Skip to content
Menu ▾
Patent pending

License Regulayer

Who authorized this action, and can an outsider check it?

Regulayer checks current human authority before consequential AI acts, then leaves an independently verifiable record.

The brake and black box for agentic AI.

Generative AI can drift from your instructions. Agentic AI can act beyond them. Regulayer keeps human authority in control before consequential answers or actions are released. It can correct, hold or stop what is not authorized, then leave independently verifiable proof of what happened.

  • 01 · Consequential AIThe problem space. AI whose answers and actions carry real consequence: money moved, a document filed, a record changed, a person affected.
  • 02 · Current human authorityYour current instructions and decisions govern what the AI is allowed to do now.
  • 03 · Control before consequenceThe consequential answer or action is governed before it is released. It can be allowed, corrected, held or stopped.
  • 04 · Verifiable AI evidenceThe control decision leaves a record that can be checked independently afterward.

Your authority does not have to live in somebody else’s cloud.

Governed action● Evidence ready
01AttemptAI attempts an answer or action
02AuthorityHuman authority applies
03ControlAllow / correct / hold / stop
04EvidenceVerifiable record
AI attempts an answer or action → Human authority applies → Allow / correct / hold / stop → Verifiable record

It runs outside the system it governs and independently of the model provider, so the governed system cannot switch it off. Deploy it on your own infrastructure: local, private and on-premises configurations are supported where the deployment allows, and enforcement and evidence signing require no network egress.

The same telegram, eight passes: the first is sharp, the last is gone. The sealed record beside it holds.

What always holds

Four properties hold across the architecture.

Outside the governed

The AI does not decide whether its own consequential action should be allowed.

Proof as a byproduct

Evidence is created as the decision is governed, not reconstructed afterward from logs or explanations.

Evidence without the underlying work

The record can establish what happened without containing the underlying work itself.

Verifiable without us

A recipient can verify the record independently. Verification does not depend on an active Regulayer licence or a call back to Regulayer.

The engine, by problem

The engine is licensed around the control problem that has to be solved.

The AI is drifting from your instructions.

It may still sound convincing. It may even be mostly correct. But it is no longer staying inside what you asked it to do. Drift Control keeps consequential outputs and actions tied to current human authority before release.

Drift Control →

What stops an AI agent before it executes an action that is no longer authorized?

For an autonomous system, detecting the mistake afterward can be too late. FailStop applies an external stop/control decision before a consequential action executes, so it can be allowed, corrected, held or stopped before consequence.

FailStop → Agentic AI →

Can we prove every consequential action an autonomous agent took, and the authority under which it acted?

The Witness preserves which human instruction, approval or limit governed at the relevant time, and the human decision where one occurred.

The Witness →

You need to prove what a person did, not guess whether AI was involved.

HumanMark records observable human participation without relying on AI detection. It attests to the record it creates.

HumanMark →

The required system state needs to be verifiable when it matters.

Turn expected system state into signed, independently verifiable evidence, including whether the required record appeared when expected.

Heartbeat →

Can our AI product enter markets that prohibit sending customer data to an external model service?

SDKontrol unlocks markets that cloud-dependent AI cannot enter. Put advanced AI inside the customer-controlled environment, so regulated, on-premises, edge and connectivity-constrained customers can be served without requiring sensitive data to move to an external model service.

SDKontrol →

Where it applies

The architecture is the same. The consequential action changes.

Agentic AI

Agents can call tools, communicate and act. Human authority governs the consequential step before it proceeds.

Robotics

Current human limits can govern a machine action before physical execution.

Vehicles

Authority can remain attached to consequential decisions while the system is moving and connectivity is limited.

Industrial systems

Current approvals, limits and operating authority can govern changes to machine state.

Human-supervised communication

The human instruction governs what the system is actually permitted to send or release.

Professional work

Human authorship, review and approval can become part of the evidence surrounding consequential work.

Autonomous laboratories

Current protocols, approvals and limits can govern a consequential experimental or robotic action. Life sciences, drug discovery and GxP

Finance

Current limits and approvals can govern consequential transactions or actions before release.

Insurance

Current policy terms, authority limits and approvals can govern a consequential claims or underwriting decision before it is issued. For insurers deploying AI, and insurers underwriting it

These are applications of the same engine, not nine separate products.

A pharmacist compounding at a glass isolator in a regulated facility

Deployment

Your authority runs where your system runs.

Regulayer is designed for deployment on infrastructure controlled by the customer.

  • The underlying work does not need to be sent to Regulayer for enforcement or evidence signing.
  • Keys are generated within the deployment rather than escrowed with Regulayer.
  • No outbound call is required for ordinary enforcement or evidence signing. Where independent witnessed time is used, a cryptographic digest can be sent to a timestamp authority, not the underlying material.
  • Air-gapped operation is part of the filed architecture; it is not presented as a current product setting.
  • Evidence can leave the environment as a single record that a recipient can verify without installing Regulayer.

Assurance

The questions your security, legal and risk teams will ask.

Where does it run?

On infrastructure controlled by the customer.

What leaves the environment?

The underlying work does not need to leave for enforcement or evidence signing. If witnessed time is used, a cryptographic digest can be sent to the timestamp authority.

Who holds the keys?

They are generated within the deployment rather than escrowed with Regulayer.

What third-party code is involved?

Signed evidence with no external signing software, cloud service or cryptographic dependency to install. Licence texts ship with the software.

What happens when a licence ends?

Records already issued do not lose their validity merely because a licence ends, and verification of existing records is not licence-gated.

What does the evidence establish?

Depending on the capability used: which authority applied, what the system attempted, what control decision was made, what resulted, and whether the record still verifies. It does not decide whether something is legally compliant, certified or admissible. Those determinations belong to the relevant court, regulator or other authority. What a Regulayer record proves, and what it does not prove.

See it for yourself

Standards and evidence alignment

Where Regulayer fits in established governance and evidence frameworks. Regulayer is not certified against these frameworks and does not make a deployment compliant; it produces the control and evidence that programs built on them can draw on.

AI governance

NIST AI RMF · ISO/IEC 42001 · ISO/IEC 23894
Regulayer supports the govern and manage functions of an AI risk program: it holds consequential outputs and actions to current human authority, and records the control decision as it is made.

Electronic evidence

FRE 902(13) and 902(14)
Signed, tamper-evident records with independent verification can support authentication workflows involving records of an electronic process or system. Admissibility remains the court’s determination.

Regulated AI

The law and standards estate
Each verified instrument is mapped to the signed evidence Regulayer produces for it.

What Regulayer contributes across these frameworks: current human authority, control before consequence, decision evidence, tamper verification, independent verification, and customer-controlled deployment.

What is licensed

Regulayer can be licensed at the level the control problem requires.

  • The engine. The complete Regulayer engine for integration into an enterprise system, platform or product.
  • One capability. A specific control or evidence capability where the problem is narrower.
  • Inside somebody else’s product. OEM and platform licensing, for embedding current-human-authority enforcement and independently verifiable evidence into what another company ships.

The commercial unit is not a list of software features. It is the authority boundary required by the system. The governed practice surface for professional work ships separately as the Regulayer Receipt. What is licensed, in full.

Intellectual property: Patent pending.

What do you need to control or prove?

Licensing begins with the problem, not the product.

Tell us what the system does, what it is allowed to do, which human authority must remain in control, and what happens if the wrong action gets through.

We return a written scope defining the control boundary, evidence and deployment.

Begin with the problem →