Skip to content

Regulated AI Navigator

From AI use case to a defensible compliance design. In minutes, with sources.

The open, community-curated knowledge graph for regulated AI — the full regulatory stack, compliance by design, and the business case in one traversal. Free to use — every claim carries its citation, inspectable node by node. Open to use and audit in the app; bulk graph export is not offered.

Graph v2.13.0updated 2026-08-28475 curated claims · 1716 sourced connections128 of 184 legal references verified48 releases (sign-in required)every change logged
  • RegulationMulti-layer and current: 88 regulations across AI, data protection, cyber & resilience, online safety & platform law, product safety & liability, financial services and sector, market & employment law, plus the standards layer — each legal claim with a verification status and date.
  • DesignCompliance by design: control objectives, reference architecture, components, patterns and the evidence plan — designed into the system, not audited onto it afterwards.
  • BusinessRisk & value: priority score, compliance cost bands, 3-year ROAI and an explicit verdict — proceed, downtier, re-architect or terminate.
See it work in 20 seconds

One use case, translated end to end

Live from the knowledge graph — not a mockup. Open the profile to check every step.

  1. The use case: AI Credit Scoring & Loan Decisioning — affects natural persons · automated decision · financial sector. Start with any AI use case — described in your words.
  2. The cross-domain footprint: 9 regulations across AI, data protection, cyber & resilience, product safety & liability, financial services, sector, market & employment law, and 23 obligations with citations — of which the AI Act dimension is High Risk. → 9 regulations across 6 regulatory domains, 23 obligations — every one with its legal citation.
  3. The technical translation: Translated into 41 architecture components and 34 standards references, for example WORM / Immutable Audit Vault, Explainability API (SHAP/LIME/CoT), Adverse-Decision Reason Generator, HITL Escalation Queue & Review UI. → translated into the architecture and evidence you must build — compliance by design.
  4. The vendor choice: 11 market layers can supply them; the strongest are Agent Observability & Model Risk Management (confidence 96/100, e.g. LangSmith); AI GRC & Governance Platforms (confidence 96/100, e.g. Credo AI); Confidential Computing & Privacy Engines (confidence 96/100, e.g. Anjuna). → and who can supply each part — scored, disputable, never an endorsement.
  5. The business verdict: Business verdict: SCOPE DOWN & DOWN-TIER — initial compliance cost €240k – €780k, annual €62k – €93k, 3-year ROAI -37%. → plus the answer pure compliance review never gives: is it worth it?

The advantage is structural: one graph instead of four workstreams

Teams today run four parallel workstreams — legal research, architecture translation, vendor screening, business case. RAIN is one traversal.

ONE knowledge graph475 claims · 1716 connectionsOpen the graph →
FastScoping in minutes, not weeks — one traversal replaces serial research.
SafeEvery claim cited, every gap visible — confidence stated, never implied.
AffordableFree & open — vs €10k–150k/yr suites — contribute-to-participate community.
CurrentVerification dates + weekly walker agents — agents propose, humans decide.
Centre of the diagram
One knowledge graph with 475 curated claims and 1716 sourced connections, graph version 2.13.0.
Fast
Scoping in minutes, not weeks — one traversal replaces serial research.
Safe
Every claim cited, every gap visible — confidence stated, never implied.
Affordable
Free & open — vs €10k–150k/yr suites — contribute-to-participate community.
Current
Verification dates + weekly walker agents — agents propose, humans decide.

What it does for you

How it works

  1. Describe or upload your use caseFree text, or a project document (PDF, DOCX, TXT, MD). The analysis runs in your browser — nothing is stored, no login.
  2. The knowledge graph traverses the regulatory stack88 regulations across AI, data protection, cyber & resilience, online safety & platform law, product safety & liability, financial services and sector, market & employment law — and the standards layer — in 28 jurisdictions across 6 world regions are traversed to the cross-domain footprint, the AI-law dimension, obligations, controls, architecture and evidence, with a visible reasoning trace and a confidence statement you can interrogate.
  3. Keep the artifacts — compliance and businessExecutive brief, Annex IV skeleton, ISO 42001 / CSA AICM mapping and a build-or-buy shortlist — plus the business lens: compliance cost bands, 3-year ROAI and a go/no-go verdict. Exportable as PDF, CSV and Markdown.

use-case identification → statutory & risk tiering → architectural control layers → vendor stack mapping

More views on the same graph

Standards watch18 standards tracked through their lifecycle stage — 0 cited in the Official Journal, so none grants a presumption of conformity yet.Open →Precedent library45 classification precedents with the articles they rest on — 3 carry documented dissenting views.Open →Evidence matrix33 evidence artifacts mapped to the obligations they discharge — reuse factor 2.6× across 53 obligations, so one artifact usually answers several regimes at once.Open →Portfolio & change blast-radiusTrack your use cases as a member: each saved conclusion is diffed against the current graph, so a change arrives as “this affects these two of your systems”, with before → after per node — no count to quote here, it depends on what you track.Open →Architecture co-pilotEach conclusion also renders as a layered system topology: the controls and components the footprint resolved, placed where they must sit in the request path — only where the graph records a placement, never guessed.Open →Stack playgroundAssemble an agentic AI stack from the shelf of typical components — live use-case matches, market-filtered regulation and gap recommendations, derived in your browser from the same graph. Free, no sign-up.Open →Implementation pack & CI gate manifestThe same footprint emits engineering templates (oversight interceptor, reason-record schema, bias-log spec, vector-ACL probe, PCCP corridor) and a compliance-gate.json your pipeline can assert on — a projection of one use case, reviewed by counsel before anyone relies on it.Open →Cross-regime crosswalk21 mappings between obligations of different regimes across 15 regime pairs — 8 established, 13 asserted and open to dispute, each with its rationale.Open →Documentation scaffolds4 document types with 25 prefilled sections generated from a conclusion — 3 follow the provision's own enumeration, 1 is practice-derived and labelled as such. Scaffolds, never finished compliance documents.Open →Confidence & track recordEvery conclusion carries a computed confidence band and an exportable evidence dossier, fingerprinted against graph v2.13.0 (9d0641791cb9…): 128 of 184 law-bearing claims carry a recorded verification date, and every one of the 48 releases is hash-chained to the one before it.Open →How it stays currentThe monitoring loop itself: five dimensions watched, weekly agents consolidating them, reconciliation against the graph, a human curator gate, a hash-chained changelog entry, and a blast-radius notification to every affected saved case — explained and proven, stage by stage.Open →Incident-reporting router7 reporting regimes with 22 verified deadlines: who reports to whom, on one clock from T0.Open →

Why not the alternatives

 RAINEnterprise governance suitesFree AI Act checkersOpen control matrices
Traceable reasoningYes — every conclusion shows the rule and the claims it usedMostly opaque scoringQuestionnaire logic, not shownNo reasoning at all
Full chain to architecture & evidenceUse case → law → obligation → control → component → evidenceTells you what to document, rarely what to buildStops at the AI Act risk class — one domain of manyFlat control lists
Build-or-buy viewPer control layer, with vendor categories and confidenceTheir own platform is the answerNoneNone
Business-risk perspective (cost, ROAI, go/no-go)Yes — Risk & Value Evaluator: priority score, cost bands, 3-year ROAI, explicit verdict— documentation focus
Community validation with named expertsNamed reviewers on the claim and in the releaseVendor-internal research teamAnonymousCommittee, slow cycles
PriceFree to use≈ €10k–150k / yearFreeFree
  • Web research34%
    10 / 29 instrumentsstale top results in 3/5 cases
  • Free checkers17%
    5 / 29 instrumentssingle-act scope by design
  • RAINavigator62%
    18 / 29 instrumentsfull chain to design & evidence
Conventional web research
10 of 29 reference instruments (34%). Confirmed stale top results in 3 of 5 cases.
Best open checker per case
5 of 29 reference instruments (17%). Legitimately correct risk-class answers in 4 of 5 cases, including the valuable negative finding.
RAI·N·avigator graph
18 of 29 reference instruments (62%). Full six-stage chain depth in 4 of 5 cases.

Machine-conducted pilot source audit, Aug 2026 — method, limitations and our own 12 found weaknesses: /study

What RAIN does not do: it does not enforce anything at runtime, it does not certify, and it is not legal advice. It is a reasoning and documentation aid — the decision stays with you and your counsel.

Categories named generically: “enterprise governance suites” = commercial AI/GRC platforms sold per seat or per system; “free AI Act checkers” = questionnaire-style classifiers; “open control matrices” = published control catalogues such as AI management-system or cloud control matrices. Price range is the publicly advertised order of magnitude, not a quote.

The knowledge graph, and the people who harden it

How the graph works, technically →

The graph in numbers
  • 475 curated claims in 16 categories
  • 1716 sourced connections (24 relation types, average 7.2 per claim)
  • 45 use-case profiles across 17 sectors
  • 70% of legal references carry a verification date (128 of 184)
  • 48 public releases · 0 orphan claims (every claim is connected)
See all numbers →
Contribute to participate
  • Every contribution carries a source — enforced in the database, not by etiquette.
  • Every contributor is named on the claim and in the release notes.
  • Gaps are public: the verification queue shows what is not yet checked.
  • Invite-only, reference-based membership with contribution credits — credits exist so that every analysis in circulation is backed by verified expert work.

Sourced, current information

Every legal claim across the multi-layer stack — AI, data protection, cyber and resilience, product safety and liability, sector and financial law, and the standards layer — carries a status and a verification date, so you can see how old the statement you are relying on is. Monitored sources trigger re-verification when an act, standard or guidance changes. Corrections are logged publicly — including our own.

Today: 128 of 184 legal references verified — the rest is visible on the public queue. Graph v2.13.0, updated 2026-08-28. Proof that we log our own mistakes: release v2.21.0 — a correction release (sign-in required).

A machine-conducted pilot source audit has been published — including the 12 weaknesses it found in our own graph read the pilot results →

Pre-registered human benchmark study: protocol published, participants wanted read the protocol →

is stated, never implied: an unverified claim is labelled as unverified.

Describe your first use case — free, no login, nothing stored.

RAIN — Regulated AI Navigator · rainavigator.org · knowledge graph v2.13.0 · not legal advice