Skip to main content

opencomplai-ai

License: AGPL-3.0 PyPI Python

The optional AI intent classification plugin for Opencomplai. It adds the --ai-intent flag to opencomplai scan, classifying how each AI callsite in your code is actually used — its decision autonomy, the subjects it acts on, and which EU AI Act risk tier and Annex III area it maps to.

All inference runs locally — models execute on your machine via llama.cpp, or via a deterministic code-signal matcher that needs no model weights at all. No code or prompts leave your environment unless you explicitly opt into the saas backend.

Prerequisites

opencomplai-ai is a plugin. Install the core engine first:

pip install opencomplai-core   # or the opencomplai / opencomplai-cli suite

Install

# Base install — only the deterministic codebert-onnx matcher, no download
pip install opencomplai-ai

# Deep install — required for the default model (qwen2.5-coder-1.5b) and
# every other generative GGUF model
pip install "opencomplai-ai[deep]"

The base install alone can only run codebert-onnx. opencomplai scan --ai-intent resolves qwen2.5-coder-1.5b by default, which needs [deep] — without it the scan fails fast with an actionable message instead of downloading the ~1 GB model first and only then discovering it can't be run.

Usage

Once installed alongside the CLI, the --ai-intent flag becomes available on the scan command:

opencomplai scan --ai-intent

By default only callsites in files with lexical findings are annotated (fast). To analyze every callsite in the repository:

opencomplai scan --ai-intent --ai-deep

Useful flags:

Flag Effect
--ai-intent Enable AI intent classification
--ai-model <id> Choose a model (see catalog below)
--ai-deep Annotate every callsite, not just those near lexical findings
--ai-verbose Show all callsite annotations (default: top 10 by risk tier)

Supported models

The default model is qwen2.5-coder-1.5b and requires the [deep] extra. GGUF models are downloaded from the Hugging Face Hub on first use and cached locally under ~/.cache/opencomplai/models/.

codebert-onnx is a deterministic Annex III / prohibited-practice / limited-risk code-signal matcher — no model weights, no download, runs on the base install. It trades recall for speed and zero setup; it is not the default.

Model ID Runtime Size Needs [deep]
codebert-onnx deterministic matcher no download no
qwen2.5-coder-0.5b llama.cpp ~400 MB yes
qwen2.5-coder-1.5b (default) llama.cpp ~1.0 GB yes
smollm2-1.7b llama.cpp ~1.1 GB yes
phi-3.5-mini llama.cpp ~2.2 GB yes
mistral-7b llama.cpp ~4.1 GB yes
opencomplai scan --ai-intent                              # default: qwen2.5-coder-1.5b, needs [deep]
opencomplai scan --ai-intent --ai-model codebert-onnx     # no download, no [deep] extra

Model download flow

On first use of a GGUF model, the plugin prompts before downloading and shows a progress bar; the download is refused up front (no prompt, no partial download) if [deep] isn't installed. codebert-onnx needs none of this in normal use — it does deterministic code-signal matching with no model artifact to fetch.

The package also contains a Python-API-only function, opencomplai_ai.downloader.ensure_model("codebert-onnx"), that exports the official PyTorch checkpoint of CodeBERT to ONNX (CodeBERT has no prebuilt ONNX build on the Hub). No CLI command calls it (opencomplai ai configure only saves your model choice), nothing reads the exported file, and it is not used for --ai-intent classification. It needs the separate [onnx] extra (optimum[onnxruntime]).

Optional extras

Extra Adds Needed for
[deep] llama-cpp-python every GGUF model, including the default qwen2.5-coder-1.5b
[onnx] optimum[onnxruntime] only the Python-API ensure_model("codebert-onnx") export — not classification, not any CLI command

Configuration

Env var Default Effect
OPENCOMPLAI_AI_TIMEOUT_SECONDS 10 Per-callsite timeout for local GGUF inference. A callsite whose completion doesn't finish in time is skipped — never reported as "minimal risk" — and a second call is refused rather than racing the abandoned worker.
OPENCOMPLAI_OFFLINE unset Block all network access outright: no model downloads, no saas calls.
OPENCOMPLAI_API_KEY unset Required to use the saas cloud backend.

Documentation

Full AI-intent guide and the model reference at docs.opencomplai.com.

License

AGPL-3.0-only. See LICENSE.

Metadata

Release files for opencomplai-ai 0.9.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for opencomplai-ai 0.9.0
File Size Uploaded
opencomplai_ai-0.9.0.tar.gz 48.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for opencomplai-ai 0.9.0
File Interpreter ABI Platform
opencomplai_ai-0.9.0-py3-none-any.whl Python 3 none any Details

Total release size: 88.6 kB

Release files / opencomplai_ai-0.9.0.tar.gz

Download URL opencomplai_ai-0.9.0.tar.gz
Size 48.1 kB
Tags Source
SHA-256 checksum
How to use checksums
1b26d248c914bf29d025fbb6ee8e964d02a1d3f3a829f2022e4438b91026f3e7
BLAKE2b-256 checksum
How to use checksums
56e8bac70335bb53ec82586251b399bcb9aa23351ffd5d70347d8b1a117ade16
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release files / opencomplai_ai-0.9.0-py3-none-any.whl

Download URL opencomplai_ai-0.9.0-py3-none-any.whl
Size 40.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7f142f293d9912a2cb51f066c4d601a7f31fde623c7a5439f57c6d769323f201
BLAKE2b-256 checksum
How to use checksums
3ca53b5698e5c39bb2d18d2c1e71876a4b7320bb53c00dd6e1e0cf514d19eb91
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release history Release notifications | RSS feed

0.9.1

2 release files

This release

0.9.0 This release

2 release files

0.8.0

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.1.2

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page