Model risk frameworks ask three questions of any model that informs a decision: who owned it, who challenged it, and what was checked before the output was used. General-purpose AI used by staff usually answers none of them, because no record is made at the moment of use. The evidence supervisors are looking for is a contemporaneous, attributable record of the human authority applied to each output: who authorised the use, what they personally checked, and when.
The supervisory text itself is summarised at SR 26-2 and OCC 2026-13, model risk management.
The gap between a validated model and a browser tab
A model inside the inventory carries a development record, validation findings, performance monitoring and an owner. A large language model an analyst opens to draft a memo, summarise a policy or sanity-check a calculation carries none of it. The output still reaches a decision.
This is not a case for banning the tool. It is a case for recording the authority around it. The control that matters is not whether the machine was right; it is whether a named person stood behind the use before the output travelled.
What a supervisor is actually asking
| The question | What answers it |
|---|---|
| Who authorised this use? | A named person, attributable to them, recorded at the time rather than reconstructed afterwards. |
| What did they check? | The specific checks that person carried out on the output, in their own words. Reported, never scored. |
| Which output? | Fingerprints binding the record to the exact file that was produced, so the declaration cannot drift onto a different document. |
| When? | The time of the declaration, and where that time came from: the device clock, marked self-asserted, or an independent time authority's countersignature, marked witnessed. |
| Has the record changed? | A seal over the whole entry and a chain to the previous one, so an altered or missing entry shows. |
Control before consequence
Most AI governance tooling watches what happened and reports afterwards. That is useful for a post-mortem and useless at the moment the output leaves the desk. Regulayer works the other way round: the record is made when the human decision is made, before the output is used, and the record is what travels.
A Regulayer Receipt is a signed, tamper-evident record of what AI was used for, and what a named person personally checked, sealed on that person's own machine. Anyone can verify it free, without an account, without contacting us, and without seeing the underlying work. The full field-by-field format is at the Regulayer Receipt.
Why the record has to be content-free
A model risk file that requires handing over the analysis itself creates a second problem. Client data, confidential pricing and privileged material cannot be posted into an evidence bundle to satisfy an examiner.
The record carries fingerprints of the file rather than the file, and nothing of the prompts. It travels to whoever asks without the work travelling with it. For a bank, that is the difference between an evidence process that can run across the first line and one that stalls at legal.
The limits
Tamper-evident, not tamper-proof. Nothing is unalterable. The guarantee is narrower and stronger: any change after sealing breaks the signature, and the break shows on verification.
It records evidence. It does not certify compliance. Model risk expectations are met by your framework, your validation and your governance, not by a file format. A receipt is one piece of evidence inside that framework. What weight your supervisor gives it is their decision.
Attested, not proved. A signature makes a declaration permanent and attributable. It does not make it true. The record says a named person declared this, at this time, and nothing has changed since. That is what it shows, and it is all it shows.
Questions people ask
Does this replace model validation?
No. Validation tests whether a model performs as intended. This records the human authority applied to a particular use of a particular output. They answer different questions, and a framework needs both.
Our staff use AI informally. Is that in scope?
That is exactly the gap. Informal use produces no record, so the first-line control cannot be evidenced even when it happened. The record is made at the point of use by the person using it, which is the only moment the facts are known.
Can the record be produced after the fact?
It can be written later, but it then says so. A private seal asserts its own time; witnessed mode carries an independent time authority countersignature. The record states which one it carries, so a reader can weigh it accordingly.
Who can verify it?
Anyone, free. The verifier runs in any browser with no account, checks the signature over the canonical record and the file fingerprints, and contacts no server.
Put a record around the AI your people already use.
The live demos sign a real record in your browser and let you alter it: change one character and verification flips to tampered. Seven days free, then $349 a month. Cancel at any time; records already signed stay independently verifiable.
Written 16 August 2026. Supervisory guidance summarised for orientation, not as legal or regulatory advice. A receipt attests what the signer declared; it does not certify compliance, and what weight it carries is decided by the reader.
