Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 78 profiles

Where do you stand? › Route 3 · Vendors & stack

I know which systems I need — who supplies them?

Pick the components you have to put in place. For each one you get the build-vs-buy reading and the market layer that supplies it, with the same scored recommendations and confidence the full analysis uses. Nothing is stored; the selection lives in the URL.

Target market(s)European UnionUnited States (federal)change

Legally-driven components are flagged when their requiring regulation sits outside your selected markets.

Target market(s)

Where will this system be used or placed on the market? The conclusion is derived for these jurisdictions — instruments that bind only elsewhere are left out.

Europe
North America
Latin America
Asia-Pacific
Middle East
Africa

Selected: European Union, United States (federal) · thin-coverage jurisdictions need verification

density

Step 1 of 2 — pick your components1 selected

Multi-Region Failover & Resilience Testing
Two-Tier Air-Gapped De-Identification Ingestion (3)
Deterministic Circuit Breaker with Reversible Shadow Execution (3)
Grounded Citational RAG (5)
Deterministic Document-Validation Pipeline (3)
Dual-Agent Guardian Topology (4)
Hardened Edge / IoT Pattern (3)
Constrained GAM with Differential-Privacy Tokenisation (2)
Glass-Box EBM with Monotonic Constraints (2)
Guarded RAG Pattern (2)
Human-in-the-Loop Core Pattern (1)
Tiered-Confidence Moderation Queue (1)
Agentic RDA Stack (6 Layers) (3)
Sandboxed Execution with SAST Gates (1)
Sovereign Resilient Enterprise Pattern (5)
Four-Layer TRiSM Enterprise Stack (2)
Cross-cutting components (22)

Step 2 of 2 — the vendor & stack view

1 of 1 selected components are covered by 1 market layer.

Named vendors are community-maintained, disputable examples — not an endorsement. The stable object is the market layer. Compare with the reference stack for your regulatory profile →

Build or buy, per component (1)

Multi-Region Failover & Resilience Testing buy (products exist) EU
A Sovereign Infrastructure product can carry this; the buyer's duties stay with you.
Required by: DORA in force

Sovereign Infrastructure — covers 1 of your components

Covers: Multi-Region Failover & Resilience Testing. This layer supplies 3 components in the graph.
Confidence: moderate (68/100)
Community-maintained examples
OVHcloud · Scaleway · STACKIT · AWS European Sovereign Cloud · Microsoft Azure EU Data Boundary · Google Cloud Sovereign Controls · Groq · CoreWeave · Lambda Labs · Together AI · Fireworks AI · Baseten · Modal · Replicate · Anyscale
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
OVHcloudnative EUFrench provider with EU-only jurisdiction and a narrower managed-AI catalog than the hyperscalers. Typical: EU-resident inference, regulated workload hosting.not checkedISO 27001 (claimed)SecNumCloud-positionedGDPR-positioned
Scalewaynative EUEU-operated cloud with GPU instances and managed inference under French corporate control. Typical: EU-resident inference, fine-tuning.not checkedISO 27001 (claimed)GDPR-positioned
STACKITnative EUGerman provider (Schwarz Group) positioned for data residency in Germany. Typical: public sector, retail data platforms.not checkedC5-positionedGDPR-positioned
AWS European Sovereign Cloudsovereign hyperscalerSeparately operated EU region set with EU-resident personnel and keys; full hyperscaler catalog. Typical: large-scale enterprise AI, regulated hosting.not checkedISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning
Microsoft Azure EU Data Boundarysovereign hyperscalerEU processing and storage boundary across Azure and Copilot services with confidential-compute options. Typical: enterprise copilots, regulated hosting.not checkedISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning
Google Cloud Sovereign Controlssovereign hyperscalerPartner-operated and data-boundary variants with external key management. Typical: regulated analytics, EU-resident inference.not checkedISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning
Groqspecialized GPU / acceleratorLPU inference hardware marketed on deterministic low latency rather than training throughput. Typical: low-latency agents, real-time decisioning.not checkedSOC 2 (claimed)
CoreWeavespecialized GPU / acceleratorGPU-dense cloud for training and high-throughput inference with dedicated capacity contracts. Typical: model training, batch inference.not checkedSOC 2 (claimed)ISO 27001 (claimed)
Lambda Labsspecialized GPU / acceleratorGPU cloud and on-prem clusters aimed at research and fine-tuning workloads. Typical: fine-tuning, research clusters.not checkedSOC 2 (claimed)
Together AIinference platformHosted open-weight model inference and fine-tuning with per-token pricing. Typical: open-weight inference, fine-tuning.not checkedSOC 2 (claimed)open-weight sovereignty positioning
Fireworks AIinference platformOptimised serving of open-weight models with function-calling and structured output support. Typical: agent tool-calling, high-QPS inference.not checkedSOC 2 (claimed)HIPAA-eligible (claimed)
Baseteninference platformModel deployment platform with autoscaling endpoints and VPC deployment options. Typical: custom model serving, VPC-isolated inference.not checkedSOC 2 (claimed)HIPAA-eligible (claimed)
Modalserverless computeServerless GPU execution for jobs, batch pipelines and sandboxed agent tasks. Typical: batch pipelines, sandboxed execution.not checkedSOC 2 (claimed)
Replicateserverless computeAPI-first hosting of community and custom models, priced per run. Typical: prototyping, multimodal inference.not checkedvendor-stated security posture
Anyscaleserverless computeManaged Ray for distributed training, serving and multi-step agent workloads. Typical: distributed training, agent fan-out.not checkedSOC 2 (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Select on
jurisdiction of the control plane (not only the data plane), operator nationality and support-access paths, key custody, C5 / C3A / SecNumCloud attestation scope, managed-AI service depth vs. isolation trade-off, exit and repatriation terms
Why this confidence
  • 1 in-scope component of this use case is supplied by this layer (Multi-Region Failover & Resilience Testing) — a direct supplied_by path in the graph.
  • The catalog use-case match is strong, so the component set this layer was derived from is reliable.
  • High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
  • 15 community-maintained example vendors recorded on the layer node.
  • Selection metrics for this layer are documented, so the shortlist can be compared objectively.
  • Only 1 of 3 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.

Next step: Check which use cases this stack could carry →