Skip to main content

opencomplai-core

License: AGPL-3.0 PyPI Python

The compliance engine at the heart of Opencomplai. opencomplai-core turns a declared system-manifest.json and your source tree into a deterministic, rule-based EU AI Act risk classification and gap report — no LLM calls, no network access, fully reproducible. The same evidence also yields a NIST AI RMF 1.0 view, re-projected through a built-in crosswalk rather than measured separately. EU AI Act evaluated; NIST AI RMF derived (partial, unreviewed); ISO 42001 native pack, attestation-led (partial, unreviewed); DORA and EBA mapped only.

It powers risk classification (UnacceptableRiskRule, AnnexIIIClassifierRule, ProfilingDetectionRule, SubstantialModificationRule) and the code-corroboration scan engine that cross-checks what a manifest claims against what the code actually does.

Install

pip install opencomplai-core

For PDF report generation, install the optional extra:

pip install "opencomplai-core[reports]"

Most users want the opencomplai meta-package (engine + CLI) or the opencomplai-cli command-line tool. Install opencomplai-core directly when you are embedding the engine in your own application.

Quick start

Classify a model from a declared manifest

from opencomplai import assess, AssessmentInput, ModelMetadata

result = assess(AssessmentInput(
    model=ModelMetadata(
        name="loan-scorer",
        version="1.0.0",
        modality="tabular",
        use_case="creditworthiness scoring for consumer loans",
        deployment_context="production",
    )
))

print(result.risk_level)        # e.g. RiskLevel.HIGH
for rule in result.rule_results:
    print(rule.rule_id, "PASS" if rule.passed else "FAIL")

Corroborate a manifest against the code

from pathlib import Path
from opencomplai_core.scan_engine import run_scan

report = run_scan(
    repo_root=Path("."),
    commit_ref="HEAD",
)

print(report.summary.result)            # PASS / CONTROL_FAIL / ...
for finding in report.findings:
    print(finding.finding_id, finding.mapped_taxonomy)

The scan engine extracts features from the repository, fuses evidence across detectors, and maps findings to EU AI Act taxonomy (Annex III high-risk areas, Article 5 prohibited practices, profiling under Article 6).

Assess several frameworks side by side

from opencomplai_core import FRAMEWORKS, SystemManifest, evaluate_targets

manifest = SystemManifest(
    system_id="loan-scorer",
    intended_purpose="creditworthiness scoring for consumer loans",
    compliance_targets=["EU_AI_ACT", "NIST_AI_RMF"],
)
reports = evaluate_targets(manifest, ["EU_AI_ACT", "NIST_AI_RMF"], commit_ref="HEAD")
for framework, report in reports.items():
    print(FRAMEWORKS[framework].label, len(report.report.articles), "requirements")

FRAMEWORKS lists what this release can assess. EU AI Act evaluated; NIST AI RMF derived (partial, unreviewed); ISO 42001 native pack, attestation-led (partial, unreviewed); DORA and EBA mapped only. See Frameworks.

What you get

  • Deterministic risk classification — same inputs always produce the same output, so results are auditable and CI-gateable.
  • Code corroboration — detect when a manifest under-declares (claims minimal risk while the code does biometric identification, profiling, etc.).
  • Merkle-linked evidence — findings carry verifiable evidence items for audit trails.

Documentation

Full docs, the EU AI Act concepts guide, and the SDK reference live at docs.opencomplai.com.

License

AGPL-3.0-only. See LICENSE.

Metadata

Release files for opencomplai-core 0.9.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for opencomplai-core 0.9.1
File Size Uploaded
opencomplai_core-0.9.1.tar.gz 460.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for opencomplai-core 0.9.1
File Interpreter ABI Platform
opencomplai_core-0.9.1-py3-none-any.whl Python 3 none any Details

Total release size: 818.1 kB

Release files / opencomplai_core-0.9.1.tar.gz

Download URL opencomplai_core-0.9.1.tar.gz
Size 460.5 kB
Tags Source
SHA-256 checksum
How to use checksums
d7819afa07e6c82f1e691ac48eb763aa323c30df8d2e4116fd1c17bfed95dfc6
BLAKE2b-256 checksum
How to use checksums
b1657de860b3d6c45dad44967982e231914c7d67f54eeadd9a0dc5cf4f1836b2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release files / opencomplai_core-0.9.1-py3-none-any.whl

Download URL opencomplai_core-0.9.1-py3-none-any.whl
Size 357.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cbb6336c86946c2349230aaf014805ed0a58054efb8d0b953693f4ee6e39f5cc
BLAKE2b-256 checksum
How to use checksums
a1b83c97563ae5e5d21107c26c6d719b78e6cd35741d641fe93c0ee83a3e20d9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.9.1 This release

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.1.2

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page