How RegAlign uses AI — and where its authority stops
RegAlign uses Compass as an assistive capability for compliance professionals. Compass can summarise, structure, draft and propose; it is not the system of record, a regulatory authority or an approval mechanism. A generated answer is not evidence of correctness, completeness or legal applicability, and any consequential adoption must pass through the owning human-controlled workflow.
Where AI is used
- Compass (assistive co-pilot)
Summarises scoped records, drafts narrative and can surface proposed remediation actions for human consideration.
Human authority: Compass does not itself approve or ratify a governed action. Consequential proposal cards require an explicit human action through the owning RegAlign workflow.
- Routine assistance
Can help structure or pre-populate candidate content where a workflow exposes that capability.
Human authority: Generated or suggested content remains distinct from the authoritative saved state until the relevant human-controlled workflow commits it.
- Extended assistance
Can assemble multi-step draft material where an enabled workflow supports it.
Human authority: Availability and authority remain workflow-specific. A model response is not a governance, compliance or regulatory decision.
Where AI is never the authority
- Final governance actions (publishing a finding, ratifying a decision, signing a board statement) by AI authority alone.
- Autonomous sanctions or regulator-facing determinations.
- Autonomous adverse decisions about a customer's customer.
Implemented controls and assurance limits
- Current Compass source identifies the configured model path and exposes selected source/citation/tool-call signals to the reviewer. Complete immutable per-call provenance remains subject to final runtime assurance.
- AI-unavailable paths return a low-confidence fallback rather than presenting a provider response as live. End-to-end degraded-mode behaviour, downstream routing and core-workflow independence remain subject to final runtime acceptance.
- Prompt-injection defences include input sanitisation, control/role-marker neutralisation and model guard rules. Runtime resistance and consistent untrusted-content wrapping across every relevant input path are not claimed as fully assured.
- AI Gateway data-use, training, retention and processing-location terms depend on the contracted Lovable plan, downstream model provider and current account configuration. RegAlign does not make a blanket no-training or data-residency claim without that evidence.
- A per-tenant internal AI usage guard can deny additional calls when its configured allowance is reached. The current estimate is a guardrail, not provider-billing reconciliation, and failed-call accounting remains an assurance item.
- Compass can be disabled at tenant level where the configured workflow exposes that control. Complete no-Compass operator regression remains part of release assurance rather than an assumed property.
Governance references
RegAlign's assistive-AI design uses human-oversight, provenance, security and risk-management controls that can support assessment against applicable AI/privacy frameworks. This page does not assign a legal risk classification, establish GDPR Article 22 applicability, or certify conformity with the EU AI Act, ICO guidance or NIST AI RMF. Those conclusions depend on the actual use case, deployment, jurisdiction and evidence available at the relevant time.
See also: Trust Centre, Public hash verifier, Compass methodology & outcomes, Security Roadmap, Vulnerability Disclosure Policy, Known Limitations.
Questions: hello@regalignplatform.com (subject [AI Use]).