Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles

Sources & Verification

Every claim in this tool resolves to one of the source layers below, and every legal or standards node carries — or visibly lacks — a verification date. Nothing here is backdated to look authoritative. If a node has no verification date, the badge on it says so.

69 claims still need a dated source. The worklist is public and each item is a small, self-contained task. Help verify the graph →
Graph v2.1.2 · 2026-08-07 · 7 source layers · 5 monitored feeds

Source layers

1
European AI Regulation, Standards Landscape & Compliance Frameworks (systematic analysis)

The regulation and standards backbone: which legal acts exist, which bodies issue them, and how the AI Act interlocks with the wider digital acquis.

2
Compliance by Design in European AI System Architectures (decision handbook)

The architectural translation: how an obligation becomes a concrete design decision rather than a policy document.

3
System Architecture & Regulatory Design for Agentic AI (RDA framework)

The agentic layer: autonomy degrees, the four-mode oversight taxonomy and the regulatory design constraints specific to agents.

4
Regulated AI in Europe & USA — A Practitioner's Guide (book: two-dimensional compliance map, use-case catalogues, seven-layer reference architecture)

The two-dimensional compliance map, the sector use-case catalogues and the seven-layer reference architecture the profiles are derived from.

5
Architectural Paradigms for Regulated Agentic AI (July 2026): US state-law patchwork, Art. 6(3) filter, cryptographic logging, Trinity Defense / Guardian Agents / HITL production patterns

The US state-law patchwork, the Art. 6(3) filter, cryptographic logging and the production oversight patterns (Trinity Defense, Guardian Agents, HITL).

6
Strategic Evaluation of Service-as-a-Software AI Workflows in Regulated Markets (Aug 2026): productized-service operating model, vertical workflow taxonomy, four-stage compliant pipeline, ISO 42001 AIMS control loop, mandatory compliance-artifact set, four-phase roadmap.

The Service-as-a-Software operating model: the four-stage compliant pipeline, the ISO 42001 control loop, the mandatory artifact set and the rollout roadmap.

7
Service as Software in Regulated Enterprise Ecosystems — autonomous agentic workflows, regulatory compliance and outcome-based scaling (community input, Aug 2026)

Community input on outcome-based scaling of autonomous agentic workflows in regulated enterprise ecosystems.

How we verify

Principle: Every legal act and standard in this graph is a moving target. A node without a lastVerified date is a claim, not a fact.

Process: Quarterly deepsearch sweep over all nodes with status fields + event-driven re-verification whenever (a) a community dispute is opened on a node, (b) a monitored feed reports a change touching a node's source, or (c) a release is prepared. Each sweep bumps lastVerified even when nothing changed — absence of change is also a finding.

When something changes: When a node's status changes (e.g. prEN → EN published, or an article amended by an Omnibus), all edges incident to that node are flagged 'review-pending' for the next curator pass; profile derivations show a currency warning until cleared.

Monitored feeds

Re-verification is driven by these feeds plus any community dispute opened on a node.

Currency coverage — the honest number

20 / 89legal & standards claims with a verification date (22%)
20 / 89with a lifecycle status (22%)
0verified more than 120 days ago (due for re-sweep)
13 / 26evidence artefacts declaring a verifiability level (50%)

The remaining claims are published as unverified rather than given an invented date. That is a deliberate choice: an unverified badge is information, a fabricated date is not. See the per-node worklist → The graph in numbers →

Auditing a single claim

Open any entry in the graph explorer to see its status, verification date, status note and every edge that derives from it. Disagree with it? Dispute it from its detail panel — a dispute triggers re-verification and is recorded in the changelog. Curators run the deep-search sweep that keeps these dates moving.

References

Every legal instrument and standard the graph relies on, listed in full and generated from the graph itself — so this chapter cannot drift from what the tool actually reasons over. Articles are nested under their parent act. 57 of 89 entries resolve to a primary public source; the rest carry no link because no authoritative URL pattern applies, not because none was looked for.

38 instruments · 21 articles · 30 standards · citation coverage in numbers →

European Union

  1. AILD — COM(2022) 496, withdrawn
    AI Liability Directive (withdrawn) · withdrawn · verified 2026-08-07 · no public source resolved
  2. AML Package (AMLR/AMLA)
    AML Package (AMLR/AMLA) · no verification date · no public source resolved
  3. CSDDD (Corporate Sustainability Due Diligence) · no verification date · EUR-Lex
  4. Cyber Resilience Act · no verification date · EUR-Lex
  5. Data Act · no verification date · EUR-Lex
  6. Data Governance Act · no verification date · EUR-Lex
  7. Digital Services Act · no verification date · EUR-Lex
  8. DORA · no verification date · EUR-Lex
  9. European Health Data Space Regulation
    EHDS · no verification date · no public source resolved
  10. eIDAS 2 (EUDI / Trust Services) · in-force · verified 2026-08-04 · EUR-Lex
  11. ePrivacy Directive · no verification date · EUR-Lex
  12. EU AI Act · no verification date · EUR-Lex
  13. GDPR · no verification date · EUR-Lex
  14. General Product Safety Regulation · no verification date · EUR-Lex
  15. Machinery Regulation · no verification date · EUR-Lex
  16. MDR / IVDR · no verification date · EUR-Lex
  17. NIS2 Directive · no verification date · EUR-Lex
  18. Revised Product Liability Directive · no verification date · EUR-Lex
  19. Unfair Commercial Practices Directive · no verification date · EUR-Lex

United States

  1. Bank Secrecy Act / FinCEN Program Rules · no verification date · Cornell LII
  2. CFAA & Anti-Scraping Regimes · no verification date · Cornell LII
  3. Colorado SB 24-205
    Colorado AI Act · no verification date · no public source resolved
  4. ECOA / CFPB Adverse-Action Regime
    ECOA / CFPB Adverse-Action Regime · no verification date · no public source resolved
  5. EEOC / Title VII Algorithmic Fairness (US) · no verification date · eCFR
  6. FINRA Rule 4511
    FINRA Rule 4511 (General Books & Records) · no verification date · no public source resolved
  7. FTC Act §5 & Endorsement / AI-Claims Guidance
    FTC Act §5 & Endorsement / AI-Claims Guidance · in-force · verified 2026-08-06 · no public source resolved
  8. HIPAA (US Health Privacy)
    HIPAA (US Health Privacy) · in-force · verified 2026-08-04 · no public source resolved
  9. New York RAISE Act
    New York RAISE Act · no verification date · no public source resolved
  10. NYC Local Law 144 (AEDT)
    NYC Local Law 144 (AEDT) · no verification date · no public source resolved
  11. Sarbanes-Oxley Act (SOX §302 / §404) · in-force · verified 2026-08-06 · Cornell LII
  12. SEC Advisers Act Rule 204-2 (Books & Records) · in-force · verified 2026-08-06 · eCFR
  13. SEC Predictive Data Analytics Rules (withdrawn 2025)
    SEC Predictive Data Analytics Rules (withdrawn 2025) · withdrawn · verified 2026-08-07 · no public source resolved
  14. SEC Regulation Best Interest · in-force · verified 2026-08-06 · eCFR
  15. SEC Rule 17a-4 (US Records Retention) · no verification date · eCFR
  16. Sector Safety Regimes (EASA / ERA / NERC CIP)
    Sector Safety Regimes (EASA / ERA / NERC CIP) · no verification date · no public source resolved
  17. TCPA / FCC AI-Voice Rules (US) · no verification date · Cornell LII
  18. USA PATRIOT Act §326 (CIP) · in-force · verified 2026-08-06 · eCFR

National & international

  1. National Tax Codes & OECD BEPS / Pillar Two
    National Tax Codes & OECD BEPS / Pillar Two · in-force · verified 2026-08-06 · no public source resolved

Standards & frameworks

ISO/IEC
  • AI risk-management guidance extending ISO 31000 — feeds the Art. 9 risk-management system.

    open in graph · no verification date · ISO
  • Robustness assessment of neural networks incl. formal methods (part 2) — supports Art. 15 evidence.

    open in graph · no verification date · ISO
  • Information-security management; control A.8.28 (secure coding) is the natural anchor for AI code-generation and QA workflows alongside ISO 42001.

    open in graph · no verification date · ISO
  • ISO/IEC 42001:2023 — certifiable AI management system (Annex SL harmonized structure, PDCA logic, synergy discount when an ISO 27001 ISMS exists). Clauses 4–10 plus Annex A controls (control count 38 vs 39 is a live community dispute — counting method differs by edition/guide). Covers an estimated 40–50% of AI Act organizational duties; organizational certificate, no product presumption of conformity.

    open in graph · published · verified 2026-08-04 · ISO
  • Guidance for AI system impact assessments — supports DPIA/FRIA-style analyses.

    open in graph · no verification date · ISO
  • Requirements for bodies auditing/certifying AIMS — accreditation basis (e.g. DAkkS) for ISO 42001 certificates.

    open in graph · no verification date · ISO
  • Five-part data-quality framework (governance, process, management) — direct evidence path for Art. 10 representativeness and completeness.

    open in graph · no verification date · ISO
  • Assessment of machine-learning classification performance: standardized metrics, test-set discipline, reporting format. The metric backbone for Art. 15 'declared accuracy' — test reports that cite it are comparable across vendors and audits.

    open in graph · published · verified 2026-08-04 · ISO
CEN/CENELEC
  • EN 18286:2026 (QMS for AI Act)

    Harmonised-norm candidate translating Art. 17 QMS into a product-focused governance framework; mappings to ISO 9001 and ISO/IEC 42001 Annex A (Annexes C & D); published as EN 18286:2026 in July 2026, OJEU citation (and with it the presumption of conformity) still pending.

    open in graph · published · verified 2026-08-04 · no public source resolved
  • Published terminology and concepts standard — the shared vocabulary layer for documentation and audits.

    open in graph · no verification date · ISO
  • Specifies event logging in AI systems — the concrete implementation target for Art. 12 record-keeping.

    open in graph · formal-vote · verified 2026-08-04 · ISO
  • JTC 21 Technical Package (prEN 18228/18229/18281–83)

    CEN-CENELEC JTC 21 technical package under standardisation request M/593 (prEN 18228 trustworthiness, 18229 risk management, 18281–83 CV/NLP evaluation et al.); staged drafts, none OJEU-cited yet — Annex III applicability (Dec 2027) is Omnibus-coupled to their availability.

    open in graph · draft · verified 2026-08-04 · no public source resolved
  • Transparency taxonomy for AI systems: structured disclosure of system composition, data provenance, capabilities and limitations. The harmonised-norm candidate backing Art. 13 instructions-for-use and deployer-information duties — defines what a complete transparency package must contain.

    open in graph · draft · verified 2026-08-04 · ISO
DIN
  • DIN SPEC 92001-1/-2/-3

    AI life-cycle quality metamodel: functionality, robustness (adversarial & corruption), traceability/explainability — German operationalisation for Art. 15.

    open in graph · no verification date · no public source resolved
BSI
  • BSI AIC4

    AI Cloud Service Compliance Criteria Catalogue: security & robustness, performance, reliability, data management, explainability, bias — audited via ISAE 3000; vendor trust evidence.

    open in graph · no verification date · no public source resolved
  • BSI C5:2026

    Cloud compliance catalogue (168 requirements): post-quantum crypto, confidential computing, container security — infrastructure evidence layer for NIS2/CRA/Art. 15; binding baseline from June 2027.

    open in graph · no verification date · no public source resolved
  • BSI GenAI Criteria Catalogue

    Criteria for integrating external generative models via API: named AI owner, central AI register, case-by-case risk analysis, multi-stage input/output validation, least privilege, prompt/permission separation.

    open in graph · no verification date · no public source resolved
NIST
  • NIST SP 800-218 (SSDF)

    Secure Software Development Framework: practices for provenance, review and vulnerability handling of generated and third-party code; SSDF-AI companion covers AI-assisted development.

    open in graph · no verification date · no public source resolved
OWASP
  • OWASP Agentic Security (AST10 / Core Risks)

    Threat framework for autonomous agents: tool misuse, excessive agency, confused-deputy, memory poisoning — with AIVSS scoring.

    open in graph · no verification date · no public source resolved
  • OWASP Top 10 for LLM Apps (2025)

    The de-facto technical security standard for GenAI applications; maps to Art. 10/14/15 and ISO 42001 Annex A controls.

    open in graph · no verification date · no public source resolved
ENISA
  • ENISA Multilayer Framework & AI Threat Landscape

    Three-layer good-practice model (cyber foundations → AI-specific → sectoral) and lifecycle threat landscape — the operational base for Art. 15 and CRA.

    open in graph · no verification date · no public source resolved
IEEE
  • IEEE CertifAIEd™

    Ethics certification (transparency, accountability, algorithmic bias, privacy) for products and professionals; interfaces with the EU ALTAI assessment list.

    open in graph · no verification date · no public source resolved
Coalition for Content Provenance and Authenticity
  • C2PA Content Credentials

    Open technical standard for cryptographically signed content provenance: manifests binding origin, toolchain and edit history to media assets. The de-facto machine-readable implementation path for Art. 50 synthetic-content marking (machine-readable format + detectability duty) — visible labels satisfy the human side, C2PA manifests the machine side. Verification at publication gates produces the disclosure evidence stream.

    open in graph · published · verified 2026-08-06 · no public source resolved
FAIR Institute
  • FAIR-AIR / FAIR-MAM

    AI extension of Factor Analysis of Information Risk: Expected Financial Loss = Loss Event Frequency (threat frequency × vulnerability) × Loss Magnitude (primary + secondary), run as Monte Carlo distributions — the standard bridge from technical AI failure modes to board-level monetary exposure.

    open in graph · no verification date · no public source resolved
Gartner
  • Gartner AI TRiSM

    AI Trust, Risk and Security Management — industry framework formalizing continuous AI oversight across four pillars: governance (inventory, AI-BOM, decision rights, change approval), trustworthiness & fairness (explainability, bias), reliability (drift, hallucination metrics), security management (prompt injection, model inversion, poisoning, leakage). No legal force; its value is the architecture it implies — the four-layer enterprise stack and the first/second-line separation this graph models as bp-trism and pat-lines-defense.

    open in graph · published · verified 2026-08-06 · no public source resolved
IASB / FASB
  • IFRS / US GAAP Reporting Assurance

    Recognition, measurement and disclosure rules that any AI-assembled financial statement, forecast or scenario model must satisfy. Model-generated figures need traceable inputs, documented assumptions and a reviewable reconciliation to the ledger before they enter a reporting cycle.

    open in graph · in-force · verified 2026-08-06 · no public source resolved
IMDA Singapore
  • IMDA Agentic AI Governance Framework (SG)

    Model AI Governance Framework for Agentic AI (Jan 2026, updated Jun 2026) — first state-issued agentic-specific guidance: bounded autonomy levels, action-space and interface restrictions, human-in-command checkpoints, automation-bias controls, logging & attribution expectations. No legal force in the EU, but the most concrete public benchmark for Art. 14-style oversight design of agent systems.

    open in graph · published · verified 2026-08-04 · no public source resolved
NIST (US)
  • NIST AI 600-1 (GenAI Profile)

    Companion profile to the AI RMF covering twelve GenAI-specific failure modes — confabulation, prompt injection, value-chain propagation and others — as the technical checklist behind Map/Measure for generative systems.

    open in graph · no verification date · no public source resolved
  • NIST AI RMF 1.0

    Govern–Map–Measure–Manage risk framework; Map/Measure functions populate the Art. 9 risk register with quantified values; the transatlantic mapping reference.

    open in graph · no verification date · no public source resolved
Open framework
  • TAGOF (Audit-as-Code)

    Operationalizes governance as code in CI/CD: policy-as-code enforcement, continuous runtime telemetry and automatically generated audit evidence — the execution layer that replaces periodic audits with continuous assurance.

    open in graph · no verification date · no public source resolved

How to cite RAIN

RAIN — Regulated AI Navigator, knowledge graph v2.1.2, 2026-08-07, rainavigator.org (accessed 2026-08-07).