Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles

AI Act Timeline

2024-08-01

AI Act enters into force

Regulation (EU) 2024/1689 in force; countdown for all staged obligations starts.

2025-02-02

Prohibitions + AI literacy

Art. 5 prohibited practices ban applies (manipulation, social scoring, untargeted face scraping, workplace emotion recognition); Art. 4 AI literacy duty.

2025-08-02

GPAI + governance + penalties

Chapter V GPAI model obligations, notification authorities, governance structures and fining provisions apply.

2026-08-02

General applicability + Art. 50

Transparency obligations for chatbots, deepfakes and synthetic content; EU-level enforcement begins.

2026-12-02

Additional prohibitions

Additional bans (deepfake CSAM et al.) and transition period for synthetic content under Art. 50(2).

2027-12-02

Annex III high-risk obligations

Digital-Omnibus-shifted deadline: standalone Annex III high-risk systems must comply (coupled to availability of harmonised standards).

2028-08-02

Annex I embedded high-risk

High-risk AI as safety components in already-regulated products (Annex I: MDR, machinery, automotive …) must comply.

2030-08-02

Public-sector legacy systems

High-risk systems operated by public authorities must comply (Art. 111(2)).

Implementation Roadmap

The delivery-side counterpart to the regulatory dates: what has to exist internally before an outcome-priced AI service can carry regulated work. See the architecture →

2026-Q4 · Phase 1

Foundational governance & architectural hardening

Establish core compliance policies and secure infrastructure enclaves.

Technical: Deploy zero-trust ingestion with PII/PHI tokenisation; stand up the model-abstraction layer.

Governance: Finalise ISO 42001 AIMS policies; execute zero-data-retention vendor contracts.

2027-Q1 · Phase 2

Workflow taxonomy & regulatory tiering

Map every vertical workflow to its risk tier.

Technical: Build HITL operator dashboards with confidence-threshold routing (C_s < θ).

Governance: Complete AI Act classifications (high vs. limited vs. minimal) per workflow.

2027-Q3 · Phase 3

Artifact automation & immutable auditability

Automate production of required compliance documentation.

Technical: Connect transaction pipelines to append-only WORM storage with external trust anchoring.

Governance: Auto-generate AI impact assessments and model cards per deployment.

2028-Q1 · Phase 4

Scaled outcome-based commercial deployment

Move client contracts to outcome-priced structures.

Technical: Continuous drift monitoring and dynamic multi-model fallback in production.

Governance: Annual ISO 42001 audits; continuous AI Act conformity validation.

Release history

6 releases so far, the latest being v2.1.2 (2026-08-07). Every change is recorded with the community challenge and the contributor that caused it. Read the full changelog →

Download the v1.5 teaser (PDF)

Control Layer & Currency

Control chain: obligation (article) → operationalized_by → control objective → satisfied_by → component/pattern; control objective → evidenced_by → evidence artifact

Mapping an obligation directly to a component answers 'what do I build?' but not 'what must be true?'. The control objective is the testable statement in between — it is what an auditor actually assesses and what a runtime check actually verifies. Separating it makes one obligation explode into several objectives, and lets one objective be satisfied by alternative components.

Coverage: 20 of 89 legal and standard claims carry a verification date (22%); 20 carry a lifecycle status. The remaining claims are published as unverified rather than backdated with an invented date — see the coverage worklist →

Currency: Every legal act and standard in this graph is a moving target. A node without a lastVerified date is a claim, not a fact.

Method

The graph encodes four source layers: (1) the EU AI Act and the surrounding digital acquis (GDPR, CRA, NIS2, DORA, PLD, Data Act, DGA, DSA, ePrivacy, GPSR plus sectoral instruments), (2) the standards landscape (CEN/CENELEC JTC 21, ISO/IEC SC 42, DIN, BSI, NIST, OWASP, ENISA, IEEE), (3) compliance-by-design architecture patterns, and (4) the Regulatory Design & Architecture (RDA) framework for agentic systems with the four-mode oversight taxonomy. Derivation logic: use case → risk class → imposed articles → implementing components & supporting standards, joined with regulation-specific requirements and threat mitigations.

About the platform

RAIN is invite-only and contribute-to-participate: membership is vouched for by an existing member and confirmed by a curator against a real professional profile, and every account carries a small balance of contribution credits. Credits are earned by hardening the graph — accepted verifications, accepted use cases, peer reviews, inviting a member who gets verified — and spent on member services such as saving an analysis or requesting an expert review, so the people who use the graph are the people who maintain it. Verification is revalidated every twelve months; what the graph currently contains and how well it is sourced is public on graph statistics.