Cross-Border Statutory Tax & Wealth Filing
ERP, custodial and exchange data reconciled across entities and jurisdictions, taxable events categorised, statutory returns drafted and electronically submitted to tax authorities, with variance-triggered human escalation.
Indicative decision support, not legal advice. Risk classification depends on your concrete deployment context and can change with scope drift — validate the result with qualified counsel.
Target market(s)European UnionUnited States (federal)change
Changes which instruments below count as in scope for this profile.
Target markets: European Union, United States (federal)
Regulatory footprint
6 instruments across 4 of 7 regulatory domains, plus 3 standards references- AI lawnone triggered
- Data protection1 instrument
- Cyber & resilience1 instrument
- Online safety & platformsnone triggered
- Product safetynone triggered
- Financial services3 instruments
- Sector & employment1 instrument
- Standards3 references
By jurisdiction
- EU3European UnionArt. 26 — Deployer Obligations, DORA, GDPR
- US2United States (federal)Sarbanes-Oxley Act (SOX §302 / §404), SEC Advisers Act Rule 204-2 (Books & Records)
- GLOBAL1Cross-jurisdictionNational Tax Codes & OECD BEPS / Pillar Two
The AI Act is one dimension of this footprint, not the whole of it — every domain above carries its own obligations and deadlines. See the instruments in the graph →
Every hop of this derivation rests on a primary source with a recently verified status. Read it as a defensible starting position, still not legal advice.
Computed weakest-link over 21 evaluated hops across 1 target market: a chain is only as strong as its weakest step, so the band follows the worst hop rather than an average that would hide it. Five factors per hop — source tier, verification age, status certainty, community hardening, derivation kind — all read from graph data, never from a hand-set score.
Why this band10 factors lowered the band — each links to the claim behind it
- Source tier: National Tax Codes & OECD BEPS / Pillar Two carries no resolvable citation — the claim is uncited. open node →
- Source tier: IFRS / US GAAP Reporting Assurance carries no resolvable citation — the claim is uncited. open node →
- Verification age: Art. 4 — AI Literacy has no recorded verification date. open node → primary source →
- Verification age: GDPR Art. 22 — Automated Decisions has no recorded verification date. open node → primary source →
- Verification age: GDPR Art. 17 — Erasure has no recorded verification date. open node → primary source →
- Verification age: GDPR Art. 25 — Data Protection by Design has no recorded verification date. open node → primary source →
- Verification age: GDPR Art. 35 — DPIA has no recorded verification date. open node → primary source →
- Verification age: Art. 25 — Value Chain / Role Flip has no recorded verification date. open node → primary source →
- Verification age: ISO/IEC 42005 (AI Impact Assessment) has no recorded verification date. open node → primary source →
- Verification age: ISO/IEC 27001:2022 + A.8.28 has no recorded verification date. open node → primary source →
Compliance brief
This use case is minimal-risk under the EU AI Act (Minimal Risk); no product-specific obligations beyond general AI literacy apply.
What is owed
- Art. 4. Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems.
- GDPR Art. 22. Right not to be subject to solely automated decisions with legal/similar effect; requires meaningful human involvement or explicit legal basis + safeguards.
- GDPR Art. 27. A controller or processor not established in the Union that falls within Art.
- GDPR Art. 17. Right to erasure collides with AI Act Art.
- GDPR Art. 25. Privacy by design & default: minimisation, pseudonymisation, PII filters in pipelines and vector stores.
Dates that bind
- 2024-08-01 — AI Act enters into force. Regulation (EU) 2024/1689 in force; countdown for all staged obligations starts.
- 2025-02-02 — Prohibitions + AI literacy. Art. 5 prohibited practices ban applies (manipulation, social scoring, untargeted face scraping, workplace emotion recognition); Art. 4 AI literacy duty.
Maximum exposure
- National Tax Codes & OECD BEPS / Pillar Two: Tax penalties, interest, criminal exposure for negligent or false filings.
- Sarbanes-Oxley Act (SOX §302 / §404): Certification liability for officers, adverse ICFR opinions, SEC enforcement.
- SEC Advisers Act Rule 204-2 (Books & Records): SEC enforcement, deficiency letters, books-and-records penalties.
- GDPR: Up to €20m or 4% of worldwide annual turnover
- DORA: Administrative penalties; periodic penalty payments for critical third parties
First five actions
- Confirm in writing whether this organisation builds/places the system on the market (provider) or only operates it (deployer), since the role is not yet established.
- Commission and confirm the Art. 4, GDPR Art. 22, GDPR Art. 27 obligations named above as active workstreams with an accountable owner.
- Stand up the named oversight design — Mode 2 — with a documented human-review procedure.
- Produce the technical documentation and evidence artefacts already mapped to this use case (HITL Escalation Queue & Review UI, Adverse-Decision Reason Generator, Bitemporal Memory (GDPR×Art.12)) before they are requested.
- Put 2024-08-01 — AI Act enters into force — into the compliance calendar with an owner and lead time.
Terms used above: · · ·
Consensus reading: Minimal Risk open in the graph →
Filing in the taxpayer's name is an irreversible external act, so the risk sits in autonomy bounds rather than AI Act tiering: materiality thresholds, retained computation evidence and WORM archiving of every inference behind a submitted figure. Advisory-side workflows additionally pull in SEC 204-2 attribution.
What the reading rests on — the provisions this classification actually pulls in:
- Art. 4 — AI Literacy
- National Tax Codes & OECD BEPS / Pillar Two
- Sarbanes-Oxley Act (SOX §302 / §404) (15 U.S.C. §7241 / §7262 (Sarbanes-Oxley §302 / §404))
- SEC Advisers Act Rule 204-2 (Books & Records) (17 CFR 275.204-2 (Advisers Act books and records))
- GDPR (Regulation (EU) 2016/679)
- DORA (Regulation (EU) 2022/2554)
- Art. 26 — Deployer Obligations
Baseline: of 100+, 40% were not definitively classifiable (18% clearly high-risk, 42% clearly low-risk). appliedAI Institute — AI Act risk classification of AI systems from a practical perspective
Applicable Regulations (6)
Legal Obligations (11)
Control Objectives (2)
Standards & Evidence
Evidence you will need (13)
The concrete deliverables this use case's obligations ask for — grouped by what kind of artifact they are. Documentation is the largest single conformity cost block, so the list is a work plan, not a reading list. Full evidence matrix →
Documents & files (1)
Written deliverables an authority or auditor can request as a file.
Assessments (3)
A structured judgement about risk, rights or a management system.
Test reports (1)
Measured results from testing, evaluation or red-teaming.
Log records (2)
Machine-generated records produced while the system runs.
Process records (5)
Traces that a process actually happened, and who did it.
Registry entries (1)
An entry in a register — internal inventory or public registry.
Architecture Blueprint
Required Technical Components (22)
Delivery Stack & Pipeline Stage (9)
Build or Buy — Vendor Layer (8)
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| LangChain / LangGraph | agent framework | Graph-structured agent runtime; interrupt/pause nodes support implementing human approval at defined steps. Typical: multi-step agents, approval workflows. | not checked | supports implementing Art. 14 oversight (claimed)supports Art. 12 step logging (claimed) |
| LlamaIndex | RAG framework | Indexing and query abstractions over documents and structured sources. Typical: enterprise RAG, document agents. | open source | retrieval-governance positioning |
| Microsoft AutoGen | multi-agent framework | Conversational multi-agent patterns with pluggable tool executors. Typical: multi-agent research, code agents. | not checked | research/OSS, no vendor certification |
| CrewAI | multi-agent framework | Role-based agent teams with task delegation and process templates. Typical: process automation, role-based agents. | not checked | vendor-stated security posture |
and 6 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| LangSmith | agent tracing & evaluation | Trace capture and evaluation over LangChain/LangGraph runs with dataset-based scoring. Typical: step tracing, regression evaluation. | not checked | SOC 2 (claimed)supports Art. 12 record-keeping (claimed) |
| Langfuse | agent tracing & evaluation | Open-source tracing, prompt management and evaluation; self-hostable for retention control. Typical: self-hosted tracing, cost/latency analytics. | open source | GDPR-positionedsupports Art. 12 record-keeping (claimed) |
| Arize AI / Phoenix | ML & LLM observability | Production monitoring with drift and performance analysis; Phoenix is the open-source tracing side. Typical: drift monitoring, production analytics. | not checked | SOC 2 (claimed)drift-monitoring positioning (SR 11-7 style, claimed) |
| Helicone | LLM gateway & logging | Proxy-level logging of prompts, costs and latency across providers. Typical: gateway logging, cost control. | not checked | SOC 2 (claimed)supports Art. 12 record-keeping (claimed) |
and 11 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Credo AI | AI governance platform | Policy packs, risk tiering and evidence workflows mapped across frameworks. Typical: AI registry, policy administration. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | ISO 42001 alignment (claimed)EU AI Act readiness positioning |
| Holistic AI | AI governance & audit | Risk assessment, bias auditing and regulatory reporting workflows. Typical: bias audit, regulatory reporting. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | NYC LL144 audit support (claimed)EU AI Act readiness positioning |
| IBM watsonx.governance | AI governance platform | Governance, factsheets and monitoring integrated with the IBM stack. Typical: factsheets, model monitoring. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | ISO 42001 alignment (claimed)Art. 11 documentation support (claimed) |
| ModelOp | AI/model governance | Model and agent inventory with automated lifecycle controls for large estates. Typical: model inventory, control automation. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | model-risk positioning (SR 11-7 style, claimed)ISO 42001 alignment (claimed) |
and 3 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Docling | document parser | Open-source layout-aware parsing of PDFs and office formats into structured chunks. Typical: RAG ingestion, air-gapped pipelines. | self-hostable | EU sovereignty positioning |
| LlamaParse | document parser | Managed parsing service tuned for tables and complex documents feeding RAG. Typical: RAG ingestion, table extraction. | not checked | SOC 2 (claimed) |
| Amazon Textract | document parser | OCR and form/table extraction with per-page pricing inside AWS. Typical: document intake, claims processing. | not checked | SOC 2 (claimed)HIPAA-eligible (claimed)ISO 27001 (claimed) |
| Diffbot | web/knowledge extraction | Structured extraction and knowledge-graph construction from web sources. Typical: market monitoring, entity resolution. | not checked | vendor-stated security posture |
and 12 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Anjuna | confidential computing | Runs workloads inside hardware enclaves without application rewrites. Typical: data-in-use protection, regulated inference. | not checked | confidential-computing positioningDORA-positioned (claimed) |
| Fortanix | confidential computing & KMS | Enclave runtime plus key management and tokenisation services. Typical: key management, data-in-use protection. | not checked | FIPS 140-2 (claimed)DORA-positioned (claimed)HIPAA-positioned (claimed) |
| Skyflow | privacy vault | Polymorphic data vault de-identifying records before they reach a model. Typical: PII vaulting, pre-model redaction. | not checked | SOC 2 (claimed)HIPAA-positionedGDPR-positioned |
| Private AI | PII detection & redaction | Detection and redaction of identifiers across text, documents and audio. Typical: inline redaction, document de-identification. | not checked | GDPR-positionedHIPAA-positioned |
and 1 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Azure AI Search | managed retrieval | Managed hybrid search with security trimming against tenant identities. Typical: ACL-aware RAG, enterprise search. | not checked | ISO 27001 (claimed)SOC 2 (claimed) |
| Databricks Unity Catalog | governed lakehouse | Catalog and lineage spanning tables, features and RAG chunks. Typical: lineage evidence, governed RAG. | not checked | SOC 2 (claimed)lineage/Art. 10 support (claimed) |
| Relyance AI | code-level data & AI lineage | Parses source repositories to map data and inference flows at code level, with CI checks on changes to those flows. Typical: data lineage, shift-left privacy review. Scope overlap: Its AI-governance reporting scope overlaps this platform's own; we have a commercial interest in the comparison. | SaaS (vendor cloud) | GDPR programme tooling (claimed)EU AI Act readiness positioning |
| Snowflake Cortex | governed lakehouse | Model calls inside the warehouse boundary with masking and clean rooms. Typical: in-warehouse inference, governed analytics. | not checked | SOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Pillar Security | agent security & inventory | Discovery, inventory and runtime policy for agents in the estate. Typical: agent registry, policy enforcement. | not checked | agent-inventory positioning |
| Lyzr | agent governance & observability | Agent platform with governance, approval and observability features. Typical: agent approval, agent analytics. | not checked | vendor-stated security posture |
| Astrix Security | non-human identity | Lifecycle governance of machine and agent identities and their grants. Typical: credential scoping, NHI inventory. | not checked | SOC 2 (claimed)NHI governance positioning |
| Britive | just-in-time access | Ephemeral, per-task privileges instead of standing credentials. Typical: JIT credentials, privilege reduction. | not checked | SOC 2 (claimed)least-privilege positioning |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| OVHcloud | native EU | French provider with EU-only jurisdiction and a narrower managed-AI catalog than the hyperscalers. Typical: EU-resident inference, regulated workload hosting. | not checked | ISO 27001 (claimed)SecNumCloud-positionedGDPR-positioned |
| Scaleway | native EU | EU-operated cloud with GPU instances and managed inference under French corporate control. Typical: EU-resident inference, fine-tuning. | not checked | ISO 27001 (claimed)GDPR-positioned |
| STACKIT | native EU | German provider (Schwarz Group) positioned for data residency in Germany. Typical: public sector, retail data platforms. | not checked | C5-positionedGDPR-positioned |
| AWS European Sovereign Cloud | sovereign hyperscaler | Separately operated EU region set with EU-resident personnel and keys; full hyperscaler catalog. Typical: large-scale enterprise AI, regulated hosting. | not checked | ISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning |
and 11 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.