Governance disclosure

Agentic AI Governance

RegAlign uses AI to remove drudgery, not to make regulated decisions. Every AI action is assistive by default and supervised by design. Nothing lands in a register, file, or Board pack without a named human accepting it.

Our five commitments

  1. Human accountability is preserved. Statutory decisions stay with statutory roles (CO / MLCO / MLRO / DPO). AI can propose; humans decide.
  2. Model-pinned and prompt-versioned. Every AI output records the model, prompt version, and input hash so decisions are reproducible.
  3. Per-tenant kill switches. Every background agent is OFF by default and can be disabled by the tenant admin or CCO at any time.
  4. No autonomous publishing. Agents file into a review queue. They never write to a live register.
  5. Auditability by default. Every AI-assisted decision is linked to the human who accepted it, with the input evidence attached.

AI-powered today

These features make live model calls via the Lovable AI Gateway under no-training terms.

Compass (assistive) AI

In-context reasoning aid for a human at the workspace. Uses an LLM via the Lovable AI Gateway.

Never publishes, files, closes, or approves.

Horizon Scanner AI

Reads regulator feeds and proposes routing + obligation deltas. LLM-assisted classifier via the Lovable AI Gateway.

Never adopts a change. Every routing is a proposal a named human accepts.

Rule-based monitoring (no AI)

Presented alongside the AI features for completeness — these are deterministic background jobs, not LLM agents.

Evidence Freshness Steward Rule-based

Deterministic rule that flags stale evidence past its freshness window and proposes re-collection tasks. No LLM.

Never marks stale evidence as fresh. Never closes a control.

Obligation Coverage Analyst Rule-based

Deterministic join between the obligation register and the control library. Surfaces uncovered obligations. No LLM.

Never binds a control. Never publishes coverage as complete.

Defensibility Agent Rule-based

Deterministic weekly digest of what a regulator would ask this week, computed from register state. No LLM.

Never files findings or opens issues. Output is a brief to a named human.

Framework mapping

Our controls align with EU AI Act Article 14 (human oversight), NIST AI RMF (Govern / Map / Measure / Manage), and ISO/IEC 42001 AI management-system principles (aligned; not certified — ISO/IEC 42001 is a paywalled standard). A summary mapping is shared with pilot customers under NDA.

What we will not do

  • We will not ship an agent that autonomously files a regulatory return.
  • We will not ship an agent that closes a finding or clears a Board action without a named human.
  • We will not fabricate evidence, citations, or attestations.

Questions? See our Trust Centre or the operator settings under AI & Agents.