New · Digital One AI Business Suite

Govern the flow.

The vendor-neutral AI governance, liability & compliance layer for the enterprise. RiverAct builds the inventory of the AI you run — on any stack — classifies its risk, names which obligation lands on it and on what date, alerts the right people, and produces the evidence that keeps you compliant, defensible and insurable.

EU AI Act-ready Drop-in overlay Duty, decision, clock EU-sovereign · IP-owned
Control Room
LIVE · 47 systems
Credit scoringfin · annex III
HIGH
HR screeninghr · annex III
HIGH
Support copilotcx · limited
LIMITED
Fraud detectionfin · high
HIGH
Prompt-injection spike · HR screening
routed to Legal + ML · oversight task open
reporting clock 71h 48m · evidence captured ✓
94
Posture
EU AI ActISO 42001NISTDORA
€35M / 7%
Max EU AI Act fine — % of global turnover, higher than GDPR
Dec 2026
Strict product liability for AI software takes effect in the EU
~35%
Annual growth of the AI-governance market through the decade
~1.5%
of organisations have adequate AI-governance headcount today
The current is rising

Three forces, arriving together

AI is being deployed faster than it can be governed — and in 2026 the consequences stopped being hypothetical. RiverAct exists for this moment.

BINDING LAW

The EU AI Act, with teeth

Four risk tiers, phased obligations, and fines up to €35M or 7% of global turnover. The high-risk regime — risk management, logging, human oversight, conformity evidence — applies from 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in regulated products, per Regulation (EU) 2026/1744. The US states run their own clocks: California's TFAIA (SB 53) since 1 January 2026, New York's RAISE Act from 1 January 2027.

SHIFTING LIABILITY

The risk moved to your balance sheet

The EU now treats AI software as a product under strict liability (from Dec 2026), while mainstream insurers exclude AI from general cover. An ungoverned incident lands directly on the enterprise.

INSURABILITY

Evidence lowers your premium

Specialist AI insurers (Munich Re, Armilla, Testudo) underwrite faster and price lower when you can show governance aligned to ISO 42001 and NIST. RiverAct produces exactly that record.

PROCUREMENT

"Show me" is now in the RFP

Fortune-500 buyers demand ISO 42001, bias audits and impact assessments before contract. Without them, vendors are treated as uninsurable liability. Governance is the price of the deal.

What RiverAct is

A control room for the AI systems you run

A drop-in, vendor-neutral overlay — no rip-and-replace. It turns governance from a quarterly export into a live capability, producing conformity evidence as a byproduct of operation.

01 · gauges

Observe

Taps any gateway, proxy or model — yours or ours, low-touch. Every call that crosses a tap becomes one normalised event; coverage is whatever you have tapped.

02 · survey

Map & classify

Live inventory with continuous shadow-AI discovery; auto risk-tiering against the EU AI Act ruleset the engine publishes in full. ISO 42001, the voluntary NIST AI RMF and DORA land one framework at a time.

03 · sensors

Monitor

Guardrail scanners over observed traffic — PII leakage and prompt-injection today; drift, bias, hallucination and toxicity are the same shape and follow. Findings are indicative and route to review, never blocking.

04 · locks

Govern

Policy-as-code that answers — allow, gate or deny, returned as a recorded decision, and a gate opens a human-oversight task. Advisory: it is not in your request path.

05 · sirens

Alert & react

Role-based alerts and runbooks so tech, legal and leadership act inside the reporting window — with the serious-incident clock computed per regime rather than guessed at.

06 · logbook

Evidence & insure

Append-only, tamper-evident audit trail, model cards, FRIA drafts, and a regulator- & insurer-ready posture score.

And the line RiverAct does not cross. It sits in no request path and it stops nothing. The Govern plane answers a question and returns a decision as JSON — a deny it returns is a finding to act on, not a refused call. Under the EU AI Act the duty to build that ability into the system sits on the provider: Art. 14(4)(e) requires that a human overseer be enabled, as appropriate and proportionate, to intervene in the operation of the system or interrupt it through a “stop” button or a similar procedure that allows it to come to a halt in a safe state. The duty to suspend the use of that system sits on the deployer — you — under Art. 26(5). Both apply from 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in regulated products, per Regulation (EU) 2026/1744. RiverAct's job is to name which of those lands on which of your systems and on what date, record what was decided, and run the clock afterwards: the duty, the decision and the clock. Refusing a live call is a gateway's job — that is Gateward.
One signal, three audiences

The right people react — fast

RiverAct's edge isn't only what it detects. It's who it tells, how fast, and what to do next — the same event, in each team's own language.

Tech & ML

Prompt-injection and PII-leak findings wired to runbooks — the system, the input pattern, and which control to change, in the tools they already use.

Legal & compliance

Plain-language risk events mapped to the exact obligation, the reporting clock, and the evidence already captured — ready for the regulator or insurer.

Leadership & board

A single posture score and exposure view — which systems, which jurisdictions, what's insured, what's at risk — without the technical noise.

Drop-in, not rip-and-replace

Governance that fits whatever you already run

Most enterprises already own a gateway, a proxy, a memory service. Governance has to watch all of it — so RiverAct is a neutral overlay, not a bolt-on to our stack.

  • ✓
    Any provider, any model. OpenAI, Anthropic, Google, open-weight, self-hosted — observed from one place.
  • ✓
    Any gateway or proxy. Works with your existing infrastructure; richer signal when paired with Gateward.
  • ✓
    Deploys where your data lives. EU-sovereign and IP-owned — fit for banks, insurers and the public sector.
Observed sources
  • Your gateway / proxy neutral
  • Direct model APIs neutral
  • Agents & copilots neutral
  • Gateward · SkilledMind deeper
One overlay — one inventory — one stream of evidence, no matter how many vendors sit underneath.
The Digital One AI Business Suite

The trust layer of a bigger system

RiverAct completes the suite — and earns its place precisely because it works standalone, then goes deeper alongside the rest.

Coverage window opening

Channel your AI before the law does.

We're onboarding a small group of design partners in regulated industries. Bring your stack as it is — RiverAct starts the record on day one.