AILP - LLM compliance SDK (@airtasystems/ailp)

    Apr 21, 2026

    Resources

    Pre-1.0: This client is under active development and is not in active production use elsewhere. Breaking changes are possible until 1.0.0; pin an exact version or a tight semver range in production.

    What is AILP?

    AILP is the AIRTA Systems client for LLM compliance risk assessment. It sends your LLM interactions to the AILP server for automated scoring against frameworks such as the EU AI Act, OWASP LLM Top 10, NIST AI RMF, and more. It works with any LLM provider. The core client has no runtime dependencies beyond native fetch.

    Install

    npm install @airtasystems/ailp

    Default server URL

    The package default is AILP_DEFAULT_BASE_URL (https://airtasystems.com/ailp, no trailing slash). You do not need NEXT_PUBLIC_AILP_BASE_URL or VITE_AILP_BASE_URL unless you use another origin (self-hosted or local). For AilpClient, pass baseUrl: AILP_DEFAULT_BASE_URL or your own origin.

    Quick start

    createAilp() and useAilp() default to the hosted API above - omit baseUrl (and base URL env vars) unless you target another server. For local or Docker, pass something like baseUrl: "http://127.0.0.1:8000".

    import { createAilp } from "@airtasystems/ailp";
    
    const ailp = createAilp({
      frameworks: ["eu-ai-act", "owasp-llm"],
      provider: "gemini",
      geminiApiKey: process.env.GEMINI_API_KEY,
    });
    
    const res = await ailp(messages, llmOutput);
    
    console.log(res.risk_level);
    console.log(res.frameworks);
    console.log(res.experts);
    console.log(res.judge_reasoning);

    Optional model hint (the model that produced llmOutput, not the internal AILP model):

    const res = await ailp(messages, llmOutput, { model: "gpt-4o-mini" });

    Provider selection

    AILP uses Gemini or OpenAI as its expert and judge LLM. Set provider and pass the matching API key; the client sends the correct X-*-Api-Key header. For different vendors on experts vs judge, use expertProvider and judgeProvider and supply both keys when needed.

    On the server, you can omit provider from JSON and set AILP_PROVIDER, AILP_EXPERT_PROVIDER, AILP_JUDGE_PROVIDER, AILP_EXPERT_MODEL, and AILP_JUDGE_MODEL in repo .config. If you omit provider from createAilp(), the SDK does not send that field so server defaults apply.

    Security: API keys

    LLM API keys are secrets. Do not ship them to browsers via NEXT_PUBLIC_* or VITE_* in production - they are baked into the bundle. Call AILP from a server route (Next.js API route, Vite server endpoint, etc.) that reads the key from a private environment variable. Public env vars are only appropriate for local demos.

    Streaming (assessStream)

    POST /assess/stream returns NDJSON (one JSON object per line). AilpClient.assessStream() calls that endpoint, invokes an optional onEvent callback for each meta, cached, phase, expert, and judge line, then resolves with the same shape as assess() from the final done line. If you proxy AILP through your own fetch, use readAilpAssessNdjsonStream(response.body, onEvent) to parse the stream.

    Works with any LLM provider

    After your OpenAI, Anthropic, or other call, pass the same messages array and the assistant text string into ailp(messages, output). See the npm README for copy-paste examples for OpenAI and Anthropic.

    Fire-and-forget wrappers

    Use wrapOpenAI for OpenAI chat completions so assessment runs in the background without blocking the user response. Use wrapLlmCall for any async LLM function with an extractOutput callback.

    React (@airtasystems/ailp/react)

    Import from @airtasystems/ailp/react so React stays out of the core bundle.

    useAilp()

    Memoized client plus assess, result, loading, error, and reset. Each assess() clears the previous result and error. Configure with NEXT_PUBLIC_* or VITE_* env vars where appropriate.

    VariableRequiredNotes
    NEXT_PUBLIC_AILP_BASE_URL / VITE_AILP_BASE_URLNoDefaults to hosted URL; set for self-hosted or local.
    NEXT_PUBLIC_AILP_PROVIDER / VITE_AILP_PROVIDERNoOmit so the server picks providers from its config (typical for production browser apps against hosted AILP).
    NEXT_PUBLIC_GEMINI_API_KEY / VITE_GEMINI_API_KEYIf client sends Gemini-
    NEXT_PUBLIC_OPENAI_API_KEY / VITE_OPENAI_API_KEYIf client sends OpenAI-
    NEXT_PUBLIC_AIRTASYSTEMS_PROGRAM_IDNoOmitted from payload when unset.
    NEXT_PUBLIC_AILP_FRAMEWORKSNoDefault eu-ai-act; use comma-separated slugs in .env.

    For advanced use, useAssess(ailp) works with an existing AilpFn from createAilp().

    Framework slugs

    SlugFramework
    eu_ai_act / eu-ai-actEU AI Act
    oecdOECD AI Principles
    owasp_llm / owasp-llmOWASP Top 10 for LLMs
    owasp_agent / owasp-agentOWASP Top 10 for Agentic Applications
    nist_ai_rmf / nist-ai-rmfNIST AI RMF
    mitre_attack / mitre-attackMITRE ATT&CK
    pldEU PLD (AI)
    fria_core / fria-coreFRIA Core
    fria_extended / fria-extendedFRIA Extended

    Risk levels (ordered)

    critical > high > medium > low > informational > compliant > indeterminate

    License

    MIT. For the authoritative API surface, types, and stream event contract, use the package README on npm.

    AILP - LLM compliance SDK (@airtasystems/ailp) | AIRTA Systems Support