Skip to main content

opencomplai-ai

License: AGPL-3.0 PyPI Python

The optional AI intent classification plugin for Opencomplai. It adds the --ai-intent flag to opencomplai scan, classifying how each AI callsite in your code is actually used — its decision autonomy, the subjects it acts on, and which EU AI Act risk tier and Annex III area it maps to.

All inference runs locally — models execute on your machine via llama.cpp, or via a deterministic code-signal matcher that needs no model weights at all. No code or prompts leave your environment unless you explicitly opt into the saas backend.

Prerequisites

opencomplai-ai is a plugin. Install the core engine first:

pip install opencomplai-core   # or the opencomplai / opencomplai-cli suite

Install

# Base install — only the deterministic codebert-onnx matcher, no download
pip install opencomplai-ai

# Deep install — required for the default model (qwen2.5-coder-1.5b) and
# every other generative GGUF model
pip install "opencomplai-ai[deep]"

The base install alone can only run codebert-onnx. opencomplai scan --ai-intent resolves qwen2.5-coder-1.5b by default, which needs [deep] — without it the scan fails fast with an actionable message instead of downloading the ~1 GB model first and only then discovering it can't be run.

Usage

Once installed alongside the CLI, the --ai-intent flag becomes available on the scan command:

opencomplai scan --ai-intent

By default only callsites in files with lexical findings are annotated (fast). To analyze every callsite in the repository:

opencomplai scan --ai-intent --ai-deep

Useful flags:

Flag Effect
--ai-intent Enable AI intent classification
--ai-model <id> Choose a model (see catalog below)
--ai-deep Annotate every callsite, not just those near lexical findings
--ai-verbose Show all callsite annotations (default: top 10 by risk tier)

Supported models

The default model is qwen2.5-coder-1.5b and requires the [deep] extra. GGUF models are downloaded from the Hugging Face Hub on first use and cached locally under ~/.cache/opencomplai/models/.

codebert-onnx is a deterministic Annex III / prohibited-practice / limited-risk code-signal matcher — no model weights, no download, runs on the base install. It trades recall for speed and zero setup; it is not the default.

Model ID Runtime Size Needs [deep]
codebert-onnx deterministic matcher no download no
qwen2.5-coder-0.5b llama.cpp ~400 MB yes
qwen2.5-coder-1.5b (default) llama.cpp ~1.0 GB yes
smollm2-1.7b llama.cpp ~1.1 GB yes
phi-3.5-mini llama.cpp ~2.2 GB yes
mistral-7b llama.cpp ~4.1 GB yes
opencomplai scan --ai-intent                              # default: qwen2.5-coder-1.5b, needs [deep]
opencomplai scan --ai-intent --ai-model codebert-onnx     # no download, no [deep] extra

Model download flow

On first use of a GGUF model, the plugin prompts before downloading and shows a progress bar; the download is refused up front (no prompt, no partial download) if [deep] isn't installed. codebert-onnx needs none of this in normal use — it does deterministic code-signal matching with no model artifact to fetch.

An explicit prefetch/export of codebert-onnx (e.g. via opencomplai ai configure) is still available for callers that want the artifact anyway: CodeBERT has no prebuilt ONNX build on the Hub, so that path exports the official PyTorch checkpoint to ONNX on first run. It needs the separate [onnx] extra (optimum[onnxruntime]) and is unrelated to --ai-intent classification.

Optional extras

Extra Adds Needed for
[deep] llama-cpp-python every GGUF model, including the default qwen2.5-coder-1.5b
[onnx] optimum[onnxruntime] only an explicit codebert-onnx ONNX export/prefetch — not classification

Configuration

Env var Default Effect
OPENCOMPLAI_AI_TIMEOUT_SECONDS 10 Per-callsite timeout for local GGUF inference. A callsite whose completion doesn't finish in time is skipped — never reported as "minimal risk" — and a second call is refused rather than racing the abandoned worker.
OPENCOMPLAI_OFFLINE unset Block all network access outright: no model downloads, no saas calls.
OPENCOMPLAI_API_KEY unset Required to use the saas cloud backend.

Documentation

Full AI-intent guide and the model reference at docs.opencomplai.com.

License

AGPL-3.0-only. See LICENSE.

Metadata

Release files for opencomplai-ai 0.8.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for opencomplai-ai 0.8.0
File Size Uploaded
opencomplai_ai-0.8.0.tar.gz 44.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for opencomplai-ai 0.8.0
File Interpreter ABI Platform
opencomplai_ai-0.8.0-py3-none-any.whl Python 3 none any Details

Total release size: 83.2 kB

Release files / opencomplai_ai-0.8.0.tar.gz

Download URL opencomplai_ai-0.8.0.tar.gz
Size 44.3 kB
Tags Source
SHA-256 checksum
How to use checksums
829118f583ef2d58142db9a619b280f0d2cebe377ab05daa32eac802fca86ce9
BLAKE2b-256 checksum
How to use checksums
e4909a35dfd9c50e23156114302cfe44bfd926b15ded29352631ba9824e4d4f4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / opencomplai_ai-0.8.0-py3-none-any.whl

Download URL opencomplai_ai-0.8.0-py3-none-any.whl
Size 38.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
96474842fc71055f89652bf602e97c16a8b7ffae659b8a8dc2d38d17afa40c39
BLAKE2b-256 checksum
How to use checksums
afa11449c967c6b19968ee775f5e9b0e914bfab418f23a4d9c659ac3035ad02d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release history Release notifications | RSS feed

0.9.1

2 release files

0.9.0

2 release files

This release

0.8.0 This release

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.1.2

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page