Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 78 profiles

Typical Use Cases in Regulated European AI

Three lenses on every use case: regulation (multi-layer, current), design (architecture & evidence) and business (risk & value). Pick one to see its , the full set of regulations it triggers across the regulatory stack, the legal obligations for and , the recommended architecture blueprint and the technical components your system design must include.

78 use cases · 35 sectors
Start from your role
Compliance leadDescribe your use case and get an executive compliance brief first.
AI engineer / architectSee which obligation lands on which part of the technical stack.
Auditor / assuranceEvery legal reference with its source and verification date, tracked on the verification queue.
Vendor / consultancyThe build-or-buy view of the reference architecture.
Graph v2.21.0updated 2026-09-22700 curated claims · 2290 sourced connections314 of 359 legal references verified87 releases (sign-in required)every change logged
What changes next
2026-12-02Art. 50(2) marking — grace period ends for legacy generative systemsEnd of the transitional grace period for the Art. 50(2) machine-readable marking duty, and ONLY for generative systems placed on the market BEFORE 2 August 2026. Systems placed on the market on or after 2 August 2026 owe the marking duty immediately. This date does not delay the rest of Art. 50, which applies from 2 August 2026. Source: https://eur-lex.europa.eu/eli/reg/2026/1744/oj
2026-12-02New Art. 5 prohibitions apply (NCII, CSAM generation)The two prohibited practices inserted into Art. 5 by Regulation (EU) 2026/1744 — generation of non-consensual intimate imagery and of child sexual abuse material — apply from 2 December 2026. The Art. 5 prohibitions that existed before the omnibus have applied since 2 February 2025. Source: https://eur-lex.europa.eu/eli/reg/2026/1744/oj
2027-08-02Regulatory sandboxesAI regulatory sandboxes operational from 2 Aug 2027 per Regulation (EU) 2026/1744.
See the full regulatory calendar →
Target market(s)European UnionUnited States (federal)change

Cards whose triggered instruments do not reach the selected markets are de-emphasised, not hidden.

Target market(s)

Where will this system be used or placed on the market? The conclusion is derived for these jurisdictions — instruments that bind only elsewhere are left out.

Europe
North America
Latin America
Asia-Pacific
Middle East
Africa

Selected: European Union, United States (federal) · thin-coverage jurisdictions need verification

Use-case profiles
density
Banking & Insurance (14)
High RiskUnverified

AI Credit Scoring & Loan Decisioning

DEthinEUUSUS-CO6/7 domains

Scoring models or agentic workflows that assess creditworthiness of natural persons and drive loan decisions.

Autonomy: human-in-the-loopProfiling of natural persons: yesAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: bothConsequential scoring: yes
13 regs4 blueprints21 links
Minimal RiskUnverified

AI Fund Administration: NAV, Investor Reporting & Fund Accounting

EUUS4/7 domains

AI systems that calculate net asset value (NAV), generate investor statements/reports, and reconcile fund-level accounting for an asset manager, AIFM/UCITS management company, or third-party fund administrator — a back-office valuation and investor-communication function distinct from front-office trade execution/advisory (uc-svc-portfolio) or trade-lifecycle settlement reconciliation (uc-svc-trade).

Autonomy: human-in-the-loopProfiling of natural persons: noAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: bothConsequential scoring: no
5 regs3 blueprints9 links
High RiskUnverified

AI Mortgage Origination & Underwriting

DEthinEUUSUS-CO4/7 domains

AI scoring, underwriting and pricing systems that evaluate residential mortgage applications from natural-person consumers, including collateral valuation and rate and fee pricing.

Autonomy: human-in-the-loopProfiling of natural persons: yesAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: bothConsequential scoring: yes
11 regs3 blueprints15 links
Limited RiskUnverified

Algorithmic Portfolio Execution & Advisory

DEthinEUUS4/7 domains

Trade execution against target parameters, automated conflict-of-interest analysis, generated client advisory communications and full attribution logging of every model inference.

11 regs6 blueprints33 links
pricingBasis points on automated AUM + usage/compute tier
oversightPre-set trade thresholds and kill-switches; named supervisor attribution on every recommendation
Minimal RiskUnverified

Cross-Border Statutory Tax & Wealth Filing

EUGLOBALUS4/7 domains

ERP, custodial and exchange data reconciled across entities and jurisdictions, taxable events categorised, statutory returns drafted and electronically submitted to tax authorities, with variance-triggered human escalation.

6 regs6 blueprints23 links
pricingOutcome-based per successfully submitted return
oversightAutomatic human escalation on material variance or exception above threshold; no unattended submission above the cap
Limited RiskUnverified

Insurance Brokerage & Multi-Carrier Policy Matching AI

EUUSUS-CO3/7 domains

AI that matches, quotes and binds insurance policies across multiple carriers on behalf of a customer — used by brokers, MGAs and comparison/aggregator platforms — distinct from an insurer pricing its own risk or deciding its own claims.

Autonomy: autonomous-with-overrideProfiling of natural persons: yesAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: bothConsequential scoring: yes
6 regs4 blueprints11 links
High RiskUnverified

Insurance Pricing & Claims Decisions

DEthinEUUSUS-CO4/7 domains

Risk pricing for life/health insurance and automated claims adjudication for natural persons.

Autonomy: human-in-the-loopProfiling of natural persons: yesAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: bothConsequential scoring: yes
8 regs3 blueprints12 links
High RiskUnverified

Insurance Underwriting & Health/Life Pricing

DEthinEUUSUS-CO3/7 domains

Eligibility and premium setting for life and health cover, derived from health records, lifestyle declarations and wearable telemetry.

Autonomy: human-in-the-loopProfiling of natural persons: yesAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: bothConsequential scoring: yes
8 regs3 blueprints21 links
High RiskUnverified

KYC & Client Onboarding Automation (Managed Service)

EUUS5/7 domains

Outsourced onboarding: OCR and semantic extraction across filings, beneficial-ownership structures and identity documents, plus sanctions/PEP screening — delivered as an outcome-priced managed service.

7 regs6 blueprints26 links
pricingPer verified identity / per resolved compliance case
oversightMandatory human review of every flagged high-risk entity before onboarding or rejection
Limited RiskcontestedUnverified

Legal Contract & Regulatory Clause Extraction

EUUS4/7 domains

Parsing of ISDA Master Agreements, Credit Support Annexes and regulatory correspondence into structured collateral, termination and exposure data.

5 regs6 blueprints24 links
pricingPer completed contract redline / outcome-based contract resolution
oversightLegal counsel sign-off on escalated high-liability terms
High RiskUnverified

Perpetual KYC & Customer Risk Rating

DEthinEUUS6/7 domains

Agentic continuous customer due diligence: document intelligence, beneficial-ownership resolution, adverse-media screening, dynamic risk re-rating.

9 regs3 blueprints14 links
pricingPer verified identity / per periodic review completed
oversightAnalyst adjudication of every high-risk or adverse-media hit
Minimal RiskUnverified

Regulatory Reporting & Model Documentation Drafting

EU2/7 domains

GenAI drafting of regulatory reports, model documentation and audit narratives with human sign-off.

2 regs2 blueprints6 links
Minimal RiskUnverified

Trade Lifecycle & Settlement Reconciliation

EUUS3/7 domains

Automated matching of multi-asset trade confirmations, exception-break identification, failed-trade resolution and cash/securities settlement reconciliation.

5 regs6 blueprints24 links
pricingPer reconciled break / outcome SLA on settled trades
oversightSupervisor attribution and thresholded escalation on unresolved breaks
Minimal RiskUnverified

Transaction Monitoring & FRAML

EU5/7 domains

Behavioural baselining for fraud and AML detection; alert triage and investigative summary generation (40–67% false-positive reduction reported).

5 regs2 blueprints9 links
Cross-Industry (7)
Minimal RiskUnverified

Automated Financial Forecasting & Audit Trails

EUUS3/7 domains

Cross-ledger aggregation, scenario simulation and draft financial statement assembly with a reviewable audit trail, presented to finance leadership for sign-off.

5 regs6 blueprints25 links
pricingPer completed financial model / reporting cycle
oversightCFO audit sign-off on a proposed-forecast review interface; no automatic posting to the ledger
Minimal RiskUnverified

Autonomous Procurement / Ops Agent

EU4/7 domains

Multi-agent procurement and contract-negotiation workflow that queries vendor APIs, negotiates terms and executes purchase orders against corporate counterparties.

Autonomy: autonomous-with-overrideProfiling of natural persons: noAffected subjects: legal-entityDeployer type: private-enterpriseRole in the value chain: both
6 regs4 blueprints16 links
Minimal RiskUnverified

Developer Code Assistant / Engineering Agent

EU3/7 domains

Code generation, review and autonomous engineering agents with filesystem/terminal/API access (CodeBuddy pattern).

Autonomy: advisoryProfiling of natural persons: noAffected subjects: noneDeployer type: private-enterpriseRole in the value chain: deployer
3 regs2 blueprints7 links
Minimal RiskUnverified

Document Intelligence & Back-Office Extraction

EU2/7 domains

Extraction, classification and summarisation of contracts, invoices and forms; the classic back-office-first pilot.

2 regs2 blueprints6 links
Minimal RiskUnverified

Dynamic Deal Desk & Quoting Engine

EU3/7 domains

Competitor price detection, margin analysis, proposal generation and direct quote issuance to B2B buyers, bounded by margin guardrails that require manager override.

5 regs6 blueprints22 links
pricingUsage-based base fee + performance bonus on closed-deal velocity
oversightMargin guardrail locks requiring manager override before a breaching quote can be issued
Minimal RiskcontestedUnverified

Recommender / Next-Best-Action

CNEU3/7 domains

Product, content or action recommendations for customers or staff.

4 regs2 blueprints9 links
Minimal RiskUnverified

Regulatory Change Management & Policy Updating

EU3/7 domains

Continuous scanning of regulatory feeds, automated mapping of new statutory duties onto internal policies and SOPs, gap analysis and drafted policy amendments routed to a compliance officer for approval.

4 regs5 blueprints19 links
pricingMonthly active compliance-monitoring fee + per-updated-policy fee
oversightCompliance-officer approval matrix before any policy or business-logic change is deployed
Healthcare (6)
Limited RiskcontestedUnverified

Clinical Documentation & Ambient Scribing

DEthinEUUS4/7 domains

Ambient capture and drafting of clinical notes from the consultation itself, with coding suggestions and clinician sign-off before anything enters the record — the ambient-scribe pattern now offered by several health-system deployments rather than any single named product.

7 regs2 blueprints11 links
High RiskUnverified

Clinical Imaging Triage & Patient Follow-Up

EUUS4/7 domains

Diagnostic imaging pipelines monitored for critical findings, then follow-up scheduling, lab orders, record updates and draft patient notifications executed in the EHR — held until the supervising physician confirms.

10 regs6 blueprints35 links
pricingPer completed patient-care workflow / per resolved follow-up
oversightRadiologist or attending physician confirms the proposed care plan before any patient-facing dispatch
High RiskUnverified

Diagnostic Decision Support

EUUS4/7 domains

AI-assisted diagnosis/triage (e.g. sepsis prediction with documented 10× false-positive reduction).

Autonomy: advisoryProfiling of natural persons: noAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: both
8 regs2 blueprints14 links
Minimal RiskUnverified

Healthcare Revenue Cycle & Medical Billing Automation

DEthinEUUS2/7 domains

AI that automates the provider-side administrative and financial processing of the healthcare revenue cycle - medical coding (CPT/ICD), claims formatting and submission, denial and appeals management, prior-authorization paperwork drafting and patient scheduling - used by provider billing offices and third-party RCM vendors. Explicitly scoped to administrative processing of care that has been ordered or delivered: not a clinical or diagnostic decision, not the payer's coverage-eligibility adjudication itself, and not scoring of individual patients' creditworthiness or eligibility.

Autonomy: autonomous-with-overrideProfiling of natural persons: noAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: bothConsequential scoring: no
4 regs2 blueprints7 links
Minimal RiskUnverified

Pharmacy Back-Office & PBM Claims Adjudication AI

EUUSUS-ILthin3/7 domains

AI performing prescription verification, drug-interaction and formulary screening, and pharmacy-benefit-manager (PBM) claims adjudication and reimbursement calculation in US pharmacy and PBM operations, distinct from general insurer prior-authorisation.

Autonomy: autonomous-with-overrideProfiling of natural persons: yesAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: bothConsequential scoring: yes
6 regs3 blueprints10 links
High RiskUnverified

Prior Authorisation & Coverage Decisions

EUUS3/7 domains

Automated insurer–provider prior-authorisation workflows and coverage adjudication.

5 regs2 blueprints8 links
Technology & Security (4)
High RiskUnverified

1:1 Biometric Access Control for Data Centres

DEthinEUUS-ILthin4/7 domains

Targeted biometric verification of enrolled staff and contractors at data-centre doors and cages, matching a presented template against the one claimed identity.

Autonomy: human-in-the-loopProfiling of natural persons: noAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: deployer
5 regs2 blueprints14 links
Minimal RiskUnverified

Autonomous IT Security Remediation Agent

EU2/7 domains

Agent that detects and contains incidents by isolating virtual machines, revoking credentials and changing firewall rules without waiting for a human.

Autonomy: fully-autonomousProfiling of natural persons: noAffected subjects: noneDeployer type: private-enterpriseRole in the value chain: deployer
3 regs3 blueprints14 links
Minimal RiskUnverified

Autonomous Penetration Testing & AI Red-Team Agents (Offensive Security Services)

EUUS4/7 domains

AI agents that plan and run penetration tests (pentests, pentesting) or red-team exercises against a customer's live systems under a signed statement of work: reconnaissance, vulnerability discovery, exploitation, post-exploitation, evidence capture and reporting, delivered by a security provider as a service or as licensed tooling. Scope limit: technical testing of systems only, with no decision about any person; staff-directed social engineering and physical intrusion are outside this reading, and defensive monitoring and response services are separate profiles.

Autonomy: autonomous-with-overrideProfiling of natural persons: noAffected subjects: noneDeployer type: private-enterpriseRole in the value chain: providerConsequential scoring: no
8 regs3 blueprints12 links
Minimal RiskUnverified

Managed IT & Security Services Provider (MSP/MSSP) AI Agent

EU3/7 domains

AI-driven monitoring, patching, ticketing and incident-response agent operated by a third-party managed service or managed security service provider across many client organisations' IT estates under contract, rather than by an organisation remediating only its own network.

Autonomy: autonomous-with-overrideProfiling of natural persons: noAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: bothConsequential scoring: no
4 regs3 blueprints8 links
Customer Operations (3)
HR & People (3)
HR & People (employment) (3)
Limited RiskUnverified

AI Payroll Processing & Compliance Automation

EUUS3/7 domains

AI that calculates gross-to-net pay, applies federal/state/local tax withholding, and runs statutory wage-and-hour compliance checks (overtime calculation, minimum-wage floors, working-time limits) for an employer's own workforce or a payroll-service-bureau's client book.

Autonomy: human-in-the-loopProfiling of natural persons: noAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: bothConsequential scoring: yes
5 regs2 blueprints8 links
High RiskUnverified

Shift Rostering, Task Allocation & Gig Dispatch

CADEthinEU4/7 domains

An algorithm builds shift rosters or dispatches jobs to employees or platform couriers from availability, demand forecasts and individual performance data, sets per-job pay or bonuses, and flags workers for deprioritisation or deactivation.

Autonomy: autonomous-with-overrideProfiling of natural persons: yesAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: deployerConsequential scoring: yes
11 regs1 blueprint13 links
High RiskUnverified

Workplace Monitoring, Safety Vision & Worker Scoring

DEthinEUGBUS4/7 domains

Cameras, telematics or wearables watch employees at work — drowsiness, distraction, PPE compliance, proximity to machinery, productivity — and the alerts feed a per-worker score used for task allocation, escalation or bonuses.

Autonomy: human-in-the-loopProfiling of natural persons: yesAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: deployerConsequential scoring: yes
13 regs1 blueprint15 links
Manufacturing & Supply Chain (3)
Minimal RiskUnverified

AI Trade Compliance: Customs Classification, Export-Control & Sanctions Screening

EUUS3/7 domains

AI that turns BOMs, part numbers and shipping documents into trade decisions for an importer, exporter, forwarder or customs broker: tariff classification and origin (HS/CN/TARIC/HTSUS), restricted-party screening of counterparties, owners and end-uses, export-licence and dual-use determination, and drafting of customs declarations and licence applications. Scope: private-sector decisions about shipments, counterparties and filings; not a customs authority's own risk targeting or a financial institution's payment screening.

Autonomy: human-in-the-loopProfiling of natural persons: noAffected subjects: natural-personDeployer type: private-enterpriseRole in the value chain: bothConsequential scoring: no
8 regs3 blueprints12 links
Minimal RiskUnverified

Procurement Variance & Vendor KPI Monitoring

EUUS3/7 domains

Purchase orders and invoices ingested, price trends analysed, anomalies and contract-term breaches flagged, vendor KPI scorecards maintained and alerts routed to the supply-chain owner.

4 regs5 blueprints20 links
pricingMonthly subscription tier + share of identified variance savings
oversightSupply-chain director authorisation required for any vendor status or payment-block change
Minimal RiskUnverified

Supplier Master Data & ESG Risk Screening

EU3/7 domains

Normalisation of BOM and supplier master data across plants, supplier risk scoring, and screening against ESG, labour, sanctions and customs criteria.

3 regs4 blueprints15 links
pricingPer screened supplier / per resolved risk case
oversightProcurement owner decision on supplier status changes
Public Sector (3)
Accounting & Audit (2)
Education (2)
High-Tech & Software (2)
Housing & real estate (2)
Industry & Energy (2)
Advertising & Media (1)
Consumer & Media (Minors) (1)
Consumer products & IoT (1)
Cross-Industry (AI/ML Infrastructure) (1)
Cross-Industry (Productivity & Admin) (1)
Energy & Utilities (1)
Energy & Utilities (Retail) (1)
GovTech / Public Sector Services (1)
Healthcare & Life Sciences (1)
Media & Platforms (1)
Media & Platforms (Age Assurance) (1)
Political communication (1)
Public safety & health (1)
Retail & E-Commerce (1)
Retail & Fashion (1)
Retail & Security (1)
Telecom & Media (1)
Transportation & Logistics (1)
Water & critical infrastructure (1)