Could I not do this with ChatGPT or Claude?
You may already use one of them, and they are useful for drafting and exploration. The relevant question is whether you also need a persistent governance model, structured decision workflows, evidence status and ownership, consistent control terminology, reusable governance artifacts, and explicit validation boundaries. AI Control Index combines those in one personal workspace, and its high-stakes outputs separate fact from assumption and flag what still needs validation.
We already have a GRC or compliance platform. What does this add?
That platform is the right place to store approved risks, controls, actions, and evidence. AI Control Index supports the work that happens before those records are ready: challenging the initial claim, finding the missing questions, qualifying the available evidence, recording conditions and dissent, and preparing the decision. It does not replace the system of record; it helps you prepare better material to put into it.
Is the output legal, audit, or compliance advice?
No. It is structured governance support based on published frameworks, standards, and regulations, and on the information you supply. It is not a legal opinion, audit assurance, compliance certification, or formal risk acceptance. Material conclusions should be reviewed by the appropriately qualified and authorised person. See the limitations in the Trust Center.
Why pay for the app when the model is free and the book explains the method?
The three serve different purposes. The free model helps you understand what should be governed. The book explains why the controls and evidence discipline matter. The app helps you apply both to your own situation, this week: your vendors, your evidence, your documents, with full export. Use the model as a reference, read the book for depth, and use Pro when the decision, evidence, and accountability are yours.
Can I use confidential information?
The app is designed for organisation-sensitive governance work, but you should still minimise sensitive information and follow your organisation's policies. Your data is stored in the EU (Amsterdam region), and under our Anthropic Zero-Data-Retention arrangement your content is not retained after the response or used to train models. For highly sensitive material, redact or anonymise what is not needed for the task. Full detail in the Trust Center.