What the public record says about your company’s AI — every week.
Regulatory Exposure Intelligence runs our AI-law and enforcement corpus against one company profile and reports what it finds: which instruments reach you and from what date, which obligations commence next, which regulators are active in your sector, what has been applied to comparable companies, and where the record holds nothing at all. Every finding links to its source.
No AI guesswork. Every finding is computed deterministically from primary sources and linked to them. No language model interprets the law. The same profile against the same corpus produces the same brief, so two weeks can be compared honestly.
What is in a brief
Six findings, and all six are always present. A finding that could not be computed is printed saying why — an omitted section reads as “nothing here”, and that is a claim we are not entitled to make.
Every instrument in the corpus that reaches the company profile, split into what is in force today and what is enacted but not yet in force, each with its jurisdiction, its commencement date, the duty it states and the penalty the instrument itself provides.
A dated calendar of commencements in the next 12 months, plus an explicit count of instruments that carry no date in the corpus — an undated instrument is listed as undated, never quietly dropped.
The direction of matched enforcement activity across the sector and states on the profile, read as a trend over the matters the corpus holds. Stated as a direction with its underlying counts, not as a prediction about anyone.
The matched matters themselves — who acted, under which instrument, against what kind of company, with the outcome as recorded and a link to the primary source for each.
Obligation areas that are in scope for this profile but carry no matched matter in the corpus held. A gap is a statement about the record, not about the company: it says what has not been enforced here yet, and says so as a count you can check.
The official source of each applicable instrument is read when the brief is produced, and the provisions that impose an obligation are quoted WORD FOR WORD, with the citation and a link to the document the words came from. Not our summary of the duty — the duty as enacted. Nothing is paraphrased, and a provision whose citation is not unique in its document is dropped rather than guessed at.
The full list of sources the brief was built from, each with the date it was last read, and an explicit count of how many are stale. You can audit the brief without asking us.
How it reaches you
The first brief is built and emailed as soon as the payment clears — you do not wait on a person to start reading. If we had to derive your company profile rather than being handed it, the brief says so, names the fields nothing established, and asks for the corrections the next one will use.
The brief re-runs against your profile weekly and is emailed to you. Each one is stamped with the corpus state it was built from, so two briefs can be compared honestly.
The corpus is scanned daily. When a new record matches your profile you hear about it then, with its source link — not at the end of the week.
Nothing in a brief is asserted without a link to the primary record it came from. Findings that could not be computed are printed saying why, rather than omitted.
Your first brief is built and emailed automatically, usually within a few minutes of purchase — you do not wait on us to start reading. If we had to derive your profile rather than being given it, the brief says so, names the fields nothing established, and asks for the corrections that every brief after it will use.
Two real briefs
Not mock-ups. Both were produced by the same engine, from the same corpus, on the date stamped inside them. One is a large enterprise whose matters are entirely public record and is named; one is a company with fewer than ten people, whose name is withheld and whose findings are not. The point of the pair is that the instruments do not sort companies by size.
RealPage, Inc. is named here rather than masked: every matter behind this brief is a public enforcement record, and a sample nobody can check is not evidence of anything. The profile below (sector, size, states, AI applications) describes the company as it is publicly known; the FINDINGS are whatever the engine computed from the corpus, unedited.
This profile is a real company from the public enforcement record: a San Francisco AI investment-advice startup with fewer than ten employees. The NAME is withheld — a tiny company does not need to be a billboard for our sales page, and the point of this sample does not depend on it. Nothing else is withheld: the instruments, the matched matters, the counts and the sources are exactly what the engine produced.
Generated from 246 enforcement matters held in the corpus on 2026-08-23, by the same pipeline that produces a subscriber’s brief.
The plans above sell access to the corpus. Regulatory Exposure Intelligence sells what we find in it, for one named company: which rules reach it and from what date, which obligations commence in the next twelve months, which regulators are active in its sector, what has been applied to comparable companies, and where the public record is silent. Every finding links to its source.
Read two real sample briefs → (one large enterprise, one startup with fewer than ten people — same engine, same corpus)
A weekly regulatory intelligence brief built for one company profile, from the AI-law and enforcement corpus. Every finding links to the source it came from. A brief every week, plus an alert when a new matching record lands.
The same brief, once, for one company profile — so you can read the real output before committing to a subscription.
The first 10 customers hold this price for 12 months. In exchange we ask for one of two things: permission to name you as a customer, or permission to publish the engagement as a case study. Your choice which, and either can be withdrawn.
Regulatory Exposure Intelligence reports what the public legal record shows. It is not legal advice, not an assessment of whether any obligation has been met, and not a prediction of enforcement. Every finding links to its source. Decisions should be taken with qualified counsel. What is in a brief →
Methodology
Findings are computed, not generated. Every finding is derived deterministically from primary sources and linked to them. No language model is called at any point in producing this brief — it does not write the findings, and it does not phrase them either.
- Where the data comes from
- Two corpora, both maintained by us and both built from primary sources. The AI-law corpus holds statutes, regulations and bills collected from official legislature and agency sites. The enforcement corpus holds actions brought by regulators — federal agencies, state attorneys general, and named foreign authorities — each recorded with the agency, the instrument, the AI application, and a link to the announcement it came from. Nothing is entered from a secondary summary without being marked as such.
- How a company is matched to the record
- A profile carries a sector, the states it operates in, and the AI applications it runs. Instruments are resolved against it by rule — jurisdiction, layer, and whether the instrument is in force on a proven date. Enforcement matters are matched on four axes: AI application, the statute cited, the home jurisdiction, and sector. The first three are treated as strong signals and sector as a weak one, because a sector match alone describes an industry rather than a company.
- How the instrument text is read
- When a brief is produced, the official source of each applicable instrument is read at that moment and is not stored. Provisions that impose an obligation and name the subject matter of the profile are quoted word for word, with the citation and a link to the document the words came from. Whitespace is normalised; nothing else is changed, and nothing is paraphrased.
- When the engine declines to answer
- A direction of travel for enforcement ("rising", "falling") is stated only when four conditions hold at once: enough dated matters, enough of them dated, enough distinct months, and comparable coverage across the two windows. That last condition exists because a collection lane going quiet looks exactly like enforcement declining. A monetary range is given only over matters that actually record an amount, and the count is printed beside it. A penalty recorded in a source that covers several matters is not attributed to any one of them. A provision whose citation is not unique in its document is dropped rather than guessed. Where a source could not be read, the brief says so instead of reporting an empty result.
- What is not in the pipeline
- No language model. Not to classify a matter, not to summarise a statute, not to phrase a finding. Every sentence in a brief is assembled from values the engine computed, by templates held in the codebase, and a test fails the build if a model call appears anywhere in the intelligence engine. This also means the brief contains no assessment of whether an obligation has been met, no prediction of enforcement, and no scoring of any individual person.
What Regulatory Exposure Intelligence is not
- Not legal advice. Regulatory Exposure Intelligence reports what the public legal record shows. It is not legal advice, not an assessment of whether any obligation has been met, and not a prediction of enforcement. Every finding links to its source. Decisions should be taken with qualified counsel.
- Not an audit. A brief reports what the public record contains. It does not inspect your systems and cannot say whether you have met an obligation.
- Not a prediction. Enforcement direction is a count of what has already happened, not a forecast about anyone.
- Never about a person. The engine scores, ranks and profiles organisations only. It produces nothing keyed to an individual.
Not sure it fits your company?
Read a sample first — they are the whole product, not an extract. If your sector or jurisdictions are not covered well by the corpus, we would rather tell you that than sell you a thin brief.
Start a Regulatory Exposure Intelligence subscription within 30 days and this amount is credited against your first month.