Skip to content
AIRAS Cloud

ARIE — AIRAS Regulatory Intelligence Engine

Regulatory reasoning that can be re-run, reviewed and defended.

ARIE is the assessment core of AIRAS Cloud. It turns an unstructured estate of AI systems into qualified, classified, obligation-mapped records — deterministically, from named legal sources, with the reasoning attached to the result.

What ARIE is

Not a model that opines. A rules engine that decides the same way twice.

  1. 01

    Discovery

    Documents, registers and vendor material are read server-side to surface candidate AI systems, with the source passage retained as lineage for every candidate.

  2. 02

    Qualification

    Each candidate is tested against the statutory definition of an AI system before any risk language is applied, so nothing is classified that does not qualify.

  3. 03

    Role and prohibition

    Operator role is determined from the facts of deployment, and prohibited-practice screening runs as a gate rather than as a score.

  4. 04

    Classification

    High-risk determination follows the regulation's own annex structure and impact triggers, with each conclusion tied to the input that produced it.

  5. 05

    Obligation mapping

    A qualified, classified system is expanded into the obligations that actually attach to it, assigned to named owners with evidence requirements.

  6. 06

    Versioned re-assessment

    A material change to purpose, data, model or deployment context reopens the assessment against the ruleset version in force at that time.

Why determinism matters to a reviewer

A governance decision is only defensible if it can be reproduced. ARIE separates the facts of a system from the rules applied to it, so a reviewer can change one fact and see precisely which obligation moved, or re-run a historic assessment against the ruleset version that was in force when the decision was taken.

That also sets the boundary of the engine's authority. ARIE decides what qualifies, what is prohibited, what is high-risk and what obligations attach. It does not decide whether the organisation accepts the residual risk — that remains a human decision, recorded with its conditions and its owner.

  • Same inputs, same ruleset version, same outcome
  • Every conclusion carries its source reference
  • Gates for prohibition, scores never override them
  • Evidence sufficiency assessed before approval is possible
  • Material change reopens assessment automatically
  • Segregation of duties enforced in workflow, not requested

What we publish, and what we protect

The regulatory sources ARIE implements are public law, and we name them. The engineering that turns those sources into consistent operational outcomes — rule weights, thresholds, condition sets and the calibration corpus used to tune them — is proprietary and stays unpublished.

Assurance reviewers are not asked to take that on trust. Under agreement we walk the engine end to end against your own scenarios, show the rule trace behind each conclusion, and provide the controlled specification for review.

Deliberate non-disclosure

Rule weights, thresholds, private calibration cases and internal condition logic are not published on this website. This is a commercial protection, not an assurance gap, and it is stated rather than implied.

Evidence status

Each claim, its status, and what stands behind it.

How to read the evidence status on this page

Verified in product
Implemented in the platform and covered by automated tests or recorded verification evidence.
Controlled document
Maintained as a version-controlled internal artefact, issued under agreement rather than published.
In external assurance
Scheduled with, or in progress with, an independent party. No external opinion is claimed until the report exists.
Not claimed
Deliberately not asserted. Stated openly so a reviewer never has to infer whether it exists.
ARIE engine — claim register
ClaimStatusWhat evidences it
The engine is deterministic: identical inputs produce an identical assessment.Verified in productCovered by the automated qualification, role, prohibition and classification suites executed against the source tree on every release.
Every conclusion is traceable to the input and ruleset version that produced it.Verified in productAssessment records carry the ruleset version and the source reference; audit history is append-only and cannot be silently edited.
Regulatory logic is derived from named legal sources, not from model output.Verified in productRule conditions cite the article they implement. Generative models are not used to decide qualification, prohibition or classification.
Rule weights, thresholds and calibration casesControlled documentHeld as controlled internal artefacts and disclosed only under agreement during assurance review. They are proprietary and are not published.
Independent third-party review of the engine's regulatory logicIn external assurancePlanned as part of the external assurance programme. No independent legal or technical opinion is claimed at present.
Automated legal advice or a compliance guaranteeNot claimedARIE produces a structured, defensible assessment for a competent human reviewer. It does not replace legal advice and does not certify compliance.

Want to test the engine against your own estate?

Bring three of your own AI systems. We will run them through qualification, role, prohibition screening and classification, and show you the reasoning behind every conclusion.

No commercial commitment. No confidential information required.