Three legal changes. Three areas in the company. And every time the same crucial question: does the information reach the responsible person in time?
Human Resources is late in taking into account the minimum wage, which was raised to €13.90 on 1 January.
A manufacturer is exporting vacuum cleaners to Great Britain without including the permitted noise level of 70 dBA, which has been in force since 1 April, in product development and conformity assessment.
An IT director only recognises the obligation to register with the BSI under NIS2 after the amendment to Section 38 of the BSIG has already entered into force.
Three examples from different areas. Behind each lies the same challenge: a change in the law has been published, but reaches the relevant departments within the company too late or remains without clear evaluation and allocation.
This affects far more than isolated cases. In the first 19 days of February 2026 alone, around 200 regulatory changes were published at European and national levels. Roughly 80 of these could be relevant to businesses. This dynamic is not concentrated in individual exceptional phases. It defines the day-to-day regulatory reality for companies.
Regulatory requirements affect companies of every size and industry – whether they manufacture, trade, employ staff or provide services. It is therefore crucial when a change within the company is identified, who assesses its relevance and how quickly a concrete measure results from it.
In many companies, this information reaches the relevant department only with a delay. The cause often lies in processes that are too sluggish for today's speed of regulatory change. Quarterly updates, Excel lists and PDF services provided by law firms offer guidance. However, for the continuous recording, assessment and implementation of changes in the law, they increasingly create a structural risk.
What are the 20% companies doing differently to ensure they incorporate regulatory changes into their processes in good time? A look at the other 80% reveals four recurring patterns: changes in the law are identified too late, their relevance remains unclear, or implementation only reaches the relevant departments after a delay.
Why the 80% reacts too late – the four patterns
- The legal register as a snapshot
A deadline, an audit, a list. Ideally meticulously created, agreed upon, filed. What happens afterwards, few people think through. Months pass between two updates – during which regulation continues. A company audited in January could already be in breach of a new requirement in February, without realising it. - The Illusion of the Quarterly Update
Reading the newsletter, keeping track of firm updates, filing PDFs – and yet a central question remains unanswered: does our company meet all relevant requirements? The quarterly update is a textbook example of reactive compliance. Information reaches the company only when the external adviser has prepared it. However, legal changes follow their own rhythm. - The Paradox of Competence
As soon as companies recognise the need for action, an obvious step often follows: they collect as many legal sources as possible. Legal databases are filled with hundreds of national and supranational sets of rules. In May 2024 alone, German federal law comprised more than 52,000 individual norms in statutes – accompanied by around 44,500 individual norms in statutory ordinances as well as state law, EU law and industry-specific requirements. This quickly creates a huge volume of information. However, the crucial question remains which obligations are actually relevant to one's own company. Without a clear relevance assessment and assignment to those responsible, precisely these obligations can easily be lost sight of in the mass. - Old knowledge that nobody questions
The most consequential decision in the land register is the entry„That doesn't concern us.“It is made casually, rarely justified and mostly never reviewed again. At the same time, the company is constantly changing: a manufacturing company with its own occupational health physician inadvertently brings the regulatory logic of a small hospital into its operations – with obligations that no one had on their radar. And the question remains:Where else have we ruled out something that's already effective?
What sets the 20% apart – the four differences
| 80% (reactive) | 20% (proactive) |
Update | Quarterly by PDF | Daily, automatically |
Relevance check | Manually, by feel | AI-powered, company-specific |
Responsibilities | Named in the organisational chart | Operationally assigned, with deadlines |
Detectability | Difficult to prove | Every decision documented and justified |
Relevance over completeness.
The 20% does not cover every legal source. It asks: What applies to our company today, at this site and in relation to these activities? Structured data such as sites, WZ codes and asset types are linked to policies, product descriptions and contracts. This makes it possible to identify and prioritise relevant obligations.
From push to pull principle.
The 80% models await external information. The 20% models use systems that detect and assess changes, and make them available the following morning as specific tasks to be carried out. If a law changes on a Tuesday, the legal register is updated on Wednesday – rather than months later.
Decisions are explainable.
The 20% legal register documents what applies, why a decision was made and whether it remains valid. During an audit, you can demonstrate your compliance and provide a clear, traceable justification for each individual assessment.
Knowledge remains in the system.
With the 80%, compliance knowledge is often held by individual staff members. If the person responsible leaves the organisation, gaps in knowledge arise which, in many cases, only become apparent during the next audit. The 20% embed this knowledge within the system: responsibilities, deadlines and documentation remain traceable – regardless of individual staff members.
The 5 questions that show the difference
Where does your company stand today?
- Was your legal register in the last7 dayschecked for relevant changes?
- Are internal documents such as guidelines and product descriptions compliant with applicable requirements linked?
- Can you traceably at the push of a button document, why a regulation was classified as not relevant?
- Does your compliance knowledge remain available if a central Skilled worker is cancelled for tomorrow?
- UseAI as a Relevance Filter– or is the evaluation done predominantly manually?
If you hesitated on one or more questions, you are not alone. Many companies work diligently and still ask themselves: Have we identified all relevant changes and evaluated them correctly?
We have developed a structured demo precisely for this point. In 30 minutes, we will show you:
- How an AI-powered legal register continuously tracks regulatory changes and filters them based on your company profile
- How relevant regulatory fields for 2026 and 2027 are already being mapped out in a structured way today
- What the complete audit trail looks like from change detection to implementation
- How your existing setup fits in – honestly and directly