | SafeAI GDPR Expert | GDPR Art-by-Art, EU AI Act risk classification, DPIA | EU market PMs |
| ๐ฅ | SafeAI HIPAA Expert | HIPAA safeguards, FDA SaMD, PHI handling | HealthTech PMs |
| ๐ณ | SafeAI FinTech Compliance | PCI-DSS v4.0, PSD2/SCA, AML/KYC, Open Banking | FinTech PMs |
| ๐ | SafeAI ASEAN Data Protection | SG, TH, MY, ID, PH country deep-dives (general overview) | ASEAN startups |
| ๐บ๐ธ | SafeAI US State Privacy Expert | CCPA, CPA, VCDPA, GPC, Opt-in consent | US market PMs |
| ๐ถ | SafeAI EdTech & Child Privacy Expert | COPPA, FERPA, AADC, Age Gating | EdTech PMs |
| ๐ค | SafeAI Ethics & Risk Expert | NIST AI RMF, Bias Testing, Human-in-the-Loop | AI/ML PMs |
| ๐ก๏ธ | SafeAI Code Scanner | Code audit โ Vibe Coding risk, secrets detection | DevSecOps / Engineers |
The SafeAI-Global suite uses a Hub-and-Spoke architecture. You always start with the Global Hub, and pivot to deep-dive Spoke experts only when you hit heavily regulated verticals.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ๐ SafeAI-Global PRD Agent (Hub) โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โข Covers 35+ Jurisdictions โ
โ โข Cross-border Data Transfers โ
โ โข Defines AI Governance โ
โโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโ
โ
[ Step 0: Auto-Detects Region & Depth ]
โ
โโโโโโโโโโโโโโโฌโโโโโโโโโโโโฌโโโโโโดโโโโโโฌโโโโโโโโโโโโฌโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโ
โผ โผ โผ โผ โผ โผ โผ
โโโโโโโโโโโโโ โโโโโโโโโโโ โโโโโโโโโโโ โโโโโโโโโโโ โโโโโโโโโโโ โโโโโโโโโโโโโ โโโโโโโโโโโโโ
โ ๐ป๐ณ Vietnam โ โ ๐ช๐บ GDPR โ โ ๐ฅ HIPAAโ โ ๐ณ Fin โ โ ๐ ASEANโ โ ๐ Stand. โ โ ๐ค AI/Riskโ
โ Complianceโ โ Expert โ โ Expert โ โ Tech โ โ Data โ โ PRD โ โ Expert โ
โโโโโโโโโโโโโค โโโโโโโโโโโค โโโโโโโโโโโค โโโโโโโโโโโค โโโโโโโโโโโค โโโโโโโโโโโโโค โโโโโโโโโโโโโค
โ โข SBV 2345โ โ โข GDPR โ โ โข SaMD โ โ โข PCI โ โ โข SG, THโ โ โข No Legalโ โ โข NIST AI โ
โ โข AI/Cyberโ โ โข AI Actโ โ โข PHI โ โ โข PSD2 โ โ โข ID, PHโ โ โข Fast TTMโ โ โข Ethics โ
โโโโโโโโโโโโโ โโโโโโโโโโโ โโโโโโโโโโโ โโโโโโโโโโโ โโโโโโโโโโโ โโโโโโโโโโโโโ โโโโโโโโโโโโโ
*(Plus specialized nodes for US Privacy, EdTech, and Code Scanning)*
> **The Hub Workflow:** Start your chat with the **Global PRD Agent**. If it detects a highly regulated domain (like Healthcare in the US, FinTech in Europe, or deep compliance requirements in Vietnam), it will automatically recommend you switch to the specialized **Spoke** skill for a deeper audit.
npx skills add datht-work/safeai-global-agentThis will show all 9 skills โ select the ones you need.
This project uses a Modular Knowledge Engine architecture. To use it in a web interface, you need to provide both the Agent Instructions (SKILL.md) and the Knowledge Base (knowledge/ folder).
| AI Tool | Setup Instructions |
|---|---|
| Google Gemini | 1. Create a new Gem 2. Paste SKILL.md into Instructions3. Upload all files from the knowledge/ folder |
| Claude (Anthropic) | 1. Create a new Project 2. Paste SKILL.md into Project Instructions3. Upload the knowledge/ folder to Project Knowledge |
| ChatGPT (OpenAI) | 1. Go to Explore GPTs โ Create 2. Paste SKILL.md into Instructions3. Upload the knowledge/ folder to Knowledge |
| GitHub Copilot | Save SKILL.md as .github/copilot-instructions.md in your repo |
| Cursor | Place SKILL.md in .cursor/rules/ and ensure the knowledge/ folder is in your workspace |
| Windsurf | Place SKILL.md in .windsurfrules and ensure the knowledge/ folder is in your workspace |
๐ป๐ณ Vietnam ยท ๐จ๐ณ China ยท ๐ฏ๐ต Japan ยท ๐ฐ๐ท South Korea ยท ๐ฎ๐ณ India ยท ๐ธ๐ฌ Singapore ยท ๐ฆ๐บ Australia ยท ๐น๐ญ Thailand ยท ๐ฒ๐พ Malaysia ยท ๐ฎ๐ฉ Indonesia ยท ๐ต๐ญ Philippines
๐ช๐บ EU ยท ๐ฌ๐ง UK ยท ๐จ๐ญ Switzerland ยท ๐น๐ท Turkey ยท ๐ฆ๐ช UAE ยท ๐ธ๐ฆ Saudi Arabia ยท ๐ฎ๐ฑ Israel ยท ๐ณ๐ฌ Nigeria ยท ๐ฟ๐ฆ South Africa ยท ๐ฐ๐ช Kenya ยท ๐ช๐ฌ Egypt
๐บ๐ธ US (Federal + CA, CO, TX, VA, NY) ยท ๐จ๐ฆ Canada ยท ๐ง๐ท Brazil (LGPD, Digital ECA) ยท ๐ฒ๐ฝ Mexico ยท ๐ฆ๐ท Argentina ยท ๐จ๐ด Colombia ยท ๐ต๐ช Peru
The agent is trained to map product features to strict international frameworks (applied automatically in Smart and Full Audit modes):
| Category | Standard | What the AI Does / Maps to in PRD |
|---|---|---|
| ๐ Security | ISO/IEC 27001 | Enforces Annex A controls (RBAC, cryptography, MFA, logging). |
| ๐ก๏ธ Privacy | ISO/IEC 27701 | Adds PII controller/processor obligations and data minimization. |
| ๐ค AI Risk | ISO/IEC 42001 | Defines an AI Impact Assessment, human oversight, and bias testing. |
| ๐ข Enterprise | SOC 2 Type II | Maps Trust Service Criteria (Security, Availability, Privacy). |
| โฟ Access | WCAG 2.2 AA | Adds perceivable/operable ACs for frontend features. |
| ๐๏ธ Legal | EAA / ADA | Checks European Accessibility Act & Americans with Disabilities Act. |
๐ก Want to see it in action? Look at examples/sample-prd-output.md for a complete compliance PRD output.
| Your Prompt | Mode Detected | What Happens |
|---|---|---|
| "Write a quick PRD for login feature" | ๐ Standard | Clean PRD, no compliance scanning |
| "Viแบฟt PRD cho app thanh toรกn tแบกi Viแปt Nam" | ๐ก๏ธ Smart | Auto-detect VN โ PDPD, Decree 53 |
| "Write a PRD for user tracking in France" | ๐ก๏ธ Smart | Auto-detect EU โ GDPR, ePrivacy |
| "Full compliance PRD for a telehealth app in California" | ๐ Full Audit | CCPA, HIPAA, FDA SaMD, ISO, WCAG |
| "Build a payment gateway for Singapore โ full audit" | ๐ Full Audit | PDPA, MAS TRM, PCI-DSS, ISO 27001 |
- โ Zero executable code โ Markdown-only skills
- โ Zero runtime dependencies โ No supply-chain risk
- โ No network calls โ No external connections
- โ No data collection โ Stateless operations
- โ CI/CD audited โ GitHub Actions security pipeline
- โ
LLM Evaluated โ Automated
promptfootesting with Golden Datasets
See SECURITY.md for full policy and CONTRIBUTING.md for knowledge standards.
See CHANGELOG.md for detailed version history.
| Version | Date | Highlights |
|---|---|---|
| v4.3.0 | 2026-03-26 | AI Engineering Roadmap: Integrated promptfoo testing, Knowledge Schema standards, and automated quarterly law audits. |
| v4.2.0 | 2026-03-18 | New Skill: SafeAI Code Scanner for Vibe Coding security auditing. |
| v4.1.0 | 2026-03-14 | DevSecOps Infrastructure: Added /safeai export opa and /safeai export terraform. Fixed Snyk Runtime Fetch vulnerability. |
| v4.0.0 | 2026-03-14 | Agile Engine & Multilingual: Added /safeai export jira and /safeai export confluence output formats. Full multilingual prompt detection and /safeai lang manual override. |
| v3.2.0 | 2026-03-13 | Custom Policy Injection โ Introduced /safeai inject command and Hybrid Compliance mode |
| v3.1.0 | 2026-03-12 | Scoring Ecosystem โ Introduced the SafeAI-Global Score (0-100) evaluating Privacy, Security, and Transparency |
| v3.0.0 | 2026-03-11 | Core Modular Knowledge Engine: Extracted all static regulations into a searchable knowledge/ Document Store |
| v2.5.0 | 2026-03-10 | Added Brazil Digital ECA (Age Signals API, Loot Box ban) |
| v2.4.0 | 2026-03-09 | /template command, Compliance Visualizer, CLI Linter, Vietnamese README |
| v2.3.0 | 2026-03-08 | Added 3 new Spoke skills: US State Privacy, EdTech/Child Privacy, and AI Ethics & Risk |
| v2.2.0 | 2026-03-06 | Compliance Depth selector (Standard/Smart/Full), ISO 27001/27701/42001, SOC 2, Accessibility, Disclaimer |
| v2.1.0 | 2026-03-06 | Multi-skill architecture, cross-linking, AI tool usage guides |
| v2.0.0 | 2026-03-05 | 35+ jurisdictions, security audit infrastructure |
| v1.0.0 | 2026-03-05 | Initial release (VN, EU, US, CN) |
We welcome contributions! Especially:
- ๐ New country regulations
- ๐ Regulation updates
- ๐ Citation corrections
- ๐ PRD template improvements
See SECURITY.md for security-related contribution guidelines.
MIT License โ see LICENSE for details.
The SafeAI-Global Knowledge Base heavily relies on up-to-date legal facts. Please audit the following major frameworks to ensure our knowledge/ directory is accurate:
- EU AI Act: Monitor AI Office guidelines ahead of the August 2, 2026 enforcement milestone.
- Vietnam PDPL: Ensure all facts align with Law No. 91/2025/QH15 and Decree 356/2025/ND-CP.
- US State Privacy: Validate enforcement for Maryland (MODPA), Indiana, Kentucky, and Rhode Island.
- ISO Standards: Review EN ISO/IEC 42001:2026 regional adoptions and ISO 27001:2022 amendments.
Action:
- Validate the facts in
knowledge/against official sources (e.g., Official Journals, NIST, ISO). - If changes exist, open a PR with updated Markdown tags.
- Run
npm run evalto ensure the PRD generator still behaves correctly viapromptfoo.
โ ๏ธ Disclaimer: This suite provides compliance guidance, not legal advice. Always consult qualified legal counsel for final compliance decisions.
Built with โค๏ธ by SafeAI-Global Team ยท v5.0.0 ยท March 2026
