Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 78 profiles
← Back
GovTech / Public Sector Services

Generative Accessibility Remediation for Public-Sector Digital Services

Limited Risk (Transparency)UnverifiedDiscuss / dispute

A vendor crawls government websites and apps and uses a language model to generate image alt-text, video captions and plain-language summaries, pushing fixes live through an embedded script and opening tickets for what it cannot resolve.

Consensus classification rationale: The regulated object is the public body's digital service, not a decision about a specific person, so the AI Act angle is narrow: Art. 50(2) requires the generated alt-text/captions/summaries (synthetic content) to be marked as AI-generated. The substantive obligations come from three parallel public-sector accessibility regimes that all name web content delivered through a contracted vendor as in scope: the EU Web Accessibility Directive, the US ADA Title II web rule (plus HHS's Section 504 rule for health-funded recipients), and the GB Public Sector Bodies Accessibility Regulations — each independently binds the public-sector customer, which is why a vendor selling into all three markets must track all three.
Decision attributes in force
Autonomyautonomous-with-overrideDrives the human-oversight duties (Art. 14, Art. 26(2)) and Art. 50 disclosure.
Profiling of natural personsnoFeeds the Art. 6(3) second-subparagraph override directly — profiling makes the derogation categorically unavailable.
Affected subjectsnoneInstruments scoped to natural persons drop out of scope when only legal entities are assessed.
Deployer typepublic-authoritySelects between the recorded alternate classification readings.
Role in the value chainproviderSplits provider duties, deployer duties and upstream GPAI duties.
Consequential scoringnoConsequential scoring of natural persons requires intrinsic interpretability, not post-hoc explanation only.

Indicative decision support, not legal advice. Risk classification depends on your concrete deployment context and can change with scope drift — validate the result with qualified counsel.

Target market(s)European UnionUnited States (federal)change

Changes which instruments below count as in scope for this profile.

Target market(s)

Where will this system be used or placed on the market? The conclusion is derived for these jurisdictions — instruments that bind only elsewhere are left out.

Europe
North America
Latin America
Asia-Pacific
Middle East
Africa

Selected: European Union, United States (federal) · thin-coverage jurisdictions need verification

Target markets: European Union, United States (federal)

Regulatory footprint

4 instruments across 1 of 7 regulatory domains, plus 1 standards reference
  • AI lawnone triggered
  • Data protectionnone triggered
  • Cyber & resiliencenone triggered
  • Online safety & platformsnone triggered
  • Product safetynone triggered
  • Financial servicesnone triggered
  • Sector & employment4 instruments
  • Standards1 reference

By jurisdiction

  • EU1European UnionEU Digital Accessibility Directives (EAA & WAD)
  • US2United States (federal)ADA Title II Web and Mobile App Accessibility Rule (US), HHS Section 504 Web and Mobile Accessibility Rule (US)
  • GB1United KingdomPublic Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018 (GB)

The AI Act is one dimension of this footprint, not the whole of it — every domain above carries its own obligations and deadlines. See the instruments in the graph →

Confidence in this chain of evidenceConfidence: Check-worthy

The chain holds, but at least one hop rests on a secondary source, an ageing verification or a practice-derived step. Check the flagged hops before you rely on them.

Computed weakest-link over 8 evaluated hops across 1 target market: a chain is only as strong as its weakest step, so the band follows the worst hop rather than an average that would hide it. Five factors per hop — source tier, verification age, status certainty, community hardening, derivation kind — all read from graph data, never from a hand-set score.

Why this band2 factors lowered the band — each links to the claim behind it
  • Source tier: HHS Section 504 Web and Mobile Accessibility Rule (US) carries no resolvable citation — the claim is uncited. open node →
  • Status certainty: HHS Section 504 Web and Mobile Accessibility Rule (US) is "enacted-not-yet-applicable", not settled in-force law. open node →

Compliance brief

This use case is limited-risk under the EU AI Act (Limited Risk (Transparency)); transparency obligations apply.

What is owed

  • Art. 50. Disclose AI interaction to natural persons; machine-readable marking of synthetic content; deepfake labelling; emotion-recognition disclosure.
  • Art. 4. Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems.

Dates that bind

  • 2024-08-01 AI Act enters into force. Regulation (EU) 2024/1689 in force; countdown for all staged obligations starts.
  • 2025-02-02 Prohibitions + AI literacy. Art. 5 prohibited practices ban applies (manipulation, social scoring, untargeted face scraping, workplace emotion recognition); Art. 4 AI literacy duty.

Maximum exposure

  • EU Digital Accessibility Directives (EAA & WAD): EAA Art. 30: Member States lay down effective, proportionate and dissuasive penalties for infringing national transposing provisions, calibrated to the extent/seriousness of non-compliance and the number of persons affected; Art. 29 gives consumers and associations a right of action before courts or competent administrative bodies. WAD Art. 9: Member States instead provide an adequate and effective enforcement procedure (e.g. an ombudsman) — a procedural/administrative remedy, not an EU-wide fine regime.
  • ADA Title II Web and Mobile App Accessibility Rule (US): DOJ enforcement and private right of action under Title II of the ADA (42 U.S.C. § 12132).
  • HHS Section 504 Web and Mobile Accessibility Rule (US): Loss of HHS federal funding and OCR (Office for Civil Rights) enforcement for non-compliant recipients.
  • Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018 (GB): Monitored by the GDS/DSIT monitoring body; enforcement escalation to the Equality and Human Rights Commission for persistent non-compliance.

First five actions

  1. Confirm in writing whether this organisation builds/places the system on the market (provider) or only operates it (deployer), since the role is not yet established.
  2. Commission and confirm the Art. 50, Art. 4 obligations named above as active workstreams with an accountable owner.
  3. Design and document a human-oversight procedure appropriate to how this system is used.
  4. Produce the technical documentation and evidence artefacts already mapped to this use case (Synthetic-Content Labelling / Watermarking, Interface Transparency & Content-Marking Layer, Document Intelligence Engine) before they are requested.
  5. Put 2024-08-01 — AI Act enters into force — into the compliance calendar with an owner and lead time.

Terms used above: · · ·

Classification precedent

Consensus reading: Limited Risk (Transparency) open in the graph →

The regulated object is the public body's digital service, not a decision about a specific person, so the AI Act angle is narrow: Art. 50(2) requires the generated alt-text/captions/summaries (synthetic content) to be marked as AI-generated. The substantive obligations come from three parallel public-sector accessibility regimes that all name web content delivered through a contracted vendor as in scope: the EU Web Accessibility Directive, the US ADA Title II web rule (plus HHS's Section 504 rule for health-funded recipients), and the GB Public Sector Bodies Accessibility Regulations — each independently binds the public-sector customer, which is why a vendor selling into all three markets must track all three.

What the reading rests on — the provisions this classification actually pulls in:

No dissenting reading is recorded for this case. That means nobody has filed one yet — not that the classification is beyond argument. file a dissent with a source →

Baseline: of 100+, 40% were not definitively classifiable (18% clearly high-risk, 42% clearly low-risk). appliedAI Institute — AI Act risk classification of AI systems from a practical perspective

Applicable Regulations (4)

EU Digital Accessibility Directives (EAA & WAD) (Directive (EU) 2019/882 of 17 April 2019 on accessibility requirements for products and services (European Accessibility Act), bundled with Directive (EU) 2016/2102 of 26 October 2016 on the accessibility of websites and mobile applications of public sector bodies (Web Accessibility Directive))
in-force · verified 2026-09-10 source EUR-Lex in force EU
EAA Art. 2(2) covers services provided to consumers after 28 June 2025, including electronic communications services, consumer banking services and e-commerce services; Annex I Section III(c) requires the websites/apps delivering them to be perceivable, operable, understandable and robust, with Section IV adding service-specific duties (e.g. IV(e): accessible identification/e-signature/payment plus a CEFR-B2 complexity cap for consumer banking). WAD Art. 1(2)/Art. 4 impose the identical standard on public sector bodies' websites and mobile apps. Neither directive mentions artificial intelligence or chatbots by name — 'automated teller machines' appears in EAA Art. 2(1)(b)(ii) only in the non-AI sense of physical self-service devices — both are technology-neutral, reaching an AI-driven interface only to the extent it IS or drives the digital front-end delivering an in-scope service. The harmonised standard EN 301 549 (V3.2.1, Commission Implementing Decision (EU) 2021/1339 of 11 August 2021) incorporates WCAG 2.1 Level AA as the de facto web/mobile baseline.
Sanctions: EAA Art. 30: Member States lay down effective, proportionate and dissuasive penalties for infringing national transposing provisions, calibrated to the extent/seriousness of non-compliance and the number of persons affected; Art. 29 gives consumers and associations a right of action before courts or competent administrative bodies. WAD Art. 9: Member States instead provide an adequate and effective enforcement procedure (e.g. an ombudsman) — a procedural/administrative remedy, not an EU-wide fine regime.
ADA Title II Web and Mobile App Accessibility Rule (US) (28 CFR Part 35, Subpart H (§ 35.200), DOJ Title II accessibility rule as amended by Interim Final Rule 2026-07663)
enacted-not-yet-applicable · verified 2026-09-18 status source ↗ source eCFR enacted — not yet applicable US
Requires state/local public entities (population 50,000+) to make web content and mobile apps — including content provided through contractors or licensors — WCAG 2.1 AA compliant, phased by entity size.
Sanctions: DOJ enforcement and private right of action under Title II of the ADA (42 U.S.C. § 12132).
HHS Section 504 Web and Mobile Accessibility Rule (US) (45 CFR § 84.84, HHS rule implementing Section 504 of the Rehabilitation Act for recipients of HHS financial assistance)
enacted-not-yet-applicable · verified 2026-09-18 status source ↗ enacted — not yet applicable US
Requires recipients of HHS federal financial assistance (e.g. county health departments) with 15+ employees to meet WCAG 2.1 AA for web content and mobile apps, phased by recipient size.
Sanctions: Loss of HHS federal funding and OCR (Office for Civil Rights) enforcement for non-compliant recipients.
Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018 (GB) (The Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018 (SI 2018/952), assimilated law as amended by SI 2022/1097 and SI 2025/557)
in-force · verified 2026-09-18 in force GB
Requires UK public sector bodies to make their websites and mobile applications perceivable, operable, understandable and robust, with a published accessibility statement.
Sanctions: Monitored by the GDS/DSIT monitoring body; enforcement escalation to the Equality and Human Rights Commission for persistent non-compliance.

Legal Obligations (2)

density
Art. 50 — Transparency Duties
Disclose AI interaction to natural persons; machine-readable marking of synthetic content; deepfake labelling; emotion-recognition disclosure.
in-force · verified 2026-08-16 source (as amended) EUR-Lexconvenience mirror — not updated artificialintelligenceact.euAmended by Regulation (EU) 2026/1744. Verified 16 Aug 2026: the popular mirrors have not yet been updated — artificialintelligenceact.eu still serves the unamended 13 June 2024 text with no disclaimer, and the Commission's AI Act Service Desk pages still show pre-omnibus text with a visible omnibus disclaimer. Read the OJ or consolidated text on EUR-Lex.
Art. 4 — AI Literacy
Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems. In force since 2 Feb 2025.
unverified · no verification date source (as amended) EUR-Lexconvenience mirror — not updated artificialintelligenceact.euAmended by Regulation (EU) 2026/1744. Verified 16 Aug 2026: the popular mirrors have not yet been updated — read the OJ or consolidated text on EUR-Lex.

Control Objectives (1)

obligation (article) → operationalized_by → control objective → satisfied_by → component/pattern; control objective → evidenced_by → evidence artifact
Art. 50
AI Interaction & Content Disclosure
Natural persons are informed they interact with an AI system, and generated/manipulated content carries both human-visible labels and machine-readable provenance (C2PA-class) that survives publication pipelines. Testable: disclosure presence across all interaction surfaces; watermark validity sampling post-publication; deepfake-path red-team (does stripped metadata get caught at the gate?).
evidenced by: Guardrail Telemetry & Sanitization Records
Art. 4
control layer: community mandate — propose objectives
Take this into your GRC tooling
A control mapping your ISO/IEC 42001 or CSA AICM workbook can ingest, and an Annex IV skeleton to start the technical file from. Indicative mappings only — cells we are not confident about are exported empty rather than filled in.

Standards & Evidence

C2PA Content Credentials
Open technical standard for cryptographically signed content provenance: manifests binding origin, toolchain and edit history to media assets. The de-facto machine-readable implementation path for Art. 50 synthetic-content marking (machine-readable format + detectability duty) — visible labels satisfy the human side, C2PA manifests the machine side. Verification at publication gates produces the disclosure evidence stream.
published · verified 2026-08-17 status unsourced publisher c2pa.org
evidence for: Art. 50

Evidence you will need (4)

The concrete deliverables this use case's obligations ask for — grouped by what kind of artifact they are. Documentation is the largest single conformity cost block, so the list is a work plan, not a reading list. Full evidence matrix →

Documents & files (1)

Written deliverables an authority or auditor can request as a file.

Instructions for Use / Transparency Docstext-derivedserves 2 obligations
Art. 13 deployer-facing documentation: intended purpose, capabilities, limitations, expected accuracy, oversight measures — plus Art. 50 user-facing disclosures.
verifiability: documented artefact — verifiable on inspection
chain: Art. 13 — Transparency to Deployers · Art. 50 — Transparency Duties · Generative Asset Production & Virtual Try-On · Omnichannel Virtual Support & Voice Bots

Test reports (1)

Measured results from testing, evaluation or red-teaming.

Accuracy, Robustness & Red-Teaming Reportspractice-derived — dispute welcomeserves 2 obligations
Art. 15 evidence: declared accuracy metrics, adversarial and corruption robustness results (DIN SPEC 92001-2, ISO 24029), penetration and jailbreak-resistance testing, groundedness evaluation scores.
verifiability: independently-attested
chain: Art. 15 — Accuracy, Robustness, Cybersecurity · Art. 15 — Accuracy, Robustness, Cybersecurity → CO: Adversarial Robustness Verified · Enterprise SDLC Code Automation & QA · LLM01 Prompt Injection

Log records (1)

Machine-generated records produced while the system runs.

Guardrail Telemetry & Sanitization Recordspractice-derived — dispute welcomeserves 3 obligations
Control-level evidence for the OWASP mappings: guardrail trigger records, blocked-prompt statistics (LLM01), runtime output-sanitization logs (LLM05), groundedness-check outcomes — the empirical proof that declared controls actually execute.
verifiability: tamper-evident
chain: Art. 15 — Accuracy, Robustness, Cybersecurity · Art. 50 — Transparency Duties → CO: AI Interaction & Content Disclosure · Art. 15 — Accuracy, Robustness, Cybersecurity → CO: Runtime Injection Defense · Dynamic Deal Desk & Quoting Engine · Enterprise Marketing Disclosure Compliance · LLM01 Prompt Injection · +3 more

Process records (1)

Traces that a process actually happened, and who did it.

AI Literacy Training Recordspractice-derived — dispute welcomeserves 2 obligations
Art. 4 evidence: role-based training curricula and completion records for staff dealing with AI systems — the one obligation that applies at every risk level.
verifiability: documented artefact — verifiable on inspection
chain: Art. 4 — AI Literacy · Art. 14 — Human Oversight → CO: Oversight Competence & Authority

Architecture Blueprint

Deterministic Document-Validation Pipeline
Schema, completeness and duplicate checks implemented as deterministic rules with a model used only for extraction, never for judgement. The absence of an evaluative step is what keeps a narrow procedural task narrow — and what makes an Art. 6(3)(a) claim documentable.
Human-in-the-Loop Core Pattern
For high-risk decision support over people (HR, credit, benefits): confidence-thresholded escalation queues, WORM audit vault, bias testing per ISO 5259 — the human decision is architecturally enforced. CORRECTED 2026-08-15: this pattern previously recommended a post-hoc explainability API (SHAP/LIME or CoT traces) as the explanation mechanism for consequential scoring of natural persons. That is the wrong default. Post-hoc local explainers are sampling-unstable, vary with perturbation choice and are susceptible to fairwashing, and an adverse-action reason that would not change the outcome if the applicant remediated it is not a defensible reason. For consequential scoring (credit, insurance pricing, tenant screening, employment scoring) use intrinsic interpretability — glass-box additive models with monotonic constraints — and keep post-hoc methods as a supplementary diagnostic only.

Required Technical Components (13)

Synthetic-Content Labelling / Watermarking
Synthetic-content labelling & watermarking: visible disclosure plus machine-readable provenance (C2PA Content Credentials) embedded in generated images, audio and video; metadata identifying artificial origin survives common transformations. Discharges Art. 50(2)/(4) for deepfakes and synthetic media; verification telemetry (watermark presence/validity checks at publication gates) is the corresponding evidence stream.
from: Art. 50
Interface Transparency & Content-Marking Layer
The disclosure surface at the engagement layer: an AI-interaction notice on every channel a natural person can reach (web, app, voice, chat, social, marketplace), machine-readable provenance marking on generated or manipulated output, and a disclosure record per interaction that can be produced on request. Sits at the interface, not in the model — a model-side label that the frontend drops is not a disclosure.
from: Art. 50
Document Intelligence Engine
OCR, layout parsing and semantic clause extraction over filings, contracts and invoices, emitting structured records with span-level source references.
from: Deterministic Document-Validation Pipeline
AI Register & Model Registry / Factsheets
AI register & model registry: central inventory of every model, agent, RAG pipeline and embedded third-party SaaS AI across the estate, with factsheets per asset. v2.0 duty: every application — internal, open-source or procured — continuously publishes a machine-readable AI-BOM and Factsheet into the register; an asset without a current AI-BOM is an inventory gap, not a formality. Feeds Colorado AIA/ LL144 disclosure duties and the Art. 11 technical file; the enforcement backstop is Shadow-AI discovery on the risk register.
from: Deterministic Document-Validation Pipeline
WORM / Immutable Audit Vault
Append-only, hash-chained audit vault (WORM object-lock storage, AES-256 at rest, TLS 1.3 in transit). Guarantees tamper-evidence within the organization's trust domain — which stops your own team, but not an admin who can rebuild the vault. Pair with an external trust anchor and key ceremonies outside the operating team for evidence that holds against the insider scenario.
from: Deterministic Document-Validation Pipeline · Human-in-the-Loop Core Pattern
HITL Escalation Queue & Review UI
HITL escalation queue & review UI ('Human-as-a-Tool': the agent calls the human like any other tool via propose-action objects). Confidence- and risk-threshold routing, SLA timers, structured accept/modify/reject verdicts with digital reviewer signature at gate release — each verdict is itself Art. 14 evidence and feeds the active-learning loop.
from: Human-in-the-Loop Core Pattern
Explainability API (SHAP/LIME/CoT)
Feature attributions for classical ML, reasoning-trace summaries for GenAI — feeds the human reviewer and the technical file.
from: Human-in-the-Loop Core Pattern
Bias Testing & Data Quality Pipeline
Representativeness checks, bias metrics and mitigation per ISO/IEC 5259; versioned datasets with lineage.
from: Human-in-the-Loop Core Pattern
Durable Checkpointing (Pause & Resume)
At oversight gates the complete operational state — working memory, conversation history, tool arguments, intermediate artifacts — is serialized into a durable checkpoint (fast KV store for sub-ms lookups, transactional backend as recovery anchor, vector store for semantic caching of past human decisions). On approval the agent deserializes and resumes at the exact step; matched precedents can shortcut re-planning entirely.
from: Human-in-the-Loop Core Pattern
Kill Switch / Graceful Degradation
Operator stop controls and degraded-mode fallbacks; real-time override (veto) channels for HOTL operation.
from: Human-in-the-Loop Core Pattern
Trust & Risk Dual Scoring
Escalation triggers built from two independent signals, because raw model confidence is uncalibrated: calibrated trust scores (prompt relevance, similarity to historic successes, cross-model consistency) plus deterministic risk scores (sensitive categories, transaction value, protected data) — either crossing its threshold forces human review.
from: Human-in-the-Loop Core Pattern
Active-Learning Feedback Loop
Human corrections at oversight gates are serialized as structured data — original context, model proposal, human edit, rationale — and fed into fine-tuning pipelines and prompt registries, systematically reducing future escalation rates instead of dying in review UIs.
from: Human-in-the-Loop Core Pattern
Confidence Scoring & Threshold Gate
Computes a probabilistic confidence score for every output and holds the transaction when the score falls below the workflow's regulatory threshold.
from: Human-in-the-Loop Core Pattern

Build or Buy — Vendor Layer (10)

The graph models vendor CATEGORIES as first-class nodes and keeps named vendors as community-maintained, disputable desc content with lastVerified dates. A category is stable; a vendor list is a currency-layer object like any standard node.
Regulated Foundation-Model Platforms
Frontier commercial APIs and open-weight models under enterprise controls: zero-data-retention tiers, data isolation, fine-tuning governance, safety alignment documentation, EU-sovereign options. Named products live in marketExamples, where the deployment model is recorded in the hosting field rather than asserted in prose. What the class buys you: a model supply relationship with contractual data handling and documentation you can pass to a customer. GPAI-chapter duties and provider due diligence attach at this layer. Selection metrics: see meta.marketLandscape.selectionMetrics.models.
unverified · verified 2026-08-18 community-maintained
selection metrics: ZDR enterprise tiers, data isolation, EU-sovereign options, fine-tuning controls, safety alignment documentation
supplies: Synthetic-Content Labelling / Watermarking
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
OpenAI (Enterprise / API)proprietary frontierEnterprise tiers offer zero-data-retention and no-training commitments over the commercial API. Typical: general copilots, document reasoning.not checkedSOC 2 (claimed)ISO 27001 (claimed)zero-data-retention tier (claimed)GDPR-positioned
Anthropic Claude (Enterprise)proprietary frontierEnterprise/ZDR tiers with published safety and model documentation practice. Typical: regulated assistants, long-context analysis.not checkedSOC 2 (claimed)ISO 27001 (claimed)zero-data-retention tier (claimed)HIPAA-eligible (claimed)
Google Gemini Enterpriseproprietary frontierVertex-hosted frontier models with regional grounding and customer-managed keys. Typical: enterprise search, multimodal workflows.not checkedSOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed)EU data-boundary positioning
Cohereproprietary frontierPrivate-cloud and on-prem deployment of retrieval-oriented models. Typical: private RAG, enterprise search.self-hostableSOC 2 (claimed)

and 7 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Runtime Security & Guardrail Vendors
First-line inline enforcement: single-pass parallel input/output evaluation proxies, injection and exfiltration defense, PII masking, grounding checks, SecOps routing. Named products live in marketExamples; prose here describes the class. What the class buys you: a policy decision point in the request path that fails closed and emits telemetry an auditor can read. Selection metrics: single-pass latency (<20 ms class), catch rates, policy-version telemetry into the AI-BOM. Consolidation matters commercially: a guardrail acquired by a platform vendor tends to follow that platform's roadmap, which is a lock-in question rather than a security one — reported acquisitions are recorded per entry as reported, not asserted here.
unverified · verified 2026-08-18 community-maintained
selection metrics: single-pass parallel evaluation latency (<20 ms class), injection/hallucination catch rates, SecOps/SIEM routing, policy versioning surfaced into the AI-BOM
supplies: Interface Transparency & Content-Marking Layer · Output Rails / Groundedness Check
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Lakeraguardrail proxyInline prompt-injection and content detection at request time. Typical: injection defence, content filtering.not checkedSOC 2 (claimed)supports Art. 15 robustness measures (claimed)
HiddenLayermodel/agent detection & responseModel-layer detection and response with adversarial-attack telemetry. Typical: model threat detection, red-team telemetry.not checkedSOC 2 (claimed)supports Art. 15 robustness measures (claimed)
Palo Alto Prisma AIRSnetwork-integrated AI securityAI runtime security folded into an existing enterprise network security estate. Typical: enterprise rollout, egress control.not checkedSOC 2 (claimed)enterprise security integration (claimed)
Cisco AI Defensenetwork-integrated AI securityDiscovery of AI usage plus inline enforcement across the corporate network. Typical: shadow-AI discovery, inline enforcement.not checkedenterprise security integration (claimed)

and 4 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Public Transparency Registers & System Cards
Authoring and publishing the outward-facing record: public AI registers, system and model cards, conformity declarations and plain-language notices, with versioning so a published statement can be tied to the system version it described. The register content is produced elsewhere; this class is the publication and version-control surface for it. Selection metrics: see meta.marketLandscape.selectionMetrics.transparency.
unverified · verified 2026-08-17 community-maintained
selection metrics: Versioning of published statements against the system version they describe; whether a card is generated from your governance record or re-authored by hand; language coverage and accessibility of the published surface; export and self-hosting of the public register; whether unpublishing leaves an auditable trail.
supplies: Interface Transparency & Content-Marking Layer · AI Register & Model Registry / Factsheets
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Saidotpublic AI registerAI register with published system cards and regulation-mapped documentation workflows. Typical: public AI register, system cards. Scope overlap: Its documentation and register scope overlaps this platform's own; we have a commercial interest in the comparison.SaaS (vendor cloud)EU AI Act documentation positioningISO 42001 alignment (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Grounding, Retrieval & Agent Memory
The grounding layer between raw sources and the model: document parsers, embedding models, vector databases and — new in the agentic era — persistent agent memory stores. Memory is the hard part: once a personal fact is embedded, GDPR Art. 17 erasure has to reach the vector and the memory record, not just the source row, and embeddings are partially reconstructable (see IronCore in the privacy layer). Retrieval quality is also a data-governance question under Art. 10: what got parsed, chunked and indexed is what the system 'knows'.
unverified · verified 2026-08-18 community-maintained
selection metrics: Parsing fidelity on your worst document class; retrieval precision/recall on a labelled set; tenant and ACL isolation model; per-vector encryption and erasure path; memory TTL and record semantics; self-host option.
supplies: Document Intelligence Engine
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Doclingdocument parserOpen-source layout-aware parsing of PDFs and office formats into structured chunks. Typical: RAG ingestion, air-gapped pipelines.self-hostableEU sovereignty positioning
LlamaParsedocument parserManaged parsing service tuned for tables and complex documents feeding RAG. Typical: RAG ingestion, table extraction.not checkedSOC 2 (claimed)
Amazon Textractdocument parserOCR and form/table extraction with per-page pricing inside AWS. Typical: document intake, claims processing.not checkedSOC 2 (claimed)HIPAA-eligible (claimed)ISO 27001 (claimed)
Diffbotweb/knowledge extractionStructured extraction and knowledge-graph construction from web sources. Typical: market monitoring, entity resolution.not checkedvendor-stated security posture

and 12 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Agentic Applications & Copilots
Finished agentic products bought rather than built: developer and productivity copilots, research assistants, SOC and support agents. The governance point is not the product but the wrapper: these tools act with delegated authority inside your estate, so they belong in the agent inventory, need scoped non-human identities and permission boundaries, and inherit deployer duties — buying the product does not buy the obligations away.
unverified · verified 2026-08-18 community-maintained
selection metrics: Permission model and identity scoping; audit log export; tenant data-handling and retention terms; deployer-duty support (disclosure, oversight, incident reporting); outcome pricing vs seat pricing.
supplies: Document Intelligence Engine
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
GitHub Copilotdeveloper copilotCode completion and agent modes inside the IDE and repository workflow. Typical: software engineering, code review.not checkedSOC 2 (claimed)enterprise data-handling commitments (claimed)
Microsoft 365 Copilotproductivity copilotAssistant across mail, documents and meetings inheriting existing tenant permissions. Typical: knowledge work, meeting summaries.not checkedISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning
Perplexity Enterpriseresearch assistantCited web and internal search with source attribution per answer. Typical: market research, citation-backed search.not checkedSOC 2 (claimed)enterprise data-handling commitments (claimed)
Cursordeveloper copilotAI-native editor with repository-wide agent edits. Typical: software engineering, refactoring.not checkedSOC 2 (claimed)privacy-mode option (claimed)

and 5 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

AI GRC & Governance Platforms
Second-line systems of record: model/agent inventory incl. third-party SaaS AI, automated risk tiering, policy administration, cross-framework mapping and control deduplication, audit-evidence generation, intake workflows. Named products live in marketExamples, which is the single source of truth for this layer — prose here describes the class, not the field. What the class buys you: one register a second line can defend, and evidence assembled once and reused across frameworks. Selection metrics: see meta.marketLandscape.selectionMetrics.grc. One compilation-reported item is deliberately kept as unverified: a claimed updated US banking model-risk guidance 'SR 26-2'. Two secondary compilations repeating it is corroboration of the rumour, not of the guidance; it stays flagged pending verification against Federal Reserve primary sources, and a curator verification proposal is filed. All alignments in this layer are vendor-positioned claims, never certifications.
unverified · verified 2026-08-18 community-maintained
selection metrics: multi-model/multi-cloud cataloging incl. third-party SaaS, automated risk tiering, regulatory reporting, independent-2nd-line deployability, cross-framework control deduplication
supplies: AI Register & Model Registry / Factsheets
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Credo AIAI governance platformPolicy packs, risk tiering and evidence workflows mapped across frameworks. Typical: AI registry, policy administration. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedISO 42001 alignment (claimed)EU AI Act readiness positioning
Holistic AIAI governance & auditRisk assessment, bias auditing and regulatory reporting workflows. Typical: bias audit, regulatory reporting. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedNYC LL144 audit support (claimed)EU AI Act readiness positioning
IBM watsonx.governanceAI governance platformGovernance, factsheets and monitoring integrated with the IBM stack. Typical: factsheets, model monitoring. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedISO 42001 alignment (claimed)Art. 11 documentation support (claimed)
ModelOpAI/model governanceModel and agent inventory with automated lifecycle controls for large estates. Typical: model inventory, control automation. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedmodel-risk positioning (SR 11-7 style, claimed)ISO 42001 alignment (claimed)

and 3 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Agent Observability & Model Risk Management
Tracing, evaluation, drift monitoring and model-validation records. This layer is where Art. 12 record-keeping becomes technically real (step-level traces, prompt/response records, retention control) and where model-risk practice in the SR 11-7 tradition — validation evidence, performance and drift monitoring, challenger comparison — is operated. Gateways and tracing tools produce the logs; the retention, integrity and access regime around them is still yours.
unverified · verified 2026-08-18 community-maintained
selection metrics: Trace completeness per agent step; log retention and immutability options; drift/quality metrics available out of the box; evaluation dataset support; export into your audit vault; self-host option.
supplies: AI Register & Model Registry / Factsheets · Explainability API (SHAP/LIME/CoT) · Bias Testing & Data Quality Pipeline · Confidence Scoring & Threshold Gate
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
LangSmithagent tracing & evaluationTrace capture and evaluation over LangChain/LangGraph runs with dataset-based scoring. Typical: step tracing, regression evaluation.not checkedSOC 2 (claimed)supports Art. 12 record-keeping (claimed)
Langfuseagent tracing & evaluationOpen-source tracing, prompt management and evaluation; self-hostable for retention control. Typical: self-hosted tracing, cost/latency analytics.open sourceGDPR-positionedsupports Art. 12 record-keeping (claimed)
Arize AI / PhoenixML & LLM observabilityProduction monitoring with drift and performance analysis; Phoenix is the open-source tracing side. Typical: drift monitoring, production analytics.not checkedSOC 2 (claimed)drift-monitoring positioning (SR 11-7 style, claimed)
HeliconeLLM gateway & loggingProxy-level logging of prompts, costs and latency across providers. Typical: gateway logging, cost control.not checkedSOC 2 (claimed)supports Art. 12 record-keeping (claimed)

and 11 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Cryptographic Evidence & Audit Ledger
Tamper-evident recording of what a system did: content-addressed decision records, hash chains and external anchoring, so a log can be shown not to have been rewritten after the fact. This is the layer that turns Art. 12 logging and Art. 19 retention from a storage question into an evidentiary one. AI Verify is carried in RAIN as a STANDARD node (sg-ai-verify), not duplicated here as a vendor.
unverified · verified 2026-08-18 community-maintained
selection metrics: Append-only guarantees and who can rotate or delete (including the vendor); anchoring mechanism (qualified timestamp, transparency log, notarisation) and whether verification works without the vendor; retention and export in a readable format at end of contract; throughput and cost at your event volume.
supplies: WORM / Immutable Audit Vault
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Fact0cryptographic evidence ledgerPositions itself as a tamper-evident ledger for AI decision records. Typical: decision records, audit trail.not checkedsupports Art. 12 record-keeping (claimed)
Tracciaaudit trail & traceabilityPositions itself around traceability of AI pipeline steps and artefacts. Typical: traceability, artifact lineage.not checkedsupports Art. 12 record-keeping (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Agent Orchestration & SDLC Toolkits
Developer middleware for multi-agent networks, tool-use chains, RAG abstraction, state and memory persistence, and model routing. Named products live in marketExamples; prose here describes the class. Regulatory posture: orchestration code is where autonomy tiering, propose-action objects and fallback routing get implemented — the framework choice constrains which controls are cheap and which are retrofits. Selection metrics: see meta.marketLandscape.selectionMetrics.orchestration.
unverified · verified 2026-08-18 community-maintained
selection metrics: broad model-API abstraction, state/memory management, error recovery, fallback routing hooks
supplies: HITL Escalation Queue & Review UI
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
LangChain / LangGraphagent frameworkGraph-structured agent runtime; interrupt/pause nodes support implementing human approval at defined steps. Typical: multi-step agents, approval workflows.not checkedsupports implementing Art. 14 oversight (claimed)supports Art. 12 step logging (claimed)
LlamaIndexRAG frameworkIndexing and query abstractions over documents and structured sources. Typical: enterprise RAG, document agents.open sourceretrieval-governance positioning
Microsoft AutoGenmulti-agent frameworkConversational multi-agent patterns with pluggable tool executors. Typical: multi-agent research, code agents.not checkedresearch/OSS, no vendor certification
CrewAImulti-agent frameworkRole-based agent teams with task delegation and process templates. Typical: process automation, role-based agents.not checkedvendor-stated security posture

and 6 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Runtime Guardrails & Enforcement
Policy enforcement in the request path: input/output validation, injection and exfiltration defence, structured-output constraints and action blocking. Distinct from observability layers because these products are in-line and can refuse. Selection questions: added latency at p95, whether enforcement is fail-open or fail-closed, whether policies are versioned artefacts, and whether the layer can be self-hosted inside your data boundary.
unverified · verified 2026-08-18 community-maintained
selection metrics: Where enforcement sits (inline proxy, sidecar, SDK) and the added latency at your token volumes; whether policy is versioned and testable as code; fail-open vs. fail-closed behaviour under guardrail outage; language and modality coverage; whether every block writes an evidence record you can cite later.
supplies: Output Rails / Groundedness Check
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Guardrails AIvalidation frameworkOpen-source validator framework for structured output and content policies in the request path. Typical: output validation, structured output.open sourcesupports Art. 15 robustness measures (claimed)
NVIDIA NeMo Guardrailsdialogue policy railsProgrammable dialogue and topic rails placed around an LLM application. Typical: topic control, dialogue policy.open sourcesupports Art. 50 interaction disclosure patterns (claimed)
Lakera AIguardrail proxyInline prompt-injection and content detection at request time. Typical: injection defence, content filtering.SaaS (vendor cloud)SOC 2 (claimed)supports Art. 15 robustness measures (claimed)
Credal AIenterprise access & policy layerPermission-aware access layer with data-loss controls in front of enterprise assistants. Typical: access control, DLP.SaaS (vendor cloud)SOC 2 (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Procurement rule: Derived from three-lines-of-defense separation: the second-line GRC platform must be procured and deployed independently of any first-line runtime or model vendor — a governance tool that only sees its own vendor's models cannot govern a multi-model estate, and closed third-party SaaS AI can only be governed contractually (intake, attestation, AI-BOM disclosure), never by inline inspection.
Outsourced delivery BPO · SaaS · Service-as-a-Software caveats

Delivery Model — BPO · SaaS · Service-as-a-Software

Spectrum
BPO: input-priced (billable hours/FTEs), linear headcount scaling, human error & attrition as primary risk
SaaS: capability-priced (software access), client operates the workload, implementation/adoption failure as primary risk
Service-as-a-Software: outcome-priced (SLA on completed work), provider-managed AI executes 60–80% of cognitive tasks with specialist supervision, algorithmic bias & non-compliance as primary risk
Caveats in regulated markets
Outcome SLAs move compliance risk onto the provider — but NOT the buyer's deployer duties: Art. 26 oversight, log retention and FRIA obligations stay with the enterprise even when execution is outsourced.
Provider role analysis is the central legal question: a productized platform that fine-tunes, re-purposes or chains models can flip into the Art. 25 provider role with full high-risk obligations.
Certified operations (ISO 42001) function as a procurement moat and shortcut third-party risk assessment — but organizational certificate ≠ product conformity (never conflate, see meta.assuranceEcosystem).
The buyer's evidence chain must reach into the provider: contractually mandated AI-BOM disclosure, ZDR certificates, bias-audit reports and logging-ledger access are the artifacts that make an outsourced workflow auditable.

Threat Profile

LLM01 Prompt Injection
Direct or indirect (RAG/files/web) instructions override system prompts — the primary attack vector on the perception layer.
mitigate with: Input Rails / Prompt Shields, Guardrail Sidecar / Interception, Trinity Defense (TCB + Command Gates + IFC), Divided-Focus Memory Tiering, Dual-Gate Validation Pipeline
LLM02 Sensitive Info Disclosure
Leakage of PII, trade secrets or system prompts in outputs.
mitigate with: PII Scrubbing / DLP-NER Layer, Output Rails / Groundedness Check, PII/PHI Redaction & Tokenisation Engine
LLM09 Misinformation
Hallucinated or wrong outputs create liability and decision risk.
mitigate with: Output Rails / Groundedness Check, Explainability API (SHAP/LIME/CoT)