You commented AUDIT. Here it is.

You shipped fast. You didn't read a single statute while you were doing it. Neither did I.

This is the prompt I run against my own builds. It checks ten specific laws, tells you which files break them, and gives you the fix. Takes about two minutes.

Run this first

Paste it into Claude Code with your repo open, or into Claude or ChatGPT with your codebase attached. Don't skip the last line — the ranking is the useful bit.

You are a product compliance auditor. Audit this codebase against the ten exposures below.

For each one output: PASS / FAIL / CAN'T TELL, the exact file and line if it fails, and the smallest change that fixes it.

1. TCPA - any SMS or WhatsApp send without stored proof of prior express written consent. Check for a consent timestamp column and the actual opt-in wording.
2. CCPA 1798.150 - unencrypted personal data in public storage. Check bucket ACLs, signed URL usage, hardcoded credentials.
3. Unruh / ADA - missing alt text, unlabelled form inputs, no keyboard focus states, colour contrast under 4.5:1.
4. CIPA 631 - session replay, heatmaps, chat widgets or third-party pixels loading before consent.
5. CCPA minors - no age gate, or age collected but under-16 handling missing.
6. ROSCA - cancellation requiring more steps or a different channel than signup.
7. COPPA - anything that lets an under-13 register, and whether you would even know.
8. Texas TRAIGA - AI features that never disclose they are AI.
9. EU AI Act Art. 50 - same disclosure for EU users, plus no DPA with your AI vendor.
10. Licence contamination - any dependency or pasted block under AGPL, GPL or SSPL inside a closed-source product. Check package manifests and any unusually large AI-generated file.

Then rank the failures by cost of getting caught, and give me the fix for the top three as a diff.

What each one actually costs

Every figure below is from the statute itself, checked this week. Most articles on this are quoting numbers that changed.

Law

What triggers it

Exposure

TCPA

Texting without written consent

$500 per text, $1,500 if wilful

CCPA (breach)

Public bucket, unencrypted data

$100–750 per user

Unruh Act

Site fails a screen reader (California)

$4,000 minimum per visit

CIPA

Session replay or chat widget recording

$5,000 per visitor

CCPA (minors)

Under-16 signs up

$7,500 per intentional violation

ROSCA

Cancelling harder than signing up

$53,088 per violation

COPPA

Under-13 registers

$53,088 per child

Texas TRAIGA

AI that doesn't say it's AI

Up to $200,000 per violation

EU AI Act

Same, for EU users

€15M or 3% of global revenue

AGPL

Licensed code pasted into your repo

$150,000 per file, and your source goes public

Two of these are new

Texas TRAIGA came into force on 1 January 2026. The EU AI Act's disclosure duty only became applicable on 2 August 2026 — five weeks ago. If your chatbot serves anyone in the EU and never says it's a bot, that one is live right now and almost nobody has caught up.

"I've got forty users. Nobody's suing me."

Mostly true. The FTC is not coming for your side project.

But three of these don't need anyone to care about you specifically:

  • Accessibility demand letters are sent by volume, by firms running automated scans. Typical settlement is £4,000–£24,000 and they never see your revenue first.

  • CIPA claims are an active class-action wave in California, aimed at whoever has the tracking script installed. That's you, not your analytics vendor.

  • Licence contamination doesn't need a plaintiff at all. Once an AGPL file is in your repo, the licence terminates automatically and every copy you ship is infringement. The remedy isn't a fine — it's publishing your source.

That last one is the one I'd actually check tonight. Your coding agent doesn't tell you where it learned a function.

What to do with the output

Fix the top three. Ignore the rest until you have paying users — a CAN'T TELL on COPPA doesn't matter at forty users, and a public storage bucket does.

Run it again after every big feature. It costs one prompt.

If it flags something you can't parse, reply to this email and send me the line. I read every one.

Not legal advice — I build things, I'm not your solicitor. If the audit lights up red on a live product with real revenue, pay someone for an hour.

— Mike

P.S. If you'd rather someone just ran this across your whole stack and handed you the fixes, that's the sort of thing we do at optimax-ai.com.