OpenComplAI: Compliance-as-Code for AI Pipelines¶
Stop manual audits → Start shipping.
OpenComplAI brings AI compliance directly into your CI/CD pipeline, turning fragmented legal mandates into automated, machine-readable "Pre-Ship Checks." The EU AI Act is evaluated natively; NIST AI RMF 1.0 is derived from the same evidence.
Why OpenComplAI?¶
Traditional GRC tools are disconnected dashboards that create "velocity tax." We shift compliance left:
- Prevent Non-Compliance: Gate releases by blocking builds that violate safety rules.
- Automated Evidence:
opencomplai checkwritescompliance-artifact.jsonwith evidence hashes for every run; it is signed only when you pass--signand a local signing key exists. - Frameworks Side by Side: Assess one system against the EU AI Act and NIST AI RMF 1.0 side by side (
compliance_targetsin the manifest, oropencomplai gaps --target EU_AI_ACT --target NIST_AI_RMF). The EU AI Act is evaluated natively; NIST AI RMF is re-projected per subcategory from that same EU AI Act evidence through a built-in crosswalk, with no scanner of its own (see NIST AI RMF). ISO/IEC 42001 is a native pack of attestation rows that read Unverified until you record an attestation underframework_inputs(--target ISO_IEC_42001). DORA and EBA are mapped only:gaps --map-to DORA|EBAadds a low-confidence citation per EU AI Act article (see Mapped regimes). Standing line: EU AI Act evaluated; NIST AI RMF derived (partial, unreviewed); ISO 42001 native pack, attestation-led (partial, unreviewed); DORA and EBA mapped only. See Frameworks.
How It Works (The 3-Minute Setup)¶
- Define: Create a compliance manifest for your model.
- Integrate: Add the OpenComplAI action to your GitHub/GitLab pipeline.
- Ship: Get an automated "Pass/Fail" result before your code ever hits production.
Check out our Dummy Repo (Sandbox) – Five fictional systems, one per gate outcome (exit codes 3, 4, 1, 1, 0). Illustrative sandbox, not legal advice. It does not scan code.
Core Components¶
- opencomplai-core — the rule engine that evaluates compliance controls and produces structured results.
- opencomplai-cli — the developer interface for creating manifests and running checks locally and in CI.
- opencomplai (Python SDK meta-package) — the programmatic interface for embedding checks into internal tooling.
Quick Start¶
Get your first compliance check running in under 15 minutes:
Quick Start — install the CLI, initialise a manifest, and run your first compliance check.
Community & Feedback¶
Join the developer community
Join our Developer Discord — the fastest place to get help with EU AI Act workflows, CI/CD integration, and feedback.
The CLI and engine are open source; the hosted dashboard is in private beta. If you are an AI engineer or ML platform lead, we want your feedback.
See Support & Community for Discord, GitHub issue templates, security reporting, and all contact options.