AI RISK & COMPLIANCE ENGINE v0.1

Know your AI.
Understand your exposure.

A practical first look at the risks, control gaps, and regulatory questions in your AI architecture. Before they become your next engineering fire.

Machine learning Generative AIRAGAutonomous systems

Your architecture.
Your browser. That’s it.

No account. No architecture uploads. No AI calls.
Answers are never sent to a server. PDF requests send only your email and contact preference.

LOCAL EVALUATION ONLY

Start with a familiar architecture

Select an example, then make it yours. Not your use case?

EXAMPLE / FINTECH

You’re exploring an example. Illustrative EU/UK customer support assistant over production ledger data and PII. It does not assess creditworthiness. Safeguards have not been assessed. Change any answer below.

Your architecture

STEP 01 / 04
DEFINE THE SYSTEM

Purpose & impact

Start with what your AI does, and what happens if it gets things wrong.

Choose the primary capability. Mixed ML/LLM systems can use Generative AI; select RAG if enterprise retrieval is involved.

Purpose matters more than sector. A support chatbot and a credit decision engine need different screening.

Operational dependency is one of the four ACRS dimensions.

Consider misuse and compromise, not just a wrong answer.

Zero retention of diagnostic answers

Answers live in page memory only. Refresh or reset to clear them. No cookies, browser storage, or analytics collect your responses. Downloaded reports remain on your device until you delete them.

See your live snapshot
A SIGNAL. NOT A CERTIFICATE.

Clarity before complexity.

01

Describe the architecture

Use an example or start fresh. Include what you know; leave uncertainty visible.

02

Understand what drives exposure

See the capability score, relevant framework priorities, and safeguards to validate.

03

Decide your next step

Use the findings to prepare your internal review, or discuss the architecture with Gamut.

Transparent by design. Grounded in methodology.

A capability score, not a compliance score

ACRS multiplies four levels (1–3) into a native score of 1–81. The display is rounded from score ÷ 81 × 100; it does not represent a probability. Native bands: Low 1–8, Medium 9–36, High 37–81. Severity floors can raise assurance depth even when the product is lower.

Structured answers map directly to the four dimensions. Special-category data or privileged access sets Access to 3; confidential/personal data or limited tools sets it to at least 2. The platform’s free-text inference and assessor sign-off are not reproduced here.

ACRS-1.1-secure-system-scope

Scope before obligation

GTSAF uses baseline and fact-triggered control candidates. NIST priorities do not imply failed controls. EU outputs are screening signals, not a legal classification, prohibition clearance, or finding of compliance.

Regulatory references checked 28 August 2026. This diagnostic does not cover every use case, legal exception, jurisdiction, or effective-date condition. Obtain qualified advice for decisions that depend on legal applicability.

No architecture data leaves this page

Evaluation happens locally without external model calls. The site host still receives ordinary web requests and may keep infrastructure logs. Requesting a PDF sends your email, request label, and contact preference to Gamut via Formspree under its privacy notice; your answers and PDF remain local. Following an external link takes you to a separate site with its own privacy practices.

Your answers are not added to links or sent to the review page. Nothing here inspects your actual infrastructure or verifies your evidence.

Methodology by Gamut
Architecture snapshotmedium assurance depth