Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 78 profiles

Where do you stand? › Route 3 · Vendors & stack

I know which systems I need — who supplies them?

Pick the components you have to put in place. For each one you get the build-vs-buy reading and the market layer that supplies it, with the same scored recommendations and confidence the full analysis uses. Nothing is stored; the selection lives in the URL.

Target market(s)European UnionUnited States (federal)change

Legally-driven components are flagged when their requiring regulation sits outside your selected markets.

Target market(s)

Where will this system be used or placed on the market? The conclusion is derived for these jurisdictions — instruments that bind only elsewhere are left out.

Europe
North America
Latin America
Asia-Pacific
Middle East
Africa

Selected: European Union, United States (federal) · thin-coverage jurisdictions need verification

density

Step 1 of 2 — pick your components4 selected

PII Scrubbing / DLP-NER LayerWORM / Immutable Audit VaultAI Register & Model Registry / FactsheetsSecure Boot & Hardened Runtime
Two-Tier Air-Gapped De-Identification Ingestion (3)
Deterministic Circuit Breaker with Reversible Shadow Execution (3)
Grounded Citational RAG (5)
Deterministic Document-Validation Pipeline (3)
Dual-Agent Guardian Topology (4)
Hardened Edge / IoT Pattern (3)
Constrained GAM with Differential-Privacy Tokenisation (2)
Glass-Box EBM with Monotonic Constraints (2)
Guarded RAG Pattern (2)
Human-in-the-Loop Core Pattern (1)
Tiered-Confidence Moderation Queue (1)
Agentic RDA Stack (6 Layers) (3)
Sandboxed Execution with SAST Gates (1)
Sovereign Resilient Enterprise Pattern (5)
Four-Layer TRiSM Enterprise Stack (2)
Cross-cutting components (22)

Step 2 of 2 — the vendor & stack view

2 of 4 selected components are covered by 4 market layers · 2 with no supplier layer in the graph.

Named vendors are community-maintained, disputable examples — not an endorsement. The stable object is the market layer. Compare with the reference stack for your regulatory profile →

Build or buy, per component (4)

AI Register & Model Registry / Factsheets buy (products exist) KRJPCNVNUS-NY
A AI GRC & Governance Platforms / Agent Observability & Model Risk Management / Public Transparency Registers & System Cards product can carry this; the buyer's duties stay with you.
Required by: AI Framework Act (KR), AI Promotion Act (JP), Algorithmic Recommendation Provisions (CN), Law on Digital Technology Industry (VN), New York RAISE Act, Standalone AI Law (VN) in forcein forcein forcein forceenacted — not yet applicablein force
Legally required in KR, JP, CN, VN, US-NY — none of your selected markets carry this driver; treat it as a market-specific requirement, not a universal one. Help verify coverage →
PII Scrubbing / DLP-NER Layer build in-house AEJPKEthinRWthinINBR+11
No market layer in the graph supplies this component — treat it as in-house engineering (or propose the missing supplier layer).
Required by: ADGM Data Protection Regulations 2021 (AE), APPI (JP), Data Protection Act 2019 (KE), Data Protection Law 058/2021 (RW), DIFC Data Protection Law No. 5/2020 (AE), DPDP Act 2023 (IN), LGPD 13.709/2018 (BR), Nigeria Data Protection Act 2023, PDP Law 27/2022 (ID), PDPA (SG), PDPL (SA), PIPA (KR), PIPEDA (CA), PIPL (CN), POPIA (ZA), Privacy Act 1988 + 2024 Amendment (AU), Revised FADP (CH), UK GDPR / DPA 2018 as amended by DUAA 2025 in forcein forceunverified — help verifyunverified — help verifyin forcein forcein forcein forcein forcein forcein forcein forcein forcein forcein forcein forcein forcein force
Legally required in AE, JP, KE, RW, IN, BR, NG, ID, SG, SA, KR, CA, CN, ZA, AU, CH, GB — none of your selected markets carry this driver; treat it as a market-specific requirement, not a universal one. Help verify coverage →
Secure Boot & Hardened Runtime build in-house EU
No market layer in the graph supplies this component — treat it as in-house engineering (or propose the missing supplier layer).
Required by: Cyber Resilience Act in force
WORM / Immutable Audit Vault buy (products exist) EUDEthinUS
A Cryptographic Evidence & Audit Ledger product can carry this; the buyer's duties stay with you.
Required by: AI Liability Directive (withdrawn), BaFin MaRisk (Mindestanforderungen an das Risikomanagement), Bank Secrecy Act / FinCEN Program Rules, FINRA Rule 4511 (General Books & Records), Revised Product Liability Directive, SEC Rule 17a-4 (US Records Retention) withdrawn — no longer lawin forcein forcein forcein forcein force
Legally required in EU, US (your selected markets); also required in DE, which you have not selected. Help verify coverage →

Public Transparency Registers & System Cards — covers 1 of your components

Covers: AI Register & Model Registry / Factsheets. This layer supplies 2 components in the graph.
Confidence: strong (70/100)
Community-maintained examples
Saidot
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Saidotpublic AI registerAI register with published system cards and regulation-mapped documentation workflows. Typical: public AI register, system cards. Scope overlap: Its documentation and register scope overlaps this platform's own; we have a commercial interest in the comparison.SaaS (vendor cloud)EU AI Act documentation positioningISO 42001 alignment (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Select on
Versioning of published statements against the system version they describe; whether a card is generated from your governance record or re-authored by hand; language coverage and accessibility of the published surface; export and self-hosting of the public register; whether unpublishing leaves an auditable trail.
Why this confidence
  • 1 in-scope component of this use case is supplied by this layer (AI Register & Model Registry / Factsheets) — a direct supplied_by path in the graph.
  • This layer's graph purpose overlaps strongly with your scope (1 of 2 components it supplies are in scope).
  • The catalog use-case match is strong, so the component set this layer was derived from is reliable.
  • High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
  • 1 community-maintained example vendor recorded on the layer node.
  • Selection metrics for this layer are documented, so the shortlist can be compared objectively.
Alternatives
  • Cryptographic Evidence & Audit Ledger — confidence moderate (68/100, -2 vs. this layer); also covers: WORM / Immutable Audit Vault
  • AI GRC & Governance Platforms — confidence moderate (66/100, -4 vs. this layer); overlapping coverage, no additional selected component

Cryptographic Evidence & Audit Ledger — covers 1 of your components

Covers: WORM / Immutable Audit Vault. This layer supplies 3 components in the graph.
Confidence: moderate (68/100)
Community-maintained examples
Fact0 · Traccia
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Fact0cryptographic evidence ledgerPositions itself as a tamper-evident ledger for AI decision records. Typical: decision records, audit trail.not checkedsupports Art. 12 record-keeping (claimed)
Tracciaaudit trail & traceabilityPositions itself around traceability of AI pipeline steps and artefacts. Typical: traceability, artifact lineage.not checkedsupports Art. 12 record-keeping (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Select on
Append-only guarantees and who can rotate or delete (including the vendor); anchoring mechanism (qualified timestamp, transparency log, notarisation) and whether verification works without the vendor; retention and export in a readable format at end of contract; throughput and cost at your event volume.
Why this confidence
  • 1 in-scope component of this use case is supplied by this layer (WORM / Immutable Audit Vault) — a direct supplied_by path in the graph.
  • The catalog use-case match is strong, so the component set this layer was derived from is reliable.
  • High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
  • 2 community-maintained example vendors recorded on the layer node.
  • Selection metrics for this layer are documented, so the shortlist can be compared objectively.
  • Only 1 of 3 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
Alternatives
  • Public Transparency Registers & System Cards — confidence strong (70/100, +2 vs. this layer); also covers: AI Register & Model Registry / Factsheets
  • AI GRC & Governance Platforms — confidence moderate (66/100, -2 vs. this layer); also covers: AI Register & Model Registry / Factsheets

AI GRC & Governance Platforms — covers 1 of your components

Covers: AI Register & Model Registry / Factsheets. This layer supplies 7 components in the graph.
Confidence: moderate (66/100)
Community-maintained examples
Credo AI · ModelOp · Holistic AI · IBM watsonx.governance · OneTrust · ServiceNow · Monitaur
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
Credo AIAI governance platformPolicy packs, risk tiering and evidence workflows mapped across frameworks. Typical: AI registry, policy administration. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedISO 42001 alignment (claimed)EU AI Act readiness positioning
Holistic AIAI governance & auditRisk assessment, bias auditing and regulatory reporting workflows. Typical: bias audit, regulatory reporting. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedNYC LL144 audit support (claimed)EU AI Act readiness positioning
IBM watsonx.governanceAI governance platformGovernance, factsheets and monitoring integrated with the IBM stack. Typical: factsheets, model monitoring. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedISO 42001 alignment (claimed)Art. 11 documentation support (claimed)
ModelOpAI/model governanceModel and agent inventory with automated lifecycle controls for large estates. Typical: model inventory, control automation. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedmodel-risk positioning (SR 11-7 style, claimed)ISO 42001 alignment (claimed)
Monitaurinsurance & lending model governanceModel governance and documentation aimed at insurance and lending supervision. Typical: insurance underwriting, credit decisioning. Scope overlap: Its model-governance scope overlaps this platform's own; we have a commercial interest in the comparison.SaaS (vendor cloud)NAIC model-governance positioning (claimed)SR 11-7 practice alignment (claimed)
OneTrustGRC & privacy platformPrivacy and AI governance modules extending an existing GRC system of record. Typical: DPIA/FRIA workflow, policy management. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison.not checkedISO 27001 (claimed)GDPR-positioned
ServiceNowintake & ITSM workflowUse-case intake, approval workflow and risk records inside an existing ITSM estate. Typical: AI intake, policy administration. Scope overlap: Its AI-governance module overlaps this platform's own scope; we have a commercial interest in the comparison.SaaS (vendor cloud)ISO 42001 alignment (claimed)EU AI Act readiness positioning

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Select on
multi-model/multi-cloud cataloging incl. third-party SaaS, automated risk tiering, regulatory reporting, independent-2nd-line deployability, cross-framework control deduplication
Why this confidence
  • 1 in-scope component of this use case is supplied by this layer (AI Register & Model Registry / Factsheets) — a direct supplied_by path in the graph.
  • The catalog use-case match is strong, so the component set this layer was derived from is reliable.
  • High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
  • 7 community-maintained example vendors recorded on the layer node.
  • Selection metrics for this layer are documented, so the shortlist can be compared objectively.
  • Only 1 of 7 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
Alternatives
  • Public Transparency Registers & System Cards — confidence strong (70/100, +4 vs. this layer); overlapping coverage, no additional selected component
  • Cryptographic Evidence & Audit Ledger — confidence moderate (68/100, +2 vs. this layer); also covers: WORM / Immutable Audit Vault

Agent Observability & Model Risk Management — covers 1 of your components

Covers: AI Register & Model Registry / Factsheets. This layer supplies 10 components in the graph.
Confidence: moderate (65/100)
Community-maintained examples
LangSmith · Langfuse · Arize AI / Phoenix · Helicone · MLflow · Ragas · Deepchecks · Fairlearn · Fiddler AI · ValidMind · WhyLabs · Evidently AI · Galileo AI · Patronus AI · Arthur AI
Filters to self-hostable, customer-VPC and open-source options when personal or confidential data cannot leave the EU.
ExampleSub-categoryWhat it doesHostingClaimed alignments
LangSmithagent tracing & evaluationTrace capture and evaluation over LangChain/LangGraph runs with dataset-based scoring. Typical: step tracing, regression evaluation.not checkedSOC 2 (claimed)supports Art. 12 record-keeping (claimed)
Langfuseagent tracing & evaluationOpen-source tracing, prompt management and evaluation; self-hostable for retention control. Typical: self-hosted tracing, cost/latency analytics.open sourceGDPR-positionedsupports Art. 12 record-keeping (claimed)
Arize AI / PhoenixML & LLM observabilityProduction monitoring with drift and performance analysis; Phoenix is the open-source tracing side. Typical: drift monitoring, production analytics.not checkedSOC 2 (claimed)drift-monitoring positioning (SR 11-7 style, claimed)
HeliconeLLM gateway & loggingProxy-level logging of prompts, costs and latency across providers. Typical: gateway logging, cost control.not checkedSOC 2 (claimed)supports Art. 12 record-keeping (claimed)
MLflowexperiment & model registryOpen-source tracking, model registry and lineage across training and deployment. Typical: model registry, validation records.open sourcemodel-validation positioning (SR 11-7 style, claimed)
RagasRAG evaluationOpen evaluation metrics for retrieval faithfulness and answer grounding. Typical: grounding checks, RAG regression.not checkedOSS, no vendor certification
Deepchecksvalidation & testingContinuous validation suites for data and model behaviour. Typical: release gating, data validation.not checkedevaluation-evidence positioning
Fairlearnfairness toolkitOpen-source fairness assessment and mitigation for classification and regression. Typical: bias testing, fairness reporting.not checkedOSS, no vendor certificationsupports Art. 10 bias examination (claimed)
Fiddler AImodel performance managementExplainability and monitoring platform aimed at regulated model risk teams. Typical: explainability, model monitoring.not checkedSOC 2 (claimed)model-risk positioning (SR 11-7 style, claimed)
ValidMindmodel risk managementModel validation documentation and workflow for banking model-risk functions. Typical: validation reports, MRM workflow.not checkedSOC 2 (claimed)model-risk positioning (SR 11-7 style, claimed)
WhyLabsdata & model monitoringTelemetry and drift monitoring over model inputs and outputs. Typical: drift detection, data quality monitoring.SaaS (vendor cloud)supports Art. 72 post-market monitoring (claimed)
Evidently AIevaluation & monitoringOpen-source evaluation and monitoring reports for ML and LLM pipelines. Typical: evaluation reports, drift detection.open sourcesupports Art. 72 post-market monitoring (claimed)
Galileo AILLM evaluation & observabilityEvaluation metrics and traces for generative applications. Typical: LLM evaluation, trace inspection.SaaS (vendor cloud)supports Art. 15 accuracy measures (claimed)
Patronus AI · eingestellt (2026-08-31)automated LLM evaluationAutomated scoring and adversarial test suites for generative output. Typical: automated evaluation, red teaming.SaaS (vendor cloud)supports Art. 15 robustness measures (claimed)
Arthur AImodel performance monitoringPerformance, bias and drift monitoring across deployed models. Typical: bias monitoring, performance monitoring.SaaS (vendor cloud)supports Art. 72 post-market monitoring (claimed)supports Art. 10 bias examination (claimed)

Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.

Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.

Select on
Trace completeness per agent step; log retention and immutability options; drift/quality metrics available out of the box; evaluation dataset support; export into your audit vault; self-host option.
Why this confidence
  • 1 in-scope component of this use case is supplied by this layer (AI Register & Model Registry / Factsheets) — a direct supplied_by path in the graph.
  • The catalog use-case match is strong, so the component set this layer was derived from is reliable.
  • High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
  • 15 community-maintained example vendors recorded on the layer node.
  • Selection metrics for this layer are documented, so the shortlist can be compared objectively.
  • Only 1 of 10 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
Alternatives
  • Public Transparency Registers & System Cards — confidence strong (70/100, +5 vs. this layer); overlapping coverage, no additional selected component
  • Cryptographic Evidence & Audit Ledger — confidence moderate (68/100, +3 vs. this layer); also covers: WORM / Immutable Audit Vault

No supplier layer recorded (2)

The graph knows no market layer for these — treat them as in-house engineering, or propose the missing supplier layer.
PII Scrubbing / DLP-NER Layer
Automated detection, pseudonymisation and blocking of personal data in inputs, retrievals and outputs.
Secure Boot & Hardened Runtime
Verified boot chain and hardened runtimes for edge/IoT deployments per CRA security-by-design.

Next step: Check which use cases this stack could carry →