Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles
← Back
Telecom & Media

Omnichannel Virtual Support & Voice Bots

Limited Risk (Transparency)UnverifiedDiscuss / dispute

Conversational agents handling account, billing, activation and troubleshooting requests across voice, chat, email and social, grounded in enterprise knowledge bases.

Classification rationale: Art. 50(1): a person interacting with the system must know it is AI, in every channel including voice. Add TCPA/FCC consent and identification rules for US outbound automation, and GDPR duties for transcripts and sentiment data. Escalation to a human must be reachable, not theoretical — impersonation and unsafe guidance are the dominant liabilities.
Evaluate risk & value →Open in graph

Indicative decision support, not legal advice. Risk classification depends on your concrete deployment context and can change with scope drift — validate the result with qualified counsel.

pricingOutcome-based per fully resolved issue (typically $0.99–$1.50)
oversightConfidence-threshold escalation to a human representative with synthesised context

Compliance brief

This use case is limited-risk under the EU AI Act (Limited Risk (Transparency)); transparency obligations apply.

What is owed

  • Art. 50. Disclose AI interaction to natural persons; machine-readable marking of synthetic content; deepfake labelling; emotion-recognition disclosure.
  • Art. 4. Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems.
  • GDPR Art. 22. Right not to be subject to solely automated decisions with legal/similar effect; requires meaningful human involvement or explicit legal basis + safeguards.
  • GDPR Art. 17. Right to erasure collides with AI Act Art.
  • GDPR Art. 25. Privacy by design & default: minimisation, pseudonymisation, PII filters in pipelines and vector stores.

Dates that bind

  • 2026-08-02General applicability + Art. 50. Transparency obligations for chatbots, deepfakes and synthetic content; EU-level enforcement begins.
  • 2026-12-02Additional prohibitions. Additional bans (deepfake CSAM et al.) and transition period for synthetic content under Art. 50(2).

Maximum exposure

  • EU AI Act: Tiered: €35m / 7% (prohibited practices); €15m / 3% (Art. 9–15 high-risk obligations incl. data governance, documentation, logging); €7.5m / 1% (Art. 99(5) — incorrect, incomplete or misleading information to notified bodies or national competent authorities)
  • GDPR: Up to €20m or 4% of worldwide annual turnover
  • TCPA / FCC AI-Voice Rules (US): Statutory damages of USD 500–1,500 per call/message, aggregated in class actions.

First five actions

  1. Confirm in writing whether this organisation builds/places the system on the market (provider) or only operates it (deployer), since the role is not yet established.
  2. Commission and confirm the Art. 50, Art. 4, GDPR Art. 22 obligations named above as active workstreams with an accountable owner.
  3. Stand up the named oversight design — Mode 3 — with a documented human-review procedure.
  4. Produce the technical documentation and evidence artefacts already mapped to this use case (Synthetic-Content Labelling / Watermarking, HITL Escalation Queue & Review UI, Bitemporal Memory (GDPR×Art.12)) before they are requested.
  5. Put 2026-08-02 — General applicability + Art. 50 — into the compliance calendar with an owner and lead time.

Terms used above: · · ·

Applicable Regulations (4)

EU AI Act (Regulation (EU) 2024/1689)
unverified · no verification date source EUR-Lex
Horizontal, risk-based product-safety law for AI systems and GPAI models. Extraterritorial market-place principle. Staged applicability 2025–2030 (Digital Omnibus: Annex III → 2 Dec 2027, Annex I → 2 Aug 2028).
Sanctions: Tiered: €35m / 7% (prohibited practices); €15m / 3% (Art. 9–15 high-risk obligations incl. data governance, documentation, logging); €7.5m / 1% (Art. 99(5) — incorrect, incomplete or misleading information to notified bodies or national competent authorities)
GDPR (Regulation (EU) 2016/679)
unverified · no verification date source EUR-Lex
Applies unchanged next to the AI Act for all personal data in training, fine-tuning, RAG and inference. Key friction points: Art. 22 automated decisions, Art. 17 erasure vs. AI Act logging, Art. 35 DPIA.
Sanctions: Up to €20m or 4% of worldwide annual turnover
ePrivacy Directive (Directive 2002/58/EC)
unverified · no verification date source EUR-Lex
Confidentiality of communications, cookies/tracking — relevant for conversational interfaces and communications data.
TCPA / FCC AI-Voice Rules (US) (47 U.S.C. §227)
unverified · no verification date source Cornell LII
Governs automated calls and texts: AI-generated voices are 'artificial' under the TCPA, requiring prior express consent, identification and opt-out on every outbound automated channel.
Sanctions: Statutory damages of USD 500–1,500 per call/message, aggregated in class actions.

Legal Obligations (6)

Art. 50 — Transparency Duties
Disclose AI interaction to natural persons; machine-readable marking of synthetic content; deepfake labelling; emotion-recognition disclosure.
unverified · no verification date read the article artificialintelligenceact.eu
Art. 4 — AI Literacy
Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems. In force since 2 Feb 2025.
unverified · no verification date read the article artificialintelligenceact.eu
GDPR Art. 22 — Automated Decisions
Right not to be subject to solely automated decisions with legal/similar effect; requires meaningful human involvement or explicit legal basis + safeguards.
unverified · no verification date read the article EUR-Lex
GDPR Art. 17 — Erasure
Right to erasure collides with AI Act Art. 12 immutable logging — resolved architecturally via bitemporal data modelling + physical partition scrub.
unverified · no verification date read the article EUR-Lex
GDPR Art. 25 — Data Protection by Design
Privacy by design & default: minimisation, pseudonymisation, PII filters in pipelines and vector stores.
unverified · no verification date read the article EUR-Lex
GDPR Art. 35 — DPIA
Data-protection impact assessment for high-risk processing — pairs with AI Act fundamental-rights impact assessment (Art. 27) for public-facing high-risk systems.
unverified · no verification date read the article EUR-Lex

Control Objectives (1)

obligation (article) → operationalized_by → control objective → satisfied_by → component/pattern; control objective → evidenced_by → evidence artifact
Art. 50
AI Interaction & Content Disclosure
Natural persons are informed they interact with an AI system, and generated/manipulated content carries both human-visible labels and machine-readable provenance (C2PA-class) that survives publication pipelines. Testable: disclosure presence across all interaction surfaces; watermark validity sampling post-publication; deepfake-path red-team (does stripped metadata get caught at the gate?).
evidenced by: Guardrail Telemetry & Sanitization Records
Art. 4
control layer: community mandate — propose objectives
GDPR Art. 22
control layer: community mandate — propose objectives
GDPR Art. 17
control layer: community mandate — propose objectives
GDPR Art. 25
control layer: community mandate — propose objectives
GDPR Art. 35
control layer: community mandate — propose objectives
Take this into your GRC tooling
A control mapping your ISO/IEC 42001 or CSA AICM workbook can ingest, and an Annex IV skeleton to start the technical file from. Indicative mappings only — cells we are not confident about are exported empty rather than filled in.

Standards & Evidence

C2PA Content Credentials
Open technical standard for cryptographically signed content provenance: manifests binding origin, toolchain and edit history to media assets. The de-facto machine-readable implementation path for Art. 50 synthetic-content marking (machine-readable format + detectability duty) — visible labels satisfy the human side, C2PA manifests the machine side. Verification at publication gates produces the disclosure evidence stream.
published · verified 2026-08-06
evidence for: Art. 50
ISO/IEC 42005 (AI Impact Assessment)
Guidance for AI system impact assessments — supports DPIA/FRIA-style analyses.
unverified · no verification date publisher ISO
evidence for: GDPR Art. 35
IEEE CertifAIEd™
Ethics certification (transparency, accountability, algorithmic bias, privacy) for products and professionals; interfaces with the EU ALTAI assessment list.
unverified · no verification date
evidence for: EU AI Act

Architecture Blueprint

Guarded RAG Pattern
For limited-risk conversational/generative systems: deterministic RAG with input rails (DLP/NER, injection blocking), retrieval rails (relevance, freshness, ACL) and output rails (groundedness check with deterministic fallback), plus synthetic-content labelling.
Mode 3 — Human-on-the-Loop
Autonomous execution with aggregate oversight: dashboards, sampling audits (5–10%), real-time veto. For high-volume, low-individual-impact steps.

Required Technical Components (12)

Synthetic-Content Labelling / Watermarking
Synthetic-content labelling & watermarking: visible disclosure plus machine-readable provenance (C2PA Content Credentials) embedded in generated images, audio and video; metadata identifying artificial origin survives common transformations. Discharges Art. 50(2)/(4) for deepfakes and synthetic media; verification telemetry (watermark presence/validity checks at publication gates) is the corresponding evidence stream.
from: Art. 50 · Guarded RAG Pattern
HITL Escalation Queue & Review UI
HITL escalation queue & review UI ('Human-as-a-Tool': the agent calls the human like any other tool via propose-action objects). Confidence- and risk-threshold routing, SLA timers, structured accept/modify/reject verdicts with digital reviewer signature at gate release — each verdict is itself Art. 14 evidence and feeds the active-learning loop.
from: GDPR Art. 22
Bitemporal Memory (GDPR×Art.12)
valid_from/valid_to + transaction time on every record: GDPR erasure removes data from the active retrieval path while the HMAC-chained immutable log survives for Art. 12 / PLD defence; tenant-scoped partitions allow physical scrub of PII.
from: GDPR Art. 17
PII Scrubbing / DLP-NER Layer
Automated detection, pseudonymisation and blocking of personal data in inputs, retrievals and outputs.
from: GDPR Art. 25 · Guarded RAG Pattern
Per-Tenant Retrieval Segmentation
Retrieval is scoped by tenant and by caller entitlement at query time, preventing cross-client and cross-role leakage through shared indexes.
from: GDPR Art. 25
Segmented Vector Store (RBAC + CMEK)
Vector indexes, embeddings and document stores are logically and physically partitioned per client, with role-based access and customer-managed encryption keys.
from: GDPR Art. 25
Live Risk Register / Posture Management
Continuously updated risk register wired to runtime posture: threat-model deltas, open defects, control status, exposure per system. Includes Shadow-AI discovery — continuous scanning for unsanctioned agents, MCP servers and AI API usage outside the register; an unregistered agent is an unmanaged Art. 12/26 liability and the empirical driver of proportionate (not blanket) controls.
from: GDPR Art. 35
Conversational Care Engine
Omnichannel voice/chat agent runtime with knowledge grounding, AI-disclosure prompts, consent handling and transcript capture.
from: TCPA / FCC AI-Voice Rules (US)
Input Rails / Prompt Shields
Pre-model validation of user input: injection detection, topic blocking, encoding checks.
from: Guarded RAG Pattern
Retrieval Rails (ACL-aware RAG)
Relevance, freshness and per-user permission checks on every retrieved chunk; curated, versioned index.
from: Guarded RAG Pattern
Output Rails / Groundedness Check
Faithfulness scoring of answers against retrieved sources; deterministic fallback instead of hallucination; schema-validated structured output.
from: Guarded RAG Pattern
Dual-Gate Validation Pipeline
Input and output validation as two independent gates (MLCommons-hazard-class semantic filters, groundedness checks, structural validators: LLM Guard sub-ms–10 ms, Llama Guard <90 ms, NeMo <50 ms, Guardrails AI 50–200 ms). Latency economics decide the architecture: sequential gate chains add 300–800 ms per agent action; parallel evaluation collapses total added latency to the slowest single check — run independent checks concurrently, reserve sequential ordering for true dependencies.
from: Guarded RAG Pattern

Delivery Stack & Pipeline Stage (9)

Service-as-a-Software delivery: the engines, patterns and artifacts this workflow needs on top of the generic obligations. See the full pipeline
Conversational Care Engine
Omnichannel voice/chat agent runtime with knowledge grounding, AI-disclosure prompts, consent handling and transcript capture.
Output Rails / Groundedness Check
Faithfulness scoring of answers against retrieved sources; deterministic fallback instead of hallucination; schema-validated structured output.
pipeline stage 4Output audit & human-in-the-loop gateway
PII Scrubbing / DLP-NER Layer
Automated detection, pseudonymisation and blocking of personal data in inputs, retrievals and outputs.
pipeline stage 1Ingestion & data isolation
HITL Escalation Queue & Review UI
HITL escalation queue & review UI ('Human-as-a-Tool': the agent calls the human like any other tool via propose-action objects). Confidence- and risk-threshold routing, SLA timers, structured accept/modify/reject verdicts with digital reviewer signature at gate release — each verdict is itself Art. 14 evidence and feeds the active-learning loop.
pipeline stage 4Output audit & human-in-the-loop gateway
Multi-Model Orchestration Layer
Vendor-neutral abstraction over 20+ foundation models across text, vision, audio and code; decouples application logic from any single provider's availability, pricing or deprecation cycle.
pipeline stage 3Multi-model routing & fallback
Guardrail Sidecar / Interception
Rule-based (NeMo/Colang), model-based (alignment checkers) and structural validators deployed as sidecar or gateway plugin (<50 ms), decoupling safety scaling from inference scaling.
Human-on-the-Loop Statistical Sampling
For lower-risk batch workflows, agents execute autonomously while auditors review a statistically representative random sample per batch to track accuracy, error classes and drift.
Inline PII/PHI Tokenisation
Personal and health data are detected and replaced with reversible cryptographic tokens before the payload leaves the isolation layer; re-identification happens only inside the tenant boundary.
Cognitive Orchestrator
The reasoning and control plane of an agentic workflow: goal decomposition, tool selection across enterprise APIs, confidence scoring per step, and a human-machine interface exposing progress, limitations and a global halt. It is the architectural home of AI Act Art. 14 oversight — oversight that lives only in a downstream UI cannot stop an executing agent.

Build or Buy — Vendor Layer (5)

The graph models vendor CATEGORIES as first-class nodes and keeps named vendors as community-maintained, disputable desc content with lastVerified dates. A category is stable; a vendor list is a currency-layer object like any standard node.
Regulated Foundation-Model Platforms
Frontier commercial APIs and open-weight models under enterprise controls: zero-data-retention tiers, data isolation, fine-tuning governance, safety alignment documentation, EU-sovereign options. Exemplary (community-maintained): Anthropic Claude (ZDR enterprise tier), OpenAI GPT enterprise, Google Gemini Enterprise, Cohere (private-cloud RAG), Mistral (EU/self-hosted), Meta Llama (open-weight sovereignty). GPAI-chapter duties and vendor due diligence attach at this layer.
unverified · verified 2026-08-06 community-maintained
selection metrics: ZDR enterprise tiers, data isolation, EU-sovereign options, fine-tuning controls, safety alignment documentation
supplies: Synthetic-Content Labelling / Watermarking
Agent Orchestration & SDLC Toolkits
Developer middleware for multi-agent networks, tool-use chains, RAG abstraction, state/memory persistence and model routing. Exemplary (community-maintained): LangChain, LlamaIndex, AutoGen, CrewAI; MCP-based tool ecosystems. Regulatory posture: orchestration code is where autonomy tiering, propose-action objects and fallback routing get implemented — the framework choice constrains which controls are cheap and which are retrofits.
unverified · verified 2026-08-06 community-maintained
selection metrics: broad model-API abstraction, state/memory management, error recovery, fallback routing hooks
supplies: HITL Escalation Queue & Review UI · Cognitive Orchestrator
AI GRC & Governance Platforms
Second-line systems of record: model/agent inventory incl. third-party SaaS AI, automated risk tiering, policy administration, cross-framework mapping & control deduplication, audit-evidence generation, intake workflows. Exemplary (community-maintained): ModelOp Center, Credo AI, IBM watsonx.governance, OneTrust, Holistic AI, Modulos (governance graph), Monitaur (insurance/lending), Fairly AI, Saidot, Trustible, Enzai, LatticeFlow (technical validation), Vanta (evidence automation), ServiceNow (intake/ITSM); data-catalog adjacency: Collibra, Alation, Informatica. Selection metrics: see meta.marketLandscape.selectionMetrics.grc.
unverified · verified 2026-08-06 community-maintained
selection metrics: multi-model/multi-cloud cataloging incl. third-party SaaS, automated risk tiering, regulatory reporting, independent-2nd-line deployability, cross-framework control deduplication
supplies: Live Risk Register / Posture Management
Runtime Security & Guardrail Vendors
First-line inline enforcement: single-pass parallel input/output evaluation proxies, injection & exfiltration defense, PII masking, grounding checks, SecOps routing. Exemplary (community-maintained): Prompt Security, HiddenLayer (MLSDR), Palo Alto AI Runtime Security, AWS Bedrock Guardrails, NVIDIA NeMo Guardrails, Guardrails AI, Robust Intelligence, LLM Guard / Llama Guard OSS class. Selection metrics: single-pass latency (<20 ms class), catch rates, policy-version telemetry into the AI-BOM.
unverified · verified 2026-08-06 community-maintained
selection metrics: single-pass parallel evaluation latency (<20 ms class), injection/hallucination catch rates, SecOps/SIEM routing, policy versioning surfaced into the AI-BOM
supplies: Input Rails / Prompt Shields · Output Rails / Groundedness Check · Dual-Gate Validation Pipeline · Guardrail Sidecar / Interception
Secure Data Infrastructure & Vector Storage
Governed retrieval substrate: vector databases, lakehouses and catalogs with tenant/namespace isolation, RBAC + client-managed keys (CMEK), lineage into RAG chunks, air-gap options. Exemplary (community-maintained): Pinecone (serverless, SOC 2), Chroma/FAISS (self-hosted/air-gapped sovereignty), Snowflake Cortex (masking, clean rooms), Databricks Unity Catalog (end-to-end lineage), Azure AI Search, AWS OpenSearch. The Art. 10 runtime data-governance duties land here.
unverified · verified 2026-08-06 community-maintained
selection metrics: namespace/tenant isolation, RBAC + CMEK, lineage into RAG chunks, SOC 2 / ISO 27001 attestations, air-gap capability
supplies: Retrieval Rails (ACL-aware RAG)
Procurement rule: Derived from three-lines-of-defense separation: the second-line GRC platform must be procured and deployed independently of any first-line runtime or model vendor — a governance tool that only sees its own vendor's models cannot govern a multi-model estate, and closed third-party SaaS AI can only be governed contractually (intake, attestation, AI-BOM disclosure), never by inline inspection.
Outsourced delivery BPO · SaaS · Service-as-a-Software caveats

Delivery Model — BPO · SaaS · Service-as-a-Software

Spectrum
BPO: input-priced (billable hours/FTEs), linear headcount scaling, human error & attrition as primary risk
SaaS: capability-priced (software access), client operates the workload, implementation/adoption failure as primary risk
Service-as-a-Software: outcome-priced (SLA on completed work), provider-managed AI executes 60–80% of cognitive tasks with specialist supervision, algorithmic bias & non-compliance as primary risk
Caveats in regulated markets
Outcome SLAs move compliance risk onto the provider — but NOT the buyer's deployer duties: Art. 26 oversight, log retention and FRIA obligations stay with the enterprise even when execution is outsourced.
Provider role analysis is the central legal question: a productized platform that fine-tunes, re-purposes or chains models can flip into the Art. 25 provider role with full high-risk obligations.
Certified operations (ISO 42001) function as a procurement moat and shortcut third-party risk assessment — but organizational certificate ≠ product conformity (never conflate, see meta.assuranceEcosystem).
The buyer's evidence chain must reach into the provider: contractually mandated AI-BOM disclosure, ZDR certificates, bias-audit reports and logging-ledger access are the artifacts that make an outsourced workflow auditable.

Threat Profile

Deceptive AI Impersonation
A voice or chat agent is perceived as human, or claims capabilities and commitments it cannot honour, breaching transparency and consumer-protection duties.
mitigate with: Output Rails / Groundedness Check, Synthetic-Content Labelling / Watermarking
LLM01 Prompt Injection
Direct or indirect (RAG/files/web) instructions override system prompts — the primary attack vector on the perception layer.
mitigate with: Input Rails / Prompt Shields, Guardrail Sidecar / Interception, Trinity Defense (TCB + Command Gates + IFC), Divided-Focus Memory Tiering, Dual-Gate Validation Pipeline
LLM02 Sensitive Info Disclosure
Leakage of PII, trade secrets or system prompts in outputs.
mitigate with: PII Scrubbing / DLP-NER Layer, Output Rails / Groundedness Check
LLM09 Misinformation
Hallucinated or wrong outputs create liability and decision risk.
mitigate with: Output Rails / Groundedness Check, Explainability API (SHAP/LIME/CoT)