A private Council of AI Investigators reads your product like an incident report waiting to happen. In ninety seconds you get ranked villains, VRSD scoring, and a ship-or-redesign verdict.
The regulatory floor moved. Insurance moved. Enterprise procurement moved. Villain's Hat lands the evidence.
Risk management (Art. 9) and record-keeping (Art. 15) enter full enforcement in August 2026 for high-risk AI systems. Investigations give you documented pre-ship analysis, versioned per release. It's what the checklist asks for.
Standalone AI liability policies emerged in 2025. Every one asks the same question: what did you do to identify misuse and harm vectors before shipping? A Villain's Hat report is the answer, dated and attributable.
Enterprise buyers now include AI safety evidence in vendor questionnaires. If your competitor can show a pre-ship audit and you can't, you lose the deal. Investigations Platform makes that evidence three clicks away.
Every investigation runs the same architecture. Screened, investigated, answered.
The Sentinel runs two independent passes on every upload. Pattern scan first, semantic verification second. Prompt injections, policy bypasses, and adversarial payloads stop here. They never reach the Council.
The Council of ten Investigators covers weaponization, minor safety, compliance, viral amplification, deception, technical exploits, brand risk, self-harm vectors, and more. Each returns a structured finding. The specific roster stays proprietary and evolves quarterly.
For every villain the Council names, the Response Council answers with a business case (PM), a design intervention (Designer), and a detection plan (QA). Root causes, second-move chains, effort estimates.
A printable A4 report. Verdict at the top. Villain rankings, VRSD scores, root causes, second-move chains, and Response Council recommendations flow through. Read it in fifteen minutes. Forward it to your team, your lawyer, or your insurer in one click.
Every villain the Council names gets scored across four dimensions, rated zero to three by the flagging Investigator, then reconciled by the Council's Verdict.
One investigation costs less than the meeting you'd have to run after a viral incident.
One-shot, no subscription. Best for agencies, one-off audits, "just this project" moments.
For teams shipping monthly. Unused credits roll over. €6.60 per investigation effective rate.
Custom Investigators for your industry, built with the founder. 4 to 6 week engagement.
| Feature | Per | Pro | Bespoke |
|---|---|---|---|
| Council of 10 Investigators | ✓ | ✓ | ✓ |
| Response Council · 3 perspectives | ✓ | ✓ | ✓ |
| Sentinel · double-pass screening | ✓ | ✓ | ✓ |
| VRSD scoring + Ship verdict | ✓ | ✓ | ✓ |
| Full PDF export (A4) | ✓ | ✓ | ✓ |
| Investigations per month | 1 · pay per use | 15 · rollover | Unlimited |
| Priority queue | — | ✓ | ✓ |
| Regulatory library updates first | — | ✓ | ✓ |
| Custom industry-specific Investigators | — | — | ✓ |
| Quarterly reviews with founder | — | — | ✓ |
| Multi-product setup | — | — | ✓ |
| Rate limit | 3/hour | 3/hour rolling | Negotiated |
The regulatory library refreshes every 90 days. New legislation like the EU AI Act 2026 becomes part of the Investigator toolkit within a quarter of passage. Pro users get updates first.
Google OAuth for authentication. Encryption at rest, TLS in transit. Row-level security means users only ever see their own investigations. Uploaded documents are stored encrypted and never used to train models.
Villain's Hat is built by Pavitra S. Tandon, who spent years designing consumer AI products before founding this. Every prompt was tested against real products before it went live.
Yes. Article 9 requires you to have "identified, analysed, and mitigated" reasonably foreseeable risks. A dated Villain's Hat investigation report, versioned per release, is documented evidence you did that work. It doesn't replace a lawyer's judgement, but it does give your compliance team something to hand to the auditor. This is the single most-asked question from buyers, so we lead with the answer.
Generic LLMs are trained to be helpful. They won't red-team your product unless you know how to prompt them to. Villain's Hat runs a curated adversarial architecture: ten specialist Investigators with domain-specific prompts, a Sentinel that catches prompt injection attempts on your upload, a Verdict that reconciles conflicting findings, and a Response Council that translates findings into fixes. It's ten focused red teams running in parallel, not one general assistant guessing.
Documents are encrypted at rest, transmitted over TLS, and stored under row-level security in your account. They are not used to train any model. Per-tier users' documents auto-delete after 12 months. Pro users' documents persist while their subscription is active plus 90 days grace after cancellation. You can export or delete anytime.
The regulatory library refreshes every 90 days with new legislation, case law, and enforcement patterns. Between refreshes, urgent additions (like a new EU AI Act guidance note) get pushed within a week to Pro and Bespoke users. Per users get the same library at the next refresh cycle.
Not yet on Pro. Bespoke customers get negotiated team access. If you need team seats before we ship them on Pro, talk to us.
If The Sentinel blocks your upload as a false positive and you can't run the investigation, you're not charged. If you completed an investigation but weren't satisfied with the depth of findings, email us within 7 days and we'll issue a credit or refund. We haven't had to do this yet, but the policy exists.
Yes. Every completed investigation exports to PDF (A4 print-ready), CSV (structured data), and JSON (full raw findings). Filename convention: YYYYMMDD-VHReport-productname-vNN.pdf so multi-year archives sort chronologically.
Because the moment we publish them, product teams stop building for safety and start building to pass our tests. The Investigators' identity, prompts, and methodology stay proprietary and update quarterly. You see the outcome, not the machinery. That's how the tool stays honest.
The Investigations Platform ships shortly. Join the waitlist for early access, launch pricing, and the "state of AI product misuse" quarterly report.
One investigation. Ninety seconds. A report your team, your lawyer, and your insurer can all read.