Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles

Regulation coverage

Every regulation in the graph resolves into concrete technical components — through an article obligation, a control objective, a design pattern or an evidence artefact that a component must produce. Pick a regulation to see its technical surface, how each component is derived, and in which of the triggering use cases it is actually part of the required stack. The gap counts show where the graph reaches a component that no use case yet requires — those are open contribution targets, not settled answers. Open the full graph →

EHDS

Primary and secondary use of electronic health data; access via health-data access bodies for AI training.

14 components0 articles / obligations4 triggering use casesopen in graph

Bias Testing & Data Quality Pipeline

75% of use cases

Representativeness checks, bias metrics and mitigation per ISO/IEC 5259; versioned datasets with lineage.

  • practice-derived3 triggering use cases require Bias Testing & Data Quality Pipeline
Triggered but not yet requiredClinical Documentation & Ambient Scribing

Confidence Scoring & Threshold Gate

75% of use cases

Computes a probabilistic confidence score for every output and holds the transaction when the score falls below the workflow's regulatory threshold.

  • practice-derived3 triggering use cases require Confidence Scoring & Threshold Gate
Triggered but not yet requiredClinical Documentation & Ambient Scribing

Explainability API (SHAP/LIME/CoT)

75% of use cases

Feature attributions for classical ML, reasoning-trace summaries for GenAI — feeds the human reviewer and the technical file.

  • practice-derived3 triggering use cases require Explainability API (SHAP/LIME/CoT)
Triggered but not yet requiredClinical Documentation & Ambient Scribing

HITL Escalation Queue & Review UI

75% of use cases

HITL escalation queue & review UI ('Human-as-a-Tool': the agent calls the human like any other tool via propose-action objects). Confidence- and risk-threshold routing, SLA timers, structured accept/modify/reject verdicts with digital reviewer signature at gate release — each verdict is itself Art. 14 evidence and feeds the active-learning loop.

  • practice-derived3 triggering use cases require HITL Escalation Queue & Review UI
Triggered but not yet requiredClinical Documentation & Ambient Scribing

Kill Switch / Graceful Degradation

75% of use cases

Operator stop controls and degraded-mode fallbacks; real-time override (veto) channels for HOTL operation.

  • practice-derived3 triggering use cases require Kill Switch / Graceful Degradation
Triggered but not yet requiredClinical Documentation & Ambient Scribing

Trust & Risk Dual Scoring

75% of use cases

Escalation triggers built from two independent signals, because raw model confidence is uncalibrated: calibrated trust scores (prompt relevance, similarity to historic successes, cross-model consistency) plus deterministic risk scores (sensitive categories, transaction value, protected data) — either crossing its threshold forces human review.

  • practice-derived3 triggering use cases require Trust & Risk Dual Scoring
Triggered but not yet requiredClinical Documentation & Ambient Scribing

WORM / Immutable Audit Vault

75% of use cases

Append-only, hash-chained audit vault (WORM object-lock storage, AES-256 at rest, TLS 1.3 in transit). Guarantees tamper-evidence within the organization's trust domain — which stops your own team, but not an admin who can rebuild the vault. Pair with an external trust anchor and key ceremonies outside the operating team for evidence that holds against the insider scenario.

  • practice-derived3 triggering use cases require WORM / Immutable Audit Vault
Triggered but not yet requiredClinical Documentation & Ambient Scribing

PII Scrubbing / DLP-NER Layer

50% of use cases

Automated detection, pseudonymisation and blocking of personal data in inputs, retrievals and outputs.

  • practice-derived2 triggering use cases require PII Scrubbing / DLP-NER Layer

Input Rails / Prompt Shields

25% of use cases

Pre-model validation of user input: injection detection, topic blocking, encoding checks.

  • practice-derived1 triggering use case require Input Rails / Prompt Shields

Model Drift & Accuracy Monitor

25% of use cases

Continuous evaluation against golden sets and sampled human verdicts; raises drift alerts and feeds the recertification cycle.

  • practice-derived1 triggering use case require Model Drift & Accuracy Monitor

Multi-Model Router & Fallback Abstraction

25% of use cases

Abstraction layer decoupling application logic from model providers: dynamic routing on capability, cost, latency SLA and regulatory constraint (sensitive-data classes pinned to ZDR private/VPC endpoints or on-prem open-weight instances); real-time health monitoring with automatic fallback to secondary endpoints or local fine-tuned models on outage/latency spikes. Discharges resilience duties (DORA-class), prevents provider lock-in, and makes model deprecations a routing-table change instead of a re-architecture. Router decisions are logged into the decision trace — model version per event is an audit-packet field.

  • practice-derived1 triggering use case require Multi-Model Router & Fallback Abstraction

Output Rails / Groundedness Check

25% of use cases

Faithfulness scoring of answers against retrieved sources; deterministic fallback instead of hallucination; schema-validated structured output.

  • practice-derived1 triggering use case require Output Rails / Groundedness Check

Retrieval Rails (ACL-aware RAG)

25% of use cases

Relevance, freshness and per-user permission checks on every retrieved chunk; curated, versioned index.

  • practice-derived1 triggering use case require Retrieval Rails (ACL-aware RAG)

Synthetic-Content Labelling / Watermarking

25% of use cases

Synthetic-content labelling & watermarking: visible disclosure plus machine-readable provenance (C2PA Content Credentials) embedded in generated images, audio and video; metadata identifying artificial origin survives common transformations. Discharges Art. 50(2)/(4) for deepfakes and synthetic media; verification telemetry (watermark presence/validity checks at publication gates) is the corresponding evidence stream.

  • practice-derived1 triggering use case require Synthetic-Content Labelling / Watermarking