MGLA
Multi-Gap Live Analysis
Vol. V · Domains · Nine regulated sectors under live analysis

Nine domains. One framework.

MGLA evaluates regulatory-technical gaps simultaneously across nine domains of operation — each with its own instruments, its own technical surface, and its own jurisdictional footprint. They are not handled as silos. They are handled in the same loop.

§ 01   The nine domains, in detail

Risk index updated continuously
01
AI
Artificial Intelligence
Instruments
EU AI Act · ISO 42001 · NIST AI RMF

Foundation models, fine-tunes, agentic systems and high-risk use cases — bound to transparency, conformity and post-market obligations.

Risk idx
29.6
● high
02
GDPR
Data Protection
Instruments
GDPR · ePrivacy · Data Act

Lawfulness, purpose, retention, transfer and data-subject rights — evaluated against the actual systems that act on personal data.

Risk idx
171.2
● critical
03
CYBER
Cybersecurity
Instruments
NIS2 · CRA · ISO 27001 · ISO 27701

Essential-entity obligations, incident reporting, supply-chain due diligence and product cybersecurity, all tied to the running stack.

Risk idx
63.4
● high
04
FINTECH
Financial Services
Instruments
DORA · MiCA · PSD3 · AML 6

Operational resilience, ICT third-party risk, crypto-asset issuance and payment-services obligations — modelled as live posture.

Risk idx
28.8
● medium
05
CONTRACT
Contractual
Instruments
B2B · DPA · SCC · MSA

DPAs, SCC modules, sub-processor chains and side letters — parsed and bound to the obligations they actually cover.

Risk idx
16.6
● medium
06
PQC
Post-Quantum Cryptography
Instruments
NIST PQC · ETSI TS · CNSA 2.0

Migration posture across handshakes, signatures and stored ciphertexts — tracked against published cryptographic timelines.

Risk idx
12.1
● low
07
WEB3
Distributed Systems
Instruments
MiCA · TFR · DLT Pilot

Token classification, issuer obligations, custody arrangements and travel-rule data flows across distributed ledgers.

Risk idx
17.5
● medium
08
ECOM
Digital Markets
Instruments
DMA · DSA · Consumer Rights

Gatekeeper obligations, marketplace duties, illegal-content procedures and dark-pattern prohibitions across consumer interfaces.

Risk idx
5.2
● low
09
SPACE
Space & Sovereignty
Instruments
EU Space Law · ITU · Outer Space

Frequency coordination, debris mitigation, payload sovereignty and dual-use export controls for orbital operations.

Risk idx
4.4
● low
§ 02
Cross-cutting

One inference call. Three regimes. Four layers.

A foundation model trained in the United States, fine-tuned in Ireland, and served to consumers in Brazil carries simultaneous obligations under the EU AI Act, GDPR, and Brazilian LGPD — bound to the same DPA, the same telemetry, the same loop.

MGLA does not split this into three tickets in three workstreams. It is one finding, evaluated across four layers, on a single timestamp.

§ 03   Matrix · selected layers × selected domains

A reading aid — the full matrix has 4 × 9 cells
Layer / Domain
AI
GDPR
CYBER
FINTECH
WEB3
Normative
EU AI Act Art. 6, 50
GDPR Art. 6, 22
NIS2 Art. 21, 23
DORA Art. 5–14
MiCA Title II–IV
Technical
model card · eval
consent · retention
SBOM · incident log
ICT register
on-chain telemetry
Contractual
provider SLA
DPA · SCC mod. 2
sub-processor MSA
CTPP register
issuer agreement
Jurisdictional
EU · UK · US
EEA · adequacy
EU establishment
home/host state
issuer domicile

Map your footprint across the nine.

We onboard the framework against your specific normative footprint — the regimes, contracts and systems that govern your operation today.

MGLA
Multi-Gap Live Analysis™

A live regulatory analysis framework, developed and maintained by IT Law 2035.

Framework
Reading
Institution
MGLA™ Multi-Gap Live Analysis™ · © 2026 IT Law 2035The MGLA framework, architecture and methodologies are proprietary.