Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles
← Back
Banking & Insurance

Transaction Monitoring & FRAML

Minimal RiskUnverifiedDiscuss / dispute

Behavioural baselining for fraud and AML detection; alert triage and investigative summary generation (40–67% false-positive reduction reported).

Classification rationale: Minimal risk while operating as behavioral baseline and triage assistant with human validation before action (the framing that also delivers the 40–67% false-positive reductions); DORA/AML dominate. Risk-class drift the moment the system auto-blocks accounts or freezes funds.
Evaluate risk & value →Open in graph
This profile is incomplete: no threats modelled. That is a gap in the graph, not a statement that nothing applies — propose the missing links →

Indicative decision support, not legal advice. Risk classification depends on your concrete deployment context and can change with scope drift — validate the result with qualified counsel.

Compliance brief

This use case is minimal-risk under the EU AI Act (Minimal Risk); no product-specific obligations beyond general AI literacy apply.

What is owed

  • Art. 4. Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems.
  • GDPR Art. 22. Right not to be subject to solely automated decisions with legal/similar effect; requires meaningful human involvement or explicit legal basis + safeguards.
  • GDPR Art. 17. Right to erasure collides with AI Act Art.
  • GDPR Art. 25. Privacy by design & default: minimisation, pseudonymisation, PII filters in pipelines and vector stores.
  • GDPR Art. 35. Data-protection impact assessment for high-risk processing — pairs with AI Act fundamental-rights impact assessment (Art.

Dates that bind

  • 2026-08-02General applicability + Art. 50. Transparency obligations for chatbots, deepfakes and synthetic content; EU-level enforcement begins.
  • 2026-12-02Additional prohibitions. Additional bans (deepfake CSAM et al.) and transition period for synthetic content under Art. 50(2).

Maximum exposure

  • GDPR: Up to €20m or 4% of worldwide annual turnover
  • DORA: Administrative penalties; periodic penalty payments for critical third parties
  • EU AI Act: Tiered: €35m / 7% (prohibited practices); €15m / 3% (Art. 9–15 high-risk obligations incl. data governance, documentation, logging); €7.5m / 1% (Art. 99(5) — incorrect, incomplete or misleading information to notified bodies or national competent authorities)

First five actions

  1. Confirm in writing whether this organisation builds/places the system on the market (provider) or only operates it (deployer), since the role is not yet established.
  2. Commission and confirm the Art. 4, GDPR Art. 22, GDPR Art. 17 obligations named above as active workstreams with an accountable owner.
  3. Stand up the named oversight design — Mode 3 — with a documented human-review procedure.
  4. Produce the technical documentation and evidence artefacts already mapped to this use case (HITL Escalation Queue & Review UI, Bitemporal Memory (GDPR×Art.12), PII Scrubbing / DLP-NER Layer) before they are requested.
  5. Put 2026-08-02 — General applicability + Art. 50 — into the compliance calendar with an owner and lead time.

Terms used above: · · ·

This brief is based on partial coverage — no threat profile is mapped yet.

Applicable Regulations (4)

GDPR (Regulation (EU) 2016/679)
unverified · no verification date source EUR-Lex
Applies unchanged next to the AI Act for all personal data in training, fine-tuning, RAG and inference. Key friction points: Art. 22 automated decisions, Art. 17 erasure vs. AI Act logging, Art. 35 DPIA.
Sanctions: Up to €20m or 4% of worldwide annual turnover
DORA (Regulation (EU) 2022/2554)
unverified · no verification date source EUR-Lex
Digital operational resilience for the financial sector: ICT third-party risk (CTPP oversight), change management, resilience testing — applies to AI-based trading, credit and KYC systems.
Sanctions: Administrative penalties; periodic penalty payments for critical third parties
AML Package (AMLR/AMLA)
unverified · no verification date
Customer due diligence, perpetual monitoring and AMLA supervisory expectations for AI-driven KYC/AML systems.
EU AI Act (Regulation (EU) 2024/1689)
unverified · no verification date source EUR-Lex
Horizontal, risk-based product-safety law for AI systems and GPAI models. Extraterritorial market-place principle. Staged applicability 2025–2030 (Digital Omnibus: Annex III → 2 Dec 2027, Annex I → 2 Aug 2028).
Sanctions: Tiered: €35m / 7% (prohibited practices); €15m / 3% (Art. 9–15 high-risk obligations incl. data governance, documentation, logging); €7.5m / 1% (Art. 99(5) — incorrect, incomplete or misleading information to notified bodies or national competent authorities)

Legal Obligations (5)

Art. 4 — AI Literacy
Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems. In force since 2 Feb 2025.
unverified · no verification date read the article artificialintelligenceact.eu
GDPR Art. 22 — Automated Decisions
Right not to be subject to solely automated decisions with legal/similar effect; requires meaningful human involvement or explicit legal basis + safeguards.
unverified · no verification date read the article EUR-Lex
GDPR Art. 17 — Erasure
Right to erasure collides with AI Act Art. 12 immutable logging — resolved architecturally via bitemporal data modelling + physical partition scrub.
unverified · no verification date read the article EUR-Lex
GDPR Art. 25 — Data Protection by Design
Privacy by design & default: minimisation, pseudonymisation, PII filters in pipelines and vector stores.
unverified · no verification date read the article EUR-Lex
GDPR Art. 35 — DPIA
Data-protection impact assessment for high-risk processing — pairs with AI Act fundamental-rights impact assessment (Art. 27) for public-facing high-risk systems.
unverified · no verification date read the article EUR-Lex

Control Objectives (0)

obligation (article) → operationalized_by → control objective → satisfied_by → component/pattern; control objective → evidenced_by → evidence artifact
Art. 4
control layer: community mandate — propose objectives
GDPR Art. 22
control layer: community mandate — propose objectives
GDPR Art. 17
control layer: community mandate — propose objectives
GDPR Art. 25
control layer: community mandate — propose objectives
GDPR Art. 35
control layer: community mandate — propose objectives
Take this into your GRC tooling
A control mapping your ISO/IEC 42001 or CSA AICM workbook can ingest, and an Annex IV skeleton to start the technical file from. Indicative mappings only — cells we are not confident about are exported empty rather than filled in.

Standards & Evidence

ISO/IEC 42005 (AI Impact Assessment)
Guidance for AI system impact assessments — supports DPIA/FRIA-style analyses.
unverified · no verification date publisher ISO
evidence for: GDPR Art. 35
IEEE CertifAIEd™
Ethics certification (transparency, accountability, algorithmic bias, privacy) for products and professionals; interfaces with the EU ALTAI assessment list.
unverified · no verification date
evidence for: EU AI Act

Architecture Blueprint

Sovereign Resilient Enterprise Pattern
For regulated finance / high-sensitivity workloads: EU-jurisdiction or EUCS-High+ cloud, confidential computing, BYOK via external HSM, multi-region failover, full FCoT/OpenTelemetry tracing, DORA-grade third-party auditing.
Mode 3 — Human-on-the-Loop
Autonomous execution with aggregate oversight: dashboards, sampling audits (5–10%), real-time veto. For high-volume, low-individual-impact steps.

Required Technical Components (15)

HITL Escalation Queue & Review UI
HITL escalation queue & review UI ('Human-as-a-Tool': the agent calls the human like any other tool via propose-action objects). Confidence- and risk-threshold routing, SLA timers, structured accept/modify/reject verdicts with digital reviewer signature at gate release — each verdict is itself Art. 14 evidence and feeds the active-learning loop.
from: GDPR Art. 22
Bitemporal Memory (GDPR×Art.12)
valid_from/valid_to + transaction time on every record: GDPR erasure removes data from the active retrieval path while the HMAC-chained immutable log survives for Art. 12 / PLD defence; tenant-scoped partitions allow physical scrub of PII.
from: GDPR Art. 17 · Sovereign Resilient Enterprise Pattern
PII Scrubbing / DLP-NER Layer
Automated detection, pseudonymisation and blocking of personal data in inputs, retrievals and outputs.
from: GDPR Art. 25
Per-Tenant Retrieval Segmentation
Retrieval is scoped by tenant and by caller entitlement at query time, preventing cross-client and cross-role leakage through shared indexes.
from: GDPR Art. 25
Segmented Vector Store (RBAC + CMEK)
Vector indexes, embeddings and document stores are logically and physically partitioned per client, with role-based access and customer-managed encryption keys.
from: GDPR Art. 25
Live Risk Register / Posture Management
Continuously updated risk register wired to runtime posture: threat-model deltas, open defects, control status, exposure per system. Includes Shadow-AI discovery — continuous scanning for unsanctioned agents, MCP servers and AI API usage outside the register; an unregistered agent is an unmanaged Art. 12/26 liability and the empirical driver of proportionate (not blanket) controls.
from: GDPR Art. 35
Multi-Region Failover & Resilience Testing
DORA-grade continuity: regional redundancy, chaos testing, exit strategies for critical third parties.
from: DORA · Sovereign Resilient Enterprise Pattern
Vendor & Model Due-Diligence Kit
Scoring model: jurisdiction (CLOUD Act exposure), zero-data-retention, BYOK support, audit evidence (C5/AIC4/ISO 42001/EN 18286:2026), tenant isolation.
from: DORA · Sovereign Resilient Enterprise Pattern
Confidential Computing Enclaves
AMD SEV / Intel TDX: data protected from the cloud operator even in memory during inference.
from: Sovereign Resilient Enterprise Pattern
BYOK via External HSM
Customer-controlled key sovereignty; cascaded encryption independent of the cloud provider.
from: Sovereign Resilient Enterprise Pattern
OpenTelemetry / FCoT Tracing
Hierarchical trace spans for every sub-task, prompt, retrieved document and API call — the reconstructible decision path for Art. 12/14 and PLD disclosure.
from: Sovereign Resilient Enterprise Pattern
Sovereign Context Layer
Governed runtime workspace operationalizing Art. 10: traceable lineage for every RAG chunk and training record at execution time, canonical version-controlled business glossary (documents Art. 10(2)(d) baseline assumptions), and continuous data-quality monitoring with threshold alerts and logged remediation for the Art. 10(3) 'error-free and complete' standard.
from: Sovereign Resilient Enterprise Pattern
Isolated Tenant Storage Enclave
Per-client storage boundary for raw payloads, intermediate artefacts and outputs, so no tenant data is co-mingled or reachable across engagements.
from: Sovereign Resilient Enterprise Pattern
Zero-Trust Ingestion Gateway
Authenticated, policy-checked entry point for client payloads; enforces tenant identity, schema validation and rate limits before any data reaches an inference path.
from: Sovereign Resilient Enterprise Pattern
Local Perimeter Execution (MCP)
Execution agents run inside the corporate perimeter and reach tools through the Model Context Protocol instead of shipping raw records to third-party model endpoints. Context is scoped to the minimum attributes the task needs, which is how data minimisation (GDPR Art. 5(1)(c)) and Art. 25 privacy-by-design survive multi-tool agent orchestration.
from: Sovereign Resilient Enterprise Pattern

Build or Buy — Vendor Layer (3)

The graph models vendor CATEGORIES as first-class nodes and keeps named vendors as community-maintained, disputable desc content with lastVerified dates. A category is stable; a vendor list is a currency-layer object like any standard node.
Agent Orchestration & SDLC Toolkits
Developer middleware for multi-agent networks, tool-use chains, RAG abstraction, state/memory persistence and model routing. Exemplary (community-maintained): LangChain, LlamaIndex, AutoGen, CrewAI; MCP-based tool ecosystems. Regulatory posture: orchestration code is where autonomy tiering, propose-action objects and fallback routing get implemented — the framework choice constrains which controls are cheap and which are retrofits.
unverified · verified 2026-08-06 community-maintained
selection metrics: broad model-API abstraction, state/memory management, error recovery, fallback routing hooks
supplies: HITL Escalation Queue & Review UI
AI GRC & Governance Platforms
Second-line systems of record: model/agent inventory incl. third-party SaaS AI, automated risk tiering, policy administration, cross-framework mapping & control deduplication, audit-evidence generation, intake workflows. Exemplary (community-maintained): ModelOp Center, Credo AI, IBM watsonx.governance, OneTrust, Holistic AI, Modulos (governance graph), Monitaur (insurance/lending), Fairly AI, Saidot, Trustible, Enzai, LatticeFlow (technical validation), Vanta (evidence automation), ServiceNow (intake/ITSM); data-catalog adjacency: Collibra, Alation, Informatica. Selection metrics: see meta.marketLandscape.selectionMetrics.grc.
unverified · verified 2026-08-06 community-maintained
selection metrics: multi-model/multi-cloud cataloging incl. third-party SaaS, automated risk tiering, regulatory reporting, independent-2nd-line deployability, cross-framework control deduplication
supplies: Live Risk Register / Posture Management · Vendor & Model Due-Diligence Kit
Secure Data Infrastructure & Vector Storage
Governed retrieval substrate: vector databases, lakehouses and catalogs with tenant/namespace isolation, RBAC + client-managed keys (CMEK), lineage into RAG chunks, air-gap options. Exemplary (community-maintained): Pinecone (serverless, SOC 2), Chroma/FAISS (self-hosted/air-gapped sovereignty), Snowflake Cortex (masking, clean rooms), Databricks Unity Catalog (end-to-end lineage), Azure AI Search, AWS OpenSearch. The Art. 10 runtime data-governance duties land here.
unverified · verified 2026-08-06 community-maintained
selection metrics: namespace/tenant isolation, RBAC + CMEK, lineage into RAG chunks, SOC 2 / ISO 27001 attestations, air-gap capability
supplies: Sovereign Context Layer · Local Perimeter Execution (MCP)
Procurement rule: Derived from three-lines-of-defense separation: the second-line GRC platform must be procured and deployed independently of any first-line runtime or model vendor — a governance tool that only sees its own vendor's models cannot govern a multi-model estate, and closed third-party SaaS AI can only be governed contractually (intake, attestation, AI-BOM disclosure), never by inline inspection.
Outsourced delivery BPO · SaaS · Service-as-a-Software caveats

Delivery Model — BPO · SaaS · Service-as-a-Software

Spectrum
BPO: input-priced (billable hours/FTEs), linear headcount scaling, human error & attrition as primary risk
SaaS: capability-priced (software access), client operates the workload, implementation/adoption failure as primary risk
Service-as-a-Software: outcome-priced (SLA on completed work), provider-managed AI executes 60–80% of cognitive tasks with specialist supervision, algorithmic bias & non-compliance as primary risk
Caveats in regulated markets
Outcome SLAs move compliance risk onto the provider — but NOT the buyer's deployer duties: Art. 26 oversight, log retention and FRIA obligations stay with the enterprise even when execution is outsourced.
Provider role analysis is the central legal question: a productized platform that fine-tunes, re-purposes or chains models can flip into the Art. 25 provider role with full high-risk obligations.
Certified operations (ISO 42001) function as a procurement moat and shortcut third-party risk assessment — but organizational certificate ≠ product conformity (never conflate, see meta.assuranceEcosystem).
The buyer's evidence chain must reach into the provider: contractually mandated AI-BOM disclosure, ZDR certificates, bias-audit reports and logging-ledger access are the artifacts that make an outsourced workflow auditable.

Threat Profile

No elevated threat profile mapped.