Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 78 profiles
← Back
Cross-Industry (AI/ML Infrastructure)

General-Purpose AI Model Training & API Provisioning

Minimal RiskUnverifiedDiscuss / dispute

An organisation trains, pretrains or substantially fine-tunes a general-purpose language/foundation model and places it on the market itself, typically offering programmatic API access to business customers who build their own products on top of it; the model generates text (and possibly other modalities) directly from prompts rather than performing a narrow, pre-defined task.

Consensus classification rationale: Minimal risk at the AI-system tier — a bare model-plus-API is not itself one of the Annex III contexts, and the Art. 50(1) direct-interaction disclosure duty falls on whichever downstream deployer builds an end-user-facing product on top, not on the API provider. But AI Act Chapter V (Arts 51-56) is a separate, model-keyed regime: Art. 53(1) binds every provider of a general-purpose AI model regardless of that AI-system risk tier, including the technical-documentation, downstream-information, copyright-policy and public training-content-summary duties. Training a model on third-party text/code scraped or licensed from the open web engages the DSM Directive's TDM regime (Arts 3-4) for the dataset-construction step, and Art. 53(1)(c) makes the provider responsible for identifying and honouring any rightholder's Art. 4(3) machine-readable reservation — see reg-dsm-copyright/dsm-4, including the current dispute over whether the training step itself (as opposed to dataset construction) is covered by the TDM exception at all. This node is the provider-role counterpart to uc-codegen, uc-procure-agent, uc-svc-creative, uc-marketing and uc-legalresearch, all of which consume a third party's GPAI model downstream and therefore do NOT carry Art. 53 obligations themselves (see roleDutyNote/gpaiUpstream in reason.ts).
This profile is incomplete:no technical components derived. That is a gap in the graph, not a statement that nothing applies — propose the missing links →
Decision attributes in force
Autonomyautonomous-with-overrideDrives the human-oversight duties (Art. 14, Art. 26(2)) and Art. 50 disclosure.
Profiling of natural personsnoFeeds the Art. 6(3) second-subparagraph override directly — profiling makes the derogation categorically unavailable.
Affected subjectsnoneInstruments scoped to natural persons drop out of scope when only legal entities are assessed.
Deployer typeprivate-enterpriseSelects between the recorded alternate classification readings.
Role in the value chainproviderSplits provider duties, deployer duties and upstream GPAI duties.

Indicative decision support, not legal advice. Risk classification depends on your concrete deployment context and can change with scope drift — validate the result with qualified counsel.

Target market(s)European UnionUnited States (federal)change

Changes which instruments below count as in scope for this profile.

Target market(s)

Where will this system be used or placed on the market? The conclusion is derived for these jurisdictions — instruments that bind only elsewhere are left out.

Europe
North America
Latin America
Asia-Pacific
Middle East
Africa

Selected: European Union, United States (federal) · thin-coverage jurisdictions need verification

Target markets: European Union, United States (federal)

Regulatory footprint

2 instruments across 2 of 7 regulatory domains, plus 3 standards references
  • AI law1 instrument
  • Data protectionnone triggered
  • Cyber & resiliencenone triggered
  • Online safety & platformsnone triggered
  • Product safetynone triggered
  • Financial servicesnone triggered
  • Sector & employment1 instrument
  • Standards3 references

By jurisdiction

  • EU2European UnionEU AI Act, EU DSM Copyright Directive (TDM, Arts 3–4)

The AI Act is one dimension of this footprint, not the whole of it — every domain above carries its own obligations and deadlines. See the instruments in the graph →

Confidence in this chain of evidenceConfidence: Check-worthy

The chain holds, but at least one hop rests on a secondary source, an ageing verification or a practice-derived step. Check the flagged hops before you rely on them.

Computed weakest-link over 7 evaluated hops across 1 target market: a chain is only as strong as its weakest step, so the band follows the worst hop rather than an average that would hide it. Five factors per hop — source tier, verification age, status certainty, community hardening, derivation kind — all read from graph data, never from a hand-set score.

Why this band6 factors lowered the band — each links to the claim behind it
  • Source tier: JTC 21 Technical Package (prEN 18228/18229/18281–83) rests on a secondary source (tracker or summary), not on the primary text. open node → primary source →
  • Source tier: IEEE CertifAIEd™ carries no resolvable citation — the claim is uncited. open node →
  • Source tier: prEN 18229-1 (Trustworthiness Framework, part 1) rests on a secondary source (tracker or summary), not on the primary text. open node → primary source →
  • Status certainty: JTC 21 Technical Package (prEN 18228/18229/18281–83) is "draft", not settled in-force law. open node → primary source →
  • Status certainty: prEN 18229-1 (Trustworthiness Framework, part 1) is "enquiry", not settled in-force law. open node → primary source →
  • Verification age: IEEE CertifAIEd™ has no recorded verification date. open node →

Compliance brief

This use case is minimal-risk under the EU AI Act (Minimal Risk); no product-specific obligations beyond general AI literacy apply.

What is owed

  • Art. 4. Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems.

Dates that bind

  • 2024-08-01 AI Act enters into force. Regulation (EU) 2024/1689 in force; countdown for all staged obligations starts.
  • 2025-02-02 Prohibitions + AI literacy. Art. 5 prohibited practices ban applies (manipulation, social scoring, untargeted face scraping, workplace emotion recognition); Art. 4 AI literacy duty.

Maximum exposure

  • EU AI Act: Tiered: €35m / 7% (prohibited practices); €15m / 3% (Art. 9–15 high-risk obligations incl. data governance, documentation, logging); €7.5m / 1% (Art. 99(5) — incorrect, incomplete or misleading information to notified bodies or national competent authorities)
  • EU DSM Copyright Directive (TDM, Arts 3–4): The Directive contains no penalty provision of its own (the text has no 'penalty' or 'sanction' clause): a reproduction or extraction not covered by the Art. 3 / Art. 4 exceptions, e.g. mining online content whose use the rightholder has expressly reserved under Art. 4(3), remains an act restricted by the rights the Directive refers to (Art. 2 of Directive 2001/29/EC, Arts 5(a) and 7(1) of Directive 96/9/EC, Art. 4(1)(a)-(b) of Directive 2009/24/EC, Art. 15(1) DSM) and is enforced through the Member States' national copyright remedies, while Art. 7(1) makes contractual provisions contrary to Art. 3 unenforceable.

First five actions

  1. Confirm in writing whether this organisation builds/places the system on the market (provider) or only operates it (deployer), since the role is not yet established.
  2. Commission and confirm the Art. 4 obligations named above as active workstreams with an accountable owner.
  3. Design and document a human-oversight procedure appropriate to how this system is used.
  4. Produce the technical documentation and evidence artefacts that a regulator or auditor would expect to see.
  5. Put 2024-08-01 — AI Act enters into force — into the compliance calendar with an owner and lead time.

Terms used above: · · ·

This brief is based on partial coverage — no technical components have been derived yet.

Classification precedent

Consensus reading: Minimal Risk open in the graph →

Minimal risk at the AI-system tier — a bare model-plus-API is not itself one of the Annex III contexts, and the Art. 50(1) direct-interaction disclosure duty falls on whichever downstream deployer builds an end-user-facing product on top, not on the API provider. But AI Act Chapter V (Arts 51-56) is a separate, model-keyed regime: Art. 53(1) binds every provider of a general-purpose AI model regardless of that AI-system risk tier, including the technical-documentation, downstream-information, copyright-policy and public training-content-summary duties. Training a model on third-party text/code scraped or licensed from the open web engages the DSM Directive's TDM regime (Arts 3-4) for the dataset-construction step, and Art. 53(1)(c) makes the provider responsible for identifying and honouring any rightholder's Art. 4(3) machine-readable reservation — see reg-dsm-copyright/dsm-4, including the current dispute over whether the training step itself (as opposed to dataset construction) is covered by the TDM exception at all. This node is the provider-role counterpart to uc-codegen, uc-procure-agent, uc-svc-creative, uc-marketing and uc-legalresearch, all of which consume a third party's GPAI model downstream and therefore do NOT carry Art. 53 obligations themselves (see roleDutyNote/gpaiUpstream in reason.ts).

What the reading rests on — the provisions this classification actually pulls in:

No dissenting reading is recorded for this case. That means nobody has filed one yet — not that the classification is beyond argument. file a dissent with a source →

Baseline: of 100+, 40% were not definitively classifiable (18% clearly high-risk, 42% clearly low-risk). appliedAI Institute — AI Act risk classification of AI systems from a practical perspective

Applicable Regulations (2)

EU AI Act (Regulation (EU) 2024/1689)
unverified · verified 2026-08-12 source (as amended) EUR-LexAmended by Regulation (EU) 2026/1744. Verified 16 Aug 2026: the popular mirrors have not yet been updated — artificialintelligenceact.eu still serves the unamended 13 June 2024 text with no disclaimer, and the Commission's AI Act Service Desk pages still show pre-omnibus text with a visible omnibus disclaimer. Read the OJ or consolidated text on EUR-Lex. in force EU
Horizontal, risk-based product-safety law for AI systems and GPAI models. Extraterritorial market-place principle. Staged applicability 2025–2030 (Digital Omnibus: Art. 50 → 2 Aug 2026, Annex III → 2 Dec 2027, Annex I → 2 Aug 2028). (Digital Omnibus: Regulation (EU) 2026/1744, in force 27 July 2026).
Sanctions: Tiered: €35m / 7% (prohibited practices); €15m / 3% (Art. 9–15 high-risk obligations incl. data governance, documentation, logging); €7.5m / 1% (Art. 99(5) — incorrect, incomplete or misleading information to notified bodies or national competent authorities)
EU DSM Copyright Directive (TDM, Arts 3–4) (Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market and amending Directives 96/9/EC and 2001/29/EC (Text with EEA relevance))
in-force · verified 2026-09-06 source EUR-Lex in force EU
Directive (EU) 2019/790 harmonises EU copyright for digital and cross-border uses and, in Articles 3 and 4, creates mandatory exceptions allowing reproductions and extractions of lawfully accessible works for text and data mining (any automated analytical technique generating information such as patterns, trends and correlations, Art. 2(2)) by research organisations and cultural heritage institutions for scientific research (Art. 3) and by anyone for any purpose (Art. 4). The Art. 4 exception applies only where rightholders have not expressly reserved the use, for online content by machine-readable means (Art. 4(3)), so an operator that trains, fine-tunes or indexes AI models on third-party text, images or code must have lawful access to that content and honour opt-outs or obtain licences. The EU AI Act (Art. 53(1)(c)) turns compliance with those Art. 4(3) reservations into an obligation for every provider of a general-purpose AI model.
Sanctions: The Directive contains no penalty provision of its own (the text has no 'penalty' or 'sanction' clause): a reproduction or extraction not covered by the Art. 3 / Art. 4 exceptions, e.g. mining online content whose use the rightholder has expressly reserved under Art. 4(3), remains an act restricted by the rights the Directive refers to (Art. 2 of Directive 2001/29/EC, Arts 5(a) and 7(1) of Directive 96/9/EC, Art. 4(1)(a)-(b) of Directive 2009/24/EC, Art. 15(1) DSM) and is enforced through the Member States' national copyright remedies, while Art. 7(1) makes contractual provisions contrary to Art. 3 unenforceable.

Legal Obligations (1)

density
Art. 4 — AI Literacy
Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems. In force since 2 Feb 2025.
unverified · no verification date source (as amended) EUR-Lexconvenience mirror — not updated artificialintelligenceact.euAmended by Regulation (EU) 2026/1744. Verified 16 Aug 2026: the popular mirrors have not yet been updated — read the OJ or consolidated text on EUR-Lex.

Control Objectives (0)

obligation (article) → operationalized_by → control objective → satisfied_by → component/pattern; control objective → evidenced_by → evidence artifact
Art. 4
control layer: community mandate — propose objectives
Take this into your GRC tooling
A control mapping your ISO/IEC 42001 or CSA AICM workbook can ingest, and an Annex IV skeleton to start the technical file from. Indicative mappings only — cells we are not confident about are exported empty rather than filled in.

Standards & Evidence

JTC 21 Technical Package (prEN 18228/18229/18281–83)
CEN-CENELEC JTC 21 technical package under standardisation request M/593 (prEN 18228 trustworthiness, 18229 risk management, 18281–83 CV/NLP evaluation et al.); staged drafts, none OJEU-cited yet — Annex III applicability (Dec 2027) is Omnibus-coupled to their availability.
draft · verified 2026-08-17 status unsourced publisher cencenelec.eu
evidence for: EU AI Act
IEEE CertifAIEd™
Ethics certification (transparency, accountability, algorithmic bias, privacy) for products and professionals; interfaces with the EU ALTAI assessment list.
unverified · no verification date
evidence for: EU AI Act
prEN 18229-1 (Trustworthiness Framework, part 1)
Part 1 of the JTC 21 trustworthiness deliverable — the framework layer other prEN 18xxx documents build on.
enquiry · verified 2026-08-11 status unsourced publisher kla.digital
evidence for: EU AI Act

Evidence you will need (4)

The concrete deliverables this use case's obligations ask for — grouped by what kind of artifact they are. Documentation is the largest single conformity cost block, so the list is a work plan, not a reading list. Full evidence matrix →

Assessments (1)

A structured judgement about risk, rights or a management system.

FRIA / AI Impact Assessment (AIIA)text-derivedserves 3 obligations
Fundamental-rights impact assessment (Art. 27, deployer-side) generalized to the AI Impact Assessment: societal, legal and operational risk evaluation per ISO/IEC 42005 and ISO 42001 Clause 8.2, defining HITL intervention parameters and acceptable-use bounds. Cadence: pre-deployment, refreshed annually and on major model updates — a stale AIIA is a finding, not a document.
verifiability: documented artefact — verifiable on inspection
chain: Art. 26 — Deployer Obligations · Art. 27 — Fundamental Rights Impact Assessment · EU AI Act · Clinical Imaging Triage & Patient Follow-Up

Test reports (1)

Measured results from testing, evaluation or red-teaming.

Accuracy, Robustness & Red-Teaming Reportspractice-derived — dispute welcomeserves 2 obligations
Art. 15 evidence: declared accuracy metrics, adversarial and corruption robustness results (DIN SPEC 92001-2, ISO 24029), penetration and jailbreak-resistance testing, groundedness evaluation scores.
verifiability: independently-attested
chain: Art. 15 — Accuracy, Robustness, Cybersecurity · Art. 15 — Accuracy, Robustness, Cybersecurity → CO: Adversarial Robustness Verified · Enterprise SDLC Code Automation & QA · LLM01 Prompt Injection

Log records (1)

Machine-generated records produced while the system runs.

Guardrail Telemetry & Sanitization Recordspractice-derived — dispute welcomeserves 3 obligations
Control-level evidence for the OWASP mappings: guardrail trigger records, blocked-prompt statistics (LLM01), runtime output-sanitization logs (LLM05), groundedness-check outcomes — the empirical proof that declared controls actually execute.
verifiability: tamper-evident
chain: Art. 15 — Accuracy, Robustness, Cybersecurity · Art. 50 — Transparency Duties → CO: AI Interaction & Content Disclosure · Art. 15 — Accuracy, Robustness, Cybersecurity → CO: Runtime Injection Defense · Dynamic Deal Desk & Quoting Engine · Enterprise Marketing Disclosure Compliance · LLM01 Prompt Injection · +3 more

Process records (1)

Traces that a process actually happened, and who did it.

AI Literacy Training Recordspractice-derived — dispute welcomeserves 2 obligations
Art. 4 evidence: role-based training curricula and completion records for staff dealing with AI systems — the one obligation that applies at every risk level.
verifiability: documented artefact — verifiable on inspection
chain: Art. 4 — AI Literacy · Art. 14 — Human Oversight → CO: Oversight Competence & Authority

Architecture Blueprint

Required Technical Components (0)

Delivery Stack & Pipeline Stage (1)

Service-as-a-Software delivery: the engines, patterns and artifacts this workflow needs on top of the generic obligations. See the full pipeline
Data Lineage & Versioning
Provenance tracking of datasets, features and embeddings; write-time attribution (source, actor, timestamp, confidence).

Threat Profile

LLM01 Prompt Injection
Direct or indirect (RAG/files/web) instructions override system prompts — the primary attack vector on the perception layer.
mitigate with: Input Rails / Prompt Shields, Guardrail Sidecar / Interception, Trinity Defense (TCB + Command Gates + IFC), Divided-Focus Memory Tiering, Dual-Gate Validation Pipeline
LLM02 Sensitive Info Disclosure
Leakage of PII, trade secrets or system prompts in outputs.
mitigate with: PII Scrubbing / DLP-NER Layer, Output Rails / Groundedness Check, PII/PHI Redaction & Tokenisation Engine
LLM09 Misinformation
Hallucinated or wrong outputs create liability and decision risk.
mitigate with: Output Rails / Groundedness Check, Explainability API (SHAP/LIME/CoT)