Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 78 profiles

Where do you stand? › Route 3 · Vendors & stack

I know which systems I need — who supplies them?

Pick the components you have to put in place. For each one you get the build-vs-buy reading and the market layer that supplies it, with the same scored recommendations and confidence the full analysis uses. Nothing is stored; the selection lives in the URL.

Target market(s)European UnionUnited States (federal)change

Legally-driven components are flagged when their requiring regulation sits outside your selected markets.

Target market(s)

Where will this system be used or placed on the market? The conclusion is derived for these jurisdictions — instruments that bind only elsewhere are left out.

Europe
North America
Latin America
Asia-Pacific
Middle East
Africa

Selected: European Union, United States (federal) · thin-coverage jurisdictions need verification

density

Step 1 of 2 — pick your components4 selected

Output Rails / Groundedness CheckHITL Escalation Queue & Review UIWORM / Immutable Audit VaultInterface Transparency & Content-Marking Layer
Two-Tier Air-Gapped De-Identification Ingestion (3)
Deterministic Circuit Breaker with Reversible Shadow Execution (3)
Grounded Citational RAG (5)
Deterministic Document-Validation Pipeline (3)
Dual-Agent Guardian Topology (4)
Hardened Edge / IoT Pattern (3)
Constrained GAM with Differential-Privacy Tokenisation (2)
Glass-Box EBM with Monotonic Constraints (2)
Guarded RAG Pattern (2)
Human-in-the-Loop Core Pattern (1)
Tiered-Confidence Moderation Queue (1)
Agentic RDA Stack (6 Layers) (3)
Sandboxed Execution with SAST Gates (1)
Sovereign Resilient Enterprise Pattern (5)
Four-Layer TRiSM Enterprise Stack (2)
Cross-cutting components (22)

Step 2 of 2 — the vendor & stack view

4 of 4 selected components are covered by 5 market layers.

Named vendors are community-maintained, disputable examples — not an endorsement. The stable object is the market layer. Compare with the reference stack for your regulatory profile →

Build or buy, per component (4)

HITL Escalation Queue & Review UI buy (products exist) KRCA
A Agent Orchestration & SDLC Toolkits product can carry this; the buyer's duties stay with you.
Required by: AI Framework Act (KR), Quebec Law 25 (CA) in forcein force
Legally required in KR, CA — none of your selected markets carry this driver; treat it as a market-specific requirement, not a universal one. Help verify coverage →
Interface Transparency & Content-Marking Layer buy (products exist) CNIN
A Runtime Security & Guardrail Vendors / Public Transparency Registers & System Cards product can carry this; the buyer's duties stay with you.
Required by: AI-Generated Synthetic Content Labeling Measures (CN), IT Act 2000 + Intermediary Guidelines 2021 (IN) in forcein force
Legally required in CN, IN — none of your selected markets carry this driver; treat it as a market-specific requirement, not a universal one. Help verify coverage →
Output Rails / Groundedness Check buy (products exist) GBCN
A Runtime Security & Guardrail Vendors / Runtime Guardrails & Enforcement product can carry this; the buyer's duties stay with you.
Required by: Crime and Policing Act 2026 (GB), Interim Measures for Generative AI Services (CN), Online Safety Act 2023 (GB) unverified — help verifyin forcein force
Legally required in GB, CN — none of your selected markets carry this driver; treat it as a market-specific requirement, not a universal one. Help verify coverage →
WORM / Immutable Audit Vault buy (products exist) EUDEthinUS
A Cryptographic Evidence & Audit Ledger product can carry this; the buyer's duties stay with you.
Required by: AI Liability Directive (withdrawn), BaFin MaRisk (Mindestanforderungen an das Risikomanagement), Bank Secrecy Act / FinCEN Program Rules, FINRA Rule 4511 (General Books & Records), Revised Product Liability Directive, SEC Rule 17a-4 (US Records Retention) withdrawn — no longer lawin forcein forcein forcein forcein force
Legally required in EU, US (your selected markets); also required in DE, which you have not selected. Help verify coverage →

Runtime Security & Guardrail Vendors — covers 2 of your components

Covers: Output Rails / Groundedness Check, Interface Transparency & Content-Marking Layer. This layer supplies 7 components in the graph.
Confidence: strong (81/100)
Community-maintained examples
Lakera · HiddenLayer · Palo Alto Prisma AIRS · Cisco AI Defense · NVIDIA NeMo Guardrails · Guardrails AI · Garak · Protect AI
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Lakeraguardrail proxyInline prompt-injection and content detection at request time. Typical: injection defence, content filtering.not checkedSOC 2 (claimed)supports Art. 15 robustness measures (claimed)
HiddenLayermodel/agent detection & responseModel-layer detection and response with adversarial-attack telemetry. Typical: model threat detection, red-team telemetry.not checkedSOC 2 (claimed)supports Art. 15 robustness measures (claimed)
Palo Alto Prisma AIRSnetwork-integrated AI securityAI runtime security folded into an existing enterprise network security estate. Typical: enterprise rollout, egress control.not checkedSOC 2 (claimed)enterprise security integration (claimed)
Cisco AI Defensenetwork-integrated AI securityDiscovery of AI usage plus inline enforcement across the corporate network. Typical: shadow-AI discovery, inline enforcement.not checkedenterprise security integration (claimed)
NVIDIA NeMo Guardrailsopen guardrail frameworkProgrammable dialogue and action rails, self-hostable alongside your models. Typical: dialogue rails, action gating.open sourcesupports Art. 15 robustness measures (claimed)
Guardrails AIopen guardrail frameworkOpen validator library for structured output checks and policy validators. Typical: output validation, schema enforcement.open sourceOSS, no vendor certification
Garakadversarial scannerOpen-source LLM vulnerability scanner used for pre-deployment probing. Typical: red-teaming, release gating.not checkedOSS, no vendor certificationsupports Art. 15 testing evidence (claimed)
Protect AIML supply-chain & model securityModel scanning and ML supply-chain security tooling (Palo Alto Networks acquisition reported 2025). Typical: model scanning, supply-chain security.SaaS (vendor cloud)supports Art. 15 cybersecurity measures (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Select on
single-pass parallel evaluation latency (<20 ms class), injection/hallucination catch rates, SecOps/SIEM routing, policy versioning surfaced into the AI-BOM
Why this confidence
  • 2 in-scope components of this use case are supplied by this layer (Output Rails / Groundedness Check, Interface Transparency & Content-Marking Layer) — a direct supplied_by path in the graph.
  • The catalog use-case match is strong, so the component set this layer was derived from is reliable.
  • High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
  • 8 community-maintained example vendors recorded on the layer node.
  • Selection metrics for this layer are documented, so the shortlist can be compared objectively.
  • Only 2 of 7 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
Alternatives
  • Public Transparency Registers & System Cards — confidence strong (70/100, -11 vs. this layer); overlapping coverage, no additional selected component
  • Cryptographic Evidence & Audit Ledger — confidence moderate (68/100, -13 vs. this layer); also covers: WORM / Immutable Audit Vault

Public Transparency Registers & System Cards — covers 1 of your components

Covers: Interface Transparency & Content-Marking Layer. This layer supplies 2 components in the graph.
Confidence: strong (70/100)
Community-maintained examples
Saidot
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Saidotpublic AI registerAI register with published system cards and regulation-mapped documentation workflows. Typical: public AI register, system cards. Scope overlap: Its documentation and register scope overlaps this platform's own; we have a commercial interest in the comparison.SaaS (vendor cloud)EU AI Act documentation positioningISO 42001 alignment (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Select on
Versioning of published statements against the system version they describe; whether a card is generated from your governance record or re-authored by hand; language coverage and accessibility of the published surface; export and self-hosting of the public register; whether unpublishing leaves an auditable trail.
Why this confidence
  • 1 in-scope component of this use case is supplied by this layer (Interface Transparency & Content-Marking Layer) — a direct supplied_by path in the graph.
  • This layer's graph purpose overlaps strongly with your scope (1 of 2 components it supplies are in scope).
  • The catalog use-case match is strong, so the component set this layer was derived from is reliable.
  • High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
  • 1 community-maintained example vendor recorded on the layer node.
  • Selection metrics for this layer are documented, so the shortlist can be compared objectively.
Alternatives
  • Runtime Security & Guardrail Vendors — confidence strong (81/100, +11 vs. this layer); also covers: Output Rails / Groundedness Check
  • Cryptographic Evidence & Audit Ledger — confidence moderate (68/100, -2 vs. this layer); also covers: WORM / Immutable Audit Vault

Cryptographic Evidence & Audit Ledger — covers 1 of your components

Covers: WORM / Immutable Audit Vault. This layer supplies 3 components in the graph.
Confidence: moderate (68/100)
Community-maintained examples
Fact0 · Traccia
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Fact0cryptographic evidence ledgerPositions itself as a tamper-evident ledger for AI decision records. Typical: decision records, audit trail.not checkedsupports Art. 12 record-keeping (claimed)
Tracciaaudit trail & traceabilityPositions itself around traceability of AI pipeline steps and artefacts. Typical: traceability, artifact lineage.not checkedsupports Art. 12 record-keeping (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Select on
Append-only guarantees and who can rotate or delete (including the vendor); anchoring mechanism (qualified timestamp, transparency log, notarisation) and whether verification works without the vendor; retention and export in a readable format at end of contract; throughput and cost at your event volume.
Why this confidence
  • 1 in-scope component of this use case is supplied by this layer (WORM / Immutable Audit Vault) — a direct supplied_by path in the graph.
  • The catalog use-case match is strong, so the component set this layer was derived from is reliable.
  • High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
  • 2 community-maintained example vendors recorded on the layer node.
  • Selection metrics for this layer are documented, so the shortlist can be compared objectively.
  • Only 1 of 3 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
Alternatives
  • Runtime Security & Guardrail Vendors — confidence strong (81/100, +13 vs. this layer); also covers: Output Rails / Groundedness Check, Interface Transparency & Content-Marking Layer
  • Public Transparency Registers & System Cards — confidence strong (70/100, +2 vs. this layer); also covers: Interface Transparency & Content-Marking Layer

Agent Orchestration & SDLC Toolkits — covers 1 of your components

Covers: HITL Escalation Queue & Review UI. This layer supplies 4 components in the graph.
Confidence: moderate (67/100)
Community-maintained examples
LangChain / LangGraph · LlamaIndex · Microsoft AutoGen · CrewAI · DSPy · Semantic Kernel · PydanticAI · Model Context Protocol (MCP) · E2B · Airia
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
LangChain / LangGraphagent frameworkGraph-structured agent runtime; interrupt/pause nodes support implementing human approval at defined steps. Typical: multi-step agents, approval workflows.not checkedsupports implementing Art. 14 oversight (claimed)supports Art. 12 step logging (claimed)
LlamaIndexRAG frameworkIndexing and query abstractions over documents and structured sources. Typical: enterprise RAG, document agents.open sourceretrieval-governance positioning
Microsoft AutoGenmulti-agent frameworkConversational multi-agent patterns with pluggable tool executors. Typical: multi-agent research, code agents.not checkedresearch/OSS, no vendor certification
CrewAImulti-agent frameworkRole-based agent teams with task delegation and process templates. Typical: process automation, role-based agents.not checkedvendor-stated security posture
DSPyprompt/program optimisationDeclarative programs with optimisers that make prompt changes reproducible and testable. Typical: evaluated pipelines, model validation.not checkedmodel-validation positioning (SR 11-7 style, claimed)
Semantic Kernelenterprise SDKMicrosoft SDK for planners and plugins inside .NET/Java estates. Typical: enterprise copilots, tool plugins.not checkedenterprise-estate integration (claimed)
PydanticAItyped agent SDKType-validated agent outputs and tool signatures for deterministic contracts. Typical: structured outputs, typed tool calls.not checkedschema-enforcement positioning
Model Context Protocol (MCP)protocol / standardOpen protocol for tool and context exposure; a protocol, not a product — governance sits in the gateway around it. Typical: tool interoperability, gateway mediation.not checkedopen protocol, no certification
E2Bsandboxed runtimeEphemeral cloud sandboxes for agent code execution with isolation per task. Typical: code agents, untrusted execution.not checkedisolation/sandbox positioning
Airiaenterprise agent platformEnterprise platform for building and running agents with connector, policy and routing layers. Typical: agent orchestration, internal copilots.SaaS (vendor cloud)EU AI Act readiness positioningSOC 2 programme positioning (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Select on
broad model-API abstraction, state/memory management, error recovery, fallback routing hooks
Why this confidence
  • 1 in-scope component of this use case is supplied by this layer (HITL Escalation Queue & Review UI) — a direct supplied_by path in the graph.
  • The catalog use-case match is strong, so the component set this layer was derived from is reliable.
  • High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
  • 10 community-maintained example vendors recorded on the layer node.
  • Selection metrics for this layer are documented, so the shortlist can be compared objectively.
  • Only 1 of 4 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
Alternatives
  • Runtime Security & Guardrail Vendors — confidence strong (81/100, +14 vs. this layer); also covers: Output Rails / Groundedness Check, Interface Transparency & Content-Marking Layer
  • Public Transparency Registers & System Cards — confidence strong (70/100, +3 vs. this layer); also covers: Interface Transparency & Content-Marking Layer

Runtime Guardrails & Enforcement — covers 1 of your components

Covers: Output Rails / Groundedness Check. This layer supplies 4 components in the graph.
Confidence: moderate (67/100)
Community-maintained examples
Guardrails AI · NVIDIA NeMo Guardrails · Lakera AI · Credal AI
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Guardrails AIvalidation frameworkOpen-source validator framework for structured output and content policies in the request path. Typical: output validation, structured output.open sourcesupports Art. 15 robustness measures (claimed)
NVIDIA NeMo Guardrailsdialogue policy railsProgrammable dialogue and topic rails placed around an LLM application. Typical: topic control, dialogue policy.open sourcesupports Art. 50 interaction disclosure patterns (claimed)
Lakera AIguardrail proxyInline prompt-injection and content detection at request time. Typical: injection defence, content filtering.SaaS (vendor cloud)SOC 2 (claimed)supports Art. 15 robustness measures (claimed)
Credal AIenterprise access & policy layerPermission-aware access layer with data-loss controls in front of enterprise assistants. Typical: access control, DLP.SaaS (vendor cloud)SOC 2 (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Select on
Where enforcement sits (inline proxy, sidecar, SDK) and the added latency at your token volumes; whether policy is versioned and testable as code; fail-open vs. fail-closed behaviour under guardrail outage; language and modality coverage; whether every block writes an evidence record you can cite later.
Why this confidence
  • 1 in-scope component of this use case is supplied by this layer (Output Rails / Groundedness Check) — a direct supplied_by path in the graph.
  • The catalog use-case match is strong, so the component set this layer was derived from is reliable.
  • High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
  • 4 community-maintained example vendors recorded on the layer node.
  • Selection metrics for this layer are documented, so the shortlist can be compared objectively.
  • Only 1 of 4 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
Alternatives
  • Runtime Security & Guardrail Vendors — confidence strong (81/100, +14 vs. this layer); also covers: Interface Transparency & Content-Marking Layer
  • Public Transparency Registers & System Cards — confidence strong (70/100, +3 vs. this layer); also covers: Interface Transparency & Content-Marking Layer

Next step: Check which use cases this stack could carry →