AI Governance & Legal Tech Case Study
Compliance screening without legal hallucinations.
EU AI Act Navigator gives non-lawyers—HR leads, operations managers, and software founders—a deterministic, source-backed screening of EU AI Act obligations. Built with three-valued logic instead of generative guesses, it leaves every finding traceable to EUR-Lex.
01
The problem
Legal compliance cannot tolerate generative hallucination.
Ask an LLM if an AI tool is "high risk" and it will often give a convincing, nuanced answer that is legally inaccurate or invents statutory certainty where none exists.
Under Regulation (EU) 2024/1689, risk tiers are not general impressions. They are strict statutory classifications tied to specific deployment contexts, organizational roles (provider vs deployer), decision mechanisms, and legal exemptions.
When a team uses an LLM wrapper for compliance, missing information is frequently hallucinated into certainty, role-based obligations are blurred, and users receive either false reassurance or unnecessary panic. The architectural requirement was clear: legal conclusions must be governed by deterministic, reproducible code.
02
Architecture
Three-valued logic with immutable provenance.
Everyday reality
Users answer 4 steps about what the tool does, who it affects, and how decisions are influenced, without needing legal training.
Three-valued evaluator
Every rule evaluates to true, false, or
unknown. Uncertainty produces an escalation review,
never a false negative.
Official source trace
Every finding pairs an everyday explanation with the exact EUR-Lex article, application date, and reviewer timestamp.
The engine runs completely client-side in the visitor's browser. No assessment facts, prompts, or findings ever touch a remote server or model API.
03
UX & Translation
Ask about everyday facts, not legal definitions.
No legal jargon
Instead of asking "Are you an Article 6(2) Annex III deployer?", the tool asks: "Does this software score, rank, or filter job candidates?"
Role distinction
Deployer obligations (human oversight, logging, employee notice) are kept strictly distinct from provider duties (CE marking, technical files).
Actionable checklists
Findings automatically compile into a prioritized action checklist with statutory deadlines (February 2025, August 2026, August 2027).
04
Statutory scope
Comprehensive coverage across the four risk tiers.
Article 5
Prohibited AI practices
Screens for social scoring, workplace emotion recognition, subliminal manipulation, and untargeted CCTV facial scraping with urgent escalations.
Annex I & III
High-risk classifications
Full coverage of employment, education, credit scoring, biometrics, critical infrastructure, and safety components of regulated machinery.
Article 50 & GPAI
Transparency & foundation models
Chatbot interaction notices, deepfake/synthetic media watermarking, and systemic risk compute thresholds for general-purpose AI providers.
05
Validation
Tested against golden scenarios and edge conditions.
Identical inputs yield identical, reproducible legal outputs every time.
Missing user facts trigger explicit review findings rather than silent omissions.
Narrow administrative tasks (scheduling, typo correction) are distinguished from substantive decision-making.
100% in-browser evaluation preserves complete corporate confidentiality and GDPR compliance.
32 automated tests covering HR recruitment, customer chatbots, credit risk, and GPAI edge cases.
Accurate phase-in dates distinguish rules taking effect in 2025, 2026, and 2027.
Working Proof
Try the screener or schedule an audit.
Run through the live questionnaire with an HR or customer service tool, or get in touch to discuss embedding deterministic compliance logic into your product architecture.