Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 78 profiles

Where do you stand? › Route 3 · Vendors & stack

I know which systems I need — who supplies them?

Pick the components you have to put in place. For each one you get the build-vs-buy reading and the market layer that supplies it, with the same scored recommendations and confidence the full analysis uses. Nothing is stored; the selection lives in the URL.

Target market(s)European UnionUnited States (federal)change

Legally-driven components are flagged when their requiring regulation sits outside your selected markets.

Target market(s)

Where will this system be used or placed on the market? The conclusion is derived for these jurisdictions — instruments that bind only elsewhere are left out.

Europe
North America
Latin America
Asia-Pacific
Middle East
Africa

Selected: European Union, United States (federal) · thin-coverage jurisdictions need verification

density

Step 1 of 2 — pick your components1 selected

Document Intelligence Engine
Two-Tier Air-Gapped De-Identification Ingestion (3)
Deterministic Circuit Breaker with Reversible Shadow Execution (3)
Grounded Citational RAG (5)
Deterministic Document-Validation Pipeline (3)
Dual-Agent Guardian Topology (4)
Hardened Edge / IoT Pattern (3)
Constrained GAM with Differential-Privacy Tokenisation (2)
Glass-Box EBM with Monotonic Constraints (2)
Guarded RAG Pattern (2)
Human-in-the-Loop Core Pattern (1)
Tiered-Confidence Moderation Queue (1)
Agentic RDA Stack (6 Layers) (3)
Sandboxed Execution with SAST Gates (1)
Sovereign Resilient Enterprise Pattern (5)
Four-Layer TRiSM Enterprise Stack (2)
Cross-cutting components (22)

Step 2 of 2 — the vendor & stack view

1 of 1 selected components are covered by 2 market layers.

Named vendors are community-maintained, disputable examples — not an endorsement. The stable object is the market layer. Compare with the reference stack for your regulatory profile →

Build or buy, per component (1)

Document Intelligence Engine buy (products exist)
A Grounding, Retrieval & Agent Memory / Agentic Applications & Copilots product can carry this; the buyer's duties stay with you.

Agentic Applications & Copilots — covers 1 of your components

Covers: Document Intelligence Engine. This layer supplies 4 components in the graph.
Confidence: moderate (67/100)
Community-maintained examples
GitHub Copilot · Microsoft 365 Copilot · Perplexity Enterprise · Cursor · Dropzone AI · Devin (Cognition) · Vanta · Fin (Intercom) · SAP
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
GitHub Copilotdeveloper copilotCode completion and agent modes inside the IDE and repository workflow. Typical: software engineering, code review.not checkedSOC 2 (claimed)enterprise data-handling commitments (claimed)
Microsoft 365 Copilotproductivity copilotAssistant across mail, documents and meetings inheriting existing tenant permissions. Typical: knowledge work, meeting summaries.not checkedISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning
Perplexity Enterpriseresearch assistantCited web and internal search with source attribution per answer. Typical: market research, citation-backed search.not checkedSOC 2 (claimed)enterprise data-handling commitments (claimed)
Cursordeveloper copilotAI-native editor with repository-wide agent edits. Typical: software engineering, refactoring.not checkedSOC 2 (claimed)privacy-mode option (claimed)
Dropzone AIsecurity operations agentAutonomous triage of security alerts with written investigation records. Typical: SOC triage, incident write-ups.not checkedSOC 2 (claimed)
Devin (Cognition)autonomous software agentLong-running software agent taking tickets to pull requests. Typical: software engineering, backlog automation.not checkedvendor-stated security posture
Vantacompliance automationContinuous control monitoring and evidence collection across frameworks. Typical: evidence automation, audit readiness.not checkedSOC 2 (claimed)ISO 27001/42001 evidence workflows (claimed)
Fin (Intercom)customer-service agentResolution-priced support agent answering from your help content. Typical: customer support, deflection.not checkedSOC 2 (claimed)GDPR-positioned
SAPembedded enterprise AIAI features and agents embedded in ERP, HR and procurement suites, governed through the vendor's own AI platform layer. Typical: embedded HR AI, procurement automation, finance automation.SaaS (vendor cloud)ISO/IEC 42001 certification claim (claimed)EU AI Act readiness positioning

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Select on
Permission model and identity scoping; audit log export; tenant data-handling and retention terms; deployer-duty support (disclosure, oversight, incident reporting); outcome pricing vs seat pricing.
Why this confidence
  • 1 in-scope component of this use case is supplied by this layer (Document Intelligence Engine) — a direct supplied_by path in the graph.
  • The catalog use-case match is strong, so the component set this layer was derived from is reliable.
  • High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
  • 9 community-maintained example vendors recorded on the layer node.
  • Selection metrics for this layer are documented, so the shortlist can be compared objectively.
  • Only 1 of 4 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
Alternatives
  • Grounding, Retrieval & Agent Memory — confidence moderate (66/100, -1 vs. this layer); overlapping coverage, no additional selected component

Grounding, Retrieval & Agent Memory — covers 1 of your components

Covers: Document Intelligence Engine. This layer supplies 8 components in the graph.
Confidence: moderate (66/100)
Community-maintained examples
Docling · LlamaParse · Amazon Textract · Diffbot · Firecrawl · Voyage AI · Nomic · Pinecone · Weaviate · Qdrant · Milvus · pgvector · Letta (MemGPT) · Mem0 · Zep · Cognee
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Doclingdocument parserOpen-source layout-aware parsing of PDFs and office formats into structured chunks. Typical: RAG ingestion, air-gapped pipelines.self-hostableEU sovereignty positioning
LlamaParsedocument parserManaged parsing service tuned for tables and complex documents feeding RAG. Typical: RAG ingestion, table extraction.not checkedSOC 2 (claimed)
Amazon Textractdocument parserOCR and form/table extraction with per-page pricing inside AWS. Typical: document intake, claims processing.not checkedSOC 2 (claimed)HIPAA-eligible (claimed)ISO 27001 (claimed)
Diffbotweb/knowledge extractionStructured extraction and knowledge-graph construction from web sources. Typical: market monitoring, entity resolution.not checkedvendor-stated security posture
Firecrawlweb/knowledge extractionCrawling and clean markdown extraction for grounding on public sources. Typical: regulatory monitoring, public-source grounding.not checkedvendor-stated security posture
Voyage AIembeddingsDomain-tuned embedding models including legal and finance variants. Typical: retrieval quality, domain RAG.not checkedvendor-stated security posture
NomicembeddingsOpen embedding models with local inference and dataset visualisation. Typical: on-prem retrieval, dataset inspection.self-hostable
Pineconevector databaseManaged serverless vector search with namespace isolation. Typical: tenant-isolated RAG, semantic search.not checkedSOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed)
Weaviatevector databaseVector database available managed or self-hosted with hybrid search. Typical: hybrid retrieval, self-hosted RAG.open sourceSOC 2 (claimed)
Qdrantvector databaseOpen-source vector store with payload filtering and on-prem deployment. Typical: air-gapped RAG, filtered retrieval.open sourceGDPR-positioned
Milvusvector databaseOpen-source vector database for very large collections. Typical: large-scale retrieval.open source
pgvectorvector databasePostgres extension keeping vectors under the same RBAC, backup and retention regime as records. Typical: record-bound retrieval, small-scale RAG.self-hostablerecord-retention alignment (claimed)
Letta (MemGPT)agent memory storePersistent agent memory with explicit memory blocks and editing. Typical: long-running agents, personalisation.self-hostable
Mem0agent memory storeMemory layer extracting durable facts from agent conversations. Typical: personalised agents, support copilots.not checkedvendor-stated security posture
Zepagent memory storeTemporal knowledge-graph memory with fact validity intervals. Typical: auditable memory, long-running agents.not checkedGDPR-positionedbitemporal record positioning
Cogneeagent memory storeOpen-source memory/knowledge pipeline building graphs from agent interactions. Typical: knowledge accumulation, research agents.self-hostable

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Select on
Parsing fidelity on your worst document class; retrieval precision/recall on a labelled set; tenant and ACL isolation model; per-vector encryption and erasure path; memory TTL and record semantics; self-host option.
Why this confidence
  • 1 in-scope component of this use case is supplied by this layer (Document Intelligence Engine) — a direct supplied_by path in the graph.
  • The catalog use-case match is strong, so the component set this layer was derived from is reliable.
  • High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
  • 16 community-maintained example vendors recorded on the layer node.
  • Selection metrics for this layer are documented, so the shortlist can be compared objectively.
  • Only 1 of 8 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
Alternatives
  • Agentic Applications & Copilots — confidence moderate (67/100, +1 vs. this layer); overlapping coverage, no additional selected component

Next step: Check which use cases this stack could carry →