Answers

AI governance and proof, in plain language.

How to prove what an AI did, comply with the law you answer to, keep data sealed, and prove a human made something. Evidence, not promises.

The problem

What is AI governance, and why does it matter now?

AI governance is proving that an AI system behaved within the rules that apply to it, and being able to show that proof later. It matters now because AI entered consequential decisions, hiring, claims, clinical and financial calls, faster than it entered evidence. Regulators, courts, and auditors are starting to ask for a verifiable record rather than a promise. Regulayer produces that record at the moment the AI acts.

How do I prove what an AI system actually did?

You attach the proof to the action itself. Regulayer records each consequential AI action as a signed, tamper-evident receipt: what happened, under what rule, and when. The receipt is a byproduct of the action, not assembled afterward, and anyone can verify it with the public key and the artifact, without contacting you. See how verifying works.

Can AI detectors tell whether something was written by AI?

Not reliably. After-the-fact detectors guess from the finished text and produce false positives, which is why schools, publishers, and courts have stopped relying on them. HumanMark takes the opposite approach: it records authorship at the moment of creation and issues a signed record. It captures, it does not detect. More on HumanMark.

The law you answer to

How do I comply with the EU AI Act?

The EU AI Act requires, among other things, marking of AI-generated content (Article 50, enforced 2 August 2026) and post-market monitoring of high-risk systems (Article 72). Compliance turns on producing verifiable evidence rather than asserting it. Regulayer maps signed, tamper-evident proof to the specific Article you answer to. Find the pack in the catalogue.

What does EU AI Act Article 50 require, and when?

Article 50 requires that AI-generated or AI-manipulated content be marked so people know what a machine made, with enforcement from 2 August 2026. HumanMark answers it by marking authorship at creation, a record bound to the human, rather than detecting it after the fact.

What does NYC Local Law 144 require for hiring AI?

It requires a bias audit and candidate notice for automated employment decision tools. The hard part is a checkable record of what the tool did and whether it was fair. Regulayer binds each automated decision to its evidence, mapped to the law, independently verifiable.

How do I keep attorney-client privilege when using AI?

Privilege can be waived when confidential client data passes through third-party AI servers. Running the model sealed and local, with no egress, answers ABA Model Rule 1.6 by architecture: the client's information never travels, so there is nothing to compel and nothing to disclose, and a signed receipt proves the work was scoped and contained. How it stays sealed.

How do I use AI on regulated manufacturing or clinical data (21 CFR Part 11, EU GMP Annex 11)?

Those rules require a contemporaneous, tamper-evident audit trail for computerized systems. Regulayer runs inside the validated environment and produces a signed receipt with a verifiable timestamp for each AI-assisted decision, feeding the audit trail those rules already require, without the data leaving the environment.

How do I satisfy HIPAA when using AI on patient data?

HIPAA turns on protected health information not leaving the perimeter. Regulayer runs the AI sealed and local with zero network egress, so PHI never crosses the boundary, and every AI-assisted decision leaves an audit artifact a compliance officer can produce on demand.

The solution

What is Regulayer?

Governance and proof at the moment of AI inference. It records what an AI did, under what boundary, as it happened, and produces a signed, independently verifiable receipt. Built in, not bolted on.

What is HumanMark?

A signed record of human authorship, made the moment a person creates something. It is not a detector and does not guess. Anyone can verify the mark for free, and the moment the work is altered, it shows.

Can I run AI without my data leaving the building?

Yes. Regulayer runs the model, the governing, and the proof on your own hardware, with no outbound call by design. Your prompts, documents, and outputs never move, and your own security team can watch the wire and confirm it.

Does Regulayer certify my compliance?

No. It is infrastructure that produces verifiable evidence. You and your auditor interpret it; you and your regulator settle it. There is no certifier in your chain whose opinion can be challenged. It makes evidence, not certification.

What is The Witness?

One sealed, content-free memory of every AI moment across your tools: what ran, when, and what a person decided about it. Ask it in plain English, hand over a sealed evidence packet, and anyone can check it offline. See it work.

Does the record read our content?

No. It stores fingerprints of moments, never words. Your documents and messages never leave your machines and are never held in the record. That is why it can be shown to an outsider without betraying an insider.

Who decides what is kept?

A person. The moment is held, a human chooses keep or remove, and that choice is sealed as its own record. The system never decides silently.

How do I verify a receipt?

Open the verifier in your browser, give it the receipt and the content, and it returns valid or invalid. No Regulayer server is involved; the cryptography is the only thing that confirms it. Free, for anyone. Try it.

How do I engage, and is my data used to train anything?

Engagement is by introduction. No data trains anything, because in the sealed deployment none of it reaches us. Verification is free and public; issuing and integrating are licensed.

My AI takes actions. Can I stop a bad one before it happens?

Yes, that is the Brake. It stops an action before it runs, or holds an output before it reaches a person, for the things your AI does that you cannot undo, payments, sends, deletes. When something goes wrong, the safe answer is the default, and every stop is a signed record you can verify. Evidence, not a guarantee.

Pick the law. Get the proof.