Last updated: 2026-04-11

What SpendLil Covers

Which compliance requirements SpendLil helps with today and what's on the roadmap.

SpendLil is building toward comprehensive AI governance. Here's what's covered today, what's coming next, and what you'll still need to handle yourself.

Covered Today

RequirementHow SpendLil HelpsRelevant Regulation
AI inventory / asset registerAuto-discovers every API key and provider in use across your accountEU AI Act Art. 26(1), UK AI principles
Usage loggingEvery AI request is logged with timestamp, model, tokens, cost, and key identifierEU AI Act Art. 26(6), GDPR Art. 30
Spend trackingReal-time cost visibility by key, provider, and modelInternal governance, budget control
AlertingConfigurable thresholds for spend, volume spikes, and new key detectionRisk management, oversight
Audit trailDashboard activity logging with 365-day retentionEU AI Act Art. 26(6), GDPR Art. 5(2)
Data minimisation (SpendLil itself)No prompt storage, no key storage, no response storage — metadata onlyGDPR Art. 5(1)(c)

Coming in Phase A

FeatureWhat It DoesRelevant Regulation
PII detectionScans prompts for personal data (emails, NI numbers, phone numbers) and alertsGDPR Art. 5, 6, 9 — lawful processing of personal data
DLP rulesConfigurable data loss prevention — flag or alert on sensitive data categoriesGDPR, sector-specific data protection
Prompt injection detectionDetects attempts to manipulate AI via prompt injection (async, non-blocking)EU AI Act Art. 15 — accuracy and robustness
Bias auditingMonitors AI outputs for patterns of bias across protected characteristicsEU AI Act Art. 10, Equality Act 2010
Human-in-the-loop approvalsRequire human review before AI decisions are actioned in high-risk casesEU AI Act Art. 14 — human oversight
EU AI Act compliance suiteTransparency disclosures, conformity assessments, rights impact assessments, incident reportsEU AI Act Art. 13, 26, 27, 62
Quality scoringScore AI outputs for quality and track degradation over timeEU AI Act Art. 9 — risk management
Outgoing webhooksSend events to Zapier/Make for custom compliance workflowsGovernance automation

You Still Need To Handle

SpendLil covers the AI-specific technical layer. These broader requirements sit with your business:

  • AI policy — a written policy covering how your business uses AI, who's responsible, and what's allowed
  • Risk assessments — for high-risk use cases, a formal assessment of potential harm (FRIA for EU AI Act)
  • Staff training — ensuring your team has AI literacy and understands their responsibilities
  • Data protection impact assessments (DPIAs) — required under GDPR when AI processes personal data at scale
  • Sector-specific compliance — FCA, SRA, GMC, Ofsted, etc. requirements specific to your industry
  • Incident response plan — what to do if an AI system causes harm or produces a discriminatory outcome
  • Supplier due diligence — assessing the AI providers you use (OpenAI, Anthropic, etc.) for their compliance posture
  • Record keeping beyond SpendLil — maintaining records of AI-related decisions, risk assessments, and compliance activities
💡 SpendLil gives you the data; you provide the governance

Think of SpendLil as the technical foundation. We give you visibility, logging, and alerts. You build the policies, training, and decision-making frameworks on top.