Skip to main content

opencomplai-ai

License: AGPL-3.0 PyPI Python

The optional AI intent classification plugin for Opencomplai. It adds the --ai-intent flag to opencomplai scan, classifying how each AI callsite in your code is actually used — its decision autonomy, the subjects it acts on, and which EU AI Act risk tier and Annex III area it maps to.

All inference runs locally — models execute on your machine via llama.cpp, or via a deterministic code-signal matcher that needs no model weights at all. No code or prompts leave your environment unless you explicitly opt into the saas backend.

Prerequisites

opencomplai-ai is a plugin. Install the core engine first:

pip install opencomplai-core   # or the opencomplai / opencomplai-cli suite

Install

# Base install — only the deterministic codebert-onnx matcher, no download
pip install opencomplai-ai

# Deep install — required for the default model (qwen2.5-coder-1.5b) and
# every other generative GGUF model
pip install "opencomplai-ai[deep]"

The base install alone can only run codebert-onnx. opencomplai scan --ai-intent resolves qwen2.5-coder-1.5b by default, which needs [deep] — without it the scan fails fast with an actionable message instead of downloading the ~1 GB model first and only then discovering it can't be run.

Usage

Once installed alongside the CLI, the --ai-intent flag becomes available on the scan command:

opencomplai scan --ai-intent

By default only callsites in files with lexical findings are annotated (fast). To analyze every callsite in the repository:

opencomplai scan --ai-intent --ai-deep

Useful flags:

Flag Effect
--ai-intent Enable AI intent classification
--ai-model <id> Choose a model (see catalog below)
--ai-deep Annotate every callsite, not just those near lexical findings
--ai-verbose Show all callsite annotations (default: top 10 by risk tier)

Supported models

The default model is qwen2.5-coder-1.5b and requires the [deep] extra. GGUF models are downloaded from the Hugging Face Hub on first use and cached locally under ~/.cache/opencomplai/models/.

codebert-onnx is a deterministic Annex III / prohibited-practice / limited-risk code-signal matcher — no model weights, no download, runs on the base install. It trades recall for speed and zero setup; it is not the default.

Model ID Runtime Size Needs [deep]
codebert-onnx deterministic matcher no download no
qwen2.5-coder-0.5b llama.cpp ~400 MB yes
qwen2.5-coder-1.5b (default) llama.cpp ~1.0 GB yes
smollm2-1.7b llama.cpp ~1.1 GB yes
phi-3.5-mini llama.cpp ~2.2 GB yes
mistral-7b llama.cpp ~4.1 GB yes
opencomplai scan --ai-intent                              # default: qwen2.5-coder-1.5b, needs [deep]
opencomplai scan --ai-intent --ai-model codebert-onnx     # no download, no [deep] extra

Model download flow

On first use of a GGUF model, the plugin prompts before downloading and shows a progress bar; the download is refused up front (no prompt, no partial download) if [deep] isn't installed. codebert-onnx needs none of this in normal use — it does deterministic code-signal matching with no model artifact to fetch.

An explicit prefetch/export of codebert-onnx (e.g. via opencomplai ai configure) is still available for callers that want the artifact anyway: CodeBERT has no prebuilt ONNX build on the Hub, so that path exports the official PyTorch checkpoint to ONNX on first run. It needs the separate [onnx] extra (optimum[onnxruntime]) and is unrelated to --ai-intent classification.

Optional extras

Extra Adds Needed for
[deep] llama-cpp-python every GGUF model, including the default qwen2.5-coder-1.5b
[onnx] optimum[onnxruntime] only an explicit codebert-onnx ONNX export/prefetch — not classification

Configuration

Env var Default Effect
OPENCOMPLAI_AI_TIMEOUT_SECONDS 10 Per-callsite timeout for local GGUF inference. A callsite whose completion doesn't finish in time is skipped — never reported as "minimal risk" — and a second call is refused rather than racing the abandoned worker.
OPENCOMPLAI_OFFLINE unset Block all network access outright: no model downloads, no saas calls.
OPENCOMPLAI_API_KEY unset Required to use the saas cloud backend.

Documentation

Full AI-intent guide and the model reference at docs.opencomplai.com.

License

AGPL-3.0-only. See LICENSE.

Metadata

Release files for opencomplai-ai 0.7.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for opencomplai-ai 0.7.0
File Size Uploaded
opencomplai_ai-0.7.0.tar.gz 44.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for opencomplai-ai 0.7.0
File Interpreter ABI Platform
opencomplai_ai-0.7.0-py3-none-any.whl Python 3 none any Details

Total release size: 82.9 kB

Release files / opencomplai_ai-0.7.0.tar.gz

Download URL opencomplai_ai-0.7.0.tar.gz
Size 44.1 kB
Tags Source
SHA-256 checksum
How to use checksums
f41fee1a08f68137f7f6048b02f2f34f940c809dd31a6ff1acebc9edc3bd9dd2
BLAKE2b-256 checksum
How to use checksums
9f6e11b91af7a6254b6d8c46f4281d0000113d47dbce6c95b08d62676d1d6d30
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release files / opencomplai_ai-0.7.0-py3-none-any.whl

Download URL opencomplai_ai-0.7.0-py3-none-any.whl
Size 38.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
fa8e96e679282fe11dbac1b76e7890daeeffac06021045768dbd35d43bdd8f6e
BLAKE2b-256 checksum
How to use checksums
a760029bdc2d6fe6671fb828c4a8d43a2d346cb6d2538c2834bd25bcaa08730f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release history Release notifications | RSS feed

0.9.1

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.1

2 release files

This release

0.7.0 This release

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.1.2

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page