From AI use case to audit-ready compliance design. In minutes, with sources.
The open, community-validated knowledge graph for regulated AI — the full regulatory stack, compliance by design, and the business case in one traversal. Free to use, hardened by named experts.
- RegulationMulti-layer and current: 38 regulations across AI, data protection, cyber & resilience, product safety & liability, financial services and sector, market & employment law, plus the standards layer — each legal claim with a verification status and date.
- DesignCompliance by design: control objectives, reference architecture, components, patterns and the evidence plan — designed into the system, not audited onto it afterwards.
- BusinessRisk & value: priority score, compliance cost bands, 3-year ROAI and an explicit verdict — proceed, downtier, re-architect or terminate.
What it does for you
How it works
- Describe or upload your use caseFree text, or a project document (PDF, DOCX, TXT, MD). The analysis runs in your browser — nothing is stored, no login.
- The knowledge graph traverses the regulatory stack38 regulations across AI, data protection, cyber & resilience, product safety & liability, financial services and sector, market & employment law — and the standards layer — are traversed to the risk class, obligations, controls, architecture and evidence, with a visible reasoning trace and a confidence statement you can interrogate.
- Keep the artifacts — compliance and businessExecutive brief, Annex IV skeleton, ISO 42001 / CSA AICM mapping and a build-or-buy shortlist — plus the business lens: compliance cost bands, 3-year ROAI and a go/no-go verdict. Exportable as PDF, CSV and Markdown.
use-case identification → statutory & risk tiering → architectural control layers → vendor stack mapping
Why not the alternatives
| RAIN | Enterprise governance suites | Free AI Act checkers | Open control matrices | |
|---|---|---|---|---|
| Traceable reasoning | Yes — every conclusion shows the rule and the claims it used | Mostly opaque scoring | Questionnaire logic, not shown | No reasoning at all |
| Full chain to architecture & evidence | Use case → law → obligation → control → component → evidence | Tells you what to document, rarely what to build | Stops at the risk class | Flat control lists |
| Build-or-buy view | Per control layer, with vendor categories and confidence | Their own platform is the answer | None | None |
| Business-risk perspective (cost, ROAI, go/no-go) | Yes — Risk & Value Evaluator: priority score, cost bands, 3-year ROAI, explicit verdict | — documentation focus | — | — |
| Community validation with named experts | Named reviewers on the claim and in the release | Vendor-internal research team | Anonymous | Committee, slow cycles |
| Price | Free to use | ≈ €10k–150k / year | Free | Free |
What RAIN does not do: it does not enforce anything at runtime, it does not certify, and it is not legal advice. It is a reasoning and documentation aid — the decision stays with you and your counsel.
Categories named generically: “enterprise governance suites” = commercial AI/GRC platforms sold per seat or per system; “free AI Act checkers” = questionnaire-style classifiers; “open control matrices” = published control catalogues such as AI management-system or cloud control matrices. Price range is the publicly advertised order of magnitude, not a quote.
The knowledge graph, and the people who harden it
- 279 curated claims in 14 categories
- 957 sourced connections (16 relation types, average 6.9 per claim)
- 35 use-case profiles across 12 sectors
- 22% of legal references carry a verification date (20 of 89)
- 6 public releases · 0 orphan claims (every claim is connected)
- Every contribution carries a source — enforced in the database, not by etiquette.
- Every contributor is named on the claim and in the release notes.
- Gaps are public: the verification queue shows what is not yet checked.
- Invite-only, reference-based membership with contribution credits — credits exist so that every analysis in circulation is backed by verified expert work.
Validated, current information
Every legal claim across the multi-layer stack — AI, data protection, cyber and resilience, product safety and liability, sector and financial law, and the standards layer — carries a status and a verification date, so you can see how old the statement you are relying on is. Monitored sources trigger re-verification when an act, standard or guidance changes. Corrections are logged publicly — including our own.
Today: 20 of 89 legal references verified — the rest is visible on the public queue. Graph v2.1.2, updated 2026-08-07. Proof that we log our own mistakes: release v2.1.1 — a correction release.
is stated, never implied: an unverified claim is labelled as unverified.
Describe your first use case — free, no login, nothing stored.
RAIN — Regulated AI Navigator · rainavigator.org · knowledge graph v2.1.2 · not legal advice