AI Guides › Workbench

The Six-Trap Launch Audit for AI-Built Apps

By Nigel Guy · 8 min read

You built the app with an AI coding tool, it works, and the plan is to "sort the legal bits once it has users". That feels sensible because nothing has gone wrong yet. But the riskiest parts of a small app are the boring defaults the AI pasted in: a font loaded from Google, a session recorder switched on, a sign-up form with no age question, an upload box with no way to report anything. The AI added them because they are common, not because they are compliant.

The rule: audit the defaults before launch, read-only, with evidence from your own code — then fix the smallest thing that closes each gap.

Why "per" is the word to worry about

Since 5 February 2026, when the main parts of the Data (Use and Access) Act 2025 came into force, the ICO can fine breaches of PECR (the cookie and marketing-email rules) up to £17.5 million or 4% of global turnover, whichever is higher, and the old "serious contravention" threshold has gone. Ofcom's Online Safety Act penalties reach £18 million or 10% of qualifying worldwide revenue. Those are ceilings, not a likely bill, but small contraventions are now fineable.

If you have US users, the arithmetic changes. The FTC's civil penalties for rule breaches such as children's privacy (COPPA) and marketing email (CAN-SPAM) are set per violation — $53,088 per violation in the FTC's January 2025 inflation adjustment, which is revised every year. Each unlawful email or child's account can count separately.

The kit at a glance

Tool What it does Cost at time of writing Best for Catch
Six-trap audit prompt (below) Reads your codebase and reports PASS / RISK / N/A with file references Free with any coding agent you already pay for; Claude Pro is about £18 a month in the UK (check claude.ai/upgrade) First pass on the whole app Sees code only, not dashboards or live pages
Browser DevTools, Network tab Shows every request a page makes before you click anything Free Proving what leaks before consent Test in a private window, banner untouched
Fontsource npm packages of open-source fonts you host yourself Free Removing Google Fonts calls Need to check licence of non-Google fonts
Microsoft Clarity Consent Mode Holds session recording until a consent signal arrives Clarity is free Apps already using Clarity Needs a banner or the Consent API wired in
Ofcom regulation checker Tells you whether the Online Safety Act applies Free Any app with uploads, comments or messaging "Unclear" still means work
ICO Children's code resources Standards for services likely to be used by under-18s Free Anything a teenager might plausibly use Applies by likelihood of access, not your intended audience

The six traps

Trap What the AI tends to leave UK rule in play
1. Age Sign-up with no age step UK GDPR (13 is the age for consent-based online services) and the ICO Children's code for under-18s
2. Fonts and third-party calls fonts.googleapis.com, CDN scripts, embeds that fire on load UK GDPR (the IP address is personal data) and PECR. A Munich court awarded €100 damages in 2022 over Google Fonts alone
3. Session replay Hotjar, Clarity or similar recording from the first page view PECR. The new statistical-purposes exception covers how a service is used, not who uses it; we found no ICO statement that it covers session replay, so treat replay as needing consent
4. Launch email A blast to everyone who ever signed up, no unsubscribe PECR: consent or the "soft opt-in" for existing customers, your identity not hidden, a working opt-out in every message
5. Subscribe button Price in the plan card, renewal and cancellation buried in terms Consumer Contracts Regulations 2013 and the CMA's unfair-practices powers under the DMCC Act 2024
6. Uploads Users can post images or text others see, no report route Online Safety Act (user-to-user services; illegal-content duties enforceable since March 2025, child-safety duties since July 2025); US DMCA if you rely on its safe harbour

A note on subscriptions: the DMCC Act's dedicated subscription regime (reminder notices, renewal cooling-off, easy online exit) was not in force at time of writing. Its start has slipped repeatedly; reports now point to 2027. Build easy online cancellation anyway.

How to use the audit prompt

Open the project in a coding agent that can read the whole repository (Claude Code, Cursor or similar). In Claude Code, switch to Plan Mode first (Shift+Tab cycles modes) so nothing is edited during the audit.

Fill in: what the app does, who it is for, where users are, and your email and payment tools.

You are a careful pre-launch compliance reviewer for a small web app built largely with AI coding tools. You are not my lawyer and must not present findings as legal advice. Your job is to find likely problems, show the evidence in the code, and suggest the smallest fix.

Context:
- What the app does: [ONE_SENTENCE_DESCRIPTION]
- Intended users and whether under-18s could plausibly use it: [AUDIENCE]
- Where users are: [UK_ONLY / UK_AND_EU / INCLUDES_US]
- Email tool: [EMAIL_PLATFORM]  Payment tool: [PAYMENT_PROVIDER]

If any of these is blank, ask me for it before you start. Do not assume.

Work in this order:
1. Read the full repository, including templates, layout files, config, environment examples and package files.
2. Check each area below and record what you find.
   a. Age: any form collecting personal data with no age question or age confirmation; any feature or copy that would appeal to children.
   b. Third-party requests on page load: list every external domain contacted (fonts, CDNs, analytics, embeds, chat widgets) and whether it loads before any consent choice.
   c. Recording and analytics: any session replay, heatmap or keystroke capture; whether it starts by default; whether it waits for consent.
   d. Marketing email: templates or code that send promotional email; presence of a working unsubscribe link, a sender identity and a contact address; whether unsubscribes are written back automatically.
   e. Subscriptions: next to each pay or subscribe action, whether price, billing interval, renewal and how to cancel are visible before payment; whether cancellation can be done online without contacting support.
   f. User content: whether users can upload or post anything others can see; whether there is a report or takedown route and a content policy page.
3. Mark anything you cannot see in code (dashboard settings, live email platform config) as UNKNOWN rather than guessing.

Output format, one section per area:
- Status: PASS, RISK, UNKNOWN or NOT APPLICABLE
- Evidence: file paths and line numbers
- Smallest fix: the specific change, described, not applied
- Needs a human: yes or no, with one line on why

Finish with a five-line summary ranked by risk.

Rules: change no files. Stop after the report and wait for me to name which fixes to make. Before replying, check that every RISK cites a real file and line, and that you have not stated any legal requirement as certain where you are unsure.

The fixes that usually close the gap

How to choose

What to skip

Guardrails

Sources

All 751 AI guides · JulieMango plans from £17/mo