Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles

Regulation coverage

Every regulation in the graph resolves into concrete technical components — through an article obligation, a control objective, a design pattern or an evidence artefact that a component must produce. Pick a regulation to see its technical surface, how each component is derived, and in which of the triggering use cases it is actually part of the required stack. The gap counts show where the graph reaches a component that no use case yet requires — those are open contribution targets, not settled answers. Open the full graph →

Data Act

source EUR-Lex

Access and re-use rights for (industrial) data, switching and interoperability duties — affects data sourcing for RAG pipelines and connected products.

14 components0 articles / obligations2 triggering use casesopen in graph

Data Lineage & Versioning

50% of use cases

Provenance tracking of datasets, features and embeddings; write-time attribution (source, actor, timestamp, confidence).

  • practice-derived1 triggering use case require Data Lineage & Versioning
Triggered but not yet requiredPredictive Maintenance in Energy Grids

Deterministic Policy Engine (OPA / Cedar)

50% of use cases

Policy-as-code decision point (PDP) with enforcement points (PEP) in front of every tool call: versioned policies in Git, microsecond evaluation, typed action schemas — authorization decided outside the model's reasoning space, never in the prompt.

  • practice-derived1 triggering use case require Deterministic Policy Engine (OPA / Cedar)
Triggered but not yet requiredPredictive Maintenance in Energy Grids

Marketplace Monitoring & Collection Engine

50% of use cases

Compliant collection of public marketplace signals with robots/ToS policy checks, rate governance and provenance capture per observation.

  • practice-derived1 triggering use case require Marketplace Monitoring & Collection Engine
Triggered but not yet requiredPredictive Maintenance in Energy Grids

Model Drift & Accuracy Monitor

50% of use cases

Continuous evaluation against golden sets and sampled human verdicts; raises drift alerts and feeds the recertification cycle.

  • practice-derived1 triggering use case require Model Drift & Accuracy Monitor
Triggered but not yet requiredPredictive Maintenance in Energy Grids

Multi-Model Router & Fallback Abstraction

50% of use cases

Abstraction layer decoupling application logic from model providers: dynamic routing on capability, cost, latency SLA and regulatory constraint (sensitive-data classes pinned to ZDR private/VPC endpoints or on-prem open-weight instances); real-time health monitoring with automatic fallback to secondary endpoints or local fine-tuned models on outage/latency spikes. Discharges resilience duties (DORA-class), prevents provider lock-in, and makes model deprecations a routing-table change instead of a re-architecture. Router decisions are logged into the decision trace — model version per event is an audit-packet field.

  • practice-derived1 triggering use case require Multi-Model Router & Fallback Abstraction
Triggered but not yet requiredPredictive Maintenance in Energy Grids

OpenTelemetry / FCoT Tracing

50% of use cases

Hierarchical trace spans for every sub-task, prompt, retrieved document and API call — the reconstructible decision path for Art. 12/14 and PLD disclosure.

  • practice-derived1 triggering use case require OpenTelemetry / FCoT Tracing
Triggered but not yet requiredPredictive Maintenance in Energy Grids

Watchdog Supervisor & Rate Limiting

50% of use cases

Cost/iteration caps, loop detection, anomaly-triggered mandatory approval (CodeBuddy 'suspicious command override').

  • practice-derived1 triggering use case require Watchdog Supervisor & Rate Limiting
Triggered but not yet requiredPredictive Maintenance in Energy Grids

WORM / Immutable Audit Vault

50% of use cases

Append-only, hash-chained audit vault (WORM object-lock storage, AES-256 at rest, TLS 1.3 in transit). Guarantees tamper-evidence within the organization's trust domain — which stops your own team, but not an admin who can rebuild the vault. Pair with an external trust anchor and key ceremonies outside the operating team for evidence that holds against the insider scenario.

  • practice-derived1 triggering use case require WORM / Immutable Audit Vault
Triggered but not yet requiredPredictive Maintenance in Energy Grids