Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles

Regulation coverage

Every regulation in the graph resolves into concrete technical components — through an article obligation, a control objective, a design pattern or an evidence artefact that a component must produce. Pick a regulation to see its technical surface, how each component is derived, and in which of the triggering use cases it is actually part of the required stack. The gap counts show where the graph reaches a component that no use case yet requires — those are open contribution targets, not settled answers. Open the full graph →

SEC Advisers Act Rule 204-2 (Books & Records)

source eCFR

Registered investment advisers must preserve records of recommendations, advisory communications and the data behind them. Where an AI agent evaluates portfolios, drafts client communications or generates recommendations, its inferences and prompts become advisory records that need an attribution chain to a named supervising person — generic system service accounts are not acceptable.

2 components0 articles / obligations2 triggering use casesopen in graph

Supervisor Attribution Chain

100% of use cases

Every model inference, data interaction and client-facing artefact is bound to an authorised supervising natural person — never to a shared service account. Required for SEC Rule 204-2 attribution, SOX segregation of duties and AI Act Art. 26 deployer oversight records.

  • named in regulationSEC Advisers Act Rule 204-2 (Books & Records) → Supervisor Attribution Chain

WORM / Immutable Audit Vault

100% of use cases

Append-only, hash-chained audit vault (WORM object-lock storage, AES-256 at rest, TLS 1.3 in transit). Guarantees tamper-evidence within the organization's trust domain — which stops your own team, but not an admin who can rebuild the vault. Pair with an external trust anchor and key ceremonies outside the operating team for evidence that holds against the insider scenario.

  • named in regulationSEC Advisers Act Rule 204-2 (Books & Records) → WORM / Immutable Audit Vault