See which obligations in your AI product are yours, and which are someone else’s.
Describe your product in your own words. Boundsmap maps everyone involved, from the company whose model you build on to the people it makes decisions about, and shows what UK and EU law requires each time responsibility changes hands, and of whom.
Free to look around: the example opens in your browser, with no sign-up. Mapping your own system is by invite while Boundsmap is in beta. Self-assessed from your own description. Not an audit, a certification, or legal advice.
The idea
The obligation is not always where you would look for it
Boundsmap works on Circial’s Roles & Boundaries Framework: five layers for who stands where, and four boundaries where responsibility changes hands. It comes from founder Iain Barclay’s doctoral research on accountability in AI systems.
Layer 1
Source Materials
The data, models and code your system draws on, made by someone else.
Boundary 1Source Materials to Capability BuildersLayer 2
Capability Builders
Whoever builds the AI capability itself.
Boundary 2Capability Builders to IntegratorsLayer 3
Integrators
Whoever wires that capability into a product people can use.
Boundary 3Integrators to OperatorsLayer 4
Operators
Whoever runs it day to day, and decides what to do with its output.Often your customer, not you.
Boundary 4Operators to Affected PartiesLayer 5
Affected Parties
The people the system makes decisions about, or acts on.
Most obligations fall on whoever stands at a layer. Some do not. Take software that scores CV matches for recruitment agencies. The agencies using it must give a named person the training and the authority to overrule its scores (EU AI Act, Article 26(2)). The company that makes the software must make that possible: build the oversight in, and write instructions a recruiter can act on (Articles 14 and 13).
Three obligations at the same boundary, on two different businesses. Boundsmap says whose each one is.
How it works
From a description to a map
Step 1
Describe
Say what your product does, the way you would explain it to someone joining the company. If you would rather not write, copy one of two prompts into your own AI assistant: one asks you questions, the other reads your code.
Step 2
Roles
Claude, Anthropic's AI model, reads your description and places everyone involved at one of the five layers. Each placement is marked as the AI's reading until you confirm or correct it.
Step 3
Boundaries
Fixed rules, not the AI, work out what UK and EU law requires at each of the four boundaries, and whose obligation each one is. Where your description does not settle something, Boundsmap asks rather than guesses.
Step 4
Summary
Save a summary you can send: the map as one picture, the obligations it lists as required, and how many questions are still open. As a PDF, or as plain text.
What you get
- A map of your system, in your words. Who supplies what, who builds it, who sells it, who uses it, and who it affects, each checked by you.
- Each obligation, named and explained. The provision, what it means in plain words, whose obligation it is, and what kind of work it is: something to write down, build in, put in a contract, or file.
- Questions instead of guesses. Where the map cannot tell, it says “Needs your answer” and waits for you.
- Gaps said out loud. Boundsmap covers UK and EU law today. If your system reaches a country it has no rules for, the map says so.
Where your product sits
Every map is this line, filled in with the people and systems in your product. This one is an example: a CV-matching product, from its AI model to the job applicants it scores.
Source Materials
Claude, from Anthropic
Boundary 1
Capability Builders
Cairnhire’s own AI team
Boundary 2
Integrators
Cairnhire’s own web developers
Boundary 3
Operators
Customer recruiters at recruitment agencies and in-house hiring teams
Boundary 4
Affected Parties
Job applicants
What Boundsmap is, and is not
- Self-assessed and checkable.
- It works from your description and your answers, and every obligation names its provision, so you or your adviser can read the law itself. It is not an audit, a certification, or legal advice.
- The AI reads; fixed rules decide.
- Your description goes to Claude, Anthropic's AI model, which works out who is involved. What the law requires is then worked out by fixed rules that Circial writes and tests, not by the AI.
- The example stays with you.
- It runs in your browser and calls no AI. Nothing you change on it is saved. You can save its summary as a PDF to share, or as Markdown to give to your AI assistant.
About Circial
A responsible AI and digital trust practice
Circial is a UK-based practice led by Iain Barclay, PhD, a time-served Principal Engineer. His doctoral research (2023) examined trustworthy data and AI accountability using decentralised technologies, building on an earlier MSc in Information Privacy and Security. Related papers on transparency and accountability in AI systems have been cited over 300 times.
Iain contributed to IEEE 7001-2021, the IEEE Standard for Transparency of Autonomous Systems, and has served as an expert reviewer for UKRI. He has led technical proposal and deliverable authorship for funded AI and LLM research projects with industry and university partners, and has spent years translating emerging regulation into engineering requirements. He is currently pursuing ISO/IEC 42001 Lead Implementer certification.
Alongside Boundsmap, Iain and his associates are available for freelance and fractional technical leadership: an engineering-led approach to AI risk and the obligations around AI systems, from data governance architecture through to applied LLM tooling.
See a finished map before you write a word
Mapping your own system is by invite while Boundsmap is in beta. To talk through how AI governance applies to your own systems, email iain@circial.com.