A safe, secure, and reliable agent can still be illegal.

SOC 2 proves the agent behaves. It doesn't prove the action is allowed. Carver checks each action against the law that governs it: jurisdiction, statute, case law, right now.

checkout-agent-v3
Regulatory OS
Dashboard
Actions
Regulators
Settings
Active agent
Overview
Monitoring
Evals
Audit log

Legality dashboard

Monitoring

US-CA · Default
Primary Active
Refresh
Action check 1 flagged
Safety evals Pass
SOC 2 / ISO 27001 Pass
Lawful here Unclear
Coverage
Regulators monitored 1,000+
Countries 50+
Acts mapped 1,000+
1,000+

Global regulators monitored

1,000+

AI-related acts mapped

50+

Countries covered

Per-agent

Legal checks, guardrails, and audits

See it work

Watch an agent get checked.

Rule changes, policy updates, and legal checks — running against live regulation.
running against live regulation
rule change
Error-resolution window shortened
12 CFR §1005.11
policy update
Sanctions list refreshed
Federal · OFAC
legal check
Filing threshold enforcement
31 CFR §1010.311
Agent action: transfer request
Checked against all three, live
cleared moments ago
Coverage

The questions that create liability
aren't on any checklist.

Same six questions, run across the frameworks your buyers already trust.
Question SOC 2 ISO 27001 NIST AI RMF AIUC-1 CARVER
Is this action permitted in the user's jurisdiction?
Does it cross a licensed-profession line?
Does this pricing trip antitrust law?
Does an automated denial meet individualized-review rules?
Is disclosure or consent required here?
Has the rule changed since you shipped?
Checked per action
Governance-adjacent
Not covered
Compliance asks if your controls are sound. Legality asks if this action is allowed. Your SOC 2 report answers the first one.
Cases

Nobody was breached.
The systems worked as designed.

That was the problem. The exposure came from the law, not the system.
RealPage

Software priced rents using competitor data. The model ran as built.

DOJ + 8 states
2024
SYSTEM
Reliable and consistent
LAW
Sherman Act §1
GAP
Automation doesn’t exempt price coordination
Correct prices. Coordinated ones.
UnitedHealth

An algorithm predicted care length, allegedly used to cut coverage.

nH Predict
class action
SYSTEM
Consistent, high throughput
LAW
CMS individualized-review rules
GAP
Overriding clinicians is a statutory issue
Reliable at the restricted thing.
Cigna · PXDX

Automated review allegedly denied batched claims in seconds.

CA bad faith
class action
SYSTEM
Fast, deterministic, auditable
LAW
CA unfair-claims statutes
GAP
Speed became the allegation
Fast, consistent, allegedly unlawful.
Unlicensed Practice

An AI agent provides advice tailored to a person's specific legal situation.

AI + legal services
UPL risk
SYSTEM
Accurate, responsive, personalized
LAW
Unauthorized practice of law
GAP
Capability can cross the licensed-profession line
Helpful advice. Potentially unauthorized practice.
Product

Legal data infrastructure for agents.

One layer between your agent and its next action.
Regulator feeds aren't enough. Carver maps acts, case law, and enforcement actions — how a rule is actually applied, not just that it exists.

Your agent asks one thing: is this allowed, here, now? Carver answers with the governing rule and its source. Anything ambiguous goes to your legal team, not through the gate.

MCP server

Drop into any stack
Checks available where the agent acts.

SDK

Check at runtime
In-request call, answer plus citation.

Evals

Regulatory evals
Adversarial testing against the statutes that apply to you. Catch it before you ship.

Frameworks

Where agents get built
LangChain, CrewAI, and the rest.

Impact models

Run your own liability model
Weight exposure by jurisdiction, product, or contract. Score against your risk appetite.
Support

FAQs

Everything you need to know about the Carver: can't find your answer here? Browse our full knowledge base.
What is legal risk in AI agents, and how is it different from safety risk?
Safety risk is about harmful output. Legal risk is about whether an action is allowed under the law that governs it - jurisdiction, statute, case law. An agent can pass every safety and security check and still take an action that's illegal. These are separate risks, and most frameworks only cover the first.
Can an AI agent be safe, secure, and reliable but still act illegally?
Yes. Safe, secure, and reliable each have an established framework - red-teaming, SOC 2/ISO 27001, NIST AI RMF. None of them check whether a specific action is legal in the jurisdiction where it's taken. An agent can meet all three standards and still violate the law that applies to that action.
What is the difference between AI compliance and AI legality?
Compliance asks if your controls are sound - do you have the right processes, certifications, and audits in place. Legality asks a narrower question: is this specific action allowed, here, today? A company can be fully compliant on paper and still take individual actions that break the law.
 Does SOC 2 or ISO 27001 certification mean an AI agent's actions are legal?
No. SOC 2 and ISO 27001 demonstrate that your systems and controls meet defined requirements - that the agent behaves as designed and data is protected. Neither certification checks whether a given action is permitted under the statute, regulation, or case law that governs it in a specific jurisdiction.
What happens if an AI agent takes an action that violates a law the developer didn't know about?
Not knowing about an applicable law doesn't necessarily protect a company from liability. An agent can work exactly as designed and still create legal exposure if its actions violate the laws that apply to them. This is why legal risk needs to be evaluated at the action level, not just through system-level controls and audits.
 Does Carver block an AI agent from taking an illegal action?
Carver determines the applicable legal requirements and recommends whether an action is allowed, restricted, or requires review. The agent governance system then decides whether to allow, block, or steer the action based on those recommendations and the organization's own policies.
Which jurisdictions does Carver cover, and how is it integrated?
Carver primarily covers the US and EU, with coverage continuously expanding across jurisdictions and regulatory domains. It can be integrated throughout the AI application lifecycle - from development and testing to runtime decisions, monitoring, and audit - so the same legal intelligence can be used before and after deployment.
 How does Carver check if an AI agent's action is legal in real time?
Carver checks an agent's intended action against the laws and regulations that apply to its location, industry, user, and activity, then determines what is allowed, restricted, or required - with the underlying legal sources for auditability. Our regulatory coverage is continuously expanding across jurisdictions and domains to reduce blind spots as the legal landscape evolves.

SOC 2 proves you were careful.
Not that you were legal.

See a legality check run against your own agent.