opencomplai-core
The compliance engine at the heart of Opencomplai.
opencomplai-core turns a declared system-manifest.json and your source tree into a
deterministic, rule-based EU AI Act risk classification and gap report — no LLM calls,
no network access, fully reproducible. The same evidence also yields a NIST AI RMF 1.0
view, re-projected through a built-in crosswalk rather than measured separately. EU AI Act evaluated; NIST AI RMF derived (partial, unreviewed); ISO 42001 native pack, attestation-led (partial, unreviewed); DORA and EBA mapped only.
It powers risk classification (UnacceptableRiskRule, AnnexIIIClassifierRule,
ProfilingDetectionRule, SubstantialModificationRule) and the code-corroboration scan
engine that cross-checks what a manifest claims against what the code actually does.
Install
pip install opencomplai-core
For PDF report generation, install the optional extra:
pip install "opencomplai-core[reports]"
Most users want the
opencomplaimeta-package (engine + CLI) or theopencomplai-clicommand-line tool. Installopencomplai-coredirectly when you are embedding the engine in your own application.
Quick start
Classify a model from a declared manifest
from opencomplai import assess, AssessmentInput, ModelMetadata
result = assess(AssessmentInput(
model=ModelMetadata(
name="loan-scorer",
version="1.0.0",
modality="tabular",
use_case="creditworthiness scoring for consumer loans",
deployment_context="production",
)
))
print(result.risk_level) # e.g. RiskLevel.HIGH
for rule in result.rule_results:
print(rule.rule_id, "PASS" if rule.passed else "FAIL")
Corroborate a manifest against the code
from pathlib import Path
from opencomplai_core.scan_engine import run_scan
report = run_scan(
repo_root=Path("."),
commit_ref="HEAD",
)
print(report.summary.result) # PASS / CONTROL_FAIL / ...
for finding in report.findings:
print(finding.finding_id, finding.mapped_taxonomy)
The scan engine extracts features from the repository, fuses evidence across detectors, and maps findings to EU AI Act taxonomy (Annex III high-risk areas, Article 5 prohibited practices, profiling under Article 6).
Assess several frameworks side by side
from opencomplai_core import FRAMEWORKS, SystemManifest, evaluate_targets
manifest = SystemManifest(
system_id="loan-scorer",
intended_purpose="creditworthiness scoring for consumer loans",
compliance_targets=["EU_AI_ACT", "NIST_AI_RMF"],
)
reports = evaluate_targets(manifest, ["EU_AI_ACT", "NIST_AI_RMF"], commit_ref="HEAD")
for framework, report in reports.items():
print(FRAMEWORKS[framework].label, len(report.report.articles), "requirements")
FRAMEWORKS lists what this release can assess. EU AI Act evaluated; NIST AI RMF derived (partial, unreviewed); ISO 42001 native pack, attestation-led (partial, unreviewed); DORA and EBA mapped only. See
Frameworks.
What you get
- Deterministic risk classification — same inputs always produce the same output, so results are auditable and CI-gateable.
- Code corroboration — detect when a manifest under-declares (claims minimal risk while the code does biometric identification, profiling, etc.).
- Merkle-linked evidence — findings carry verifiable evidence items for audit trails.
Documentation
Full docs, the EU AI Act concepts guide, and the SDK reference live at docs.opencomplai.com.
License
AGPL-3.0-only. See LICENSE.
Metadata
Release files for opencomplai-core 0.9.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| opencomplai_core-0.9.0.tar.gz | 456.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| opencomplai_core-0.9.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 813.5 kB
Release files / opencomplai_core-0.9.0.tar.gz
| Download URL | opencomplai_core-0.9.0.tar.gz |
|---|---|
| Size | 456.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
88dcd809855b645368800e22005cc96ea446ed09318a881a0abb5e44937fa75d
|
|
BLAKE2b-256 checksum How to use checksums |
50217e04c503dc0b7b75fe0642acca42cc92b965ea7a2643ff1f2cb50b9ebf70
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.
Transparency logRelease files / opencomplai_core-0.9.0-py3-none-any.whl
| Download URL | opencomplai_core-0.9.0-py3-none-any.whl |
|---|---|
| Size | 356.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6bb9b6c1bb6e3aed32a2c1fb6bda46ad515e1168567d09005f0dacfd3e3f526c
|
|
BLAKE2b-256 checksum How to use checksums |
977620e535233830eccb48da7ede23ec627788de63fe37ac24d6aa2db036c81a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.
Transparency log