Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles

Regulation coverage

Every regulation in the graph resolves into concrete technical components — through an article obligation, a control objective, a design pattern or an evidence artefact that a component must produce. Pick a regulation to see its technical surface, how each component is derived, and in which of the triggering use cases it is actually part of the required stack. The gap counts show where the graph reaches a component that no use case yet requires — those are open contribution targets, not settled answers. Open the full graph →

NIS2 Directive

source EUR-Lex

Cyber-resilience duties for essential/important entities: supply-chain risk management, incident response, 24h early warning / 72h notification. AI components count as operational IT in scope.

5 components0 articles / obligations4 triggering use casesopen in graph

OpenTelemetry / FCoT Tracing

75% of use cases

Hierarchical trace spans for every sub-task, prompt, retrieved document and API call — the reconstructible decision path for Art. 12/14 and PLD disclosure.

Triggered but not yet requiredPredictive Maintenance in Energy Grids

SBOM & Dependency Management

50% of use cases

Software bill of materials incl. model weights and datasets; automated vulnerability patching pipeline.

WORM / Immutable Audit Vault

50% of use cases

Append-only, hash-chained audit vault (WORM object-lock storage, AES-256 at rest, TLS 1.3 in transit). Guarantees tamper-evidence within the organization's trust domain — which stops your own team, but not an admin who can rebuild the vault. Pair with an external trust anchor and key ceremonies outside the operating team for evidence that holds against the insider scenario.

Unified Incident-Response Runbook

25% of use cases

One procedure reconciling AI Act Art. 73, GDPR Art. 33 (72h), DORA and NIS2 (24h/72h) timelines and recipients.

  • named in regulationNIS2 Directive → Unified Incident-Response Runbook
  • evidence artefactNIS2 Directive → Post-Market Monitoring Plan & Incident Reports → produced by Unified Incident-Response RunbookPost-Market Monitoring Plan & Incident Reports

Vendor & Model Due-Diligence Kit

25% of use cases

Scoring model: jurisdiction (CLOUD Act exposure), zero-data-retention, BYOK support, audit evidence (C5/AIC4/ISO 42001/EN 18286:2026), tenant isolation.

  • named in regulationNIS2 Directive → Vendor & Model Due-Diligence Kit