Skip to content
Regulayer™Human Control for AI
Book a live demo

Technical overview · for engineers and licensees

An enforcement point at the moment of effect.

Regulayer™ runs outside the model, between an AI agent and the systems it acts on. Every proposed action is checked against the current authority of a named person before it takes effect, and every decision is written to a signed record that anyone can check offline.

Runs inside your environment. Your data does not leave it. No cloud service of ours.

At a glance

The engine, from the outside.

Placement
In the path, before a consequential action takes effect: a tool call, an API call, a write, a payment, a batch release. Outside the model and outside the agent.
The caller supplies
The proposed action and its target, the agent that proposes it, and the named person whose authority applies.
What comes back
Allow, send back to correct, hold, or stop. Every answer carries a reference to its record.
Failure mode
Fail closed. If the check cannot complete, the action does not run, and the record says stopped or unknown, never a success it cannot show.
Decision time
2 ms median, 3 ms p95.Measured across 158 live decisions
Deployment
Inside your environment: on premises, on your own servers, or a sandbox for a pilot. Your data does not leave it. No cloud service of ours is required.
Models
Model-agnostic. Change the model and the check stays where it is.
Record
One entry per decision, allowed or refused, signed. Tamper-evident: any change after sealing fails verification.
Verification
In the browser or offline, with the open verifier. No account, no call to Regulayer™.

Integration

Where it connects.

The agent or its tool wrapperA call before the tool runs.The wrapper asks first. The tool runs only on allow.
NVIDIA OpenShellTrusted middleware in the request path.Outside the sandbox, where NVIDIA names this check.How it fits the NVIDIA stack
MCPStatus, record export and verification.

Checking a record

From the checker’s side.

Drop the record into the open verifier. It checks in your browser, with no account and no call to us.

Change one character and it fails.

Measured

Measured at scale.

69,199Agent actions evaluated in one run, by 320 agents against 80 protected resources.Scale test
7,457Actions re-decided mid-transaction when authority changed while they were in flight.Same run, 578 authority changes
428,521Records verified, all intact, in 7.2 seconds by separate code.Independent verification

Standards

What it supplies evidence toward.

StandardWhat it asksWhat Regulayer™ supplies
Court & litigation
FRE 901(b)(9)Evidence describing a process or system and showing that it produces an accurate result.A record of each decision, made by the process that decided it, that anyone can check.
FRE 902(13)Certified records generated by an electronic process or system.Designed to support self-authentication, with the certification of a qualified person.
FRE 902(14)Certified data copied from an electronic device, storage medium or file.Designed to support self-authentication, with the certification of a qualified person.
FRE 903An attesting witness is needed only where the governing law requires one.A signed record of each decision, with no attesting witness involved.
Pharma & medical
21 CFR Part 11 §11.10(e)Secure, computer-generated, time-stamped audit trails of operator entries and actions.A time-stamped, signed record of each AI action, made as it happens.
21 CFR Part 11 §11.10(g)Authority checks, so only authorized individuals can use the system, sign, alter a record or perform the operation.Each action checked against a named person’s current authority before it runs.
21 CFR 211.22(c)The quality unit approves or rejects procedures and specifications.That a named, authorized person in the quality unit made the decision, and when.
21 CFR 211.68(b)Controls over computer systems, with changes made only by authorized personnel.Automated actions that run only under a named person’s authority, each one recorded.
21 CFR 211.188(b)(11)The batch record identifies the person performing or checking each significant step, including a step performed by automated equipment.The named person whose authority covered each automated step.
EU GMP Annex 11Audit trails, access control and data integrity for GMP computerised systems.System-generated records of GMP-relevant AI actions, with the person responsible.
EU GMP Annex 22 (draft)AI in GMP, under human review and oversight.The AI output and the human decision on it, recorded together.
FDA and EMA Good AI Practice, Principle 6Documentation of data and decisions that is detailed, traceable and verifiable.A traceable record of each AI decision that anyone can verify.
ALCOA+Data that is attributable, legible, contemporaneous, original and accurate, and complete, consistent, enduring and available.Attributable is the first letter: each action carries the named person whose authority it ran under, recorded as it happens.
EU AI Act
EU AI Act, Article 12Record-keeping: automatic recording of events over the lifetime of the system.An automatic record of every decision.
EU AI Act, Article 14Human oversight, including the ability to intervene or stop.Designed to support it: a named person’s authority, checked before each action, which that person can withdraw.
Insurance & financial services
NAIC AI Model BulletinSections 3 and 4A written program for AI systems used by insurers: risk controls, oversight of third-party systems, documentation.A signed record that the controls operated, action by action, with the named person whose authority applied.
NYDFS 23 NYCRR Part 500§500.6Audit trails, and records of what authorized users did.A signed record of each AI action and the authorized person it ran under.
EU DORARegulation 2022/2554ICT risk management, and the detection and reporting of ICT-related incidents.A tamper-evident record of each AI action, ready for incident reconstruction.
Standards
ISO/IEC 42001An AI management system, with operation and monitoring records.Operation-time evidence: who authorized each action, and what happened.
ISO/IEC 23894AI risk management, with the process recorded.Per-action evidence of the control applied, and its outcome.
NIST AI RMFGovern, Map, Measure and Manage AI risk.Evidence for each action: the authority it ran under, and the outcome.
EN 18286A quality management system for AI Act purposes. Citation in the Official Journal pending.Records the quality system can draw on.

Regulayer™ supplies the evidence. Your auditor, regulator or court makes the determination.

The laws and standards

Research

Sources.

  1. Li et al., Harvard, COLM 2024. Measuring and Controlling Instruction (In)Stability in Language Model Dialogs. Instructions drifted within eight rounds, even with two chatbots talking to each other.
  2. Qin et al., 2024. SysBench: Can Large Language Models Follow System Messages? In multi-turn sessions, the share of GPT-4o sessions that followed every rule fell from 84.8% after turn 1 to 33.7% after turn 5.
  3. OWASP, 2025. Top 10 for LLM Applications 2025, LLM01: Prompt Injection.
  4. Related: Panavas et al., July 2026. HANDBOOK.md: A Benchmark for Long-Context Agentic Instruction Following. Agents working to long policy documents: under strict grading, the best model passed 36.2% of trials, and most frontier models stayed below 25%.

Licensing

Embed it in your own stack.

Enterprises, AI platforms, OEMs, agentic-system providers and regulated operators license the engine and run it on their own infrastructure. SDKontrol carries the same control inside a vendor’s own product.

Patent pending.