Back to Air Control PRODUCT FACULTY
Project documentation

Air Control.

By Neil Munro

Air Control helps product managers determine an EU AI Act risk classification from a product description.

The problem

Product managers building AI products need to understand their EU AI Act risk classification early, but the tools and guidance don't serve them. Existing GRC and governance platforms — Vanta, OneTrust, Credo AI, Collibra — are top-down, built for the Chief Risk Officer, require company-wide implementation, and start at roughly $10k/year with no trial for a single PM.

The official EU AI Act checker is coarse-grained and ambiguous: it mostly defines "High Risk," lists articles as generic URLs, and doesn't correlate its answers to the specifics of a product. A PM is left without confidence, unable to clearly communicate a classification and its implications to legal, engineering, and leadership.

The solution

AIR Control is a bottom-up, PM-focused risk classifier that "speaks Engineering" but "understands Legal." A product manager enters a product description and receives an EU AI Act risk classification and rationale, mapped back to explicit parts of the regulation.

Beyond the classification (Prohibited, High, Limited, Minimal, Exempt, or Unable to Classify), it produces a decision log to support communication across legal, engineering, and risk. A disagreement flow lets users challenge a classification and append feedback to reports. The value framing is velocity protection — giving a PM the evidence to walk into a legal or risk review and show exactly how the product maps to the Act.

How it works

The system runs a five-stage streamed pipeline: SIGNALS (scoring input quality against a signals matrix), CLASSIFICATION (risk tier plus provider/deployer role), MAP (mapping description snippets to specific article text with links), WARNINGS (future risk-transformation scenarios), and INFO (obligations and next steps). Each stage runs as a separate API call for control and evaluability, using structured SYSTEM, STAGE, and SYSTEM RULES prompts.

It runs on Gemini-3.5-Flash, chosen after evaluation for low cost (~10–12 cents per full pipeline) and consistent output; Claude Sonnet was stricter but felt less predictable. Rules require citing specific articles, never inventing capabilities, downgrading confidence when evidence is thin, and rejecting non-product-description or prompt-injection inputs. RAG is deemed unnecessary. Evaluation uses LLM-as-a-judge for signals, classification, and role, recorded via OpenTelemetry into Arize Phoenix; Prohibited and High Risk cases scored 100%, while the Limited/Minimal boundary remains genuinely ambiguous and needs human judgment.

Who it's for

The product is B2C, targeting product managers with little to no budget who face enterprise procurement barriers. The persona is "George," a PM at a UK fintech with regulated-API (PSD2) experience but minimal AI delivery experience, who needs fast, evidence-backed understanding of AI risk to make go/no-go decisions and communicate them to architecture, legal, operations, marketing, and leadership.

Revenue is a free tier (2 assessments/month, no decision log) plus a $20/month subscription (10 full assessments with decision logs, rollover credits, regulatory-pulse notifications) and a $10/month Linear integration add-on. MCP, the disagreement flow, and regulatory pulse are seen as key to retention.

Why it matters

The AI governance tooling market is estimated to grow to $3.4bn by 2030 at a 35–40% CAGR as the AI Act's staggered deadlines take effect. Incorrect classifications carry stakes of €35M+ fines, most firms still rely on fragmented spreadsheets, and non-EU companies need these tools to keep access to the European single market — yet there is almost no bottom-up, PM-focused option.

A solo-operated startup in discovery, AIR Control plans a launch to fewer than 10 trial users — including three with PSD2 and legal-interpretation experience — to test the core retention question. Given the legal nature of the output, a clear disclaimer and human review are built in, with legal review of output and terms required before launch.

At a glance

Project
Air Control
Built by
Neil Munro
One-liner
Air Control helps product managers determine an EU AI Act risk classification from a product description.
View the project page