Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles

Regulation coverage

Every regulation in the graph resolves into concrete technical components — through an article obligation, a control objective, a design pattern or an evidence artefact that a component must produce. Pick a regulation to see its technical surface, how each component is derived, and in which of the triggering use cases it is actually part of the required stack. The gap counts show where the graph reaches a component that no use case yet requires — those are open contribution targets, not settled answers. Open the full graph →

AML Package (AMLR/AMLA)

Customer due diligence, perpetual monitoring and AMLA supervisory expectations for AI-driven KYC/AML systems.

23 components0 articles / obligations3 triggering use casesopen in graph

Isolated Tenant Storage Enclave

100% of use cases

Per-client storage boundary for raw payloads, intermediate artefacts and outputs, so no tenant data is co-mingled or reachable across engagements.

  • practice-derived3 triggering use cases require Isolated Tenant Storage Enclave

Multi-Region Failover & Resilience Testing

100% of use cases

DORA-grade continuity: regional redundancy, chaos testing, exit strategies for critical third parties.

  • practice-derived3 triggering use cases require Multi-Region Failover & Resilience Testing

OpenTelemetry / FCoT Tracing

100% of use cases

Hierarchical trace spans for every sub-task, prompt, retrieved document and API call — the reconstructible decision path for Art. 12/14 and PLD disclosure.

  • practice-derived3 triggering use cases require OpenTelemetry / FCoT Tracing

Sovereign Context Layer

100% of use cases

Governed runtime workspace operationalizing Art. 10: traceable lineage for every RAG chunk and training record at execution time, canonical version-controlled business glossary (documents Art. 10(2)(d) baseline assumptions), and continuous data-quality monitoring with threshold alerts and logged remediation for the Art. 10(3) 'error-free and complete' standard.

  • practice-derived3 triggering use cases require Sovereign Context Layer

Vendor & Model Due-Diligence Kit

100% of use cases

Scoring model: jurisdiction (CLOUD Act exposure), zero-data-retention, BYOK support, audit evidence (C5/AIC4/ISO 42001/EN 18286:2026), tenant isolation.

  • practice-derived3 triggering use cases require Vendor & Model Due-Diligence Kit

Zero-Trust Ingestion Gateway

100% of use cases

Authenticated, policy-checked entry point for client payloads; enforces tenant identity, schema validation and rate limits before any data reaches an inference path.

  • practice-derived3 triggering use cases require Zero-Trust Ingestion Gateway

WORM / Immutable Audit Vault

67% of use cases

Append-only, hash-chained audit vault (WORM object-lock storage, AES-256 at rest, TLS 1.3 in transit). Guarantees tamper-evidence within the organization's trust domain — which stops your own team, but not an admin who can rebuild the vault. Pair with an external trust anchor and key ceremonies outside the operating team for evidence that holds against the insider scenario.

  • practice-derived2 triggering use cases require WORM / Immutable Audit Vault
Triggered but not yet requiredTransaction Monitoring & FRAML

Agent Identity & Access (IdP)

33% of use cases

Per-agent identities, short-lived scoped tokens, OBO flow enforcement — the identity substrate of agentic zero trust.

  • practice-derived1 triggering use case require Agent Identity & Access (IdP)

Bias Testing & Data Quality Pipeline

33% of use cases

Representativeness checks, bias metrics and mitigation per ISO/IEC 5259; versioned datasets with lineage.

  • practice-derived1 triggering use case require Bias Testing & Data Quality Pipeline

Central Credential Vault

33% of use cases

Agents never hold target-system keys; the gateway injects centrally managed credentials after policy checks.

  • practice-derived1 triggering use case require Central Credential Vault

Confidence Scoring & Threshold Gate

33% of use cases

Computes a probabilistic confidence score for every output and holds the transaction when the score falls below the workflow's regulatory threshold.

  • practice-derived1 triggering use case require Confidence Scoring & Threshold Gate

Deterministic Policy Engine (OPA / Cedar)

33% of use cases

Policy-as-code decision point (PDP) with enforcement points (PEP) in front of every tool call: versioned policies in Git, microsecond evaluation, typed action schemas — authorization decided outside the model's reasoning space, never in the prompt.

  • practice-derived1 triggering use case require Deterministic Policy Engine (OPA / Cedar)

Document Intelligence Engine

33% of use cases

OCR, layout parsing and semantic clause extraction over filings, contracts and invoices, emitting structured records with span-level source references.

  • practice-derived1 triggering use case require Document Intelligence Engine

Explainability API (SHAP/LIME/CoT)

33% of use cases

Feature attributions for classical ML, reasoning-trace summaries for GenAI — feeds the human reviewer and the technical file.

  • practice-derived1 triggering use case require Explainability API (SHAP/LIME/CoT)

HITL Escalation Queue & Review UI

33% of use cases

HITL escalation queue & review UI ('Human-as-a-Tool': the agent calls the human like any other tool via propose-action objects). Confidence- and risk-threshold routing, SLA timers, structured accept/modify/reject verdicts with digital reviewer signature at gate release — each verdict is itself Art. 14 evidence and feeds the active-learning loop.

  • practice-derived1 triggering use case require HITL Escalation Queue & Review UI

Identity & Sanctions Screening Engine

33% of use cases

Beneficial-ownership resolution, sanctions/PEP list matching and alert scoring with tunable thresholds and full match-evidence capture.

  • practice-derived1 triggering use case require Identity & Sanctions Screening Engine

Kill Switch / Graceful Degradation

33% of use cases

Operator stop controls and degraded-mode fallbacks; real-time override (veto) channels for HOTL operation.

  • practice-derived1 triggering use case require Kill Switch / Graceful Degradation

Multi-Model Router & Fallback Abstraction

33% of use cases

Abstraction layer decoupling application logic from model providers: dynamic routing on capability, cost, latency SLA and regulatory constraint (sensitive-data classes pinned to ZDR private/VPC endpoints or on-prem open-weight instances); real-time health monitoring with automatic fallback to secondary endpoints or local fine-tuned models on outage/latency spikes. Discharges resilience duties (DORA-class), prevents provider lock-in, and makes model deprecations a routing-table change instead of a re-architecture. Router decisions are logged into the decision trace — model version per event is an audit-packet field.

  • practice-derived1 triggering use case require Multi-Model Router & Fallback Abstraction

PII Scrubbing / DLP-NER Layer

33% of use cases

Automated detection, pseudonymisation and blocking of personal data in inputs, retrievals and outputs.

  • practice-derived1 triggering use case require PII Scrubbing / DLP-NER Layer

Trust & Risk Dual Scoring

33% of use cases

Escalation triggers built from two independent signals, because raw model confidence is uncalibrated: calibrated trust scores (prompt relevance, similarity to historic successes, cross-model consistency) plus deterministic risk scores (sensitive categories, transaction value, protected data) — either crossing its threshold forces human review.

  • practice-derived1 triggering use case require Trust & Risk Dual Scoring

Watchdog Supervisor & Rate Limiting

33% of use cases

Cost/iteration caps, loop detection, anomaly-triggered mandatory approval (CodeBuddy 'suspicious command override').

  • practice-derived1 triggering use case require Watchdog Supervisor & Rate Limiting