Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 78 profiles

Regulatory Calendar

Grouped by regime, because a use case runs on several clocks at once. The AI Act is the only domain whose staged dates are fixed in the graph today; for the others the instruments are in force and their duties bite on entry into application, which is stated per instrument rather than invented as a date.

Standards and assessment infrastructure run on their own clock — see the standards & guidance lifecycle tracker →

Target market(s)European UnionUnited States (federal)change

Entries for markets outside your selection stay visible below, de-emphasised — history is never hidden.

Target market(s)

Where will this system be used or placed on the market? The conclusion is derived for these jurisdictions — instruments that bind only elsewhere are left out.

Europe
North America
Latin America
Asia-Pacific
Middle East
Africa

Selected: European Union, United States (federal) · thin-coverage jurisdictions need verification

Jurisdiction swimlanes — major new regimes

One lane per regime, built only from dated facts already on the graph. A regime with no dated milestone says so and links to the verification queue instead of inventing a date.

CN 8 instruments
KR 3 instruments
  • AI Framework Act (KR) in force in force since 22 Jan 2026 (promulgated 21 Jan 2025)
  • PIPA (KR) in force in force; 2023 amendment ADM rights effective Mar 2024
JP 4 instruments
VN 3 instruments
GB 8 instruments
BR 3 instruments
CA 7 instruments

AI law — staged dates

2024-08-01

AI Act enters into force

Regulation (EU) 2024/1689 in force; countdown for all staged obligations starts.

2025-02-02

Prohibitions + AI literacy

Art. 5 prohibited practices ban applies (manipulation, social scoring, untargeted face scraping, workplace emotion recognition); Art. 4 AI literacy duty.

2025-08-02

GPAI + governance + penalties

Chapter V GPAI model obligations, notification authorities, governance structures and fining provisions apply. The GPAI Code of Practice was published 10 July 2025 with 21 signatories.

2026-07-27

Digital Omnibus in force

Regulation (EU) 2026/1744 in force since 27 July 2026 (Council adoption 29 June, OJ L, 24 July 2026; CELEX 32026R1744): fixes the high-risk application dates at 2 Dec 2027 (Annex III standalone) and 2 Aug 2028 (Annex I embedded), and the softened Art. 4 AI-literacy duty takes effect on this date. Source: https://eur-lex.europa.eu/eli/reg/2026/1744/oj

2026-08-02

General applicability + Art. 50 transparency applies

Art. 50 transparency duties APPLY from 2 August 2026 — chatbot disclosure, deepfake labelling, synthetic-content and emotion-recognition disclosure are binding now, not next December. EU-level enforcement begins. Confirmed against Regulation (EU) 2026/1744 (OJ L, 24.7.2026; CELEX 32026R1744). Source: https://eur-lex.europa.eu/eli/reg/2026/1744/oj

2026-09-11

CRA incident & vulnerability reporting applies

Cyber Resilience Act Art. 14 reporting duties for actively exploited vulnerabilities and severe incidents apply from 11 Sep 2026 (coordinator CSIRT + ENISA).

2026-12-02

Art. 50(2) marking — grace period ends for legacy generative systems

End of the transitional grace period for the Art. 50(2) machine-readable marking duty, and ONLY for generative systems placed on the market BEFORE 2 August 2026. Systems placed on the market on or after 2 August 2026 owe the marking duty immediately. This date does not delay the rest of Art. 50, which applies from 2 August 2026. Source: https://eur-lex.europa.eu/eli/reg/2026/1744/oj

2026-12-02

New Art. 5 prohibitions apply (NCII, CSAM generation)

The two prohibited practices inserted into Art. 5 by Regulation (EU) 2026/1744 — generation of non-consensual intimate imagery and of child sexual abuse material — apply from 2 December 2026. The Art. 5 prohibitions that existed before the omnibus have applied since 2 February 2025. Source: https://eur-lex.europa.eu/eli/reg/2026/1744/oj

2027-08-02

Regulatory sandboxes

AI regulatory sandboxes operational from 2 Aug 2027 per Regulation (EU) 2026/1744.

2027-12-02

Annex III high-risk obligations (Art. 6(2))

Standalone Annex III high-risk systems must comply from 2 Dec 2027 — fixed date under Regulation (EU) 2026/1744, no longer coupled to standards availability.

2028-08-02

Annex I embedded high-risk (Art. 6(1))

High-risk AI as safety components in already-regulated products (Annex I: MDR, machinery, automotive …) must comply from 2 Aug 2028 — fixed date under Regulation (EU) 2026/1744.

2030-08-02

Public-sector legacy systems

High-risk systems placed on the market or put into service by public authorities before the relevant application date must comply by 2 August 2030 (Art. 111(2)). Source: https://eur-lex.europa.eu/eli/reg/2024/1689/oj

Other regimes in scope

data protection

28 instruments · no staged dates recorded in the graph

cyber & resilience

8 instruments · no staged dates recorded in the graph

online safety & platform law

4 instruments · no staged dates recorded in the graph

product safety & liability

5 instruments · no staged dates recorded in the graph

sector, market & employment law

95 instruments · no staged dates recorded in the graph

Implementation Roadmap

The delivery-side counterpart to the regulatory dates: what has to exist internally before an outcome-priced AI service can carry regulated work. See the architecture →

2026-Q4 · Phase 1

Foundational governance & architectural hardening

Establish core compliance policies and secure infrastructure enclaves.

Technical: Deploy zero-trust ingestion with PII/PHI tokenisation; stand up the model-abstraction layer.

Governance: Finalise ISO 42001 AIMS policies; execute zero-data-retention vendor contracts.

2027-Q1 · Phase 2

Workflow taxonomy & regulatory tiering

Map every vertical workflow to its risk tier.

Technical: Build HITL operator dashboards with confidence-threshold routing (C_s < θ).

Governance: Complete AI Act classifications (high vs. limited vs. minimal) per workflow.

2027-Q3 · Phase 3

Artifact automation & immutable auditability

Automate production of required compliance documentation.

Technical: Connect transaction pipelines to append-only WORM storage with external trust anchoring.

Governance: Auto-generate AI impact assessments and model cards per deployment.

2028-Q1 · Phase 4

Scaled outcome-based commercial deployment

Move client contracts to outcome-priced structures.

Technical: Continuous drift monitoring and dynamic multi-model fallback in production.

Governance: Annual ISO 42001 audits; continuous AI Act conformity validation.

Release history

87 releases so far, the latest being v2.56.0 (2026-09-22). Every change is recorded with the community challenge and the contributor that caused it. Read the full changelog →

Download the v1.5 teaser (PDF)

Control Layer & Currency

Control chain: obligation (article) → operationalized_by → control objective → satisfied_by → component/pattern; control objective → evidenced_by → evidence artifact

Mapping an obligation directly to a component answers 'what do I build?' but not 'what must be true?'. The control objective is the testable statement in between — it is what an auditor actually assesses and what a runtime check actually verifies. Separating it makes one obligation explode into several objectives, and lets one objective be satisfied by alternative components.

Coverage: 314 of 359 legal and standard claims carry a verification date (87%); 312 carry a lifecycle status. The remaining claims are published as unverified rather than backdated with an invented date — see the coverage worklist →

Currency: Every legal act and standard in this graph is a moving target. A node without a lastVerified date is a claim, not a fact.

Method

The graph encodes four source layers: (1) the EU AI Act and the surrounding digital acquis (GDPR, CRA, NIS2, DORA, PLD, Data Act, DGA, DSA, ePrivacy, GPSR plus sectoral instruments), (2) the standards landscape (CEN/CENELEC JTC 21, ISO/IEC SC 42, DIN, BSI, NIST, OWASP, ENISA, IEEE), (3) compliance-by-design architecture patterns, and (4) the Regulatory Design & Architecture (RDA) framework for agentic systems with the four-mode oversight taxonomy. Derivation logic: use case → risk class → imposed articles → implementing components & supporting standards, joined with regulation-specific requirements and threat mitigations.

About the platform

RAIN is free to join and contribute-to-participate: sign up yourself, or be invited by an existing member — either way every account is confirmed by a curator against a real professional profile, and carries a small balance of contribution credits. Credits are earned by hardening the graph — accepted verifications, accepted use cases, peer reviews, inviting a member who gets verified — and spent on member services such as saving an analysis or requesting an expert review, so the people who use the graph are the people who maintain it. Verification is revalidated every twelve months; what the graph currently contains and how well it is sourced is public on graph statistics.