Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 45 profiles

Cross-regime crosswalk

One AI system rarely sits under one regime. Where two obligations from different regimes ask for substantially the same thing, the work — and the evidence — is reusable. Every mapping below is an interpretive claim, so it carries its reasoning and its confidence openly.

Target market(s)European UnionUnited States (federal)change
Target market(s)

Where will this system be used or placed on the market? The conclusion is derived for these jurisdictions — instruments that bind only elsewhere are left out.

Europe
North America
Latin America
Asia-Pacific
Middle East
Africa

Selected: European Union, United States (federal) · thin-coverage jurisdictions need verification

The crosswalk in numbers

21mappings in scope
8established
13asserted — dispute welcome
15regime pairs connected
9artifacts serving several regimes
How to read a mappingA crosswalk edge is an interpretive claim about two obligations from different regimes, never a fact read off one text. Each edge carries a rationale, a confidence marker and an open dispute route.

Regime pairs

Which regimes the graph currently connects, and how confident those connections are.

RegimeRegimeMappingsEstablishedAsserted
EU AI ActGDPR413
EU AI ActISO/IEC 42001:2023 (AIMS)312
EU AI ActNIST AI RMF 1.0202
AI Framework Act (KR)EU AI Act101
EU AI ActEN 18286:2026 (QMS for AI Act)110
EU AI ActISO/IEC 23894 (AI Risk Management)110
EU AI ActISO/IEC 42005 (AI Impact Assessment)110
EU AI ActISO/IEC 5259 (Data Quality for ML)110
EU AI ActISO/IEC 27001:2022 + A.8.28110
EU AI ActNIST AI 600-1 (GenAI Profile)101
EU AI ActNIS2 Directive101
EU AI ActDORA101
EU AI ActColorado AI Act101
EU AI ActNYC Local Law 144 (AEDT)101
GDPRNIS2 Directive110

Every mapping, with its reasoning

Comply once, evidence many

Computed from the graph's evidenced_by edges, not asserted here: these artifacts already discharge obligations in more than one regime. Build them first.

  • Event Logs & Decision Traces10 regimes
    • EU AI ActArt. 12 — Record-Keeping / Logging · CO: Log Completeness & Coverage · CO: Log Integrity & Non-Repudiation · CO: Non-Human Identity Governance
    • DORADORA · DORA Art. 19 — Major ICT-Incident Reporting
    • GDPRGDPR · GDPR Art. 33/34 — Personal-Data Breach Notification
    • HIPAA (US Health Privacy)HIPAA (US Health Privacy) · HIPAA Breach Notification Rule
    • NIS2 DirectiveNIS2 Directive · NIS2 Art. 23 — Significant-Incident Reporting
    • AI Liability Directive (withdrawn)AI Liability Directive (withdrawn)
    • Cyber Resilience ActCRA Art. 14 — Vulnerability & Severe-Incident Reporting
    • FprEN ISO/IEC 24970 (AI Logging)FprEN ISO/IEC 24970 (AI Logging)
    • Revised Product Liability DirectiveRevised Product Liability Directive
    • SEC Cybersecurity Disclosure Rules (Item 1.05 Form 8-K)SEC Form 8-K Item 1.05 — Material Cybersecurity Incident
  • Serious-Incident Register5 regimes
    • Cyber Resilience ActCRA Art. 14 — Vulnerability & Severe-Incident Reporting
    • DORADORA Art. 19 — Major ICT-Incident Reporting
    • EU AI ActArt. 72/73 — Post-Market Monitoring & Incidents
    • NIS2 DirectiveNIS2 Art. 23 — Significant-Incident Reporting
    • SEC Cybersecurity Disclosure Rules (Item 1.05 Form 8-K)SEC Form 8-K Item 1.05 — Material Cybersecurity Incident
  • Post-Market Monitoring Plan & Incident Reports3 regimes
    • EU AI ActArt. 72/73 — Post-Market Monitoring & Incidents · CO: Performance Monitoring & Drift Management
    • DORADORA
    • NIS2 DirectiveNIS2 Directive
  • Vendor & Model Due-Diligence Records3 regimes
    • EU AI ActArt. 26 — Deployer Obligations · CO: Embedded-AI Vendor Governance
    • DORADORA
    • HIPAA (US Health Privacy)HIPAA (US Health Privacy)
  • Human-Oversight Protocol & Intervention Records2 regimes
    • EU AI ActArt. 14 — Human Oversight · CO: Log Access & Retention Governance · CO: Oversight Competence & Authority
    • GDPRGDPR Art. 22 — Automated Decisions
  • SBOM & Vulnerability Management Records2 regimes
    • Cyber Resilience ActCyber Resilience Act
    • NIS2 DirectiveNIS2 Directive
  • Immutable Decision Ledger (WORM)2 regimes
    • EU AI ActCO: Log Integrity & Non-Repudiation · Art. 12 — Record-Keeping / Logging
    • IFRS / US GAAP Reporting AssuranceIFRS / US GAAP Reporting Assurance
  • Personal-Data Breach Notification Record2 regimes
    • GDPRGDPR Art. 33/34 — Personal-Data Breach Notification
    • HIPAA (US Health Privacy)HIPAA Breach Notification Rule
  • Individual Explanation Letters & Counterfactual Records2 regimes
    • EU AI ActArt. 86 — Right to explanation of individual decision-making
    • GDPRGDPR Art. 22 — Automated Decisions

Indicative decision support, not legal advice. Risk classification depends on your concrete deployment context and can change with scope drift — validate the result with qualified counsel.