Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 78 profiles
← Back
Transportation & Logistics

AI Freight Brokerage & Carrier Matching

Limited Risk (Transparency)UnverifiedDiscuss / dispute

AI that matches shippers with motor carriers, prices spot/contract freight, dispatches loads and scores carrier and owner-operator performance on behalf of a third-party freight brokerage or digital freight marketplace (not a carrier automating its own fleet).

Consensus classification rationale: An AI engine that matches shippers with carriers, prices freight and dispatches loads for compensation is acting as a property broker — the statutory definition (49 U.S.C. § 13102(2)) turns on arranging the transportation, not on how — so the operator needs FMCSA broker authority (49 U.S.C. §§ 13904, 14916(a)), a $75,000 BMC-84 surety bond or BMC-85 trust fund (49 CFR § 387.307) and Part 371 record-keeping, however automated the decision. Where the engine allocates loads to individual self-employed owner-operators who work in the EU based on their individual behaviour or characteristics, or monitors and evaluates their performance and behaviour, it profiles natural persons with a direct effect on their income: that is high-risk under AI Act Annex III point 4(b) (and the Art. 6(3) derogation is unavailable to a system that profiles), while assigning a load by lane, price or capacity alone is not caught; and a platform organising their work through automated systems is exposed to the Platform Work Directive's presumption of employment and algorithmic-management duties, due for transposition by 2 December 2026. Pick-up and delivery windows agreed in EU road-haulage contracts must respect the driving-time, break and rest rules, a duty Regulation (EC) No 561/2006 Art. 10(4) places on consignors, freight forwarders, principal contractors and subcontractors as well as on the carrier. GDPR governs the drivers', dispatchers' and shipper contacts' personal data where the controller is established in the EU or targets or monitors people there (Art. 3), and because the score decides an individual's access to work and pay, the recommended architecture includes an intrinsically interpretable scorer.
Decision attributes in force
Autonomyautonomous-with-overrideDrives the human-oversight duties (Art. 14, Art. 26(2)) and Art. 50 disclosure.
Profiling of natural personsyesFeeds the Art. 6(3) second-subparagraph override directly — profiling makes the derogation categorically unavailable.
Deployer typeprivate-enterpriseSelects between the recorded alternate classification readings.
Role in the value chainbothSplits provider duties, deployer duties and upstream GPAI duties.
Consequential scoringnoConsequential scoring of natural persons requires intrinsic interpretability, not post-hoc explanation only.
if dataSubjectType = natural-personHigh RiskAnnex III point 4(b) — an engine that allocates loads to individual self-employed drivers based on their individual behaviour or characteristics, or monitors and evaluates their performance and behaviour, is high-risk when those drivers work in the Union; scoring them is profiling of natural persons, so the Art. 6(3) derogation is unavailable.

Indicative decision support, not legal advice. Risk classification depends on your concrete deployment context and can change with scope drift — validate the result with qualified counsel.

Target market(s)European UnionUnited States (federal)change

Changes which instruments below count as in scope for this profile.

Target market(s)

Where will this system be used or placed on the market? The conclusion is derived for these jurisdictions — instruments that bind only elsewhere are left out.

Europe
North America
Latin America
Asia-Pacific
Middle East
Africa

Selected: European Union, United States (federal) · thin-coverage jurisdictions need verification

Target markets: European Union, United States (federal)

Regulatory footprint

5 instruments across 3 of 7 regulatory domains, plus 6 standards references
  • AI law1 instrument
  • Data protection1 instrument
  • Cyber & resiliencenone triggered
  • Online safety & platformsnone triggered
  • Product safetynone triggered
  • Financial servicesnone triggered
  • Sector & employment3 instruments
  • Standards6 references

By jurisdiction

  • EU4European UnionDriving Times, Breaks and Rest Periods — Regulation (EC) No 561/2006, EU AI Act, GDPR, Platform Work Directive (EU) 2024/2831
  • US1United States (federal)FMCSA Property Broker Licensing & Financial Responsibility

The AI Act is one dimension of this footprint, not the whole of it — every domain above carries its own obligations and deadlines. See the instruments in the graph →

Confidence in this chain of evidenceConfidence: Check-worthy

The chain holds, but at least one hop rests on a secondary source, an ageing verification or a practice-derived step. Check the flagged hops before you rely on them.

Computed weakest-link over 24 evaluated hops across 1 target market: a chain is only as strong as its weakest step, so the band follows the worst hop rather than an average that would hide it. Five factors per hop — source tier, verification age, status certainty, community hardening, derivation kind — all read from graph data, never from a hand-set score.

Why this band7 factors lowered the band — each links to the claim behind it
  • Source tier: Driving Times, Breaks and Rest Periods — Regulation (EC) No 561/2006 carries no resolvable citation — the claim is uncited. open node →
  • Source tier: JTC 21 Technical Package (prEN 18228/18229/18281–83) rests on a secondary source (tracker or summary), not on the primary text. open node → primary source →
  • Source tier: IEEE CertifAIEd™ carries no resolvable citation — the claim is uncited. open node →
  • Source tier: prEN 18229-1 (Trustworthiness Framework, part 1) rests on a secondary source (tracker or summary), not on the primary text. open node → primary source →
  • Status certainty: JTC 21 Technical Package (prEN 18228/18229/18281–83) is "draft", not settled in-force law. open node → primary source →
  • Status certainty: prEN 18229-1 (Trustworthiness Framework, part 1) is "enquiry", not settled in-force law. open node → primary source →
  • Verification age: IEEE CertifAIEd™ has no recorded verification date. open node →

Compliance brief

This use case is limited-risk under the EU AI Act (Limited Risk (Transparency)); transparency obligations apply.

What is owed

  • Art. 50. Disclose AI interaction to natural persons; machine-readable marking of synthetic content; deepfake labelling; emotion-recognition disclosure.
  • Art. 4. Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems.
  • GDPR Art. 22. Right not to be subject to solely automated decisions with legal/similar effect; requires meaningful human involvement or explicit legal basis + safeguards.
  • GDPR Art. 27. A controller or processor not established in the Union that falls within Art.
  • GDPR Art. 17. Right to erasure collides with AI Act Art.

Dates that bind

  • 2024-08-01 AI Act enters into force. Regulation (EU) 2024/1689 in force; countdown for all staged obligations starts.
  • 2025-02-02 Prohibitions + AI literacy. Art. 5 prohibited practices ban applies (manipulation, social scoring, untargeted face scraping, workplace emotion recognition); Art. 4 AI literacy duty.

Maximum exposure

  • FMCSA Property Broker Licensing & Financial Responsibility: Knowingly operating as a broker without registration under 49 U.S.C. § 13904 or the financial security required by § 13906 exposes the person to a civil penalty of up to $10,000 per violation under 49 U.S.C. § 14916(c)(1), adjusted for inflation to $13,676 per violation in 49 CFR Part 386 App. B(g)(2) (as published at retrieval, 2026-09-18), and to liability to the injured party for all valid claims incurred without regard to amount (§ 14916(c)(2)); the liability applies jointly and severally to any corporate entity or partnership involved and to its individual officers, directors and principals (§ 14916(d)). Where a claim payment or judgment takes the bond or trust fund below $75,000, the surety or financial institution must notify FMCSA (49 CFR § 387.307(e)(1)-(4)), and FMCSA gives the broker written notice that its operating authority will be suspended within 7 business days of service of the notice unless the broker provides written evidence that the notification was sent in error, that the bond or trust fund has been restored to $75,000, or that the pending claims were satisfied without using bond or trust-fund assets; if the broker does not respond within those 7 business days FMCSA enters the suspension (§ 387.307(e)(5)-(6)).
  • EU AI Act: Tiered: €35m / 7% (prohibited practices); €15m / 3% (Art. 9–15 high-risk obligations incl. data governance, documentation, logging); €7.5m / 1% (Art. 99(5) — incorrect, incomplete or misleading information to notified bodies or national competent authorities)
  • Platform Work Directive (EU) 2024/2831: Member States lay down effective, proportionate and dissuasive penalties (Art. 27); infringements of Arts 7–11 are also GDPR infringements where personal data is concerned (Art. 7(3)).
  • Driving Times, Breaks and Rest Periods: Member-State roadside/undertaking-level enforcement; penalties under national transposing law and EU cross-border infringement rules (Directive 2006/22/EC).
  • GDPR: Up to €20m or 4% of worldwide annual turnover

First five actions

  1. Confirm in writing whether this organisation builds/places the system on the market (provider) or only operates it (deployer), since the role is not yet established.
  2. Commission and confirm the Art. 50, Art. 4, GDPR Art. 22 obligations named above as active workstreams with an accountable owner.
  3. Design and document a human-oversight procedure appropriate to how this system is used.
  4. Produce the technical documentation and evidence artefacts already mapped to this use case (Synthetic-Content Labelling / Watermarking, Interface Transparency & Content-Marking Layer, HITL Escalation Queue & Review UI) before they are requested.
  5. Put 2024-08-01 — AI Act enters into force — into the compliance calendar with an owner and lead time.

Terms used above: · · ·

Classification precedent

Consensus reading: Limited Risk (Transparency) open in the graph →

An AI engine that matches shippers with carriers, prices freight and dispatches loads for compensation is acting as a property broker — the statutory definition (49 U.S.C. § 13102(2)) turns on arranging the transportation, not on how — so the operator needs FMCSA broker authority (49 U.S.C. §§ 13904, 14916(a)), a $75,000 BMC-84 surety bond or BMC-85 trust fund (49 CFR § 387.307) and Part 371 record-keeping, however automated the decision. Where the engine allocates loads to individual self-employed owner-operators who work in the EU based on their individual behaviour or characteristics, or monitors and evaluates their performance and behaviour, it profiles natural persons with a direct effect on their income: that is high-risk under AI Act Annex III point 4(b) (and the Art. 6(3) derogation is unavailable to a system that profiles), while assigning a load by lane, price or capacity alone is not caught; and a platform organising their work through automated systems is exposed to the Platform Work Directive's presumption of employment and algorithmic-management duties, due for transposition by 2 December 2026. Pick-up and delivery windows agreed in EU road-haulage contracts must respect the driving-time, break and rest rules, a duty Regulation (EC) No 561/2006 Art. 10(4) places on consignors, freight forwarders, principal contractors and subcontractors as well as on the carrier. GDPR governs the drivers', dispatchers' and shipper contacts' personal data where the controller is established in the EU or targets or monitors people there (Art. 3), and because the score decides an individual's access to work and pay, the recommended architecture includes an intrinsically interpretable scorer.

What the reading rests on — the provisions this classification actually pulls in:

No dissenting reading is recorded for this case. That means nobody has filed one yet — not that the classification is beyond argument. file a dissent with a source →

Baseline: of 100+, 40% were not definitively classifiable (18% clearly high-risk, 42% clearly low-risk). appliedAI Institute — AI Act risk classification of AI systems from a practical perspective

Applicable Regulations (5)

FMCSA Property Broker Licensing & Financial Responsibility (49 U.S.C. § 13904 (Registration of brokers); 49 U.S.C. § 14916 (Unlawful brokerage activities); 49 CFR Part 371 (Brokers of Property); 49 CFR § 387.307 (Property broker surety bond or trust fund))
in-force · verified 2026-09-21 source eCFR in force US
Federal regime under which a person who, for compensation, arranges transportation of property by motor carrier in interstate or foreign commerce (a 'broker', 49 U.S.C. § 13102(2)) may provide interstate brokerage services only if registered with FMCSA under § 13904 and financially secured under § 13906 (49 U.S.C. § 14916(a)). The financial security is a $75,000 BMC-84 surety bond or BMC-85 trust fund providing for payments to shippers or motor carriers if the broker fails to carry out its contracts, agreements or arrangements for supplying transportation (49 CFR § 387.307(a)); Part 371 adds a three-year record of each brokered transaction (§ 371.3) and requires a broker acting for a person bound by law or FMCSA regulation as to the transmittal of bills or payments to abide by the law that applies to that person (§ 371.10).
Sanctions: Knowingly operating as a broker without registration under 49 U.S.C. § 13904 or the financial security required by § 13906 exposes the person to a civil penalty of up to $10,000 per violation under 49 U.S.C. § 14916(c)(1), adjusted for inflation to $13,676 per violation in 49 CFR Part 386 App. B(g)(2) (as published at retrieval, 2026-09-18), and to liability to the injured party for all valid claims incurred without regard to amount (§ 14916(c)(2)); the liability applies jointly and severally to any corporate entity or partnership involved and to its individual officers, directors and principals (§ 14916(d)). Where a claim payment or judgment takes the bond or trust fund below $75,000, the surety or financial institution must notify FMCSA (49 CFR § 387.307(e)(1)-(4)), and FMCSA gives the broker written notice that its operating authority will be suspended within 7 business days of service of the notice unless the broker provides written evidence that the notification was sent in error, that the bond or trust fund has been restored to $75,000, or that the pending claims were satisfied without using bond or trust-fund assets; if the broker does not respond within those 7 business days FMCSA enters the suspension (§ 387.307(e)(5)-(6)).
EU AI Act (Regulation (EU) 2024/1689)
unverified · verified 2026-08-12 source (as amended) EUR-LexAmended by Regulation (EU) 2026/1744. Verified 16 Aug 2026: the popular mirrors have not yet been updated — artificialintelligenceact.eu still serves the unamended 13 June 2024 text with no disclaimer, and the Commission's AI Act Service Desk pages still show pre-omnibus text with a visible omnibus disclaimer. Read the OJ or consolidated text on EUR-Lex. in force EU
Horizontal, risk-based product-safety law for AI systems and GPAI models. Extraterritorial market-place principle. Staged applicability 2025–2030 (Digital Omnibus: Art. 50 → 2 Aug 2026, Annex III → 2 Dec 2027, Annex I → 2 Aug 2028). (Digital Omnibus: Regulation (EU) 2026/1744, in force 27 July 2026).
Sanctions: Tiered: €35m / 7% (prohibited practices); €15m / 3% (Art. 9–15 high-risk obligations incl. data governance, documentation, logging); €7.5m / 1% (Art. 99(5) — incorrect, incomplete or misleading information to notified bodies or national competent authorities)
Platform Work Directive (EU) 2024/2831 (Directive (EU) 2024/2831 of the European Parliament and of the Council of 23 October 2024 on improving working conditions in platform work)
enacted-not-yet-applicable · verified 2026-09-15 status source ↗ source EUR-Lex enacted — not yet applicable EU
Chapter III governs algorithmic management by digital labour platforms: Art. 7 limits the personal data automated monitoring and decision-making systems may process; Art. 9 requires transparency towards platform workers and their representatives on automated monitoring and decision-making systems; Art. 10 requires human oversight of the impact of such systems on working conditions; Art. 11 gives workers the right to an explanation and human review of significant decisions, including account restriction, suspension or termination. Member States must transpose by 2 December 2026 (Art. 29(1)) — until then the duties are upcoming, not binding.
Sanctions: Member States lay down effective, proportionate and dissuasive penalties (Art. 27); infringements of Arts 7–11 are also GDPR infringements where personal data is concerned (Art. 7(3)).
Driving Times, Breaks and Rest Periods — Regulation (EC) No 561/2006 (Regulation (EC) No 561/2006 on the harmonisation of certain social legislation relating to road transport)
in-force · verified 2026-09-18 in force EU
EU rules on drivers' daily/weekly driving time, breaks and rest periods for goods and passenger road transport; Art. 10(2) requires the transport undertaking to organise drivers' work so they can comply.
Sanctions: Member-State roadside/undertaking-level enforcement; penalties under national transposing law and EU cross-border infringement rules (Directive 2006/22/EC).
GDPR (Regulation (EU) 2016/679)
in-force · verified 2026-09-05 source EUR-Lex in force EU
Applies unchanged next to the AI Act for all personal data in training, fine-tuning, RAG and inference. Key friction points: Art. 22 automated decisions, Art. 17 erasure vs. AI Act logging, Art. 35 DPIA.
Sanctions: Up to €20m or 4% of worldwide annual turnover

Legal Obligations (12)

density
Art. 50 — Transparency Duties
Disclose AI interaction to natural persons; machine-readable marking of synthetic content; deepfake labelling; emotion-recognition disclosure.
in-force · verified 2026-08-16 source (as amended) EUR-Lexconvenience mirror — not updated artificialintelligenceact.euAmended by Regulation (EU) 2026/1744. Verified 16 Aug 2026: the popular mirrors have not yet been updated — artificialintelligenceact.eu still serves the unamended 13 June 2024 text with no disclaimer, and the Commission's AI Act Service Desk pages still show pre-omnibus text with a visible omnibus disclaimer. Read the OJ or consolidated text on EUR-Lex.
Art. 4 — AI Literacy
Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems. In force since 2 Feb 2025.
unverified · no verification date source (as amended) EUR-Lexconvenience mirror — not updated artificialintelligenceact.euAmended by Regulation (EU) 2026/1744. Verified 16 Aug 2026: the popular mirrors have not yet been updated — read the OJ or consolidated text on EUR-Lex.
GDPR Art. 22 — Automated Decisions
Right not to be subject to solely automated decisions with legal/similar effect; requires meaningful human involvement or explicit legal basis + safeguards.
unverified · no verification date read the article EUR-Lex
GDPR Art. 27 — EU Representative
A controller or processor not established in the Union that falls within Art. 3(2) scope (offering goods or services to, or monitoring the behaviour of, data subjects in the Union) must designate in writing a representative established in a Member State where the relevant data subjects are. The representative is mandated to be addressed by supervisory authorities and data subjects, in addition to or instead of the controller/processor, on all compliance issues — without prejudice to legal action against the controller/processor itself. Exempt: (a) occasional processing that does not involve large-scale special-category or criminal-conviction data and is unlikely to result in a risk to individuals, or (b) public authorities or bodies.
in-force · verified 2026-09-10 read the article EUR-Lex
GDPR Art. 17 — Erasure
Right to erasure collides with AI Act Art. 12 immutable logging — resolved architecturally via bitemporal data modelling + physical partition scrub.
unverified · no verification date read the article EUR-Lex
GDPR Art. 25 — Data Protection by Design
Privacy by design & default: minimisation, pseudonymisation, PII filters in pipelines and vector stores.
unverified · no verification date read the article EUR-Lex
GDPR Art. 35 — DPIA
Data-protection impact assessment for high-risk processing — pairs with AI Act fundamental-rights impact assessment (Art. 27) for public-facing high-risk systems.
unverified · no verification date read the article EUR-Lex
GDPR Art. 33/34 — Personal-Data Breach Notification
Notification of a personal-data breach to the supervisory authority and, where the risk to individuals is high, to the affected individuals themselves.
in-force · verified 2026-08-11 read the article EUR-Lex
GDPR Art. 32 — Security of Processing
Controller and processor implement technical and organisational measures appropriate to the risk, including pseudonymisation and encryption, and measures ensuring the ongoing confidentiality, integrity, availability and resilience of processing systems. Access to personal data by an unauthorised recipient — including one reached through a derived index such as a vector store — is the harm this article addresses.
in-force · verified 2026-08-17 read the article EUR-Lex
GDPR Art. 9 — Special Categories of Personal Data
Processing of health, biometric and other special-category data is prohibited unless one of the Art. 9(2) conditions applies; where it is permitted, the appropriate safeguards travel with it. This is the anchor for de-identification of clinical imaging and for the minimisation of health data in training and retrieval corpora.
in-force · verified 2026-08-17 read the article EUR-Lex
GDPR Art. 88 — Processing in the Employment Context
Opening clause: Member States may provide more specific rules for processing employees' personal data in the employment context, by law or by collective agreement, including suitable safeguards for human dignity, legitimate interests and fundamental rights, with particular regard to monitoring systems at the workplace. It is the bridge through which national employment rules — in Germany the BetrVG co-determination right and § 26 BDSG — govern workplace AI alongside the GDPR itself.
in-force · verified 2026-08-17 read the article EUR-Lex
Art. 25 — Value Chain / Role Flip
A deployer becomes the provider (full Art. 8–17 duties) by re-branding, changing intended purpose, or making a substantial modification — e.g. deep fine-tuning or wiring a model into autonomous agent toolchains.
unverified · no verification date read the article artificialintelligenceact.eu

Control Objectives (3)

obligation (article) → operationalized_by → control objective → satisfied_by → component/pattern; control objective → evidenced_by → evidence artifact
Art. 50
AI Interaction & Content Disclosure
Natural persons are informed they interact with an AI system, and generated/manipulated content carries both human-visible labels and machine-readable provenance (C2PA-class) that survives publication pipelines. Testable: disclosure presence across all interaction surfaces; watermark validity sampling post-publication; deepfake-path red-team (does stripped metadata get caught at the gate?).
evidenced by: Guardrail Telemetry & Sanitization Records
Art. 4
control layer: community mandate — propose objectives
GDPR Art. 22
control layer: community mandate — propose objectives
GDPR Art. 27
control layer: community mandate — propose objectives
GDPR Art. 17
control layer: community mandate — propose objectives
GDPR Art. 25
Vector & Chunk-Level Access Control
Practice-derived control objective (not named by any provision's own text): the requesting principal's read rights on every retrieved source segment are enforced before generation. Token- or claim-based ACL filtering is applied twice — at the chunker, which writes the source ACL into chunk metadata at ingestion, and at query time in the vector store, which filters candidates by the caller's entitlements — and a response-grounding check re-validates the caller's rights on each cited segment BEFORE the answer is composed. Testable: retrieval probe with a low-privilege principal against a restricted corpus; ACL drift reconciliation between source system and index; red-team reconstruction attempt from similarity results alone.
ISO/IEC 42001 clause A.7 (indicative)
evidenced by: Vector ACL Verification Report
GDPR Art. 35
control layer: community mandate — propose objectives
GDPR Art. 33/34
control layer: community mandate — propose objectives
GDPR Art. 32
Vector & Chunk-Level Access Control
Practice-derived control objective (not named by any provision's own text): the requesting principal's read rights on every retrieved source segment are enforced before generation. Token- or claim-based ACL filtering is applied twice — at the chunker, which writes the source ACL into chunk metadata at ingestion, and at query time in the vector store, which filters candidates by the caller's entitlements — and a response-grounding check re-validates the caller's rights on each cited segment BEFORE the answer is composed. Testable: retrieval probe with a low-privilege principal against a restricted corpus; ACL drift reconciliation between source system and index; red-team reconstruction attempt from similarity results alone.
ISO/IEC 42001 clause A.7 (indicative)
evidenced by: Vector ACL Verification Report
GDPR Art. 9
control layer: community mandate — propose objectives
GDPR Art. 88
control layer: community mandate — propose objectives
Art. 25
control layer: community mandate — propose objectives
Take this into your GRC tooling
A control mapping your ISO/IEC 42001 or CSA AICM workbook can ingest, and an Annex IV skeleton to start the technical file from. Indicative mappings only — cells we are not confident about are exported empty rather than filled in.

Standards & Evidence

C2PA Content Credentials
Open technical standard for cryptographically signed content provenance: manifests binding origin, toolchain and edit history to media assets. The de-facto machine-readable implementation path for Art. 50 synthetic-content marking (machine-readable format + detectability duty) — visible labels satisfy the human side, C2PA manifests the machine side. Verification at publication gates produces the disclosure evidence stream.
published · verified 2026-08-17 status unsourced publisher c2pa.org
evidence for: Art. 50
ISO/IEC 42005 (AI Impact Assessment)
Guidance for AI system impact assessments — supports DPIA/FRIA-style analyses.
unverified · no verification date publisher ISO
evidence for: GDPR Art. 35
ISO/IEC 27001:2022 + A.8.28
Information-security management; control A.8.28 (secure coding) is the natural anchor for AI code-generation and QA workflows alongside ISO 42001.
unverified · no verification date publisher ISO
evidence for: GDPR Art. 32
JTC 21 Technical Package (prEN 18228/18229/18281–83)
CEN-CENELEC JTC 21 technical package under standardisation request M/593 (prEN 18228 trustworthiness, 18229 risk management, 18281–83 CV/NLP evaluation et al.); staged drafts, none OJEU-cited yet — Annex III applicability (Dec 2027) is Omnibus-coupled to their availability.
draft · verified 2026-08-17 status unsourced publisher cencenelec.eu
evidence for: EU AI Act
IEEE CertifAIEd™
Ethics certification (transparency, accountability, algorithmic bias, privacy) for products and professionals; interfaces with the EU ALTAI assessment list.
unverified · no verification date
evidence for: EU AI Act
prEN 18229-1 (Trustworthiness Framework, part 1)
Part 1 of the JTC 21 trustworthiness deliverable — the framework layer other prEN 18xxx documents build on.
enquiry · verified 2026-08-11 status unsourced publisher kla.digital
evidence for: EU AI Act

Evidence you will need (11)

The concrete deliverables this use case's obligations ask for — grouped by what kind of artifact they are. Documentation is the largest single conformity cost block, so the list is a work plan, not a reading list. Full evidence matrix →

Documents & files (1)

Written deliverables an authority or auditor can request as a file.

Instructions for Use / Transparency Docstext-derivedserves 2 obligations
Art. 13 deployer-facing documentation: intended purpose, capabilities, limitations, expected accuracy, oversight measures — plus Art. 50 user-facing disclosures.
verifiability: documented artefact — verifiable on inspection
chain: Art. 13 — Transparency to Deployers · Art. 50 — Transparency Duties · Generative Asset Production & Virtual Try-On · Omnichannel Virtual Support & Voice Bots

Assessments (3)

A structured judgement about risk, rights or a management system.

FRIA / AI Impact Assessment (AIIA)text-derivedserves 3 obligations
Fundamental-rights impact assessment (Art. 27, deployer-side) generalized to the AI Impact Assessment: societal, legal and operational risk evaluation per ISO/IEC 42005 and ISO 42001 Clause 8.2, defining HITL intervention parameters and acceptable-use bounds. Cadence: pre-deployment, refreshed annually and on major model updates — a stale AIIA is a finding, not a document.
verifiability: documented artefact — verifiable on inspection
chain: Art. 26 — Deployer Obligations · Art. 27 — Fundamental Rights Impact Assessment · EU AI Act · Clinical Imaging Triage & Patient Follow-Up
Data Protection Impact Assessment (DPIA)text-derivedserves 2 obligations
GDPR Art. 35 assessment for high-risk processing; supervisory-authority consultation where residual risk stays high. ISO/IEC 42005 provides the AI-specific method.
verifiability: documented artefact — verifiable on inspection
chain: § 26 Abs. 1 S. 1 — Erforderlichkeit für Begründung, Durchführung, Beendigung · GDPR Art. 35 — DPIA
Third-Party AI Data & ZDR Certificatepractice-derived — dispute welcome
Binding vendor terms on zero data retention, non-training use, sub-processor list and security boundary, with technical verification records.
verifiability: independently-attested
chain: Art. 25 — Value Chain / Role Flip · Generative Asset Production & Virtual Try-On

Test reports (1)

Measured results from testing, evaluation or red-teaming.

Vector ACL Verification Reportpractice-derived — dispute welcome
Practice-derived artifact: the measured result of probing the retrieval path with low-privilege principals, the ACL reconciliation between source repositories and the index, and the outcome of the response-grounding rights re-check. Records which corpora were probed, which principals were used and every segment that was returned without an entitlement.
verifiability: self-asserted
chain: GDPR Art. 32 — Security of Processing → CO: Vector & Chunk-Level Access Control

Log records (2)

Machine-generated records produced while the system runs.

Event Logs & Decision Tracestext-derivedserves 17 obligations
The single highest-leverage artifact: hash-chained, WORM-stored logs with structured decision traces. Required capability fields per FprEN ISO/IEC 24970: input/output traces, execution timestamps, acting user/agent identity, referenced sources, human overrides. Audit-packet spec per event: model version, system-prompt/context hash, hyper-parameters (temperature, top-p), output payload, confidence score, active policy-ruleset versions, human override record. Simultaneously serves AI Act Art. 12, GDPR accountability, DORA incident reporting, NIS2 logging, PLD disclosure duties and its rebuttable defect presumption; financial-sector regimes push retention to 7 years (SEC 17a-4-class WORM rules). Credibility bar: anchor hash-chain heads externally (qualified timestamp / eIDAS ledger) so integrity survives an insider with admin rights.
verifiability: externally-anchored
chain: Art. 12 — Record-Keeping / Logging · CRA Art. 14 — Vulnerability & Severe-Incident Reporting · DORA Art. 19 — Major ICT-Incident Reporting · GDPR Art. 33/34 — Personal-Data Breach Notification · HIPAA Breach Notification Rule · NIS2 Art. 23 — Significant-Incident Reporting · +21 more
Guardrail Telemetry & Sanitization Recordspractice-derived — dispute welcomeserves 3 obligations
Control-level evidence for the OWASP mappings: guardrail trigger records, blocked-prompt statistics (LLM01), runtime output-sanitization logs (LLM05), groundedness-check outcomes — the empirical proof that declared controls actually execute.
verifiability: tamper-evident
chain: Art. 15 — Accuracy, Robustness, Cybersecurity · Art. 50 — Transparency Duties → CO: AI Interaction & Content Disclosure · Art. 15 — Accuracy, Robustness, Cybersecurity → CO: Runtime Injection Defense · Dynamic Deal Desk & Quoting Engine · Enterprise Marketing Disclosure Compliance · LLM01 Prompt Injection · +3 more

Process records (4)

Traces that a process actually happened, and who did it.

Human-Oversight Protocol & Intervention Recordspractice-derived — dispute welcomeserves 5 obligations
Art. 14 evidence: documented oversight design (gates, thresholds, veto powers), reviewer qualification, and the record of actual approvals, overrides and escalations — also the GDPR Art. 22 meaningful-human-involvement proof.
verifiability: documented artefact — verifiable on inspection
chain: Art. 11 — automated individual decision-making · Art. 14 — Human Oversight · GDPR Art. 22 — Automated Decisions · Art. 12 — Record-Keeping / Logging → CO: Log Access & Retention Governance · Art. 14 — Human Oversight → CO: Oversight Competence & Authority · Clinical Imaging Triage & Patient Follow-Up
Individual Explanation Letters & Counterfactual Recordspractice-derived — dispute welcomeserves 5 obligations
Practice-derived artifact: the issued adverse-decision explanations together with the attribution run, model version and counterfactual scenario that each letter rested on, so an authority or a court can check that the stated reasons are the reasons the system actually used.
verifiability: self-asserted
chain: Art. 11 — automated individual decision-making · Art. 18 — Obligation to assess the creditworthiness of the consumer · Art. 21 — examination of an application · Art. 86 — Right to explanation of individual decision-making · GDPR Art. 22 — Automated Decisions
AI Literacy Training Recordspractice-derived — dispute welcomeserves 2 obligations
Art. 4 evidence: role-based training curricula and completion records for staff dealing with AI systems — the one obligation that applies at every risk level.
verifiability: documented artefact — verifiable on inspection
chain: Art. 4 — AI Literacy · Art. 14 — Human Oversight → CO: Oversight Competence & Authority
Personal-Data Breach Notification Recordtext-derivedserves 2 obligations
The GDPR Art. 33(5) record of every personal-data breach: facts, effects, remedial action, plus the notification sent to the supervisory authority and, where required, the data subjects.
verifiability: tamper-evident
chain: GDPR Art. 33/34 — Personal-Data Breach Notification · HIPAA Breach Notification Rule

Architecture Blueprint

Intent Policy Router with Confidence-Thresholded HITL Queue
Requests are classified into intent classes with explicit policy per class; anything below the calibrated confidence threshold, or in a class marked consequential, is routed to a human queue with its context attached instead of being answered.
Deterministic Circuit Breaker with Reversible Shadow Execution
Deterministic, non-model-mediated thresholds trip the agent out of autonomy (rate, blast radius, error budget, anomaly count), and every consequential action is first executed in shadow against a reversible transaction envelope so the effect can be inspected and rolled back before it becomes real.
Transparent Multi-Metric Scorecard with Dispute Workflow
Scores are decomposed into named, separately reported metrics with their weights published to the scored person, and a dispute workflow lets that person contest an input, trigger re-computation and receive a reasoned answer within a recorded deadline. The dispute record is retained as evidence.
Glass-Box EBM with Monotonic Constraints
Intrinsically interpretable scoring: an explainable boosting machine / generalised additive model whose per-feature shape functions ARE the model, exported as exact lookup tables so an adverse-action reason is read off the model rather than approximated after the fact. Monotonicity is enforced per feature at fit time — higher utilisation can never improve a score — which makes the direction of every reason contractual instead of empirical, and makes a remediation instruction ('reduce utilisation') actually true of the model. Interaction terms are capped and enumerated so the score decomposition sums exactly.

Required Technical Components (24)

Synthetic-Content Labelling / Watermarking
Synthetic-content labelling & watermarking: visible disclosure plus machine-readable provenance (C2PA Content Credentials) embedded in generated images, audio and video; metadata identifying artificial origin survives common transformations. Discharges Art. 50(2)/(4) for deepfakes and synthetic media; verification telemetry (watermark presence/validity checks at publication gates) is the corresponding evidence stream.
from: Art. 50
Interface Transparency & Content-Marking Layer
The disclosure surface at the engagement layer: an AI-interaction notice on every channel a natural person can reach (web, app, voice, chat, social, marketplace), machine-readable provenance marking on generated or manipulated output, and a disclosure record per interaction that can be produced on request. Sits at the interface, not in the model — a model-side label that the frontend drops is not a disclosure.
from: Art. 50
HITL Escalation Queue & Review UI
HITL escalation queue & review UI ('Human-as-a-Tool': the agent calls the human like any other tool via propose-action objects). Confidence- and risk-threshold routing, SLA timers, structured accept/modify/reject verdicts with digital reviewer signature at gate release — each verdict is itself Art. 14 evidence and feeds the active-learning loop.
from: GDPR Art. 22 · Intent Policy Router with Confidence-Thresholded HITL Queue · Transparent Multi-Metric Scorecard with Dispute Workflow
Adverse-Decision Reason Generator
Practice-derived component: converts feature attributions (SHAP or an equivalent attribution method) into an individually understandable, legally defensible explanation of an adverse decision — the role the AI system played, the main elements the decision rested on, and counterfactual scenarios stating what would have had to differ for a different outcome. Reason codes are generated from the decisioning path, not from a marketing template, and every issued letter is retained with the model version and the attribution run behind it. Honesty condition: a reason is only usable if acting on it would actually change the outcome, which non-monotonic feature interactions can break (see the post-hoc instability threat).
from: GDPR Art. 22 · Glass-Box EBM with Monotonic Constraints
Bitemporal Memory (GDPR×Art.12)
valid_from/valid_to + transaction time on every record: GDPR erasure removes data from the active retrieval path while the HMAC-chained immutable log survives for Art. 12 / PLD defence; tenant-scoped partitions allow physical scrub of PII.
from: GDPR Art. 17
PII Scrubbing / DLP-NER Layer
Automated detection, pseudonymisation and blocking of personal data in inputs, retrievals and outputs.
from: GDPR Art. 25
Per-Tenant Retrieval Segmentation
Retrieval is scoped by tenant and by caller entitlement at query time, preventing cross-client and cross-role leakage through shared indexes.
from: GDPR Art. 25
Segmented Vector Store (RBAC + CMEK)
Vector indexes, embeddings and document stores are logically and physically partitioned per client, with role-based access and customer-managed encryption keys.
from: GDPR Art. 25 · GDPR Art. 32
PII/PHI Redaction & Tokenisation Engine
The engine behind inline tokenisation: pre-model interception that replaces identifiers with reversible tokens before a payload leaves the isolation boundary, plus a detokenisation gate that re-identifies only for authorised callers inside the boundary and logs every re-identification. Complements the DLP/NER scrubbing layer, which blocks or masks rather than preserving reversible reference.
from: GDPR Art. 25
DICOM De-Identification Pipeline
Practice-derived component: removal and replacement of identifying attributes in imaging studies before they leave the clinical system — header attributes per the DICOM confidentiality profiles, burned-in pixel text detected and masked, private tags dropped rather than trusted, and a consistent pseudonym per patient so longitudinal studies stay linkable without re-identifying anyone. Re-identification risk on the de-identified corpus is measured, not assumed.
from: GDPR Art. 25 · GDPR Art. 9
Live Risk Register / Posture Management
Continuously updated risk register wired to runtime posture: threat-model deltas, open defects, control status, exposure per system. Includes Shadow-AI discovery — continuous scanning for unsanctioned agents, MCP servers and AI API usage outside the register; an unregistered agent is an unmanaged Art. 12/26 liability and the empirical driver of proportionate (not blanket) controls.
from: GDPR Art. 35
Unified Incident-Response Runbook
One procedure reconciling AI Act Art. 73, GDPR Art. 33 (72h), DORA and NIS2 (24h/72h) timelines and recipients.
from: GDPR Art. 33/34
Retrieval Rails (ACL-aware RAG)
Relevance, freshness and per-user permission checks on every retrieved chunk; curated, versioned index.
from: GDPR Art. 32
Zero-Data-Retention Vendor Binding
Sensitive inference is contractually and technically restricted to endpoints under zero-data-retention and non-training terms, evidenced per vendor and re-validated annually.
from: Art. 25
Agent Discovery & Registry Endpoint
The marketplace/discovery API through which external agents find, authenticate against and transact with your agents: published capability descriptors, counterparty authentication, per-counterparty rate and value limits, and a resolvable record of which external principal initiated which transaction. Without it, business-to-agent traffic is anonymous inbound automation.
from: Art. 25
Confidence Scoring & Threshold Gate
Computes a probabilistic confidence score for every output and holds the transaction when the score falls below the workflow's regulatory threshold.
from: Intent Policy Router with Confidence-Thresholded HITL Queue
Deterministic Policy Engine (OPA / Cedar)
Policy-as-code decision point (PDP) with enforcement points (PEP) in front of every tool call: versioned policies in Git, microsecond evaluation, typed action schemas — authorization decided outside the model's reasoning space, never in the prompt.
from: Intent Policy Router with Confidence-Thresholded HITL Queue
Kill Switch / Graceful Degradation
Operator stop controls and degraded-mode fallbacks; real-time override (veto) channels for HOTL operation.
from: Deterministic Circuit Breaker with Reversible Shadow Execution
Multi-Region Failover & Resilience Testing
DORA-grade continuity: regional redundancy, chaos testing, exit strategies for critical third parties.
from: Deterministic Circuit Breaker with Reversible Shadow Execution
OpenTelemetry / FCoT Tracing
Hierarchical trace spans for every sub-task, prompt, retrieved document and API call — the reconstructible decision path for Art. 12/14 and PLD disclosure.
from: Deterministic Circuit Breaker with Reversible Shadow Execution
Explainability API (SHAP/LIME/CoT)
Feature attributions for classical ML, reasoning-trace summaries for GenAI — feeds the human reviewer and the technical file.
from: Transparent Multi-Metric Scorecard with Dispute Workflow · Glass-Box EBM with Monotonic Constraints
WORM / Immutable Audit Vault
Append-only, hash-chained audit vault (WORM object-lock storage, AES-256 at rest, TLS 1.3 in transit). Guarantees tamper-evidence within the organization's trust domain — which stops your own team, but not an admin who can rebuild the vault. Pair with an external trust anchor and key ceremonies outside the operating team for evidence that holds against the insider scenario.
from: Transparent Multi-Metric Scorecard with Dispute Workflow · Glass-Box EBM with Monotonic Constraints
Bias Testing & Data Quality Pipeline
Representativeness checks, bias metrics and mitigation per ISO/IEC 5259; versioned datasets with lineage.
from: Transparent Multi-Metric Scorecard with Dispute Workflow · Glass-Box EBM with Monotonic Constraints
Data Lineage & Versioning
Provenance tracking of datasets, features and embeddings; write-time attribution (source, actor, timestamp, confidence).
from: Glass-Box EBM with Monotonic Constraints

Build or Buy — Vendor Layer (13)

The graph models vendor CATEGORIES as first-class nodes and keeps named vendors as community-maintained, disputable desc content with lastVerified dates. A category is stable; a vendor list is a currency-layer object like any standard node.
Regulated Foundation-Model Platforms
Frontier commercial APIs and open-weight models under enterprise controls: zero-data-retention tiers, data isolation, fine-tuning governance, safety alignment documentation, EU-sovereign options. Named products live in marketExamples, where the deployment model is recorded in the hosting field rather than asserted in prose. What the class buys you: a model supply relationship with contractual data handling and documentation you can pass to a customer. GPAI-chapter duties and provider due diligence attach at this layer. Selection metrics: see meta.marketLandscape.selectionMetrics.models.
unverified · verified 2026-08-18 community-maintained
selection metrics: ZDR enterprise tiers, data isolation, EU-sovereign options, fine-tuning controls, safety alignment documentation
supplies: Synthetic-Content Labelling / Watermarking
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
OpenAI (Enterprise / API)proprietary frontierEnterprise tiers offer zero-data-retention and no-training commitments over the commercial API. Typical: general copilots, document reasoning.not checkedSOC 2 (claimed)ISO 27001 (claimed)zero-data-retention tier (claimed)GDPR-positioned
Anthropic Claude (Enterprise)proprietary frontierEnterprise/ZDR tiers with published safety and model documentation practice. Typical: regulated assistants, long-context analysis.not checkedSOC 2 (claimed)ISO 27001 (claimed)zero-data-retention tier (claimed)HIPAA-eligible (claimed)
Google Gemini Enterpriseproprietary frontierVertex-hosted frontier models with regional grounding and customer-managed keys. Typical: enterprise search, multimodal workflows.not checkedSOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed)EU data-boundary positioning
Cohereproprietary frontierPrivate-cloud and on-prem deployment of retrieval-oriented models. Typical: private RAG, enterprise search.self-hostableSOC 2 (claimed)

and 7 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Runtime Security & Guardrail Vendors
First-line inline enforcement: single-pass parallel input/output evaluation proxies, injection and exfiltration defense, PII masking, grounding checks, SecOps routing. Named products live in marketExamples; prose here describes the class. What the class buys you: a policy decision point in the request path that fails closed and emits telemetry an auditor can read. Selection metrics: single-pass latency (<20 ms class), catch rates, policy-version telemetry into the AI-BOM. Consolidation matters commercially: a guardrail acquired by a platform vendor tends to follow that platform's roadmap, which is a lock-in question rather than a security one — reported acquisitions are recorded per entry as reported, not asserted here.
unverified · verified 2026-08-18 community-maintained
selection metrics: single-pass parallel evaluation latency (<20 ms class), injection/hallucination catch rates, SecOps/SIEM routing, policy versioning surfaced into the AI-BOM
supplies: Interface Transparency & Content-Marking Layer · Output Rails / Groundedness Check
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Lakeraguardrail proxyInline prompt-injection and content detection at request time. Typical: injection defence, content filtering.not checkedSOC 2 (claimed)supports Art. 15 robustness measures (claimed)
HiddenLayermodel/agent detection & responseModel-layer detection and response with adversarial-attack telemetry. Typical: model threat detection, red-team telemetry.not checkedSOC 2 (claimed)supports Art. 15 robustness measures (claimed)
Palo Alto Prisma AIRSnetwork-integrated AI securityAI runtime security folded into an existing enterprise network security estate. Typical: enterprise rollout, egress control.not checkedSOC 2 (claimed)enterprise security integration (claimed)
Cisco AI Defensenetwork-integrated AI securityDiscovery of AI usage plus inline enforcement across the corporate network. Typical: shadow-AI discovery, inline enforcement.not checkedenterprise security integration (claimed)

and 4 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Public Transparency Registers & System Cards
Authoring and publishing the outward-facing record: public AI registers, system and model cards, conformity declarations and plain-language notices, with versioning so a published statement can be tied to the system version it described. The register content is produced elsewhere; this class is the publication and version-control surface for it. Selection metrics: see meta.marketLandscape.selectionMetrics.transparency.
unverified · verified 2026-08-17 community-maintained
selection metrics: Versioning of published statements against the system version they describe; whether a card is generated from your governance record or re-authored by hand; language coverage and accessibility of the published surface; export and self-hosting of the public register; whether unpublishing leaves an auditable trail.
supplies: Interface Transparency & Content-Marking Layer
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Saidotpublic AI registerAI register with published system cards and regulation-mapped documentation workflows. Typical: public AI register, system cards. Scope overlap: Its documentation and register scope overlaps this platform's own; we have a commercial interest in the comparison.SaaS (vendor cloud)EU AI Act documentation positioningISO 42001 alignment (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Agent Orchestration & SDLC Toolkits
Developer middleware for multi-agent networks, tool-use chains, RAG abstraction, state and memory persistence, and model routing. Named products live in marketExamples; prose here describes the class. Regulatory posture: orchestration code is where autonomy tiering, propose-action objects and fallback routing get implemented — the framework choice constrains which controls are cheap and which are retrofits. Selection metrics: see meta.marketLandscape.selectionMetrics.orchestration.
unverified · verified 2026-08-18 community-maintained
selection metrics: broad model-API abstraction, state/memory management, error recovery, fallback routing hooks
supplies: HITL Escalation Queue & Review UI
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
LangChain / LangGraphagent frameworkGraph-structured agent runtime; interrupt/pause nodes support implementing human approval at defined steps. Typical: multi-step agents, approval workflows.not checkedsupports implementing Art. 14 oversight (claimed)supports Art. 12 step logging (claimed)
LlamaIndexRAG frameworkIndexing and query abstractions over documents and structured sources. Typical: enterprise RAG, document agents.open sourceretrieval-governance positioning
Microsoft AutoGenmulti-agent frameworkConversational multi-agent patterns with pluggable tool executors. Typical: multi-agent research, code agents.not checkedresearch/OSS, no vendor certification
CrewAImulti-agent frameworkRole-based agent teams with task delegation and process templates. Typical: process automation, role-based agents.not checkedvendor-stated security posture

and 6 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Agent Observability & Model Risk Management
Tracing, evaluation, drift monitoring and model-validation records. This layer is where Art. 12 record-keeping becomes technically real (step-level traces, prompt/response records, retention control) and where model-risk practice in the SR 11-7 tradition — validation evidence, performance and drift monitoring, challenger comparison — is operated. Gateways and tracing tools produce the logs; the retention, integrity and access regime around them is still yours.
unverified · verified 2026-08-18 community-maintained
selection metrics: Trace completeness per agent step; log retention and immutability options; drift/quality metrics available out of the box; evaluation dataset support; export into your audit vault; self-host option.
supplies: Adverse-Decision Reason Generator · Confidence Scoring & Threshold Gate · OpenTelemetry / FCoT Tracing · Explainability API (SHAP/LIME/CoT) · Bias Testing & Data Quality Pipeline
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
LangSmithagent tracing & evaluationTrace capture and evaluation over LangChain/LangGraph runs with dataset-based scoring. Typical: step tracing, regression evaluation.not checkedSOC 2 (claimed)supports Art. 12 record-keeping (claimed)
Langfuseagent tracing & evaluationOpen-source tracing, prompt management and evaluation; self-hostable for retention control. Typical: self-hosted tracing, cost/latency analytics.open sourceGDPR-positionedsupports Art. 12 record-keeping (claimed)
Arize AI / PhoenixML & LLM observabilityProduction monitoring with drift and performance analysis; Phoenix is the open-source tracing side. Typical: drift monitoring, production analytics.not checkedSOC 2 (claimed)drift-monitoring positioning (SR 11-7 style, claimed)
HeliconeLLM gateway & loggingProxy-level logging of prompts, costs and latency across providers. Typical: gateway logging, cost control.not checkedSOC 2 (claimed)supports Art. 12 record-keeping (claimed)

and 11 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

AI GRC & Governance Platforms
Second-line systems of record: model/agent inventory incl. third-party SaaS AI, automated risk tiering, policy administration, cross-framework mapping and control deduplication, audit-evidence generation, intake workflows. Named products live in marketExamples, which is the single source of truth for this layer — prose here describes the class, not the field. What the class buys you: one register a second line can defend, and evidence assembled once and reused across frameworks. Selection metrics: see meta.marketLandscape.selectionMetrics.grc. One compilation-reported item is deliberately kept as unverified: a claimed updated US banking model-risk guidance 'SR 26-2'. Two secondary compilations repeating it is corroboration of the rumour, not of the guidance; it stays flagged pending verification against Federal Reserve primary sources, and a curator verification proposal is filed. All alignments in this layer are vendor-positioned claims, never certifications.
unverified · verified 2026-08-18 community-maintained
selection metrics: multi-model/multi-cloud cataloging incl. third-party SaaS, automated risk tiering, regulatory reporting, independent-2nd-line deployability, cross-framework control deduplication
supplies: Adverse-Decision Reason Generator · Live Risk Register / Posture Management
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Credo AIAI governance platformPolicy packs, risk tiering and evidence workflows mapped across frameworks. Typical: AI registry, policy administration. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedISO 42001 alignment (claimed)EU AI Act readiness positioning
Holistic AIAI governance & auditRisk assessment, bias auditing and regulatory reporting workflows. Typical: bias audit, regulatory reporting. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedNYC LL144 audit support (claimed)EU AI Act readiness positioning
IBM watsonx.governanceAI governance platformGovernance, factsheets and monitoring integrated with the IBM stack. Typical: factsheets, model monitoring. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedISO 42001 alignment (claimed)Art. 11 documentation support (claimed)
ModelOpAI/model governanceModel and agent inventory with automated lifecycle controls for large estates. Typical: model inventory, control automation. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedmodel-risk positioning (SR 11-7 style, claimed)ISO 42001 alignment (claimed)

and 3 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Grounding, Retrieval & Agent Memory
The grounding layer between raw sources and the model: document parsers, embedding models, vector databases and — new in the agentic era — persistent agent memory stores. Memory is the hard part: once a personal fact is embedded, GDPR Art. 17 erasure has to reach the vector and the memory record, not just the source row, and embeddings are partially reconstructable (see IronCore in the privacy layer). Retrieval quality is also a data-governance question under Art. 10: what got parsed, chunked and indexed is what the system 'knows'.
unverified · verified 2026-08-18 community-maintained
selection metrics: Parsing fidelity on your worst document class; retrieval precision/recall on a labelled set; tenant and ACL isolation model; per-vector encryption and erasure path; memory TTL and record semantics; self-host option.
supplies: Bitemporal Memory (GDPR×Art.12) · Per-Tenant Retrieval Segmentation · Segmented Vector Store (RBAC + CMEK) · Retrieval Rails (ACL-aware RAG) · Data Lineage & Versioning
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Doclingdocument parserOpen-source layout-aware parsing of PDFs and office formats into structured chunks. Typical: RAG ingestion, air-gapped pipelines.self-hostableEU sovereignty positioning
LlamaParsedocument parserManaged parsing service tuned for tables and complex documents feeding RAG. Typical: RAG ingestion, table extraction.not checkedSOC 2 (claimed)
Amazon Textractdocument parserOCR and form/table extraction with per-page pricing inside AWS. Typical: document intake, claims processing.not checkedSOC 2 (claimed)HIPAA-eligible (claimed)ISO 27001 (claimed)
Diffbotweb/knowledge extractionStructured extraction and knowledge-graph construction from web sources. Typical: market monitoring, entity resolution.not checkedvendor-stated security posture

and 12 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Confidential Computing & Privacy Engines
Data-in-use protection and pre-model privacy interception: enclave and runtime encryption, key management, tokenisation vaults, PII detection and redaction, application-layer and vector encryption. Named products live in marketExamples; prose here describes the class. Select on: enclave attestation support, key custody model (external HSM / BYOK), detokenisation audit trail, latency added per call, and coverage of the identifier classes your regime actually names. Selection metrics: see meta.marketLandscape.selectionMetrics.privacy.
unverified · verified 2026-08-18 community-maintained
selection metrics: enclave attestation support, key custody (external HSM / BYOK), detokenisation audit trail, added latency per call, coverage of the identifier classes your regime names, in-boundary deployment option
supplies: PII/PHI Redaction & Tokenisation Engine · DICOM De-Identification Pipeline
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Anjunaconfidential computingRuns workloads inside hardware enclaves without application rewrites. Typical: data-in-use protection, regulated inference.not checkedconfidential-computing positioningDORA-positioned (claimed)
Fortanixconfidential computing & KMSEnclave runtime plus key management and tokenisation services. Typical: key management, data-in-use protection.not checkedFIPS 140-2 (claimed)DORA-positioned (claimed)HIPAA-positioned (claimed)
Skyflowprivacy vaultPolymorphic data vault de-identifying records before they reach a model. Typical: PII vaulting, pre-model redaction.not checkedSOC 2 (claimed)HIPAA-positionedGDPR-positioned
Private AIPII detection & redactionDetection and redaction of identifiers across text, documents and audio. Typical: inline redaction, document de-identification.not checkedGDPR-positionedHIPAA-positioned

and 1 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Secure Data Infrastructure & Vector Storage
Governed retrieval substrate: vector databases, lakehouses and catalogs with tenant/namespace isolation, RBAC and client-managed keys (CMEK), lineage into RAG chunks, air-gap options, and code-level data and AI lineage. Named products live in marketExamples; prose here describes the class. What the class buys you: retrieval that can be scoped per requester and traced back to a source record. The Art. 10 runtime data-governance duties land here. Selection metrics: see meta.marketLandscape.selectionMetrics.data.
unverified · verified 2026-08-18 community-maintained
selection metrics: namespace/tenant isolation, RBAC + CMEK, lineage into RAG chunks, SOC 2 / ISO 27001 attestations, air-gap capability
supplies: Retrieval Rails (ACL-aware RAG) · Data Lineage & Versioning
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Azure AI Searchmanaged retrievalManaged hybrid search with security trimming against tenant identities. Typical: ACL-aware RAG, enterprise search.not checkedISO 27001 (claimed)SOC 2 (claimed)
Databricks Unity Cataloggoverned lakehouseCatalog and lineage spanning tables, features and RAG chunks. Typical: lineage evidence, governed RAG.not checkedSOC 2 (claimed)lineage/Art. 10 support (claimed)
Relyance AIcode-level data & AI lineageParses source repositories to map data and inference flows at code level, with CI checks on changes to those flows. Typical: data lineage, shift-left privacy review. Scope overlap: Its AI-governance reporting scope overlaps this platform's own; we have a commercial interest in the comparison.SaaS (vendor cloud)GDPR programme tooling (claimed)EU AI Act readiness positioning
Snowflake Cortexgoverned lakehouseModel calls inside the warehouse boundary with masking and clean rooms. Typical: in-warehouse inference, governed analytics.not checkedSOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Agentic Execution Governance
The youngest tier: governance of what an agent is allowed to do at execution time — non-human identity, per-task scoping, action approval, agent inventory and agent-level red-teaming. Named products live in marketExamples; prose here describes the class. Because the category is new, capability claims outrun deployments: ask for a reference in your own regime before believing a control is covered, and treat entries with limited public verification as unconfirmed. Selection metrics: see meta.marketLandscape.selectionMetrics.agentgov.
unverified · verified 2026-08-18 community-maintained
selection metrics: non-human identity inventory completeness, credential time-to-live and revocation latency, per-action approval hooks, agent-level red-team coverage, evidence export a 2nd line can read, deployment references in your regime
supplies: Agent Discovery & Registry Endpoint
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Pillar Securityagent security & inventoryDiscovery, inventory and runtime policy for agents in the estate. Typical: agent registry, policy enforcement.not checkedagent-inventory positioning
Lyzragent governance & observabilityAgent platform with governance, approval and observability features. Typical: agent approval, agent analytics.not checkedvendor-stated security posture
Astrix Securitynon-human identityLifecycle governance of machine and agent identities and their grants. Typical: credential scoping, NHI inventory.not checkedSOC 2 (claimed)NHI governance positioning
Britivejust-in-time accessEphemeral, per-task privileges instead of standing credentials. Typical: JIT credentials, privilege reduction.not checkedSOC 2 (claimed)least-privilege positioning

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Runtime Guardrails & Enforcement
Policy enforcement in the request path: input/output validation, injection and exfiltration defence, structured-output constraints and action blocking. Distinct from observability layers because these products are in-line and can refuse. Selection questions: added latency at p95, whether enforcement is fail-open or fail-closed, whether policies are versioned artefacts, and whether the layer can be self-hosted inside your data boundary.
unverified · verified 2026-08-18 community-maintained
selection metrics: Where enforcement sits (inline proxy, sidecar, SDK) and the added latency at your token volumes; whether policy is versioned and testable as code; fail-open vs. fail-closed behaviour under guardrail outage; language and modality coverage; whether every block writes an evidence record you can cite later.
supplies: Deterministic Policy Engine (OPA / Cedar) · Output Rails / Groundedness Check
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Guardrails AIvalidation frameworkOpen-source validator framework for structured output and content policies in the request path. Typical: output validation, structured output.open sourcesupports Art. 15 robustness measures (claimed)
NVIDIA NeMo Guardrailsdialogue policy railsProgrammable dialogue and topic rails placed around an LLM application. Typical: topic control, dialogue policy.open sourcesupports Art. 50 interaction disclosure patterns (claimed)
Lakera AIguardrail proxyInline prompt-injection and content detection at request time. Typical: injection defence, content filtering.SaaS (vendor cloud)SOC 2 (claimed)supports Art. 15 robustness measures (claimed)
Credal AIenterprise access & policy layerPermission-aware access layer with data-loss controls in front of enterprise assistants. Typical: access control, DLP.SaaS (vendor cloud)SOC 2 (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Sovereign Infrastructure
Compute and storage under EU jurisdictional control. Two structurally different offers, and the difference is the decision: native EU providers give full jurisdictional isolation with narrower service catalogs and thinner managed-AI tooling; hyperscaler sovereign constructions give the broad catalog with contractual and operational isolation, where the residual question is the control plane, support access and operational metadata rather than the data plane. Named offers live in marketExamples, which is the single source of truth for this layer — prose here describes the class, not the field. Claimed alignments recorded per entry: positioning for BSI C5 / C3A and ANSSI SecNumCloud attestation, NIS2 and DORA third-party requirements. Nothing here is an endorsement, and no provider in this category is 'CLOUD-Act-proof' by label alone — ask who holds the keys and who administers the plane.
unverified · verified 2026-08-18 community-maintained
selection metrics: jurisdiction of the control plane (not only the data plane), operator nationality and support-access paths, key custody, C5 / C3A / SecNumCloud attestation scope, managed-AI service depth vs. isolation trade-off, exit and repatriation terms
supplies: Multi-Region Failover & Resilience Testing
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
OVHcloudnative EUFrench provider with EU-only jurisdiction and a narrower managed-AI catalog than the hyperscalers. Typical: EU-resident inference, regulated workload hosting.not checkedISO 27001 (claimed)SecNumCloud-positionedGDPR-positioned
Scalewaynative EUEU-operated cloud with GPU instances and managed inference under French corporate control. Typical: EU-resident inference, fine-tuning.not checkedISO 27001 (claimed)GDPR-positioned
STACKITnative EUGerman provider (Schwarz Group) positioned for data residency in Germany. Typical: public sector, retail data platforms.not checkedC5-positionedGDPR-positioned
AWS European Sovereign Cloudsovereign hyperscalerSeparately operated EU region set with EU-resident personnel and keys; full hyperscaler catalog. Typical: large-scale enterprise AI, regulated hosting.not checkedISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning

and 11 more in the stack advisor →

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Cryptographic Evidence & Audit Ledger
Tamper-evident recording of what a system did: content-addressed decision records, hash chains and external anchoring, so a log can be shown not to have been rewritten after the fact. This is the layer that turns Art. 12 logging and Art. 19 retention from a storage question into an evidentiary one. AI Verify is carried in RAIN as a STANDARD node (sg-ai-verify), not duplicated here as a vendor.
unverified · verified 2026-08-18 community-maintained
selection metrics: Append-only guarantees and who can rotate or delete (including the vendor); anchoring mechanism (qualified timestamp, transparency log, notarisation) and whether verification works without the vendor; retention and export in a readable format at end of contract; throughput and cost at your event volume.
supplies: WORM / Immutable Audit Vault
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Fact0cryptographic evidence ledgerPositions itself as a tamper-evident ledger for AI decision records. Typical: decision records, audit trail.not checkedsupports Art. 12 record-keeping (claimed)
Tracciaaudit trail & traceabilityPositions itself around traceability of AI pipeline steps and artefacts. Typical: traceability, artifact lineage.not checkedsupports Art. 12 record-keeping (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Procurement rule: Derived from three-lines-of-defense separation: the second-line GRC platform must be procured and deployed independently of any first-line runtime or model vendor — a governance tool that only sees its own vendor's models cannot govern a multi-model estate, and closed third-party SaaS AI can only be governed contractually (intake, attestation, AI-BOM disclosure), never by inline inspection.
Outsourced delivery BPO · SaaS · Service-as-a-Software caveats

Delivery Model — BPO · SaaS · Service-as-a-Software

Spectrum
BPO: input-priced (billable hours/FTEs), linear headcount scaling, human error & attrition as primary risk
SaaS: capability-priced (software access), client operates the workload, implementation/adoption failure as primary risk
Service-as-a-Software: outcome-priced (SLA on completed work), provider-managed AI executes 60–80% of cognitive tasks with specialist supervision, algorithmic bias & non-compliance as primary risk
Caveats in regulated markets
Outcome SLAs move compliance risk onto the provider — but NOT the buyer's deployer duties: Art. 26 oversight, log retention and FRIA obligations stay with the enterprise even when execution is outsourced.
Provider role analysis is the central legal question: a productized platform that fine-tunes, re-purposes or chains models can flip into the Art. 25 provider role with full high-risk obligations.
Certified operations (ISO 42001) function as a procurement moat and shortcut third-party risk assessment — but organizational certificate ≠ product conformity (never conflate, see meta.assuranceEcosystem).
The buyer's evidence chain must reach into the provider: contractually mandated AI-BOM disclosure, ZDR certificates, bias-audit reports and logging-ledger access are the artifacts that make an outsourced workflow auditable.

Threat Profile

LLM06 Excessive Agency
Over-broad rights/functions of autonomous agents lead to uncontrolled actions.
mitigate with: MCP Gateway / Proxy, Agentic Zero Trust, Per-Action Autonomy Tiering, Trinity Defense (TCB + Command Gates + IFC), Deterministic Policy Engine (OPA / Cedar), Guardian Agents (Runtime Policy Enforcement), Non-Human Identity Credential Broker, Tool-Use Boundary Proxy