Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles

Regulation coverage

Every regulation in the graph resolves into concrete technical components — through an article obligation, a control objective, a design pattern or an evidence artefact that a component must produce. Pick a regulation to see its technical surface, how each component is derived, and in which of the triggering use cases it is actually part of the required stack. The gap counts show where the graph reaches a component that no use case yet requires — those are open contribution targets, not settled answers. Open the full graph →

New York RAISE Act

New York frontier-model safety law, effective 1 January 2027: safety plans, incident disclosure and audit duties for large model developers — relevant when sourcing frontier models for EU/US dual deployments.

4 components0 articles / obligations0 triggering use casesopen in graph

AI Register & Model Registry / Factsheets

0% of use cases

AI register & model registry: central inventory of every model, agent, RAG pipeline and embedded third-party SaaS AI across the estate, with factsheets per asset. v2.0 duty: every application — internal, open-source or procured — continuously publishes a machine-readable AI-BOM and Factsheet into the register; an asset without a current AI-BOM is an inventory gap, not a formality. Feeds Colorado AIA/ LL144 disclosure duties and the Art. 11 technical file; the enforcement backstop is Shadow-AI discovery on the risk register.

  • named in regulationNew York RAISE Act → AI Register & Model Registry / FactsheetsSafety plans and model provenance are recorded per frontier model in the AI/model register.

Live Risk Register / Posture Management

0% of use cases

Continuously updated risk register wired to runtime posture: threat-model deltas, open defects, control status, exposure per system. Includes Shadow-AI discovery — continuous scanning for unsanctioned agents, MCP servers and AI API usage outside the register; an unregistered agent is an unmanaged Art. 12/26 liability and the empirical driver of proportionate (not blanket) controls.

  • named in regulationNew York RAISE Act → Live Risk Register / Posture ManagementFrontier-model safety findings feed the live risk register of the deploying organisation.

Unified Incident-Response Runbook

0% of use cases

One procedure reconciling AI Act Art. 73, GDPR Art. 33 (72h), DORA and NIS2 (24h/72h) timelines and recipients.

  • named in regulationNew York RAISE Act → Unified Incident-Response RunbookSafety-incident disclosure duties require a runbook with defined notification paths to the NY AG.

Vendor & Model Due-Diligence Kit

0% of use cases

Scoring model: jurisdiction (CLOUD Act exposure), zero-data-retention, BYOK support, audit evidence (C5/AIC4/ISO 42001/EN 18286:2026), tenant isolation.

  • named in regulationNew York RAISE Act → Vendor & Model Due-Diligence KitFrontier-model sourcing: safety-plan and audit evidence must be collected from the developer during due diligence.