Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles
← Back
Industry & Energy

Visual Quality Inspection (Manufacturing)

Minimal RiskUnverifiedDiscuss / dispute

Computer-vision defect detection on production lines.

Classification rationale: Minimal risk unless it becomes a safety function under the Machinery Regulation (then Annex I high-risk); DIN SPEC 92001-2 robustness evidence either way.
Evaluate risk & value →Open in graph
This profile is incomplete: no threats modelled. That is a gap in the graph, not a statement that nothing applies — propose the missing links →

Indicative decision support, not legal advice. Risk classification depends on your concrete deployment context and can change with scope drift — validate the result with qualified counsel.

Compliance brief

This use case is minimal-risk under the EU AI Act (Minimal Risk); no product-specific obligations beyond general AI literacy apply.

What is owed

  • Art. 4. Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems.

Dates that bind

  • 2026-08-02General applicability + Art. 50. Transparency obligations for chatbots, deepfakes and synthetic content; EU-level enforcement begins.
  • 2026-12-02Additional prohibitions. Additional bans (deepfake CSAM et al.) and transition period for synthetic content under Art. 50(2).

Maximum exposure

  • Cyber Resilience Act: Up to €15m or 2.5% of worldwide annual turnover

First five actions

  1. Confirm in writing whether this organisation builds/places the system on the market (provider) or only operates it (deployer), since the role is not yet established.
  2. Commission and confirm the Art. 4 obligations named above as active workstreams with an accountable owner.
  3. Stand up the named oversight design — Mode 3 — with a documented human-review procedure.
  4. Produce the technical documentation and evidence artefacts already mapped to this use case (SBOM & Dependency Management, Secure Boot & Hardened Runtime, Kill Switch / Graceful Degradation) before they are requested.
  5. Put 2026-08-02 — General applicability + Art. 50 — into the compliance calendar with an owner and lead time.

Terms used above: · · ·

This brief is based on partial coverage — no threat profile is mapped yet.

Applicable Regulations (3)

Machinery Regulation (Regulation (EU) 2023/1230)
unverified · no verification date source EUR-Lex
Safety requirements for machinery incl. AI-driven safety functions; Annex I gateway into AI Act high-risk for embedded systems.
Cyber Resilience Act (Regulation (EU) 2024/2847)
unverified · no verification date source EUR-Lex
Security-by-design for products with digital elements over the full lifecycle: vulnerability management, patching, SBOM. Complements AI Act Art. 15 at product level.
Sanctions: Up to €15m or 2.5% of worldwide annual turnover
General Product Safety Regulation (Regulation (EU) 2023/988)
unverified · no verification date source EUR-Lex
Residual product-safety net for consumer products not covered by sector law.

Legal Obligations (1)

Art. 4 — AI Literacy
Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems. In force since 2 Feb 2025.
unverified · no verification date read the article artificialintelligenceact.eu

Control Objectives (0)

obligation (article) → operationalized_by → control objective → satisfied_by → component/pattern; control objective → evidenced_by → evidence artifact
Art. 4
control layer: community mandate — propose objectives
Take this into your GRC tooling
A control mapping your ISO/IEC 42001 or CSA AICM workbook can ingest, and an Annex IV skeleton to start the technical file from. Indicative mappings only — cells we are not confident about are exported empty rather than filled in.

Standards & Evidence

ENISA Multilayer Framework & AI Threat Landscape
Three-layer good-practice model (cyber foundations → AI-specific → sectoral) and lifecycle threat landscape — the operational base for Art. 15 and CRA.
unverified · no verification date
evidence for: Cyber Resilience Act
NIST SP 800-218 (SSDF)
Secure Software Development Framework: practices for provenance, review and vulnerability handling of generated and third-party code; SSDF-AI companion covers AI-assisted development.
unverified · no verification date
evidence for: Cyber Resilience Act
ISO/IEC 27001:2022 + A.8.28
Information-security management; control A.8.28 (secure coding) is the natural anchor for AI code-generation and QA workflows alongside ISO 42001.
unverified · no verification date publisher ISO
evidence for: Cyber Resilience Act

Architecture Blueprint

Hardened Edge / IoT Pattern
For critical-infrastructure and industrial AI: robustness hardening against corruption/covariate shift (DIN SPEC 92001-2), secure boot, SBOM management, physical kill switch, NIS2 incident telemetry.
Mode 3 — Human-on-the-Loop
Autonomous execution with aggregate oversight: dashboards, sampling audits (5–10%), real-time veto. For high-volume, low-individual-impact steps.

Required Technical Components (4)

SBOM & Dependency Management
Software bill of materials incl. model weights and datasets; automated vulnerability patching pipeline.
from: Cyber Resilience Act · Hardened Edge / IoT Pattern
Secure Boot & Hardened Runtime
Verified boot chain and hardened runtimes for edge/IoT deployments per CRA security-by-design.
from: Cyber Resilience Act · Hardened Edge / IoT Pattern
Kill Switch / Graceful Degradation
Operator stop controls and degraded-mode fallbacks; real-time override (veto) channels for HOTL operation.
from: Hardened Edge / IoT Pattern
Unified Incident-Response Runbook
One procedure reconciling AI Act Art. 73, GDPR Art. 33 (72h), DORA and NIS2 (24h/72h) timelines and recipients.
from: Hardened Edge / IoT Pattern

Threat Profile

No elevated threat profile mapped.