Sentinel — AI-Governance & Export-Control Readiness Assessor
One deterministic pass over the two legal questions a regulated AI programme must answer together: is it lawful to build and use — and is it lawful to move?
01The problem
A serious AI or autonomous-system programme sits under two bodies of law that are almost never assessed together. The EU AI Act asks whether the system is lawful to build and use — its risk tier and the obligations that tier triggers. Export control asks whether it is lawful to move the system, its source, its model weights or its compute across a border — the EU Dual-Use Regulation 2021/821 and the Wassenaar lists it implements, with US EAR/ITAR exposure layered on top. In practice these are handled by different teams on different timelines, and the seam between them is where a compliant-looking product becomes an unlawful export — or an export-cleared item quietly breaches a prohibited-practice rule. Add a moving compliance calendar — staggered application dates, with the Digital Omnibus reshuffling Annex III timing — and most organisations are answering yesterday's question.
02What I built
Sentinel takes a nine-input description of a deployment — capability, sector, data, sensitivity and context, autonomy level, oversight model, role, jurisdictions of build and use, and dual-use context — and returns both answers in one pass.
- EU AI Act classifier: prohibited (Art 5), high-risk (Annex III / Annex I), limited (Art 50) or minimal, with the exact provider/deployer obligations and a GPAI (Arts 53–55) overlay; the timeline is dated to the 2025–26 Digital Omnibus, including Annex III high-risk moving to 2 December 2027.
- Dual-use export screen: EU Reg. 2021/821 — the Art 5 cyber-surveillance catch-all and Art 4 — plus Wassenaar Categories 3/4/5 (intrusion software, IP-network surveillance, cryptography, advanced compute), with an honest flag where US ITAR/EAR may also bite.
- Meaningful-human-control and auditability measures matched to the autonomy level — human-in-command / in-the-loop, Art 12/26 logging, FRIA/DPIA, post-market monitoring — then a clear verdict and an audit-ready control record exportable to HTML, JSON or print/PDF.
- A deterministic rules engine — pure functions, no model, no probabilistic prediction — in plain HTML/CSS/JS that runs offline from file://.
03Two regimes, one set of facts
Sentinel's premise is a piece of legal analysis: the AI Act question and the export-control question draw on almost identical facts — what the system does, its data and autonomy, its sectors, its jurisdictions — so they can and should be answered together, early enough to change the design. The control philosophy is “regulated by design”: human authority, auditability and export screening treated as properties of the system, not paperwork appended to it. The engine is deterministic because a governance conclusion must be reproducible and explainable — the same inputs always give the same, traceable answer. And it is scrupulous about the state of the law: every line is tagged legal fact, reasoned assessment, verify or action; positions are dated July 2026; and the Digital Omnibus is reported precisely as what it is — adopted but awaiting Official Journal publication, flagged “confirm before you rely on it” rather than asserted as in force.
04Why an employer deploying AI needs both halves
Any bank, commodity house or technology business deploying AI now owns both problems at once — AI Act readiness and the export exposure of the models, code and compute it moves across borders. Sentinel demonstrates that I hold the full seam in one head: risk-tier classification, dual-use screening, and the human-oversight and logging controls that make a deployment defensible. That maps directly onto sanctions and export-control advisory, AI-governance counsel work, and the growing category of matters where the two collide — and it puts the assessment early enough in a programme to still change the design.
