Governance disclosure
Agentic AI Governance
RegAlign uses AI to remove drudgery, not to make regulated decisions. Every AI action is assistive by default and supervised by design. Nothing lands in a register, file, or Board pack without a named human accepting it.
Our five commitments
- Human accountability is preserved. Statutory decisions stay with statutory roles (CO / MLCO / MLRO / DPO). AI can propose; humans decide.
- Model-pinned and prompt-versioned. Every AI output records the model, prompt version, and input hash so decisions are reproducible.
- Per-tenant kill switches. Every background agent is OFF by default and can be disabled by the tenant admin or CCO at any time.
- No autonomous publishing. Agents file into a review queue. They never write to a live register.
- Auditability by default. Every AI-assisted decision is linked to the human who accepted it, with the input evidence attached.
AI-powered today
These features make live model calls via the Lovable AI Gateway under no-training terms.
Compass (assistive) AI
In-context reasoning aid for a human at the workspace. Uses an LLM via the Lovable AI Gateway.
Never publishes, files, closes, or approves.
Horizon Scanner AI
Reads regulator feeds and proposes routing + obligation deltas. LLM-assisted classifier via the Lovable AI Gateway.
Never adopts a change. Every routing is a proposal a named human accepts.
Rule-based monitoring (no AI)
Presented alongside the AI features for completeness — these are deterministic background jobs, not LLM agents.
Evidence Freshness Steward Rule-based
Deterministic rule that flags stale evidence past its freshness window and proposes re-collection tasks. No LLM.
Never marks stale evidence as fresh. Never closes a control.
Obligation Coverage Analyst Rule-based
Deterministic join between the obligation register and the control library. Surfaces uncovered obligations. No LLM.
Never binds a control. Never publishes coverage as complete.
Defensibility Agent Rule-based
Deterministic weekly digest of what a regulator would ask this week, computed from register state. No LLM.
Never files findings or opens issues. Output is a brief to a named human.
Framework mapping
Our controls align with EU AI Act Article 14 (human oversight), NIST AI RMF (Govern / Map / Measure / Manage), and ISO/IEC 42001 AI management-system principles (aligned; not certified — ISO/IEC 42001 is a paywalled standard). A summary mapping is shared with pilot customers under NDA.
What we will not do
- We will not ship an agent that autonomously files a regulatory return.
- We will not ship an agent that closes a finding or clears a Board action without a named human.
- We will not fabricate evidence, citations, or attestations.
Questions? See our Trust Centre or the operator settings under AI & Agents.