Legal and Regulatory Infrastructure for Agents

A compliant agent can still create an open obligation.

SOC 2 proves the agent behaves. It doesn't prove the action was allowed. Carver checks every action against the law that governs it: jurisdiction, statute, case law, obligation, control.

Book a DemoAI-powered regulatory intelligence workflow visualization
The Gap

Every agent action carries legal exposure.

Regulatory intelligence reports what a regulator published. It doesn't identify which agent that applies to, or whether that agent already has a control for it.

Carver connects agent behavior to legal obligation directly, agent by agent.

Data collected

Retention, consent, disclosure.

Decisions made

Explainability, review.

Messages sent

Consent, marketing law.

Media generated

Labeling, disclosure.

Actions triggered

extends the surface.
Legal Assurance

How obligations are discovered, mapped, tested, and resolved.

A crawler and obligation extractor build the underlying corpus (RCG) continuously. Each agent runs through discovery, mapping, eval construction, testing, observability, remediation, and drift detection.

00 · Foundation — continuous

Crawler
Extractor
RCG · Obligation Library

01–07 · Obligation intelligence — per agent

Discovery
Mapping
Eval Constructor
Reg Evals
Observability
Remediation
Drift

Regulation changes → Re-discovery for affected agents

Regulation changes → Re-discovery for affected agents
00
Continuous, not per agent

Regulatory Corpus Buildout

A crawler ingests regulator updates as published. An extractor turns that text into structured obligations — the library everything below runs on. RCG lives here: versioned, provenance-backed.
01
Input in, obligations out, at any volume

Obligation Discovery

PRD, agent description, claim, or complaint in: relevant regulations and applicable obligations out, scoped to that agent. Runs at claims-volume, not just at design time.
POST /v1/discovery { "agent_id": "checkout-agent-v3", "input_type": "prd", "text": "..." } 200 { "obligations": [ { "id": "obl_4471", "statute": "CCPA §1798.100", "surface": "data_collected" }, { "id": "obl_4472", "statute": "TCPA §227(b)", "surface": "message_sent" } ] }
Illustrative request/response shape.
02
Per agent, not generic

Obligation-to-Control Mapping

Each obligation maps to a concrete control. Two agents at the same company can carry different obligation sets, so mapping is never generic.
03
Obligations become tests

Eval Constructor

Each mapped obligation compiles into a test case: an eval suite built automatically as obligations are discovered, not hand-written after the fact.
04
Continuous today · red-teaming on the roadmap

Reg Evals

Carver runs the eval suite against agent behavior continuously, surfacing gaps before incidents. This tests what an agent does, separate from regulatory intelligence, which reports what a regulator published. Adversarial red-teaming is in active development.
05
On the logs you already have

Observability Integration

Carver reads existing agent logs, tags interactions for legality, and alerts on non-compliant behavior as it happens. No new monitoring stack.
06
Flags need an owner

Remediation

Flagged interactions route to the right team with tracked status: open, in review, resolved.
07
Law doesn't hold still

Regulatory Drift

When a regulation changes, agents mapped against the old version are stale. Carver flags exactly which agents need re-mapping.
Drift re-triggers Discovery and Mapping for affected agents.
Fleet view

Status across every agent.

The dashboard rolls up mapping and flag status across the fleet: which agents are current, which are stale on mapping, which have open flags.

Agent Regulatory Register

GC
Agents Tracked 7 5 in production · 2 in build
Open Incidents 2 1 Sev-2 contained · 1 investigating
Evidence Audits Due ≤30d 2 CMS-0057-F readiness window
Portfolio Liability Exposure $2.1M–$4.8M Annualized, all agents

Importance × Status

Compliant Review Attention
Illustrative portfolio view. The register scopes to your fleet, not ours.

See it run against one of your agents.

Book a demo to run obligation discovery and mapping on a real agent, with your PRD or spec.