NewSnippets: tell the AI about you and your company once.See how New modelClaude Sonnet 5.5 is now available.Read more
FREE · 12 ROUNDS · ~5 MINUTES

Allow, gate, or block? You decide.

Twelve requests that could plausibly land in your inbox this week. Some are outright prohibited, some are permitted with the right controls, and some are ordinary work you shouldn't get in the way of. Most people can't tell which is which - and the ones who block everything score no better than the ones who wave it all through.

No sign-up, no email Works as a team workshop Every answer cites its article
TIP
Keys 1 · 2 · 3 to answer, ↵ to continue. Handy when you're projecting it.
ai-act-triage12 ROUNDS · ~5 MIN
YOU ARE THE AI GOVERNANCE OWNER

Twelve requests land in your inbox.

For each one, make the call: wave it through, allow it with controls and a record, or refuse it outright. You'll see the reasoning and the article after every answer.

Both kinds of mistake are counted. Letting something dangerous through is the obvious failure - but blocking work the Regulation permits is scored against you too, because that's how a company ends up with shadow AI.

Why there are two scores

Over-blocking isn't caution. It's a leak.

Every compliance quiz rewards saying no. Real life doesn't. A governance function that refuses work the Regulation plainly permits doesn't reduce the company's exposure - it moves that work onto personal accounts and free tiers, where there's no log, no owner and no redaction. That's how a careful company ends up with the least defensible estate.

So the game scores both directions. Miss a prohibited practice and your safety drops. Block a permitted one and your usefulness drops. The people you want deciding these questions score well on both.

The Human Firewall
safe · unusable
The Governance Owner
safe · trusted
The Coin Flipper
neither
The Enabler
fast · exposed
USEFULNESS →
SAFETY →
What twelve rounds actually teach

Four ideas that survive the walk back to someone's desk.

The deck is built so that the pattern emerges from playing rather than from a slide. Every answer names the provision it comes from, in plain language.

The bans are a floor
Art. 5 isn't a risk to be weighed against a business case. Three rounds are prohibited practices, and no amount of process makes them acceptable.
High-risk means controls, not refusal
Hiring and creditworthiness are permitted with a named overseer, a record and a notice. People who reflexively block these are getting it wrong in the other direction.
Transparency is usually a fifteen-minute fix
Most Art. 50 problems are a missing disclosure or an unmarked file - cheap to solve, expensive to discover after launch.
Most AI use is simply fine
A quarter of the deck is minimal-risk work. Recognising that quickly is what keeps a governance function credible enough to be listened to on the hard ones.
Run it with your team

A 23-minute workshop that produces an actual decision list.

This is the format we'd use. It works for a team of five or a room of fifty, needs no preparation, and ends with something written down rather than a feeling that everyone should be careful.

01 5 min
Everyone plays alone first
Five minutes, phones or laptops, no discussion. People commit to a call before hearing anyone else's - otherwise the loudest person in the room sets the answer.
02 5 min
Compare the two scores, not the total
Ask for a show of hands on safety, then on usefulness. The spread is the conversation: your team almost certainly splits into firewalls and enablers, and both think they're being responsible.
03 8 min
Replay the three that split the room
Project the game and re-read those requests aloud. Have someone argue each call before you reveal it. Disagreement here is the point - it's where your actual policy is undefined.
04 5 min
Write down what you'd do on Monday
For each contested one, name who decides in real life and what they'd need to see. That list is the beginning of a usable internal policy, drafted by the people who'll have to follow it.
Want the scenarios on paper?
The starter kit has all twelve written out, plus a curriculum outline and the evidence checklist. No form, no email - it's just a PDF.
Download the kit
On the answer key

Each round maps to a specific provision - the prohibited practices in Art. 5, the Annex III high-risk categories, the transparency duties in Art. 50, and the provider-role trap in Art. 25. The scenarios are simplified so that one call is clearly better than the others; real requests arrive with less clarity and more context, which is exactly why the discussion in step three matters more than the score. The Annex III high-risk obligations apply from 2 December 2027, after the Digital Omnibus moved the date; the game treats them as the controls a careful company puts in place before then.

Not legal advice

A plain-language teaching aid built on Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, not advice on your situation. Confirm current requirements against the consolidated text and with your own counsel. Nothing here is recorded: the game runs entirely in your browser and no answers leave it.

Last reviewed 28 September 2026.

Trial
A $5 balance to start. No card needed.
From game to habit

The hard part isn't the quiz. It's next Tuesday.

StickyPrompts makes the same call in the prompt path, every day, for everyone - and writes the record while it does it. Start free with a $5 trial balance.