Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 78 profiles

Service-as-a-Software in Regulated Markets

Outcome-priced AI service delivery: autonomous workflows execute the bulk of execution-heavy cognitive work while domain specialists act as supervisors, auditors and escalation owners. The compliance consequence is that accountability shifts to measured outcomes — accuracy, escalation rates and evidence — rather than billable effort.

This is the design lens: compliance designed into the system — control objectives, components, patterns and the evidence plan — not audited onto it afterwards.

Graph v2.21.0 · 4 pipeline stages · 6 mandatory artifacts

Enterprise chassis — Four-Layer TRiSM Enterprise Stack

Enterprise-wide chassis (per-workload blueprints plug into layers 2–4)

The enterprise-wide chassis (vs. per-workload blueprints): (1) Governance layer / System of Record — register, AI-BOM, intake, risk tiering; (2) Knowledge & context layer / System of Context — governed RAG, lineage, tenant isolation; (3) Orchestration & execution layer / System of Action — agent frameworks, multi-model routing & fallback; (4) Runtime inspection layer / System of Defense — inline single-pass guardrail proxies, HITL gateway, immutable logging. Per-workload blueprints (Guarded RAG, HITL Core, RDA stack…) instantiate inside layers 2–4; layer 1 is shared. Structural rule: layer 1 is second-line and vendor-independent (pat-lines-defense).
Layer 1 · Governance layer — System of Record
AI register, AI-BOM, intake portal, risk tiering. Shared across all workloads; second-line and vendor-independent.
Layer 2 · Knowledge & context layer — System of Context
Governed RAG, lineage, tenant isolation and segmented vector storage.
Layer 3 · Orchestration & execution layer — System of Action
Agent frameworks, multi-model routing and fallback, tool authorisation.
Layer 4 · Runtime inspection layer — System of Defense
Inline single-pass guardrail proxies, HITL gateway, immutable logging.
Procurement rule: Derived from three-lines-of-defense separation: the second-line GRC platform must be procured and deployed independently of any first-line runtime or model vendor — a governance tool that only sees its own vendor's models cannot govern a multi-model estate, and closed third-party SaaS AI can only be governed contractually (intake, attestation, AI-BOM disclosure), never by inline inspection.

Vendor market layer

Functional vendor categories (17)

The graph models vendor CATEGORIES as first-class nodes and keeps named vendors as community-maintained, disputable desc content with lastVerified dates. A category is stable; a vendor list is a currency-layer object like any standard node.
AI GRC & Governance Platforms
Second-line systems of record: model/agent inventory incl. third-party SaaS AI, automated risk tiering, policy administration, cross-framework mapping and control deduplication, audit-evidence generation, intake workflows. Named products live in marketExamples, which is the single source of truth for this layer — prose here describes the class, not the field. What the class buys you: one register a second line can defend, and evidence assembled once and reused across frameworks. Selection metrics: see meta.marketLandscape.selectionMetrics.grc. One compilation-reported item is deliberately kept as unverified: a claimed updated US banking model-risk guidance 'SR 26-2'. Two secondary compilations repeating it is corroboration of the rumour, not of the guidance; it stays flagged pending verification against Federal Reserve primary sources, and a curator verification proposal is filed. All alignments in this layer are vendor-positioned claims, never certifications.
unverified · verified 2026-08-18 community-maintained
selection metrics: multi-model/multi-cloud cataloging incl. third-party SaaS, automated risk tiering, regulatory reporting, independent-2nd-line deployability, cross-framework control deduplication
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Credo AIAI governance platformPolicy packs, risk tiering and evidence workflows mapped across frameworks. Typical: AI registry, policy administration. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedISO 42001 alignment (claimed)EU AI Act readiness positioning
Holistic AIAI governance & auditRisk assessment, bias auditing and regulatory reporting workflows. Typical: bias audit, regulatory reporting. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedNYC LL144 audit support (claimed)EU AI Act readiness positioning
IBM watsonx.governanceAI governance platformGovernance, factsheets and monitoring integrated with the IBM stack. Typical: factsheets, model monitoring. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedISO 42001 alignment (claimed)Art. 11 documentation support (claimed)
ModelOpAI/model governanceModel and agent inventory with automated lifecycle controls for large estates. Typical: model inventory, control automation. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedmodel-risk positioning (SR 11-7 style, claimed)ISO 42001 alignment (claimed)
Monitaurinsurance & lending model governanceModel governance and documentation aimed at insurance and lending supervision. Typical: insurance underwriting, credit decisioning. Scope overlap: Its model-governance scope overlaps this platform's own; we have a commercial interest in the comparison.SaaS (vendor cloud)NAIC model-governance positioning (claimed)SR 11-7 practice alignment (claimed)
OneTrustGRC & privacy platformPrivacy and AI governance modules extending an existing GRC system of record. Typical: DPIA/FRIA workflow, policy management. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedISO 27001 (claimed)GDPR-positioned
ServiceNowintake & ITSM workflowUse-case intake, approval workflow and risk records inside an existing ITSM estate. Typical: AI intake, policy administration. Scope overlap: Its AI-governance module overlaps this platform's own scope; we have a commercial interest in the comparison.SaaS (vendor cloud)ISO 42001 alignment (claimed)EU AI Act readiness positioning

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Runtime Security & Guardrail Vendors
First-line inline enforcement: single-pass parallel input/output evaluation proxies, injection and exfiltration defense, PII masking, grounding checks, SecOps routing. Named products live in marketExamples; prose here describes the class. What the class buys you: a policy decision point in the request path that fails closed and emits telemetry an auditor can read. Selection metrics: single-pass latency (<20 ms class), catch rates, policy-version telemetry into the AI-BOM. Consolidation matters commercially: a guardrail acquired by a platform vendor tends to follow that platform's roadmap, which is a lock-in question rather than a security one — reported acquisitions are recorded per entry as reported, not asserted here.
unverified · verified 2026-08-18 community-maintained
selection metrics: single-pass parallel evaluation latency (<20 ms class), injection/hallucination catch rates, SecOps/SIEM routing, policy versioning surfaced into the AI-BOM
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Lakeraguardrail proxyInline prompt-injection and content detection at request time. Typical: injection defence, content filtering.not checkedSOC 2 (claimed)supports Art. 15 robustness measures (claimed)
HiddenLayermodel/agent detection & responseModel-layer detection and response with adversarial-attack telemetry. Typical: model threat detection, red-team telemetry.not checkedSOC 2 (claimed)supports Art. 15 robustness measures (claimed)
Palo Alto Prisma AIRSnetwork-integrated AI securityAI runtime security folded into an existing enterprise network security estate. Typical: enterprise rollout, egress control.not checkedSOC 2 (claimed)enterprise security integration (claimed)
Cisco AI Defensenetwork-integrated AI securityDiscovery of AI usage plus inline enforcement across the corporate network. Typical: shadow-AI discovery, inline enforcement.not checkedenterprise security integration (claimed)
NVIDIA NeMo Guardrailsopen guardrail frameworkProgrammable dialogue and action rails, self-hostable alongside your models. Typical: dialogue rails, action gating.open sourcesupports Art. 15 robustness measures (claimed)
Guardrails AIopen guardrail frameworkOpen validator library for structured output checks and policy validators. Typical: output validation, schema enforcement.open sourceOSS, no vendor certification
Garakadversarial scannerOpen-source LLM vulnerability scanner used for pre-deployment probing. Typical: red-teaming, release gating.not checkedOSS, no vendor certificationsupports Art. 15 testing evidence (claimed)
Protect AIML supply-chain & model securityModel scanning and ML supply-chain security tooling (Palo Alto Networks acquisition reported 2025). Typical: model scanning, supply-chain security.SaaS (vendor cloud)supports Art. 15 cybersecurity measures (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Secure Data Infrastructure & Vector Storage
Governed retrieval substrate: vector databases, lakehouses and catalogs with tenant/namespace isolation, RBAC and client-managed keys (CMEK), lineage into RAG chunks, air-gap options, and code-level data and AI lineage. Named products live in marketExamples; prose here describes the class. What the class buys you: retrieval that can be scoped per requester and traced back to a source record. The Art. 10 runtime data-governance duties land here. Selection metrics: see meta.marketLandscape.selectionMetrics.data.
unverified · verified 2026-08-18 community-maintained
selection metrics: namespace/tenant isolation, RBAC + CMEK, lineage into RAG chunks, SOC 2 / ISO 27001 attestations, air-gap capability
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Azure AI Searchmanaged retrievalManaged hybrid search with security trimming against tenant identities. Typical: ACL-aware RAG, enterprise search.not checkedISO 27001 (claimed)SOC 2 (claimed)
Databricks Unity Cataloggoverned lakehouseCatalog and lineage spanning tables, features and RAG chunks. Typical: lineage evidence, governed RAG.not checkedSOC 2 (claimed)lineage/Art. 10 support (claimed)
Relyance AIcode-level data & AI lineageParses source repositories to map data and inference flows at code level, with CI checks on changes to those flows. Typical: data lineage, shift-left privacy review. Scope overlap: Its AI-governance reporting scope overlaps this platform's own; we have a commercial interest in the comparison.SaaS (vendor cloud)GDPR programme tooling (claimed)EU AI Act readiness positioning
Snowflake Cortexgoverned lakehouseModel calls inside the warehouse boundary with masking and clean rooms. Typical: in-warehouse inference, governed analytics.not checkedSOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Regulated Foundation-Model Platforms
Frontier commercial APIs and open-weight models under enterprise controls: zero-data-retention tiers, data isolation, fine-tuning governance, safety alignment documentation, EU-sovereign options. Named products live in marketExamples, where the deployment model is recorded in the hosting field rather than asserted in prose. What the class buys you: a model supply relationship with contractual data handling and documentation you can pass to a customer. GPAI-chapter duties and provider due diligence attach at this layer. Selection metrics: see meta.marketLandscape.selectionMetrics.models.
unverified · verified 2026-08-18 community-maintained
selection metrics: ZDR enterprise tiers, data isolation, EU-sovereign options, fine-tuning controls, safety alignment documentation
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
OpenAI (Enterprise / API)proprietary frontierEnterprise tiers offer zero-data-retention and no-training commitments over the commercial API. Typical: general copilots, document reasoning.not checkedSOC 2 (claimed)ISO 27001 (claimed)zero-data-retention tier (claimed)GDPR-positioned
Anthropic Claude (Enterprise)proprietary frontierEnterprise/ZDR tiers with published safety and model documentation practice. Typical: regulated assistants, long-context analysis.not checkedSOC 2 (claimed)ISO 27001 (claimed)zero-data-retention tier (claimed)HIPAA-eligible (claimed)
Google Gemini Enterpriseproprietary frontierVertex-hosted frontier models with regional grounding and customer-managed keys. Typical: enterprise search, multimodal workflows.not checkedSOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed)EU data-boundary positioning
Cohereproprietary frontierPrivate-cloud and on-prem deployment of retrieval-oriented models. Typical: private RAG, enterprise search.self-hostableSOC 2 (claimed)
Mistral AIopen-weight / EUEU-headquartered provider; positions its open-weight offering for EU sovereignty and auditability requirements — the open-source exemption question is contested and not treated here as settled. Typical: sovereign deployments, self-hosted inference.self-hostableEU sovereignty positioning
Meta Llamaopen-weight / EUOpenly licensed weights that can be self-hosted under your own jurisdiction and inspection regime. Typical: self-hosted inference, air-gapped deployments.not checkedopen-weight sovereignty positioning
Gretelsynthetic dataSynthetic tabular and text generation with privacy metrics for training-data substitution. Typical: bias mitigation, data minimisation.not checkedArt. 10 data-governance support (claimed)GDPR-positioned
Tonic.aisynthetic dataDe-identification and synthetic test data for regulated development environments. Typical: test data, de-identified pipelines.not checkedSOC 2 (claimed)HIPAA-positioned
MOSTLY AIsynthetic dataSynthetic data generation with fairness and representativeness reporting. Typical: bias mitigation, data sharing.not checkedGDPR-positionedArt. 10 data-governance support (claimed)
Scale AIfine-tuning / data opsHuman labelling, evaluation and RLHF pipelines for enterprise fine-tuning. Typical: fine-tuning, model evaluation.not checkedSOC 2 (claimed)evaluation-evidence positioning
Weights & Biasesfine-tuning / MLOpsExperiment tracking, model registry and evaluation records across training runs. Typical: training records, model registry.not checkedSOC 2 (claimed)Art. 11 documentation support (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Agent Orchestration & SDLC Toolkits
Developer middleware for multi-agent networks, tool-use chains, RAG abstraction, state and memory persistence, and model routing. Named products live in marketExamples; prose here describes the class. Regulatory posture: orchestration code is where autonomy tiering, propose-action objects and fallback routing get implemented — the framework choice constrains which controls are cheap and which are retrofits. Selection metrics: see meta.marketLandscape.selectionMetrics.orchestration.
unverified · verified 2026-08-18 community-maintained
selection metrics: broad model-API abstraction, state/memory management, error recovery, fallback routing hooks
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
LangChain / LangGraphagent frameworkGraph-structured agent runtime; interrupt/pause nodes support implementing human approval at defined steps. Typical: multi-step agents, approval workflows.not checkedsupports implementing Art. 14 oversight (claimed)supports Art. 12 step logging (claimed)
LlamaIndexRAG frameworkIndexing and query abstractions over documents and structured sources. Typical: enterprise RAG, document agents.open sourceretrieval-governance positioning
Microsoft AutoGenmulti-agent frameworkConversational multi-agent patterns with pluggable tool executors. Typical: multi-agent research, code agents.not checkedresearch/OSS, no vendor certification
CrewAImulti-agent frameworkRole-based agent teams with task delegation and process templates. Typical: process automation, role-based agents.not checkedvendor-stated security posture
DSPyprompt/program optimisationDeclarative programs with optimisers that make prompt changes reproducible and testable. Typical: evaluated pipelines, model validation.not checkedmodel-validation positioning (SR 11-7 style, claimed)
Semantic Kernelenterprise SDKMicrosoft SDK for planners and plugins inside .NET/Java estates. Typical: enterprise copilots, tool plugins.not checkedenterprise-estate integration (claimed)
PydanticAItyped agent SDKType-validated agent outputs and tool signatures for deterministic contracts. Typical: structured outputs, typed tool calls.not checkedschema-enforcement positioning
Model Context Protocol (MCP)protocol / standardOpen protocol for tool and context exposure; a protocol, not a product — governance sits in the gateway around it. Typical: tool interoperability, gateway mediation.not checkedopen protocol, no certification
E2Bsandboxed runtimeEphemeral cloud sandboxes for agent code execution with isolation per task. Typical: code agents, untrusted execution.not checkedisolation/sandbox positioning
Airiaenterprise agent platformEnterprise platform for building and running agents with connector, policy and routing layers. Typical: agent orchestration, internal copilots.SaaS (vendor cloud)EU AI Act readiness positioningSOC 2 programme positioning (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Productized Vertical AI (Service-as-a-Software)
Turnkey domain execution platforms delivering outcomes under SLA: multi-model engines plus industry playbooks plus embedded guardrails, operated by the provider with specialist QA. Named products live in marketExamples; a certification appears as a certification only where a certificate or registry reference is recorded on the entry. The buyer's duties do not disappear — see meta.deliveryModels.regulatedCaveats and ctl-thirdparty-ai. Selection metrics: see meta.marketLandscape.selectionMetrics.productized.
unverified · verified 2026-08-18 community-maintained
selection metrics: ISO 42001 certification, outcome-based SLAs with compliance artifacts included, domain playbook depth, auditability of the provider's own pipeline
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
eClerx GenAI360Outcome-priced domain platformTurnkey ComplianceOps / CareOps / ContentOps class modules operated by the provider with specialist QA. Typical: compliance operations, customer operations, content operations.not checkedISO 42001 (claimed)
WNSManaged AI-enabled business processBusiness-process provider delivering AI-assisted domain execution under SLA. Typical: finance operations, customer operations.not checkedSOC 2 (claimed)
workflows.ioAI-native agency OSAI-native operating system for agency-style delivery of repeatable knowledge work. Typical: content operations, marketing operations.not checkedGDPR-positioned

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Sovereign Infrastructure
Compute and storage under EU jurisdictional control. Two structurally different offers, and the difference is the decision: native EU providers give full jurisdictional isolation with narrower service catalogs and thinner managed-AI tooling; hyperscaler sovereign constructions give the broad catalog with contractual and operational isolation, where the residual question is the control plane, support access and operational metadata rather than the data plane. Named offers live in marketExamples, which is the single source of truth for this layer — prose here describes the class, not the field. Claimed alignments recorded per entry: positioning for BSI C5 / C3A and ANSSI SecNumCloud attestation, NIS2 and DORA third-party requirements. Nothing here is an endorsement, and no provider in this category is 'CLOUD-Act-proof' by label alone — ask who holds the keys and who administers the plane.
unverified · verified 2026-08-18 community-maintained
selection metrics: jurisdiction of the control plane (not only the data plane), operator nationality and support-access paths, key custody, C5 / C3A / SecNumCloud attestation scope, managed-AI service depth vs. isolation trade-off, exit and repatriation terms
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
OVHcloudnative EUFrench provider with EU-only jurisdiction and a narrower managed-AI catalog than the hyperscalers. Typical: EU-resident inference, regulated workload hosting.not checkedISO 27001 (claimed)SecNumCloud-positionedGDPR-positioned
Scalewaynative EUEU-operated cloud with GPU instances and managed inference under French corporate control. Typical: EU-resident inference, fine-tuning.not checkedISO 27001 (claimed)GDPR-positioned
STACKITnative EUGerman provider (Schwarz Group) positioned for data residency in Germany. Typical: public sector, retail data platforms.not checkedC5-positionedGDPR-positioned
AWS European Sovereign Cloudsovereign hyperscalerSeparately operated EU region set with EU-resident personnel and keys; full hyperscaler catalog. Typical: large-scale enterprise AI, regulated hosting.not checkedISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning
Microsoft Azure EU Data Boundarysovereign hyperscalerEU processing and storage boundary across Azure and Copilot services with confidential-compute options. Typical: enterprise copilots, regulated hosting.not checkedISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning
Google Cloud Sovereign Controlssovereign hyperscalerPartner-operated and data-boundary variants with external key management. Typical: regulated analytics, EU-resident inference.not checkedISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning
Groqspecialized GPU / acceleratorLPU inference hardware marketed on deterministic low latency rather than training throughput. Typical: low-latency agents, real-time decisioning.not checkedSOC 2 (claimed)
CoreWeavespecialized GPU / acceleratorGPU-dense cloud for training and high-throughput inference with dedicated capacity contracts. Typical: model training, batch inference.not checkedSOC 2 (claimed)ISO 27001 (claimed)
Lambda Labsspecialized GPU / acceleratorGPU cloud and on-prem clusters aimed at research and fine-tuning workloads. Typical: fine-tuning, research clusters.not checkedSOC 2 (claimed)
Together AIinference platformHosted open-weight model inference and fine-tuning with per-token pricing. Typical: open-weight inference, fine-tuning.not checkedSOC 2 (claimed)open-weight sovereignty positioning
Fireworks AIinference platformOptimised serving of open-weight models with function-calling and structured output support. Typical: agent tool-calling, high-QPS inference.not checkedSOC 2 (claimed)HIPAA-eligible (claimed)
Baseteninference platformModel deployment platform with autoscaling endpoints and VPC deployment options. Typical: custom model serving, VPC-isolated inference.not checkedSOC 2 (claimed)HIPAA-eligible (claimed)
Modalserverless computeServerless GPU execution for jobs, batch pipelines and sandboxed agent tasks. Typical: batch pipelines, sandboxed execution.not checkedSOC 2 (claimed)
Replicateserverless computeAPI-first hosting of community and custom models, priced per run. Typical: prototyping, multimodal inference.not checkedvendor-stated security posture
Anyscaleserverless computeManaged Ray for distributed training, serving and multi-step agent workloads. Typical: distributed training, agent fan-out.not checkedSOC 2 (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Confidential Computing & Privacy Engines
Data-in-use protection and pre-model privacy interception: enclave and runtime encryption, key management, tokenisation vaults, PII detection and redaction, application-layer and vector encryption. Named products live in marketExamples; prose here describes the class. Select on: enclave attestation support, key custody model (external HSM / BYOK), detokenisation audit trail, latency added per call, and coverage of the identifier classes your regime actually names. Selection metrics: see meta.marketLandscape.selectionMetrics.privacy.
unverified · verified 2026-08-18 community-maintained
selection metrics: enclave attestation support, key custody (external HSM / BYOK), detokenisation audit trail, added latency per call, coverage of the identifier classes your regime names, in-boundary deployment option
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Anjunaconfidential computingRuns workloads inside hardware enclaves without application rewrites. Typical: data-in-use protection, regulated inference.not checkedconfidential-computing positioningDORA-positioned (claimed)
Fortanixconfidential computing & KMSEnclave runtime plus key management and tokenisation services. Typical: key management, data-in-use protection.not checkedFIPS 140-2 (claimed)DORA-positioned (claimed)HIPAA-positioned (claimed)
Skyflowprivacy vaultPolymorphic data vault de-identifying records before they reach a model. Typical: PII vaulting, pre-model redaction.not checkedSOC 2 (claimed)HIPAA-positionedGDPR-positioned
Private AIPII detection & redactionDetection and redaction of identifiers across text, documents and audio. Typical: inline redaction, document de-identification.not checkedGDPR-positionedHIPAA-positioned
IronCore Labsencrypted vector searchApplication-layer encryption for embeddings, addressing vector-reconstruction risk. Typical: encrypted RAG, erasure support.not checkedGDPR-positionederasure/embedding-risk positioning

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Agentic Execution Governance
The youngest tier: governance of what an agent is allowed to do at execution time — non-human identity, per-task scoping, action approval, agent inventory and agent-level red-teaming. Named products live in marketExamples; prose here describes the class. Because the category is new, capability claims outrun deployments: ask for a reference in your own regime before believing a control is covered, and treat entries with limited public verification as unconfirmed. Selection metrics: see meta.marketLandscape.selectionMetrics.agentgov.
unverified · verified 2026-08-18 community-maintained
selection metrics: non-human identity inventory completeness, credential time-to-live and revocation latency, per-action approval hooks, agent-level red-team coverage, evidence export a 2nd line can read, deployment references in your regime
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Pillar Securityagent security & inventoryDiscovery, inventory and runtime policy for agents in the estate. Typical: agent registry, policy enforcement.not checkedagent-inventory positioning
Lyzragent governance & observabilityAgent platform with governance, approval and observability features. Typical: agent approval, agent analytics.not checkedvendor-stated security posture
Astrix Securitynon-human identityLifecycle governance of machine and agent identities and their grants. Typical: credential scoping, NHI inventory.not checkedSOC 2 (claimed)NHI governance positioning
Britivejust-in-time accessEphemeral, per-task privileges instead of standing credentials. Typical: JIT credentials, privilege reduction.not checkedSOC 2 (claimed)least-privilege positioning

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Grounding, Retrieval & Agent Memory
The grounding layer between raw sources and the model: document parsers, embedding models, vector databases and — new in the agentic era — persistent agent memory stores. Memory is the hard part: once a personal fact is embedded, GDPR Art. 17 erasure has to reach the vector and the memory record, not just the source row, and embeddings are partially reconstructable (see IronCore in the privacy layer). Retrieval quality is also a data-governance question under Art. 10: what got parsed, chunked and indexed is what the system 'knows'.
unverified · verified 2026-08-18 community-maintained
selection metrics: Parsing fidelity on your worst document class; retrieval precision/recall on a labelled set; tenant and ACL isolation model; per-vector encryption and erasure path; memory TTL and record semantics; self-host option.
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Doclingdocument parserOpen-source layout-aware parsing of PDFs and office formats into structured chunks. Typical: RAG ingestion, air-gapped pipelines.self-hostableEU sovereignty positioning
LlamaParsedocument parserManaged parsing service tuned for tables and complex documents feeding RAG. Typical: RAG ingestion, table extraction.not checkedSOC 2 (claimed)
Amazon Textractdocument parserOCR and form/table extraction with per-page pricing inside AWS. Typical: document intake, claims processing.not checkedSOC 2 (claimed)HIPAA-eligible (claimed)ISO 27001 (claimed)
Diffbotweb/knowledge extractionStructured extraction and knowledge-graph construction from web sources. Typical: market monitoring, entity resolution.not checkedvendor-stated security posture
Firecrawlweb/knowledge extractionCrawling and clean markdown extraction for grounding on public sources. Typical: regulatory monitoring, public-source grounding.not checkedvendor-stated security posture
Voyage AIembeddingsDomain-tuned embedding models including legal and finance variants. Typical: retrieval quality, domain RAG.not checkedvendor-stated security posture
NomicembeddingsOpen embedding models with local inference and dataset visualisation. Typical: on-prem retrieval, dataset inspection.self-hostable
Pineconevector databaseManaged serverless vector search with namespace isolation. Typical: tenant-isolated RAG, semantic search.not checkedSOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed)
Weaviatevector databaseVector database available managed or self-hosted with hybrid search. Typical: hybrid retrieval, self-hosted RAG.open sourceSOC 2 (claimed)
Qdrantvector databaseOpen-source vector store with payload filtering and on-prem deployment. Typical: air-gapped RAG, filtered retrieval.open sourceGDPR-positioned
Milvusvector databaseOpen-source vector database for very large collections. Typical: large-scale retrieval.open source
pgvectorvector databasePostgres extension keeping vectors under the same RBAC, backup and retention regime as records. Typical: record-bound retrieval, small-scale RAG.self-hostablerecord-retention alignment (claimed)
Letta (MemGPT)agent memory storePersistent agent memory with explicit memory blocks and editing. Typical: long-running agents, personalisation.self-hostable
Mem0agent memory storeMemory layer extracting durable facts from agent conversations. Typical: personalised agents, support copilots.not checkedvendor-stated security posture
Zepagent memory storeTemporal knowledge-graph memory with fact validity intervals. Typical: auditable memory, long-running agents.not checkedGDPR-positionedbitemporal record positioning
Cogneeagent memory storeOpen-source memory/knowledge pipeline building graphs from agent interactions. Typical: knowledge accumulation, research agents.self-hostable

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Agent Observability & Model Risk Management
Tracing, evaluation, drift monitoring and model-validation records. This layer is where Art. 12 record-keeping becomes technically real (step-level traces, prompt/response records, retention control) and where model-risk practice in the SR 11-7 tradition — validation evidence, performance and drift monitoring, challenger comparison — is operated. Gateways and tracing tools produce the logs; the retention, integrity and access regime around them is still yours.
unverified · verified 2026-08-18 community-maintained
selection metrics: Trace completeness per agent step; log retention and immutability options; drift/quality metrics available out of the box; evaluation dataset support; export into your audit vault; self-host option.
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
LangSmithagent tracing & evaluationTrace capture and evaluation over LangChain/LangGraph runs with dataset-based scoring. Typical: step tracing, regression evaluation.not checkedSOC 2 (claimed)supports Art. 12 record-keeping (claimed)
Langfuseagent tracing & evaluationOpen-source tracing, prompt management and evaluation; self-hostable for retention control. Typical: self-hosted tracing, cost/latency analytics.open sourceGDPR-positionedsupports Art. 12 record-keeping (claimed)
Arize AI / PhoenixML & LLM observabilityProduction monitoring with drift and performance analysis; Phoenix is the open-source tracing side. Typical: drift monitoring, production analytics.not checkedSOC 2 (claimed)drift-monitoring positioning (SR 11-7 style, claimed)
HeliconeLLM gateway & loggingProxy-level logging of prompts, costs and latency across providers. Typical: gateway logging, cost control.not checkedSOC 2 (claimed)supports Art. 12 record-keeping (claimed)
MLflowexperiment & model registryOpen-source tracking, model registry and lineage across training and deployment. Typical: model registry, validation records.open sourcemodel-validation positioning (SR 11-7 style, claimed)
RagasRAG evaluationOpen evaluation metrics for retrieval faithfulness and answer grounding. Typical: grounding checks, RAG regression.not checkedOSS, no vendor certification
Deepchecksvalidation & testingContinuous validation suites for data and model behaviour. Typical: release gating, data validation.not checkedevaluation-evidence positioning
Fairlearnfairness toolkitOpen-source fairness assessment and mitigation for classification and regression. Typical: bias testing, fairness reporting.not checkedOSS, no vendor certificationsupports Art. 10 bias examination (claimed)
Fiddler AImodel performance managementExplainability and monitoring platform aimed at regulated model risk teams. Typical: explainability, model monitoring.not checkedSOC 2 (claimed)model-risk positioning (SR 11-7 style, claimed)
ValidMindmodel risk managementModel validation documentation and workflow for banking model-risk functions. Typical: validation reports, MRM workflow.not checkedSOC 2 (claimed)model-risk positioning (SR 11-7 style, claimed)
WhyLabsdata & model monitoringTelemetry and drift monitoring over model inputs and outputs. Typical: drift detection, data quality monitoring.SaaS (vendor cloud)supports Art. 72 post-market monitoring (claimed)
Evidently AIevaluation & monitoringOpen-source evaluation and monitoring reports for ML and LLM pipelines. Typical: evaluation reports, drift detection.open sourcesupports Art. 72 post-market monitoring (claimed)
Galileo AILLM evaluation & observabilityEvaluation metrics and traces for generative applications. Typical: LLM evaluation, trace inspection.SaaS (vendor cloud)supports Art. 15 accuracy measures (claimed)
Patronus AI · eingestellt (2026-08-31)automated LLM evaluationAutomated scoring and adversarial test suites for generative output. Typical: automated evaluation, red teaming.SaaS (vendor cloud)supports Art. 15 robustness measures (claimed)
Arthur AImodel performance monitoringPerformance, bias and drift monitoring across deployed models. Typical: bias monitoring, performance monitoring.SaaS (vendor cloud)supports Art. 72 post-market monitoring (claimed)supports Art. 10 bias examination (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Agentic Applications & Copilots
Finished agentic products bought rather than built: developer and productivity copilots, research assistants, SOC and support agents. The governance point is not the product but the wrapper: these tools act with delegated authority inside your estate, so they belong in the agent inventory, need scoped non-human identities and permission boundaries, and inherit deployer duties — buying the product does not buy the obligations away.
unverified · verified 2026-08-18 community-maintained
selection metrics: Permission model and identity scoping; audit log export; tenant data-handling and retention terms; deployer-duty support (disclosure, oversight, incident reporting); outcome pricing vs seat pricing.
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
GitHub Copilotdeveloper copilotCode completion and agent modes inside the IDE and repository workflow. Typical: software engineering, code review.not checkedSOC 2 (claimed)enterprise data-handling commitments (claimed)
Microsoft 365 Copilotproductivity copilotAssistant across mail, documents and meetings inheriting existing tenant permissions. Typical: knowledge work, meeting summaries.not checkedISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning
Perplexity Enterpriseresearch assistantCited web and internal search with source attribution per answer. Typical: market research, citation-backed search.not checkedSOC 2 (claimed)enterprise data-handling commitments (claimed)
Cursordeveloper copilotAI-native editor with repository-wide agent edits. Typical: software engineering, refactoring.not checkedSOC 2 (claimed)privacy-mode option (claimed)
Dropzone AIsecurity operations agentAutonomous triage of security alerts with written investigation records. Typical: SOC triage, incident write-ups.not checkedSOC 2 (claimed)
Devin (Cognition)autonomous software agentLong-running software agent taking tickets to pull requests. Typical: software engineering, backlog automation.not checkedvendor-stated security posture
Vantacompliance automationContinuous control monitoring and evidence collection across frameworks. Typical: evidence automation, audit readiness.not checkedSOC 2 (claimed)ISO 27001/42001 evidence workflows (claimed)
Fin (Intercom)customer-service agentResolution-priced support agent answering from your help content. Typical: customer support, deflection.not checkedSOC 2 (claimed)GDPR-positioned
SAPembedded enterprise AIAI features and agents embedded in ERP, HR and procurement suites, governed through the vendor's own AI platform layer. Typical: embedded HR AI, procurement automation, finance automation.SaaS (vendor cloud)ISO/IEC 42001 certification claim (claimed)EU AI Act readiness positioning

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Runtime Guardrails & Enforcement
Policy enforcement in the request path: input/output validation, injection and exfiltration defence, structured-output constraints and action blocking. Distinct from observability layers because these products are in-line and can refuse. Selection questions: added latency at p95, whether enforcement is fail-open or fail-closed, whether policies are versioned artefacts, and whether the layer can be self-hosted inside your data boundary.
unverified · verified 2026-08-18 community-maintained
selection metrics: Where enforcement sits (inline proxy, sidecar, SDK) and the added latency at your token volumes; whether policy is versioned and testable as code; fail-open vs. fail-closed behaviour under guardrail outage; language and modality coverage; whether every block writes an evidence record you can cite later.
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Guardrails AIvalidation frameworkOpen-source validator framework for structured output and content policies in the request path. Typical: output validation, structured output.open sourcesupports Art. 15 robustness measures (claimed)
NVIDIA NeMo Guardrailsdialogue policy railsProgrammable dialogue and topic rails placed around an LLM application. Typical: topic control, dialogue policy.open sourcesupports Art. 50 interaction disclosure patterns (claimed)
Lakera AIguardrail proxyInline prompt-injection and content detection at request time. Typical: injection defence, content filtering.SaaS (vendor cloud)SOC 2 (claimed)supports Art. 15 robustness measures (claimed)
Credal AIenterprise access & policy layerPermission-aware access layer with data-loss controls in front of enterprise assistants. Typical: access control, DLP.SaaS (vendor cloud)SOC 2 (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Cryptographic Evidence & Audit Ledger
Tamper-evident recording of what a system did: content-addressed decision records, hash chains and external anchoring, so a log can be shown not to have been rewritten after the fact. This is the layer that turns Art. 12 logging and Art. 19 retention from a storage question into an evidentiary one. AI Verify is carried in RAIN as a STANDARD node (sg-ai-verify), not duplicated here as a vendor.
unverified · verified 2026-08-18 community-maintained
selection metrics: Append-only guarantees and who can rotate or delete (including the vendor); anchoring mechanism (qualified timestamp, transparency log, notarisation) and whether verification works without the vendor; retention and export in a readable format at end of contract; throughput and cost at your event volume.
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Fact0cryptographic evidence ledgerPositions itself as a tamper-evident ledger for AI decision records. Typical: decision records, audit trail.not checkedsupports Art. 12 record-keeping (claimed)
Tracciaaudit trail & traceabilityPositions itself around traceability of AI pipeline steps and artefacts. Typical: traceability, artifact lineage.not checkedsupports Art. 12 record-keeping (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

AI Asset Discovery & Shadow-AI Inventory
Automated discovery of AI in an existing estate: model and agent detection in source repositories, LLM API egress in cloud and network telemetry, AI features switched on inside employee SaaS, reconciliation against the CMDB and the AI register, ownership attribution and drift between declared and observed estate. Distinct from the GRC layer, which is the system of record for what is already known: this class finds the population that record is supposed to cover. Selection metrics: see meta.marketLandscape.selectionMetrics.discovery.
unverified · verified 2026-08-17 community-maintained
selection metrics: Coverage of the estate you actually have (repos, cloud accounts, SaaS tenants, network egress) rather than the connector count; false-positive rate on detected AI usage; whether findings reconcile into your existing register rather than a second inventory; ownership attribution quality; agent-based vs. agentless deployment; whether discovery data leaves your tenancy.
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Truyoshadow-AI discoveryDiscovery of AI usage across SaaS and cloud accounts with intake and governance workflow on top. Typical: shadow-AI inventory, AI intake. Scope overlap: Its governance-workflow scope overlaps this platform's own; we have a commercial interest in the comparison.SaaS (vendor cloud)EU AI Act readiness positioningGDPR programme tooling (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

AI Supply-Chain Security & AIBOM
Bills of materials for AI: base architecture, training-data dependencies, fine-tuning history and licence lineage of a model, plus scanning of third-party pretrained weights and model artifacts for backdoors, poisoning and tampering before ingestion. Adjacent to, but not the same as, software SBOM tooling — the unit of analysis is a weights artifact and its provenance. Selection metrics: see meta.marketLandscape.selectionMetrics.supplychain.
unverified · verified 2026-08-17 community-maintained
selection metrics: Whether the AIBOM records training-data and fine-tuning lineage or only package dependencies; artifact formats scanned (safetensors, pickle, GGUF, container images); detection basis for tampering and poisoning (signature, behavioural, provenance attestation) and its false-positive rate; support for signing and verifying weights in your own pipeline; whether ingestion can be blocked, not just reported.
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Cranium AIAIBOM & model provenanceAI bill-of-materials generation, model-provenance capture and third-party model risk scanning. Typical: AIBOM, third-party model ingestion. Scope overlap: Its AI-governance reporting scope overlaps this platform's own; we have a commercial interest in the comparison.SaaS (vendor cloud)NIST AI RMF alignment (claimed)EU AI Act readiness positioning

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Public Transparency Registers & System Cards
Authoring and publishing the outward-facing record: public AI registers, system and model cards, conformity declarations and plain-language notices, with versioning so a published statement can be tied to the system version it described. The register content is produced elsewhere; this class is the publication and version-control surface for it. Selection metrics: see meta.marketLandscape.selectionMetrics.transparency.
unverified · verified 2026-08-17 community-maintained
selection metrics: Versioning of published statements against the system version they describe; whether a card is generated from your governance record or re-authored by hand; language coverage and accessibility of the published surface; export and self-hosting of the public register; whether unpublishing leaves an auditable trail.
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Saidotpublic AI registerAI register with published system cards and regulation-mapped documentation workflows. Typical: public AI register, system cards. Scope overlap: Its documentation and register scope overlaps this platform's own; we have a commercial interest in the comparison.SaaS (vendor cloud)EU AI Act documentation positioningISO 42001 alignment (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Market dynamics: Thin wrappers around foundation-model APIs commoditize as providers absorb enterprise features; durable moats are (a) integrated GRC infrastructure spanning heterogeneous clouds and legacy estates, and (b) productized vertical execution with certified operations. Cross-framework control deduplication ('governance graph' products) is the market's rediscovery of this graph's reuse principle — one operational control mapped to many regimes at once.

Reference stacks by regulatory profile

Three illustrative assemblies across the five procurement tiers, taken from the Aug 2026 vendor research compilation. They are starting points for a build-or-buy conversation, not certified stacks: no combination of the products below makes a deployment compliant, and every vendor name here is a community-disputable example rather than an endorsement.

Five procurement tiers (5)

Tier 1 · Sovereign infrastructure — where compute, storage and the control plane sit, and under whose law.
Tier 2 · Confidential computing & privacy engines — protection of data in use and pre-model interception of identifiers.
Tier 3 · Runtime AI security — inline guardrails, injection defence and action interception at request time.
Tier 4 · Agentic execution governance — non-human identity, per-task scoping, action approval and agent inventory.
Tier 5 · Governance systems of record — the 2nd-line registry, control evidence and regulatory reporting.

Financial services

Credit scoring and pricing, agentic trading and portfolio support, agentic procurement and deal desks — Annex III high-risk classes plus DORA operational resilience and Fed SR 11-7 model-risk practice; retained-records rules (SEC 17a-4, FINRA 4511) reach agent memory.
Sovereign infrastructure
Hyperscaler sovereign construction where the managed-AI catalog is needed (AWS European Sovereign Cloud, Microsoft Cloud for Sovereignty); native EU (OVHcloud, STACKIT) where the control plane must stay national.
Confidential computing & privacy
Fortanix or Anjuna for data-in-use and key custody (Fortanix positioned for DORA data-in-use expectations); Skyflow for payment/identifier tokenisation.
Runtime AI security
Lakera/Check Point or Palo Alto Prisma AIRS inline; Azure AI Content Safety where the workload already sits there.
Agentic execution governance
Pillar Security or Microsoft Agent Governance Toolkit for non-human identity and action approval; Mindgard for agent red-teaming cycles.
Governance systems of record
ModelOp or ValidMind for model-risk documentation and validation (claims alignment with SR 11-7 practice; reported updated US banking guidance 'SR 26-2' pending verification); Credo AI or IBM watsonx.governance for the AI Act registry.

Healthcare

Clinical documentation, triage support and diagnostic assistance — HIPAA where US data is involved, FDA SaMD where the function is a medical device, AI Act Annex I/III where the system is a safety component or an Annex III use.
Sovereign infrastructure
EU-region deployment with in-boundary inference; native EU providers where patient data must not touch a non-EU-controlled plane.
Confidential computing & privacy
Private AI or Skyflow for PHI redaction and tokenisation before the model call; Fortanix for data-in-use (claims HIPAA alignment).
Runtime AI security
Guardrail layer tuned for clinical hallucination and unsafe-advice classes (NeMo Guardrails, Aim Security, Lakera).
Agentic execution governance
Keep autonomy low: action approval and per-task scoping (Pillar Security class) rather than autonomous execution.
Governance systems of record
Enzai or Holistic AI for the AI Act and clinical-governance registry; ValidMind for performance validation evidence.

Public sector

Benefit eligibility, casework triage and citizen-facing assistants — Annex III public-service classes, NIS2 for essential entities, and sovereignty bars (BSI C5/C3A, ANSSI SecNumCloud) that most tenders now encode.
Sovereign infrastructure
Native EU or nationally qualified providers (OVHcloud/SecNumCloud-qualified offers, STACKIT, Scaleway); hyperscaler sovereign constructions only where the tender accepts the control-plane residual.
Confidential computing & privacy
BYOK/HYOK with external key custody; IronCore Labs class encryption for vector stores holding case data.
Runtime AI security
Self-hostable guardrails (NeMo Guardrails) so the inline security layer does not itself export prompts.
Agentic execution governance
Human decision retained by law: registry, action logging and non-human identity, not autonomous action.
Governance systems of record
Sprinto or Enzai for control automation and the public accountability record; Monitaur for decision-level auditability.

Delivery models

BPO · SaaS · Service-as-a-Software

BPO: input-priced (billable hours/FTEs), linear headcount scaling, human error & attrition as primary risk
SaaS: capability-priced (software access), client operates the workload, implementation/adoption failure as primary risk
Service-as-a-Software: outcome-priced (SLA on completed work), provider-managed AI executes 60–80% of cognitive tasks with specialist supervision, algorithmic bias & non-compliance as primary risk
Caveats in regulated markets
Outcome SLAs move compliance risk onto the provider — but NOT the buyer's deployer duties: Art. 26 oversight, log retention and FRIA obligations stay with the enterprise even when execution is outsourced.
Provider role analysis is the central legal question: a productized platform that fine-tunes, re-purposes or chains models can flip into the Art. 25 provider role with full high-risk obligations.
Certified operations (ISO 42001) function as a procurement moat and shortcut third-party risk assessment — but organizational certificate ≠ product conformity (never conflate, see meta.assuranceEcosystem).
The buyer's evidence chain must reach into the provider: contractually mandated AI-BOM disclosure, ZDR certificates, bias-audit reports and logging-ledger access are the artifacts that make an outsourced workflow auditable.

Translational pipeline

Use case → risk tier → control layers → vendor stack

use-case identification → statutory & risk tiering → architectural control layers → vendor stack mapping
useCase —classified_as→ riskClass —imposes→ article —operationalized_by→ control objective —satisfied_by→ component/pattern —supplied_by→ vendorCategory; evidence hangs off obligations and control objectives throughout.
Enterprises fail in one of two directions: over-engineering (redundant controls, latency, cost) or under-engineering (regulatory exposure). The pipeline forces proportionality: the risk tier — not the vendor pitch — decides the control depth, and the control set — not the incumbent stack — decides the vendor shortlist.
Intake binding
The operational front door is a structured intake portal (comp-intake): business objective, autonomy degree, data sensitivity, deployment context → automated tier proposal via the detectors + evaluator pipeline → approval workflow → register entry with AI-BOM stub. Nothing reaches production without passing through it — Shadow-AI discovery is the enforcement backstop.

SaaS 1.0 vs. Service as Software

The structural shift: software stops being a tool a human operates and becomes the digital labour layer that completes the outcome. Every row changes what a regulator can inspect.

Structural dimensionSaaS 1.0Service as Software (SaaS 2.0)
Primary functional roleSystem of record / engagementSystem of action / digital labour layer
Cognitive ownershipHuman reasons, software executes commandsAI agent reasons, plans and executes autonomously
Monetization architecturePer-seat subscription licensingOutcome-based, transaction-based or hybrid-metered
Interface & interactionDashboard, GUI, web portalAPI orchestration, background execution, local MCP
Economic value propositionEfficiency — speeds up human tasksTask completion — replaces or scales cognitive labour
Gross margin profile80–90%50–60% (inference and compute cost per task)
Enterprise integration pointUser provisioning and feature adoptionDeep API integration, data pipelines, dynamic governance
Regulatory centre of gravityAccess control and data processingAutonomy bounds, logging, attribution and human oversight

Unit economics under outcome pricing

Hybrid base-plus-outcome: a base fee covers infrastructure, model access and continuous compliance monitoring; outcome tiers bill per verified completion, protecting the provider against un-recouped inference cost during exploratory usage.
Task granularity and dynamic model routing: routine reasoning goes to small fine-tuned models, frontier models are reserved for edge cases — the routing policy itself becomes a documented design decision under Art. 11.
Caveat: Outcome pricing moves execution risk to the provider but not the buyer's deployer duties: Art. 26 oversight, log retention and FRIA obligations stay with the enterprise.

Agentic execution stack — seven layers in three tiers

The layered architecture that replaces frontend + database + manual operations, grouped into Engagement (who and what talks to your agents), Capabilities (how they decide and act) and Data (what is kept, and as which kind of record). Each layer carries a specific statutory hook: oversight that is not in the layer where the action happens cannot stop it. The layer taxonomy is adapted from the Al-Risk.ai / Agentico.ai agentic enterprise stack model (2025); the obligations mapping is ours.

1

Interfaces

Web, app and voice surfaces, digital wallets, social channels, enterprise collaboration tools and marketplace/discovery APIs. Every one of them needs an AI-interaction notice, machine-readable marking of generated or manipulated output, and a disclosure record that survives the session. Public social surfaces add DSA duties; consumer-facing surfaces add accessibility (European Accessibility Act) and sector conduct rules.

2

Third-party agents

Inbound and outbound agent-to-agent interaction: discovery, authentication of the counterparty, mandate and value limits, and a resolvable answer to 'which external principal caused this transaction'. This is where liability allocation stops being theoretical — an external agent acting on your system can flip roles along the value chain.

3

Controls

Guardrails, confidence minima, disbursement and margin caps, non-human identity and the fail-safe stop. Breaching a limit halts all sub-agents and reverts to a safe state rather than continuing at degraded confidence; agents hold ephemeral, per-task credentials rather than standing grants.

4

Orchestration

Goal-directed reasoning, tool selection across enterprise APIs, confidence scoring per step, and the human-machine interface with a global halt control. The orchestration policy is a documented design decision, not an implementation detail.

5

Intelligence

Model routing between small fine-tuned models and frontier models, inference economics, drift monitoring and explanation surfaces. Which model answered which request is part of the technical documentation trail.

6

Tools

Agents execute inside the corporate perimeter and reach tools over MCP with context scoped to the minimum attributes required. Every action leaves through one schema-validated boundary that rejects out-of-contract calls and records the attempt either way, instead of shipping raw records to third-party endpoints.

7

Systems of record

Databases and lakes, tokenisation, vector and graph stores, file systems, agent-workforce accounting — and agent memory treated as a regulated record rather than a cache, with retention schedules, erasure paths that do not break the audit trail, and jurisdictional placement of both data and control plane.

Implementation priorities (5)

1. Maintain a central inventory of AI use cases and agentic workflows, each catalogued by domain, data dependencies, outcome metric and applicable framework — with a named natural person accountable for each deployment.
2. Move procurement from per-seat licensing to outcome-aligned, consumption-metered contracts that tie spend to verified results and push evidence duties into the provider contract.
3. Mandate oversight infrastructure across every execution layer: accessible HMI, anti-automation-bias safeguards, WORM logging, emergency stop and an unbroken attribution chain.
4. Inventory non-human identities the way you inventory employees: every agent and tool caller has its own identity, a credential lifetime measured in minutes, and an owner who can revoke it — no agent holds a standing credential into production.
5. Decide explicitly whether your agents' memory is a record. If a supervisor could ask for it, it needs a retention schedule, an export format and a jurisdiction — deciding by default means the storage tier decided for you.

Operating model

Operating dimensionLegacy BPO / IT servicesTraditional SaaSService-as-a-Software
Primary value metricInput (billable hours & FTEs)Capability (software access)Outcome (SLA & completed work)
Scaling mechanismLinear headcount expansionUser subscriptionsAlgorithmic execution at scale
Operational responsibilityShared / vendor manual labourClient internal teamsProvider-managed AI systems
Unit economicsHigh variable labour costHigh gross margin, low serviceHigh margin, non-linear revenue
Primary exposure riskHuman error & attritionImplementation / adoption failureAlgorithmic bias & non-compliance

The four-stage compliant pipeline

1

Ingestion & data isolation

Client payload → zero-trust gateway → PII/PHI anonymisation → isolated tenant enclave

Personal and health data are detected and tokenised before any payload reaches an inference path; storage, indexes and embeddings are partitioned per client with RBAC and customer-managed keys.

2

Deterministic prompt & guardrail orchestration

Sanitised payload → input guardrails → entitlement-scoped retrieval → prompt construction

Retrieval is scoped by tenant and caller entitlement; input rails screen for injection and out-of-policy requests before context is assembled.

3

Multi-model routing & fallback

Dynamic router → policy & SLA evaluation → private endpoint → inference (fallback to local open-source model on failure)

Routing decisions consider capability, regulatory constraint, cost and latency. Sensitive workloads are pinned to private, zero-data-retention endpoints; health breaches degrade to secondary or locally hosted models instead of failing the workflow.

4

Output audit & human-in-the-loop gateway

Output rails → confidence score C_s vs. θ → (C_s ≥ θ) immutable ledger → delivery · (C_s < θ) escalation queue → specialist verdict

Every execution writes an audit packet — timestamp, model version, prompt, context hash, parameters, output, confidence and any human override — to WORM storage.

Human oversight: where the threshold sits

Human-in-the-loop (confidence-threshold routing)

High-stakes workflows — identity screening, legal clause extraction, anything affecting a person's access to a service — compute C_s per output. Below θ the transaction pauses and a specialist verdict completes it, logged as part of the decision record.

Human-on-the-loop (statistical sampling)

Lower-risk batch work runs autonomously with randomised, statistically representative sampling per batch to measure accuracy, classify errors and detect drift.

ISO/IEC 42001 governance loop

Clause 4 — Context of the organisation

Defines organisational boundaries, per-vertical regulatory requirements and client risk appetite as deployment parameters.

Clauses 5 & 6 — Leadership & planning

AI governance board owns the responsible-AI policy, bias tolerances and risk-treatment strategy.

Clause 8 — Operational control & impact assessment

Pre-deployment risk and impact assessment, data-quality controls and the HITL intervention framework.

Clauses 9 & 10 — Evaluation & improvement

Performance monitoring, drift tracking, internal audit and recertification.

Mandatory compliance artifacts

Artifact set per deployed workflow (6)

AI Impact Assessment (AIIA)
EU AI Act Art. 27; ISO 42001 Clause 8.2
Societal, legal and operational risk evaluation per workflow, including the defined HITL intervention parameters and residual-risk acceptance.
review: Pre-deployment; refreshed annually or on any material model change. · minimum verifiability: independently-attested · AI Impact Assessment (AIIA)
AI System Model Card
NIST AI RMF; AI Act Art. 11 / Annex IV
Model lineage, architecture, pre-training data sources, context limits, evaluation benchmarks and known failure modes.
review: Maintained per model release; published in the deployment repository. · minimum verifiability: tamper-evident · AI System Model Card
Algorithmic Bias & Fairness Audit Report
AI Act Art. 10; EEOC; CFPB
Quantitative demographic-parity, disparate-impact and false-positive distribution analysis against a fixed test baseline.
review: Quarterly automated evaluation plus independent review annually. · minimum verifiability: independently-attested · Algorithmic Bias & Fairness Audit Report
Immutable Decision Ledger (WORM)
AI Act Art. 12; SEC Rule 17a-4; FINRA 4511
Per-execution audit packet: timestamp, model version, system prompt, input-context hash, hyper-parameters, output payload, confidence score and human override record.
review: Continuous real-time generation; retained 6–7 years on WORM storage. · minimum verifiability: externally-anchored · Immutable Decision Ledger (WORM)
Human Oversight Operating Standard (SOP)
AI Act Art. 14; ISO 42001 Annex A.8
Binding procedure defining supervisor roles, competence, review-queue handling, override authority and escalation thresholds θ per workflow.
review: Semi-annual operational review; signed off by operations leadership. · minimum verifiability: tamper-evident · Human Oversight Operating Standard (SOP)
Third-Party AI Data & ZDR Certificate
GDPR Art. 28; ISO 27001 / ISO 42001
Binding vendor terms on zero data retention, non-training use, sub-processor list and security boundary, with technical verification records.
review: Validated at vendor onboarding; annual supplier audit. · minimum verifiability: independently-attested · Third-Party AI Data & ZDR Certificate

Implementation roadmap

2026-Q4 · Phase 1

Foundational governance & architectural hardening

Establish core compliance policies and secure infrastructure enclaves.

Technical: Deploy zero-trust ingestion with PII/PHI tokenisation; stand up the model-abstraction layer.

Governance: Finalise ISO 42001 AIMS policies; execute zero-data-retention vendor contracts.

2027-Q1 · Phase 2

Workflow taxonomy & regulatory tiering

Map every vertical workflow to its risk tier.

Technical: Build HITL operator dashboards with confidence-threshold routing (C_s < θ).

Governance: Complete AI Act classifications (high vs. limited vs. minimal) per workflow.

2027-Q3 · Phase 3

Artifact automation & immutable auditability

Automate production of required compliance documentation.

Technical: Connect transaction pipelines to append-only WORM storage with external trust anchoring.

Governance: Auto-generate AI impact assessments and model cards per deployment.

2028-Q1 · Phase 4

Scaled outcome-based commercial deployment

Move client contracts to outcome-priced structures.

Technical: Continuous drift monitoring and dynamic multi-model fallback in production.

Governance: Annual ISO 42001 audits; continuous AI Act conformity validation.

Key takeaways

Every workflow in the use-case catalog marked as a managed service maps into this pipeline — open a profile to see its delivery stack, or run one through the risk & value evaluator.