Skip to main content

opencomplai-ai

License: AGPL-3.0 PyPI Python

The optional AI intent classification plugin for Opencomplai. It adds the --ai-intent flag to opencomplai scan, classifying how each AI callsite in your code is actually used — its decision autonomy, the subjects it acts on, and which EU AI Act risk tier and Annex III area it maps to.

All inference runs locally — models execute on your machine via llama.cpp, or via a deterministic code-signal matcher that needs no model weights at all. No code or prompts leave your environment unless you explicitly opt into the saas backend.

Prerequisites

opencomplai-ai is a plugin. Install the core engine first:

pip install opencomplai-core   # or the opencomplai / opencomplai-cli suite

Install

# Base install — only the deterministic codebert-onnx matcher, no download
pip install opencomplai-ai

# Deep install — required for the default model (qwen2.5-coder-1.5b) and
# every other generative GGUF model
pip install "opencomplai-ai[deep]"

The base install alone can only run codebert-onnx. opencomplai scan --ai-intent resolves qwen2.5-coder-1.5b by default, which needs [deep] — without it the scan fails fast with an actionable message instead of downloading the ~1 GB model first and only then discovering it can't be run.

Usage

Once installed alongside the CLI, the --ai-intent flag becomes available on the scan command:

opencomplai scan --ai-intent

By default only callsites in files with lexical findings are annotated (fast). To analyze every callsite in the repository:

opencomplai scan --ai-intent --ai-deep

Useful flags:

Flag Effect
--ai-intent Enable AI intent classification
--ai-model <id> Choose a model (see catalog below)
--ai-deep Annotate every callsite, not just those near lexical findings
--ai-verbose Show all callsite annotations (default: top 10 by risk tier)

Supported models

The default model is qwen2.5-coder-1.5b and requires the [deep] extra. GGUF models are downloaded from the Hugging Face Hub on first use and cached locally under ~/.cache/opencomplai/models/.

codebert-onnx is a deterministic Annex III / prohibited-practice / limited-risk code-signal matcher — no model weights, no download, runs on the base install. It trades recall for speed and zero setup; it is not the default.

Model ID Runtime Size Needs [deep]
codebert-onnx deterministic matcher no download no
qwen2.5-coder-0.5b llama.cpp ~400 MB yes
qwen2.5-coder-1.5b (default) llama.cpp ~1.0 GB yes
smollm2-1.7b llama.cpp ~1.1 GB yes
phi-3.5-mini llama.cpp ~2.2 GB yes
mistral-7b llama.cpp ~4.1 GB yes
opencomplai scan --ai-intent                              # default: qwen2.5-coder-1.5b, needs [deep]
opencomplai scan --ai-intent --ai-model codebert-onnx     # no download, no [deep] extra

Model download flow

On first use of a GGUF model, the plugin prompts before downloading and shows a progress bar; the download is refused up front (no prompt, no partial download) if [deep] isn't installed. codebert-onnx needs none of this in normal use — it does deterministic code-signal matching with no model artifact to fetch.

An explicit prefetch/export of codebert-onnx (e.g. via opencomplai ai configure) is still available for callers that want the artifact anyway: CodeBERT has no prebuilt ONNX build on the Hub, so that path exports the official PyTorch checkpoint to ONNX on first run. It needs the separate [onnx] extra (optimum[onnxruntime]) and is unrelated to --ai-intent classification.

Optional extras

Extra Adds Needed for
[deep] llama-cpp-python every GGUF model, including the default qwen2.5-coder-1.5b
[onnx] optimum[onnxruntime] only an explicit codebert-onnx ONNX export/prefetch — not classification

Configuration

Env var Default Effect
OPENCOMPLAI_AI_TIMEOUT_SECONDS 10 Per-callsite timeout for local GGUF inference. A callsite whose completion doesn't finish in time is skipped — never reported as "minimal risk" — and a second call is refused rather than racing the abandoned worker.
OPENCOMPLAI_OFFLINE unset Block all network access outright: no model downloads, no saas calls.
OPENCOMPLAI_API_KEY unset Required to use the saas cloud backend.

Documentation

Full AI-intent guide and the model reference at docs.opencomplai.com.

License

AGPL-3.0-only. See LICENSE.

Metadata

Release files for opencomplai-ai 0.5.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for opencomplai-ai 0.5.0
File Size Uploaded
opencomplai_ai-0.5.0.tar.gz 44.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for opencomplai-ai 0.5.0
File Interpreter ABI Platform
opencomplai_ai-0.5.0-py3-none-any.whl Python 3 none any Details

Total release size: 82.9 kB

Release files / opencomplai_ai-0.5.0.tar.gz

Download URL opencomplai_ai-0.5.0.tar.gz
Size 44.1 kB
Tags Source
SHA-256 checksum
How to use checksums
e14d4452a11c2ae359daf865ef832cbdd0e87749a1b1d01e65a66be59abb9d9f
BLAKE2b-256 checksum
How to use checksums
4e5d069e93a8cb5087ef82411413aba6b56ad73026771c3cf8222508bbb6c74d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 26, 2026.

Transparency log

Release files / opencomplai_ai-0.5.0-py3-none-any.whl

Download URL opencomplai_ai-0.5.0-py3-none-any.whl
Size 38.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
206c31de4c44bbf081c5a7941b6fda1c52c31f68caade7aeee043f96d72f71eb
BLAKE2b-256 checksum
How to use checksums
5b62d542b250e99d26df0048a014ccb6c711c07a12aade6ad0abc11923b9a311
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 26, 2026.

Transparency log

Release history Release notifications | RSS feed

0.9.1

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

This release

0.5.0 This release

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.1.2

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page