Framework

The AI Regulatory OS

A complete regulatory operating system for AI systems — from raw data to governance, liability, and insurance.

Architecture overview

Click any layer to explore ↓
Layer 1 — Data Foundation

RegWatch

The regulatory data engine powering every layer above. Continuously ingested, structured, and scored across 1000+ regulators.

RegWatch

Real-time regulatory data across every major jurisdiction. Structured, classified, and ready for machine consumption by every layer above.

1000+
Regulators
100+
Jurisdictions
Personalization
AI
Modeling
CareFlow — Digital Health Example

RegWatch monitors FDA, CMS, HIPAA, all 50 state medical boards, EU MDR, and GDPR health provisions in real time — delivering a structured feed of every regulatory change relevant to CareFlow's appointment booking, prescription management, and post-operative care agents.

Layer 2 — Regulatory Intelligence

Shared. Structured. Live.

Four intelligence outputs — each combining multiple signals — consumed by both paths above.

Regulatory Signals

Change timeseries and structured regulatory context. The raw feed — what changed, when, where, and what it means.

Agent Training

Jurisdiction-aware memory and RL environments. Regulations expressed as constraints for training and runtime context.

Risk & Testing

Evals, test scenarios, scoring models, and compliance forecasts. Feeds release gates and liability estimation.

Audit Support

Explainability layer, evidence collection, and structured decision logs. Why the agent decided what it did — feeds L5 Audit directly.

CareFlow — Digital Health Example

Regulatory Signals

A new CMS telehealth billing rule triggers an alert. CareFlow's billing agent gets an updated constraint within hours.

Agent Training

The appointment agent tracks California CMIA and Texas HB 300 simultaneously — two different consent regimes, automatically resolved.

Risk & Testing

The prescription agent scores 0.78 compliance risk against the EU. Forecasting flags MDR certification as a blocker for the Q3 launch.

Audit Support

Every prescription decision is logged with the regulatory context active at decision time — ready for FDA complaint response.

Layer 3 — Functional Paths

Two Paths. One Stack.

Tech and business run in parallel from the same intelligence layer. Eight tech functions across two rows, four business functions.
Tech Path

Context mgmt

Reg context injection, MCP server, jurisdiction memory for live agents.

Release mgmt

RegOps gate, geo-specific deploy checks, pre-release compliance pass/fail.

Regulatory agents

Contract monitoring, document compliance, data governance agents.

Re-eval

Continuous re-evaluation when underlying models change post-deployment.

Circuit breakers

Automated stop conditions, kill switches, confidence threshold triggers.

Safe comms

Agent-to-agent and human-agent provenance, signed payloads, injection prevention.

Security

Guardrail enforcement, shadow AI detection, trust boundary management.

Reg observability

Live monitoring of agent behavior against regulatory expectations.

Business Path

Product dev

Future opportunities, competitive risk analysis, scenario-led roadmap decisions.

Marketing

Regulatory trust positioning, market entry signals, jurisdiction readiness.

Legal

Anticipate regulatory risk, contract updates, governance sign-off trail.

Compliance

Continuous monitoring, structured reporting, cross-jurisdiction coverage.

CareFlow — Digital Health Example
Tech Path

Circuit breakers

Prescription agent auto-pauses if confidence drops below threshold or jurisdiction mismatch is detected.

Safe comms

All agent-to-EHR messages are signed — injection attacks cannot alter prescriptions.

Re-eval

When the LLM vendor updates the model, CareFlow's test suite re-runs automatically.

Reg observability

Live dashboard shows which agents are operating within regulatory bounds.

Business Path

Product dev

CMS reimbursement expansion identified as opportunity for a new billing module.

Marketing

Cleared to promote HIPAA-certified status in three new states after automated compliance checks.

Legal

Updated consent language automatically generates contract redlines.

Compliance

Continuous monitoring across all states with automated reporting.

Layer 4 — Internal · Shared

AI Governance

Business-level oversight of the full AI lifecycle — from conceptualization through deployment to live operations.

Policy & guardrails

Sets and enforces guardrail policies. Updates propagate automatically to all deployment environments.

Geo oversight

Jurisdiction-specific rule enforcement. Ensures agents behave correctly where regulations differ.

Lifecycle mgmt

Oversees the full arc — conceptualization, approval, deployment, and ongoing operations.

AI Audit coordination

Prepares evidence packages and decision logs for external auditors. Bridges L3 to L5.

Resilience & recovery

Failure mode registry, regulatory notification SLAs (DORA 72h, HIPAA breach), fallback behavior definitions, and post-incident reporting templates.

Liability ownership

Maps each agent action class to a responsible party — developer, deployer, operator, or user — using EU AI Act provider/deployer definitions. Machine-readable for insurers.

CareFlow — Digital Health Example

Resilience & recovery

When the post-op care agent fails mid-session, the recovery protocol notifies the patient, logs the incident, and files a HIPAA breach report within the 60-day window — automatically.

Liability ownership

A prescription error is traced: the LLM vendor owns the model failure, CareFlow owns the deployment decision, and the prescribing physician owns the final sign-off. Machine-readable for insurers.

Layer 5 — External Entities

Risk. Verified Externally.

Independent parties consuming governance outputs to verify compliance, quantify exposure, and underwrite risk.

AI Audit

External verification of agent behavior against regulatory expectations using observability and decision log data from L2.

AI Liability · Cert

Compliance estimation across jurisdictions. Feeds from audit findings, legal sign-offs, and the liability ownership map in L4.

AI Insurance

Regulatory exposure quantified for underwriting. Receives from the liability chain or directly from governance via the evidence package.

AI Resilience

External continuity verification. Validates that recovery protocols meet regulatory SLAs and that fallback behavior is certified compliant.

CareFlow — Digital Health Example

AI Audit

External auditor verifies the appointment agent accessed no records outside permitted scope. Zero violations across 2.3M interactions.

AI Liability · Cert

EU MDR certification confirmed for the post-op agent. Q3 EU launch unblocked. Liability: €0.2M vs €4.8M unmitigated.

AI Insurance

Prescription agent underwritten at 0.4% annual premium — 60% below market rate for unaudited AI systems.

AI Resilience

CareFlow's recovery SLA certified at 4-hour RTO — satisfying HIPAA continuity requirements and state medical board standards.

See How Carver RegWatch Automates Horizon Scanning

1000+ regulators monitored continuously — consultation papers, draft rules, and enforcement signals delivered before they become obligations.

Ready to See RegWatch on Your Regulatory Universe?

3D radar display with a white pointer and three black dots on green circular concentric rings.