From AI use case to a defensible compliance design. In minutes, with sources.
The open, community-curated knowledge graph for regulated AI — the full regulatory stack, compliance by design, and the business case in one traversal. Free to use — every claim carries its citation, inspectable node by node. Open to use and audit in the app; bulk graph export is not offered.
- RegulationMulti-layer and current: 88 regulations across AI, data protection, cyber & resilience, online safety & platform law, product safety & liability, financial services and sector, market & employment law, plus the standards layer — each legal claim with a verification status and date.
- DesignCompliance by design: control objectives, reference architecture, components, patterns and the evidence plan — designed into the system, not audited onto it afterwards.
- BusinessRisk & value: priority score, compliance cost bands, 3-year ROAI and an explicit verdict — proceed, downtier, re-architect or terminate.
One use case, translated end to end
Live from the knowledge graph — not a mockup. Open the profile to check every step.
- The use case: AI Credit Scoring & Loan Decisioning — affects natural persons · automated decision · financial sector. Start with any AI use case — described in your words.
- The cross-domain footprint: 9 regulations across AI, data protection, cyber & resilience, product safety & liability, financial services, sector, market & employment law, and 23 obligations with citations — of which the AI Act dimension is High Risk. → 9 regulations across 6 regulatory domains, 23 obligations — every one with its legal citation.
- The technical translation: Translated into 41 architecture components and 34 standards references, for example WORM / Immutable Audit Vault, Explainability API (SHAP/LIME/CoT), Adverse-Decision Reason Generator, HITL Escalation Queue & Review UI. → translated into the architecture and evidence you must build — compliance by design.
- The vendor choice: 11 market layers can supply them; the strongest are Agent Observability & Model Risk Management (confidence 96/100, e.g. LangSmith); AI GRC & Governance Platforms (confidence 96/100, e.g. Credo AI); Confidential Computing & Privacy Engines (confidence 96/100, e.g. Anjuna). → and who can supply each part — scored, disputable, never an endorsement.
- The business verdict: Business verdict: SCOPE DOWN & DOWN-TIER — initial compliance cost €240k – €780k, annual €62k – €93k, 3-year ROAI -37%. → plus the answer pure compliance review never gives: is it worth it?
The advantage is structural: one graph instead of four workstreams
Teams today run four parallel workstreams — legal research, architecture translation, vendor screening, business case. RAIN is one traversal.
- Centre of the diagram
- One knowledge graph with 475 curated claims and 1716 sourced connections, graph version 2.13.0.
- Fast
- Scoping in minutes, not weeks — one traversal replaces serial research.
- Safe
- Every claim cited, every gap visible — confidence stated, never implied.
- Affordable
- Free & open — vs €10k–150k/yr suites — contribute-to-participate community.
- Current
- Verification dates + weekly walker agents — agents propose, humans decide.
What it does for you
How it works
- Describe or upload your use caseFree text, or a project document (PDF, DOCX, TXT, MD). The analysis runs in your browser — nothing is stored, no login.
- The knowledge graph traverses the regulatory stack88 regulations across AI, data protection, cyber & resilience, online safety & platform law, product safety & liability, financial services and sector, market & employment law — and the standards layer — in 28 jurisdictions across 6 world regions are traversed to the cross-domain footprint, the AI-law dimension, obligations, controls, architecture and evidence, with a visible reasoning trace and a confidence statement you can interrogate.
- Keep the artifacts — compliance and businessExecutive brief, Annex IV skeleton, ISO 42001 / CSA AICM mapping and a build-or-buy shortlist — plus the business lens: compliance cost bands, 3-year ROAI and a go/no-go verdict. Exportable as PDF, CSV and Markdown.
use-case identification → statutory & risk tiering → architectural control layers → vendor stack mapping
More views on the same graph
Why not the alternatives
| RAIN | Enterprise governance suites | Free AI Act checkers | Open control matrices | |
|---|---|---|---|---|
| Traceable reasoning | Yes — every conclusion shows the rule and the claims it used | Mostly opaque scoring | Questionnaire logic, not shown | No reasoning at all |
| Full chain to architecture & evidence | Use case → law → obligation → control → component → evidence | Tells you what to document, rarely what to build | Stops at the AI Act risk class — one domain of many | Flat control lists |
| Build-or-buy view | Per control layer, with vendor categories and confidence | Their own platform is the answer | None | None |
| Business-risk perspective (cost, ROAI, go/no-go) | Yes — Risk & Value Evaluator: priority score, cost bands, 3-year ROAI, explicit verdict | — documentation focus | — | — |
| Community validation with named experts | Named reviewers on the claim and in the release | Vendor-internal research team | Anonymous | Committee, slow cycles |
| Price | Free to use | ≈ €10k–150k / year | Free | Free |
What RAIN does not do: it does not enforce anything at runtime, it does not certify, and it is not legal advice. It is a reasoning and documentation aid — the decision stays with you and your counsel.
Categories named generically: “enterprise governance suites” = commercial AI/GRC platforms sold per seat or per system; “free AI Act checkers” = questionnaire-style classifiers; “open control matrices” = published control catalogues such as AI management-system or cloud control matrices. Price range is the publicly advertised order of magnitude, not a quote.
The knowledge graph, and the people who harden it
How the graph works, technically →
- 475 curated claims in 16 categories
- 1716 sourced connections (24 relation types, average 7.2 per claim)
- 45 use-case profiles across 17 sectors
- 70% of legal references carry a verification date (128 of 184)
- 48 public releases · 0 orphan claims (every claim is connected)
- Every contribution carries a source — enforced in the database, not by etiquette.
- Every contributor is named on the claim and in the release notes.
- Gaps are public: the verification queue shows what is not yet checked.
- Invite-only, reference-based membership with contribution credits — credits exist so that every analysis in circulation is backed by verified expert work.
Sourced, current information
Every legal claim across the multi-layer stack — AI, data protection, cyber and resilience, product safety and liability, sector and financial law, and the standards layer — carries a status and a verification date, so you can see how old the statement you are relying on is. Monitored sources trigger re-verification when an act, standard or guidance changes. Corrections are logged publicly — including our own.
Today: 128 of 184 legal references verified — the rest is visible on the public queue. Graph v2.13.0, updated 2026-08-28. Proof that we log our own mistakes: release v2.21.0 — a correction release (sign-in required).
A machine-conducted pilot source audit has been published — including the 12 weaknesses it found in our own graph read the pilot results →
Pre-registered human benchmark study: protocol published, participants wanted read the protocol →
is stated, never implied: an unverified claim is labelled as unverified.
Describe your first use case — free, no login, nothing stored.
RAIN — Regulated AI Navigator · rainavigator.org · knowledge graph v2.13.0 · not legal advice