The vendor-neutral AI governance, liability & compliance layer for the enterprise. RiverAct builds the inventory of the AI you run — on any stack — classifies its risk, names which obligation lands on it and on what date, alerts the right people, and produces the evidence that keeps you compliant, defensible and insurable.
AI is being deployed faster than it can be governed — and in 2026 the consequences stopped being hypothetical. RiverAct exists for this moment.
Four risk tiers, phased obligations, and fines up to €35M or 7% of global turnover. The high-risk regime — risk management, logging, human oversight, conformity evidence — applies from 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in regulated products, per Regulation (EU) 2026/1744. The US states run their own clocks: California's TFAIA (SB 53) since 1 January 2026, New York's RAISE Act from 1 January 2027.
The EU now treats AI software as a product under strict liability (from Dec 2026), while mainstream insurers exclude AI from general cover. An ungoverned incident lands directly on the enterprise.
Specialist AI insurers (Munich Re, Armilla, Testudo) underwrite faster and price lower when you can show governance aligned to ISO 42001 and NIST. RiverAct produces exactly that record.
Fortune-500 buyers demand ISO 42001, bias audits and impact assessments before contract. Without them, vendors are treated as uninsurable liability. Governance is the price of the deal.
A drop-in, vendor-neutral overlay — no rip-and-replace. It turns governance from a quarterly export into a live capability, producing conformity evidence as a byproduct of operation.
Taps any gateway, proxy or model — yours or ours, low-touch. Every call that crosses a tap becomes one normalised event; coverage is whatever you have tapped.
Live inventory with continuous shadow-AI discovery; auto risk-tiering against the EU AI Act ruleset the engine publishes in full. ISO 42001, the voluntary NIST AI RMF and DORA land one framework at a time.
Guardrail scanners over observed traffic — PII leakage and prompt-injection today; drift, bias, hallucination and toxicity are the same shape and follow. Findings are indicative and route to review, never blocking.
Policy-as-code that answers — allow, gate or deny, returned as a recorded decision, and a gate opens a human-oversight task. Advisory: it is not in your request path.
Role-based alerts and runbooks so tech, legal and leadership act inside the reporting window — with the serious-incident clock computed per regime rather than guessed at.
Append-only, tamper-evident audit trail, model cards, FRIA drafts, and a regulator- & insurer-ready posture score.
RiverAct's edge isn't only what it detects. It's who it tells, how fast, and what to do next — the same event, in each team's own language.
Prompt-injection and PII-leak findings wired to runbooks — the system, the input pattern, and which control to change, in the tools they already use.
Plain-language risk events mapped to the exact obligation, the reporting clock, and the evidence already captured — ready for the regulator or insurer.
A single posture score and exposure view — which systems, which jurisdictions, what's insured, what's at risk — without the technical noise.
Most enterprises already own a gateway, a proxy, a memory service. Governance has to watch all of it — so RiverAct is a neutral overlay, not a bolt-on to our stack.
RiverAct completes the suite — and earns its place precisely because it works standalone, then goes deeper alongside the rest.
The gateway that routes and controls your AI traffic.
↗Live model health and intelligent routing.
↗Governed memory and reusable skills.
Inventory, classify, alert, prove, insure — on any stack.
We're onboarding a small group of design partners in regulated industries. Bring your stack as it is — RiverAct starts the record on day one.