How AI scan review works
What the AI drafts after a scan, how confidence works, why every draft waits in the review queue for a person, and how the monthly budget behaves.
What the AI drafts, and when
A scan matches every cookie it finds against the known list first. Recognized cookies need no help. For each cookie the known list did not recognize, AI drafts three fields: a category, a provider, and a plain-language purpose. This runs automatically after every successful scan — scheduled or manual, each run spending one of the month's ten — and you can also trigger it yourself from the AI review section on the Cookies tab, which sits above the inventory it feeds. Its button reads Review cookies — or Review 12 cookies, counting the rows a review would actually touch.
The reason AI sits at this step and only this step: an unrecognized cookie is exactly the case a lookup table cannot solve. Someone has to propose what an undocumented cookie is for. AI is good at drafting that proposal. It is not allowed to decide it.
Risk flags: analysis, not verdicts
Alongside the drafts, the AI raises flags about firing behavior the scan evidenced. Two examples of the kind of thing it catches:
- A marketing pixel set cookies during a crawl that granted no consent.
- Ad identifiers were written to
localStorage— storage that cookie-only gating would miss entirely.
Read flags for what they are. They describe what the scan observed, and they exist for you to act on. They are not a compliance verdict. Whether an observed behavior is a violation depends on your jurisdiction, your configuration, and facts the scan cannot see. A flag tells you where to look. You decide what it means.
Confidence is coarse on purpose
Each purpose draft carries a confidence word: high, medium, or low. Those map to 90%, 60%, and 30%. The model chooses a word, not a number.
Why words instead of decimals: a model that reports 87.3% confidence is dressing a guess in false precision. The number would look like measurement and read like authority, and it is neither. Three coarse levels tell you what you actually need for triage: high means verify and approve, medium means read it closely, low means expect to rewrite it.
Everything is a draft until you approve it
Every field the AI writes (category, provider, purpose) lands in the review queue as a draft. Nothing is approved and nothing is published without a person.
The reason is accountability. A published cookie inventory is a statement your organization makes to visitors and regulators. A model can accelerate the drafting, but it cannot be the party responsible for the claim. So the AI proposes, the queue holds, and a person approves. That order does not change.
The budget: 10 reviews per site per month
Each site gets 10 AI reviews per calendar month. A scheduled scan uses one automatically. The AI review section on the Cookies tab shows the meter, so you can see how many remain before you spend one.
AI review is the only metered feature in the product. Scans and pageviews are never metered, and never will count against anything. The line is deliberate: the evidence pipeline is the compliance-critical path, so it is never rationed. The AI is a drafting convenience layered on top, so it is the one thing that meters.
When a site runs out of budget:
- Scans keep running, and they stay complete and correct. Nothing about scan quality degrades.
- Unrecognized cookies still land in the review queue. They just arrive without AI drafts.
- Drafting resumes on the 1st of the next month.
If you are rationing, spend reviews where the unknowns are: a site you just onboarded, or a site whose tag setup changed. A stable site whose scan matches last month's rarely needs one.