Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles

Service-as-a-Software in Regulated Markets

Outcome-priced AI service delivery: autonomous workflows execute the bulk of execution-heavy cognitive work while domain specialists act as supervisors, auditors and escalation owners. The compliance consequence is that accountability shifts to measured outcomes — accuracy, escalation rates and evidence — rather than billable effort.

This is the design lens: compliance designed into the system — control objectives, components, patterns and the evidence plan — not audited onto it afterwards.

Graph v2.1.2 · 4 pipeline stages · 6 mandatory artifacts

Enterprise chassis — Four-Layer TRiSM Enterprise Stack

Enterprise-wide chassis (per-workload blueprints plug into layers 2–4)

The enterprise-wide chassis (vs. per-workload blueprints): (1) Governance layer / System of Record — register, AI-BOM, intake, risk tiering; (2) Knowledge & context layer / System of Context — governed RAG, lineage, tenant isolation; (3) Orchestration & execution layer / System of Action — agent frameworks, multi-model routing & fallback; (4) Runtime inspection layer / System of Defense — inline single-pass guardrail proxies, HITL gateway, immutable logging. Per-workload blueprints (Guarded RAG, HITL Core, RDA stack…) instantiate inside layers 2–4; layer 1 is shared. Structural rule: layer 1 is second-line and vendor-independent (pat-lines-defense).
Layer 1 · Governance layer — System of Record
AI register, AI-BOM, intake portal, risk tiering. Shared across all workloads; second-line and vendor-independent.
Layer 2 · Knowledge & context layer — System of Context
Governed RAG, lineage, tenant isolation and segmented vector storage.
Layer 3 · Orchestration & execution layer — System of Action
Agent frameworks, multi-model routing and fallback, tool authorisation.
Layer 4 · Runtime inspection layer — System of Defense
Inline single-pass guardrail proxies, HITL gateway, immutable logging.
Procurement rule: Derived from three-lines-of-defense separation: the second-line GRC platform must be procured and deployed independently of any first-line runtime or model vendor — a governance tool that only sees its own vendor's models cannot govern a multi-model estate, and closed third-party SaaS AI can only be governed contractually (intake, attestation, AI-BOM disclosure), never by inline inspection.

Vendor market layer

Six functional vendor categories (6)

The graph models vendor CATEGORIES as first-class nodes and keeps named vendors as community-maintained, disputable desc content with lastVerified dates. A category is stable; a vendor list is a currency-layer object like any standard node.
AI GRC & Governance Platforms
Second-line systems of record: model/agent inventory incl. third-party SaaS AI, automated risk tiering, policy administration, cross-framework mapping & control deduplication, audit-evidence generation, intake workflows. Exemplary (community-maintained): ModelOp Center, Credo AI, IBM watsonx.governance, OneTrust, Holistic AI, Modulos (governance graph), Monitaur (insurance/lending), Fairly AI, Saidot, Trustible, Enzai, LatticeFlow (technical validation), Vanta (evidence automation), ServiceNow (intake/ITSM); data-catalog adjacency: Collibra, Alation, Informatica. Selection metrics: see meta.marketLandscape.selectionMetrics.grc.
unverified · verified 2026-08-06 community-maintained
selection metrics: multi-model/multi-cloud cataloging incl. third-party SaaS, automated risk tiering, regulatory reporting, independent-2nd-line deployability, cross-framework control deduplication
Runtime Security & Guardrail Vendors
First-line inline enforcement: single-pass parallel input/output evaluation proxies, injection & exfiltration defense, PII masking, grounding checks, SecOps routing. Exemplary (community-maintained): Prompt Security, HiddenLayer (MLSDR), Palo Alto AI Runtime Security, AWS Bedrock Guardrails, NVIDIA NeMo Guardrails, Guardrails AI, Robust Intelligence, LLM Guard / Llama Guard OSS class. Selection metrics: single-pass latency (<20 ms class), catch rates, policy-version telemetry into the AI-BOM.
unverified · verified 2026-08-06 community-maintained
selection metrics: single-pass parallel evaluation latency (<20 ms class), injection/hallucination catch rates, SecOps/SIEM routing, policy versioning surfaced into the AI-BOM
Secure Data Infrastructure & Vector Storage
Governed retrieval substrate: vector databases, lakehouses and catalogs with tenant/namespace isolation, RBAC + client-managed keys (CMEK), lineage into RAG chunks, air-gap options. Exemplary (community-maintained): Pinecone (serverless, SOC 2), Chroma/FAISS (self-hosted/air-gapped sovereignty), Snowflake Cortex (masking, clean rooms), Databricks Unity Catalog (end-to-end lineage), Azure AI Search, AWS OpenSearch. The Art. 10 runtime data-governance duties land here.
unverified · verified 2026-08-06 community-maintained
selection metrics: namespace/tenant isolation, RBAC + CMEK, lineage into RAG chunks, SOC 2 / ISO 27001 attestations, air-gap capability
Regulated Foundation-Model Platforms
Frontier commercial APIs and open-weight models under enterprise controls: zero-data-retention tiers, data isolation, fine-tuning governance, safety alignment documentation, EU-sovereign options. Exemplary (community-maintained): Anthropic Claude (ZDR enterprise tier), OpenAI GPT enterprise, Google Gemini Enterprise, Cohere (private-cloud RAG), Mistral (EU/self-hosted), Meta Llama (open-weight sovereignty). GPAI-chapter duties and vendor due diligence attach at this layer.
unverified · verified 2026-08-06 community-maintained
selection metrics: ZDR enterprise tiers, data isolation, EU-sovereign options, fine-tuning controls, safety alignment documentation
Agent Orchestration & SDLC Toolkits
Developer middleware for multi-agent networks, tool-use chains, RAG abstraction, state/memory persistence and model routing. Exemplary (community-maintained): LangChain, LlamaIndex, AutoGen, CrewAI; MCP-based tool ecosystems. Regulatory posture: orchestration code is where autonomy tiering, propose-action objects and fallback routing get implemented — the framework choice constrains which controls are cheap and which are retrofits.
unverified · verified 2026-08-06 community-maintained
selection metrics: broad model-API abstraction, state/memory management, error recovery, fallback routing hooks
Productized Vertical AI (Service-as-a-Software)
Turnkey domain execution platforms delivering outcomes under SLA: multi-model engines + industry playbooks + embedded guardrails, operated by the provider with specialist QA. Exemplary (community-maintained): eClerx GenAI360 (ISO 42001-certified; ComplianceOps/CareOps/ContentOps class modules), WNS, workflows.io (AI-native agency OS). Buyer's duties do not disappear — see meta.deliveryModels.regulatedCaveats and ctl-thirdparty-ai.
unverified · verified 2026-08-06 community-maintained
selection metrics: ISO 42001 certification, outcome-based SLAs with compliance artifacts included, domain playbook depth, auditability of the provider's own pipeline
Market dynamics: Thin wrappers around foundation-model APIs commoditize as providers absorb enterprise features; durable moats are (a) integrated GRC infrastructure spanning heterogeneous clouds and legacy estates, and (b) productized vertical execution with certified operations. Cross-framework control deduplication ('governance graph' products) is the market's rediscovery of this graph's reuse principle — one operational control mapped to many regimes at once.

Delivery models

BPO · SaaS · Service-as-a-Software

BPO: input-priced (billable hours/FTEs), linear headcount scaling, human error & attrition as primary risk
SaaS: capability-priced (software access), client operates the workload, implementation/adoption failure as primary risk
Service-as-a-Software: outcome-priced (SLA on completed work), provider-managed AI executes 60–80% of cognitive tasks with specialist supervision, algorithmic bias & non-compliance as primary risk
Caveats in regulated markets
Outcome SLAs move compliance risk onto the provider — but NOT the buyer's deployer duties: Art. 26 oversight, log retention and FRIA obligations stay with the enterprise even when execution is outsourced.
Provider role analysis is the central legal question: a productized platform that fine-tunes, re-purposes or chains models can flip into the Art. 25 provider role with full high-risk obligations.
Certified operations (ISO 42001) function as a procurement moat and shortcut third-party risk assessment — but organizational certificate ≠ product conformity (never conflate, see meta.assuranceEcosystem).
The buyer's evidence chain must reach into the provider: contractually mandated AI-BOM disclosure, ZDR certificates, bias-audit reports and logging-ledger access are the artifacts that make an outsourced workflow auditable.

Translational pipeline

Use case → risk tier → control layers → vendor stack

use-case identification → statutory & risk tiering → architectural control layers → vendor stack mapping
useCase —classified_as→ riskClass —imposes→ article —operationalized_by→ control objective —satisfied_by→ component/pattern —supplied_by→ vendorCategory; evidence hangs off obligations and control objectives throughout.
Enterprises fail in one of two directions: over-engineering (redundant controls, latency, cost) or under-engineering (regulatory exposure). The pipeline forces proportionality: the risk tier — not the vendor pitch — decides the control depth, and the control set — not the incumbent stack — decides the vendor shortlist.
Intake binding
The operational front door is a structured intake portal (comp-intake): business objective, autonomy degree, data sensitivity, deployment context → automated tier proposal via the detectors + evaluator pipeline → approval workflow → register entry with AI-BOM stub. Nothing reaches production without passing through it — Shadow-AI discovery is the enforcement backstop.

SaaS 1.0 vs. Service as Software

The structural shift: software stops being a tool a human operates and becomes the digital labour layer that completes the outcome. Every row changes what a regulator can inspect.

Structural dimensionSaaS 1.0Service as Software (SaaS 2.0)
Primary functional roleSystem of record / engagementSystem of action / digital labour layer
Cognitive ownershipHuman reasons, software executes commandsAI agent reasons, plans and executes autonomously
Monetization architecturePer-seat subscription licensingOutcome-based, transaction-based or hybrid-metered
Interface & interactionDashboard, GUI, web portalAPI orchestration, background execution, local MCP
Economic value propositionEfficiency — speeds up human tasksTask completion — replaces or scales cognitive labour
Gross margin profile80–90%50–60% (inference and compute cost per task)
Enterprise integration pointUser provisioning and feature adoptionDeep API integration, data pipelines, dynamic governance
Regulatory centre of gravityAccess control and data processingAutonomy bounds, logging, attribution and human oversight

Unit economics under outcome pricing

Hybrid base-plus-outcome: a base fee covers infrastructure, model access and continuous compliance monitoring; outcome tiers bill per verified completion, protecting the provider against un-recouped inference cost during exploratory usage.
Task granularity and dynamic model routing: routine reasoning goes to small fine-tuned models, frontier models are reserved for edge cases — the routing policy itself becomes a documented design decision under Art. 11.
Caveat: Outcome pricing moves execution risk to the provider but not the buyer's deployer duties: Art. 26 oversight, log retention and FRIA obligations stay with the enterprise.

Agentic execution stack

The layered architecture that replaces frontend + database + manual operations. Each layer carries a specific statutory hook — oversight that is not in the orchestrator cannot stop an executing agent.

1

Cognitive Orchestrator

Goal-directed reasoning, tool selection across enterprise APIs, confidence scoring per step, and the human-machine interface with a global halt control.

2

Model routing & inference economics

Dynamic routing between small fine-tuned models and frontier models; the routing policy is a documented design decision, not an implementation detail.

3

Local perimeter execution (MCP)

Agents execute inside the corporate perimeter and reach tools over MCP with context scoped to the minimum attributes required, instead of shipping raw records to third-party endpoints.

obligations: GDPR
4

Guardrails & fail-safe stop

Confidence minima, disbursement and margin caps, variance thresholds. Breaching a limit halts all sub-agents and reverts to a safe state rather than continuing at degraded confidence.

5

Immutable record & attribution

WORM-grade event logs of decision paths, API calls, prompt changes and data access — each bound to a named supervising natural person, never a shared service account.

Implementation priorities (3)

1. Maintain a central inventory of AI use cases and agentic workflows, each catalogued by domain, data dependencies, outcome metric and applicable framework — with a named natural person accountable for each deployment.
2. Move procurement from per-seat licensing to outcome-aligned, consumption-metered contracts that tie spend to verified results and push evidence duties into the provider contract.
3. Mandate oversight infrastructure across every execution layer: accessible HMI, anti-automation-bias safeguards, WORM logging, emergency stop and an unbroken attribution chain.

Operating model

Operating dimensionLegacy BPO / IT servicesTraditional SaaSService-as-a-Software
Primary value metricInput (billable hours & FTEs)Capability (software access)Outcome (SLA & completed work)
Scaling mechanismLinear headcount expansionUser subscriptionsAlgorithmic execution at scale
Operational responsibilityShared / vendor manual labourClient internal teamsProvider-managed AI systems
Unit economicsHigh variable labour costHigh gross margin, low serviceHigh margin, non-linear revenue
Primary exposure riskHuman error & attritionImplementation / adoption failureAlgorithmic bias & non-compliance

The four-stage compliant pipeline

1

Ingestion & data isolation

Client payload → zero-trust gateway → PII/PHI anonymisation → isolated tenant enclave

Personal and health data are detected and tokenised before any payload reaches an inference path; storage, indexes and embeddings are partitioned per client with RBAC and customer-managed keys.

2

Deterministic prompt & guardrail orchestration

Sanitised payload → input guardrails → entitlement-scoped retrieval → prompt construction

Retrieval is scoped by tenant and caller entitlement; input rails screen for injection and out-of-policy requests before context is assembled.

3

Multi-model routing & fallback

Dynamic router → policy & SLA evaluation → private endpoint → inference (fallback to local open-source model on failure)

Routing decisions consider capability, regulatory constraint, cost and latency. Sensitive workloads are pinned to private, zero-data-retention endpoints; health breaches degrade to secondary or locally hosted models instead of failing the workflow.

4

Output audit & human-in-the-loop gateway

Output rails → confidence score C_s vs. θ → (C_s ≥ θ) immutable ledger → delivery · (C_s < θ) escalation queue → specialist verdict

Every execution writes an audit packet — timestamp, model version, prompt, context hash, parameters, output, confidence and any human override — to WORM storage.

Human oversight: where the threshold sits

Human-in-the-loop (confidence-threshold routing)

High-stakes workflows — identity screening, legal clause extraction, anything affecting a person's access to a service — compute C_s per output. Below θ the transaction pauses and a specialist verdict completes it, logged as part of the decision record.

Human-on-the-loop (statistical sampling)

Lower-risk batch work runs autonomously with randomised, statistically representative sampling per batch to measure accuracy, classify errors and detect drift.

ISO/IEC 42001 governance loop

Clause 4 — Context of the organisation

Defines organisational boundaries, per-vertical regulatory requirements and client risk appetite as deployment parameters.

Clauses 5 & 6 — Leadership & planning

AI governance board owns the responsible-AI policy, bias tolerances and risk-treatment strategy.

Clause 8 — Operational control & impact assessment

Pre-deployment risk and impact assessment, data-quality controls and the HITL intervention framework.

Clauses 9 & 10 — Evaluation & improvement

Performance monitoring, drift tracking, internal audit and recertification.

Mandatory compliance artifacts

Artifact set per deployed workflow (6)

AI Impact Assessment (AIIA)
EU AI Act Art. 27; ISO 42001 Clause 8.2
Societal, legal and operational risk evaluation per workflow, including the defined HITL intervention parameters and residual-risk acceptance.
review: Pre-deployment; refreshed annually or on any material model change. · minimum verifiability: independently-attested · AI Impact Assessment (AIIA)
AI System Model Card
NIST AI RMF; AI Act Art. 11 / Annex IV
Model lineage, architecture, pre-training data sources, context limits, evaluation benchmarks and known failure modes.
review: Maintained per model release; published in the deployment repository. · minimum verifiability: tamper-evident · AI System Model Card
Algorithmic Bias & Fairness Audit Report
AI Act Art. 10; EEOC; CFPB
Quantitative demographic-parity, disparate-impact and false-positive distribution analysis against a fixed test baseline.
review: Quarterly automated evaluation plus independent review annually. · minimum verifiability: independently-attested · Algorithmic Bias & Fairness Audit Report
Immutable Decision Ledger (WORM)
AI Act Art. 12; SEC Rule 17a-4; FINRA 4511
Per-execution audit packet: timestamp, model version, system prompt, input-context hash, hyper-parameters, output payload, confidence score and human override record.
review: Continuous real-time generation; retained 6–7 years on WORM storage. · minimum verifiability: externally-anchored · Immutable Decision Ledger (WORM)
Human Oversight Operating Standard (SOP)
AI Act Art. 14; ISO 42001 Annex A.8
Binding procedure defining supervisor roles, competence, review-queue handling, override authority and escalation thresholds θ per workflow.
review: Semi-annual operational review; signed off by operations leadership. · minimum verifiability: tamper-evident · Human Oversight Operating Standard (SOP)
Third-Party AI Data & ZDR Certificate
GDPR Art. 28; ISO 27001 / ISO 42001
Binding vendor terms on zero data retention, non-training use, sub-processor list and security boundary, with technical verification records.
review: Validated at vendor onboarding; annual supplier audit. · minimum verifiability: independently-attested · Third-Party AI Data & ZDR Certificate

Implementation roadmap

2026-Q4 · Phase 1

Foundational governance & architectural hardening

Establish core compliance policies and secure infrastructure enclaves.

Technical: Deploy zero-trust ingestion with PII/PHI tokenisation; stand up the model-abstraction layer.

Governance: Finalise ISO 42001 AIMS policies; execute zero-data-retention vendor contracts.

2027-Q1 · Phase 2

Workflow taxonomy & regulatory tiering

Map every vertical workflow to its risk tier.

Technical: Build HITL operator dashboards with confidence-threshold routing (C_s < θ).

Governance: Complete AI Act classifications (high vs. limited vs. minimal) per workflow.

2027-Q3 · Phase 3

Artifact automation & immutable auditability

Automate production of required compliance documentation.

Technical: Connect transaction pipelines to append-only WORM storage with external trust anchoring.

Governance: Auto-generate AI impact assessments and model cards per deployment.

2028-Q1 · Phase 4

Scaled outcome-based commercial deployment

Move client contracts to outcome-priced structures.

Technical: Continuous drift monitoring and dynamic multi-model fallback in production.

Governance: Annual ISO 42001 audits; continuous AI Act conformity validation.

Key takeaways

Every workflow in the use-case catalog marked as a managed service maps into this pipeline — open a profile to see its delivery stack, or run one through the risk & value evaluator.