AscentAI vs FinregE: how they compare in 2026

AscentAI profileFinregE profile
Last verifiedSeptember 3, 2026

AscentAI and FinregE both build a firm's regulatory obligations register and then tell it which changes hit which obligation. AscentAI sits in the top two bands on five of fifteen axes and FinregE on four, and each publishes something the other does not. AscentAI publishes its terms, and they carry the most developed professional responsibility position in this category: it is not a law firm or an attorney, no attorney client relationship is created or implied, privilege can arise only between the user and their own attorney, and the subject matter is stated to vary between jurisdictions and regulators. It also names its attestation candidly as SOC 2 Type I rather than blurring it into a Type II. FinregE's answer is who relies on it: the Financial Conduct Authority selected it to redesign, host and manage the FCA Handbook website, which is a regulator adopting the product to publish its own rulebook, alongside a strategic investment from Moody's and ISO/IEC 27001:2022 certification.

At a glance

Category
AscentAIRegulatory & Compliance Counsel
FinregERegulatory & Compliance Counsel
Founded
AscentAINot published
FinregE2018
Headquarters
AscentAIChicago, Illinois, United States
FinregELondon, United Kingdom
Last verified
AscentAISep 1, 2026
FinregEAug 29, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

AscentAI
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models are the engine of the capability the buyer is actually paying for, sitting on a content and workflow product that would survive without them. What distinguishes AscentAI from a regulatory news feed is the obligations layer: the platform derives a firm-specific register of obligations from the rule corpus and then automatically assesses which incoming changes hit which obligation, with auto-generated summaries of what changed. The company's own framing puts this at the centre, describing itself as delivering fully processed information ready for action, unlike document-based vendors, and a 2022 announcement describes patented AI and natural language processing technology as the mechanism. Strip the models out and a real product remains: a global regulatory content database across a stated 98 countries and 1,000 sources, a manually maintained obligations register, collaborative workflows, audit trails and GRC integrations. That is the B shape rather than the A shape. The rebrand from Ascent Technologies to AscentAI in March 2025 is branding and was not treated as evidence of centrality.

FinregE
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI RIG is named as a distinct engine and reaches across all seven modules rather than sitting in one: classification, tagging, prioritisation, summarisation, obligation extraction, obligation to control mapping, policy drafting assistance and question answering. The vendor states production AI since 2018 and holds an Innovate UK AI grant and an Imperial College NLP research collaboration, so the model work is evidenced rather than asserted. Held at B rather than A because the spine underneath is a regulatory registry and workflow system that would still function as a rules inventory, task tracker and control testing tool with the AI removed. The AI makes it fast; it is not the only thing being sold. Compare Reveal at A, where removing the models removes most of the product.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

AscentAI
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is asserted in strong terms across the marketing and measured nowhere, and the agreement says something materially different. The product pages promise a high-confidence regulatory register, a rock-solid inventory of corporate obligations, a single enterprise-wide source of regulatory truth, that a user will never miss a regulatory update, and that accurate change management automation powered by AI eliminates human error. No benchmark, error rate, test set, precision or recall figure for obligation extraction or applicability assessment was located on any surface read. Grounding is real in one respect that matters here: Rule Compare shows the new and former versions of a rule side by side with changes redlined, so a user can open the underlying regulatory text rather than take a summary on trust. Against the marketing, the terms of service state that all Content is for informational purposes only, may not reflect the most current regulatory developments, and is not guaranteed to be correct, complete or up to date, and the History Views clause describes the register as reflecting Ascent's best guess of the rules applicable to the customer. Graded on the agreement per the documents-beat-marketing rule.

FinregE
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

The claim is squarely made and the documentation behind it is not published. The vendor states that every AI output is fully source cited for audit defensibility, and separately that governance documents remain traceable back to regulatory requirements. Source citation on generated output is the right architecture for this use case and is more than most of the category claims. What does not exist anywhere in public: any accuracy figure, any extraction precision or recall number for obligation extraction, any hallucination rate, any published evaluation or test set, any independent benchmark, and any statement of what the system does when it cannot answer. Searched the home page, the AI Regulatory Expert page, the horizon scanning page, the RIG MAPS page, the news and blog index and the Terms of Use on 29 Aug 2026. Obligation extraction against regulatory text is a measurable task and nothing measured is published.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

AscentAI
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

What the system does alone is described and what constrains it is not. Automation is the explicit pitch: changes are captured in real time, applicability against the obligations inventory is assessed automatically, and summaries are auto-generated, with the vendor stating that every update is automatically assessed for applicability and presented to users ready for action. Nothing located describes a review point inside the product, a confidence threshold at which the system defers, or what happens after an assessment is wrong. The audit trail is a record of activity rather than a control over it. The one real oversight statement is contractual rather than functional: the terms tell the user that if a problem is too complex to be addressed by Ascent and its Solutions they should consult a Compliance Professional, and that the user is solely responsible for compliance with applicable laws and for any use made of the Solutions. That places the duty rather than describing a mechanism. This matters more than usual in this category, where the output is consumed by people who cannot spot a wrong answer.

FinregE
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

The oversight model is documented in product terms rather than asserted as a principle. Output is framed throughout as AI assisted and AI guided rather than autonomous: the AI proposes obligations, suggests policy language and recommends control alignments, and FinregE Workflows routes every regulatory assessment to named stakeholders through defined approval chains with assigned ownership. The audit trail records who assessed, what changed, when, why it was actioned, the supporting evidence and the routing history, so a human decision point is recorded rather than implied. Held at B because no autonomy threshold is published: nothing states where the system acts without review, and no confidence score or escalation rule is described. The oversight is structural, from workflow design, rather than a stated policy a buyer could test.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

AscentAI
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

One unattributed testimonial carries the whole of it. The home page quotes a compliance executive at a large financial services firm on the difficulty of finding vendors who identify a firm's obligations rather than merely stating the rules; no organisation, name or date is attached. No customer logos were located anywhere on the surfaces read, which is unusual, and the partner logos that do appear, MCO, LogicGate, Onspring, Resolver and Corestream, are GRC integrations rather than customers. Claims of scale are made about the corpus rather than the customer base. First-party announcements describe partnerships with Halo Ai and with Diligent and are announcements rather than deployment evidence. Checked the home page, the RLM Platform page, the Compliance buyer page, the security page and the terms of service on 1 September 2026; the Resources library, the blog and the Regulatory Roundup were not opened, so a named dated customer outcome was neither found nor excluded.

FinregE
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

The strongest evidence on this record and the most unusual on the index so far: the vendor was selected by the Financial Conduct Authority to redesign, host and manage the FCA Handbook website. A regulator adopting the product to publish its own rulebook is a materially different class of evidence from a customer logo, because the buyer is the body whose text the product structures. Also named: a strategic investment from Moody's Corporation, FSQS registration, and a published case study claiming a 60 percent reduction in cost and a 100 percent reduction in risk at a UK bank. Held at B on two gaps. The case study figures carry no methodology, no baseline and no measurement period, and a 100 percent risk reduction is the unfalsifiable absolute shape this index does not credit. Every customer testimonial is anonymised by tier and sector rather than named. Note for a later reader: the home page counters for jurisdictions covered, weekly change volume, uptime and user numbers render client side and returned zero when fetched on 29 Aug 2026, so those figures were not captured and are not relied on here.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

AscentAI
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Technical protection is published in detail and the handling of customer content is not addressed at all. The security page is specific about the perimeter: AES-256 at rest using FIPS 140-2 validated hardware security modules with automatic key rotation, TLS 1.2 or 1.3 in transit, runtime secret injection rather than hardcoded secrets, SSO with phishing-resistant WebAuthn factors, role-based employee access and automatic deprovisioning on termination. None of that speaks to the questions this axis asks. No position on training was located, in the terms, on the security page or anywhere else. No retention or deletion commitment for customer content exists. No data processing agreement is published. Segregation between customers, users or matters is never described. Two clauses run the other way and deserve naming: the terms advise that the customer should not send confidential information in response to the Site, and state that Ascent cannot guarantee the confidentiality of any communication or material transmitted to it via the Site or by email, disclaiming liability for third-party interception. Those are scoped to communications rather than to platform data, but they are the only confidentiality statements located.

FinregE
DD on Privilege and Confidentiality PostureNothing published on how client confidences are handled by a product built to ingest them.

Nothing published that a buyer could check. No confidentiality commitment, no statement on how customer content is handled, no data processing agreement and no privacy policy were located. The only legal document published on the site is a Terms of Use that governs the marketing website rather than the platform, disclaiming the accuracy of site content and excluding liability for reliance on it. A buyer who clicked Terms of Use expecting product terms would find a website disclaimer. Checked the site navigation, the full site footer, the company page, the contact page, the sitemap page and the Terms of Use on 29 Aug 2026. This is an absence of publication rather than a finding about the product, and the platform serves Tier 1 banks and a regulator, so contractual protections almost certainly exist in the paper a customer signs. They are not public, and this index grades what is public.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

AscentAI
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

This is the most developed professional responsibility posture located in the pull so far, and it stops one limb short of the top band. The terms carry four separate headed treatments of the question. Ascent states that it is not a law firm, attorney, nor does it dispense legal advice, and that a user requiring legal advice agrees to contact their attorney. A section headed that the Site and Solutions are not legal services states that no attorney-client relationship is created or implied, and expressly addresses privilege, saying any such relationship and any privileges related to it may only be formed between the user and that attorney under its own engagement and conflict checking procedures. A further section states that Ascent is not a law or compliance firm, may not perform services performed by a Compliance Professional, and that its Solutions, forms and templates are not a substitute for one. Jurisdiction limits are named rather than implied: the subject matter is said to vary from jurisdiction to jurisdiction and between regulatory bodies, to be subject to differing interpretation by courts and regulators, and no general tool is claimed to fit every circumstance, with a direction to consult a Compliance Professional in the user's area. What is absent is the supervision and competence dimension: nothing addresses how the product supports a practitioner's own duties, and no bar or ethics guidance is named anywhere.

FinregE
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Not addressed in any located material. The product outputs regulatory interpretations, obligation extractions and drafted policy language, and the vendor markets to Legal and General Counsel as one of six named stakeholder audiences, so the question of whether output constitutes advice is live. Nothing states that output is not legal advice, nothing addresses the role of the qualified professional reviewing it, and no professional responsibility positioning of any kind was located. Checked the home page, the company page, the AI Regulatory Expert page, the stakeholder sections addressed to Legal and General Counsel, and the Terms of Use on 29 Aug 2026. The workflow design does require human assessment and sign off, which is the substance of the protection, but the vendor never says so in these terms.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

AscentAI
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

Nothing published addresses how the AI itself is governed. Searched the AscentAI capability page under Our Difference, the AscentAI Security page, the RLM Platform, AscentHorizon and AscentFocus product pages and the Company section on 2 September 2026, and located no responsible AI principles, no model governance framework, no statement of what is tested before a model ships, no named internal owner for AI decisions, and nothing on uneven output across jurisdictions, regulators or obligation types. The security page is thorough and entirely about infrastructure: AES-256 at rest with FIPS 140-2 validated hardware security modules, TLS 1.2 and 1.3 in transit, annual penetration testing, and a programme aligned to the NIST Cybersecurity Framework. That is cybersecurity governance rather than model governance, and this index grades the two separately. The one adjacent statement sits on the AI capability page, where the vendor says in house compliance experts verify all regulatory data, which describes a human check rather than a governance structure and is credited on the oversight axis instead. The absence matters more than usual for this product, because the platform decides which of a stated 400,000 obligations across 98 countries apply to a given institution, and a systematic skew in that matching would surface as an undetected compliance gap rather than as a visible error. The Vanta hosted Trust Center at trust.ascentregtech.com is published and holds the SOC 2 Type I attestation; it renders client side and its contents could not be read on 2 September 2026, so it is the rebuttal route.

FinregE
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

Nothing published about this vendor's own model governance. The gap is worth naming precisely because the vendor publishes extensively about AI governance as a customer problem: blog material on AI governance frameworks for banks, coverage of the EU AI Act and AI governance regimes as tracked subject matter, and a public sector offering that helps agencies ensure AI governance. None of that is disclosure about FinregE's own system. Located nothing on model evaluation, bias testing, human review of model behaviour, drift monitoring, an AI policy, or ISO 42001. Checked the home page, the AI Regulatory Expert page, the company page and the blog index on 29 Aug 2026. Research limitation recorded rather than assumed: the home page FAQ includes an entry asking whether the AI is suitable for regulated environments, and the answers render client side and did not load, so that answer is unread. If it contains governance disclosure this grade is a correction candidate.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

AscentAI
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

The perimeter is documented well and what happens to customer content after processing is not addressed. Published and specific: AES-256 at rest with FIPS 140-2 validated hardware security modules and automatic key rotation, RSA-2048 and SHA-256 named as accepted algorithms, TLS 1.2 or 1.3 in transit, secret management by runtime injection with HSM-backed key storage, annual penetration testing plus regular vulnerability scanning with named tooling categories, centrally managed endpoints with mobile device management enforcing disk encryption and screen lock, endpoint alerting monitored around the clock, remote access secured through Tailscale on WireGuard, malware-blocking DNS, and security training delivered through Vanta at onboarding with annual recertification. Against that, three of the limbs this axis names are simply absent: no retention period is published for customer content, no deletion commitment or route is described, and no subprocessor list exists anywhere on the property. No incident or breach notification practice was located either. The privacy policy, recovered through search after the page would not fetch directly, addresses website visitors and states that customer data is primarily stored in the United States while it may be transferred and accessed from around the world.

FinregE
DD on AI Safety and Data StewardshipNothing published on retention, deletion or access for a system that holds client documents.

No stewardship position located for customer content passing through the AI. Nothing states whether customer documents, policies and control libraries uploaded to the platform are used to improve models, how long inputs and outputs persist, whether processing is segregated by tenant, or what happens to derived artifacts. Security controls exist and are graded separately under Security Certifications, and are not double counted here. Checked the home page, the horizon scanning page, the company page, the site footer and the Terms of Use on 29 Aug 2026 and located no privacy policy, no data processing agreement and no security page. For a platform ingesting a regulated institution's internal policies, procedures and control libraries, this is the disclosure a buyer most needs and it is entirely absent from public material.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

AscentAI
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

The allocation of loss is published, readable in advance, and points in one direction throughout. Liability is capped twice over: the limitation clause caps at the previous six months of customer payments where a jurisdiction does not permit outright exclusion, and a separate Liability Cap section caps aggregate cumulative liability at the annual fee paid, expressly stating that the cap includes indirect and consequential damages regardless of jurisdiction. Warranties are disclaimed in full, with Ascent declining to guarantee the accuracy, completeness, timeliness, reliability, suitability or usefulness of any portion of the Site and placing the entire risk as to accuracy on the user. The limitation clause opens by stating that Ascent will not be liable for any loss caused by the user's reliance on information obtained through the Site, which is precisely the exposure this product creates. Indemnification runs one way only, from customer to vendor. There is no vendor indemnity of any kind, no warranty on output, and no insurance position. The History Views clause adds a further targeted disclaimer of all liability for the obligations history the platform presents. This is a C rather than a D because every limb of it is published and a buyer can read the whole allocation before signing.

FinregE
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

No product liability position published. The only published legal document is a website Terms of Use, which excludes liability to any user for loss arising out of the use of, or reliance on, content on the site, and excludes representations that content is complete, accurate or up to date. That is a marketing site disclaimer and it says nothing about the platform, its output, or recourse when an obligation extraction or a policy mapping is wrong. Nothing was located on indemnity, warranty, service levels, or a remedy where AI output is incorrect. Checked the site footer, the Terms of Use and the sitemap page on 29 Aug 2026. Recorded as an absence of published product terms rather than as a limitation the vendor has imposed, since the operative terms are in a signed contract this index cannot see.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

AscentAI
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Integration is central to the product rather than decorative, and the direction of movement is described. The platform is marketed as integrating with leading GRC platforms so that obligations, policies and controls reflect current regulatory requirements, which states what actually moves: obligations flow out of the register into the policy and control records held elsewhere. Five GRC partners are named on the home page, MCO, LogicGate, Onspring, Resolver and Corestream, and a policy and control engine is described for automated change proliferation and end-to-end oversight within GRC. First-party announcements describe two further integrations with substance: Diligent's regulatory compliance management solution consuming Ascent's monitoring and interpretation so that obligations update automatically and alert the user to assess impact, and Halo Ai consuming Ascent's enriched regulatory data through named endpoints to surface obligations into its own workflow engine. What is missing is depth an implementer could work from: no public API reference, developer portal or integration documentation index was located on the site navigation on 1 September 2026, and the endpoints referenced in the Halo Ai announcement are not documented publicly.

FinregE
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

The claim is made at architecture level and no integration is documented. The vendor describes an API first architecture, states that infrastructure is only valuable if it connects, and positions the platform as the brains of the compliance function feeding intelligence into tools teams already use. A customer testimonial from a global legal professional services firm specifically credits access to the regulatory data feed through customised APIs with filtering. What does not exist in public: any named integration or connector, any GRC platform the product sits beside, any API documentation, any authentication or scope detail, and any statement of what moves in which direction. Checked the home page, the ecosystem integration section, the automated compliance solutions page and the platform footer links on 29 Aug 2026. Compare Regology at B, which names ServiceNow, Archer and Hyperproof and states that no rip and replace is required.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

AscentAI
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Cloud delivery is implied throughout and neither the tenancy model nor a residency option is stated. There is a hosted application at app.ascentregtech.com and the terms describe Ascent hosting its Solutions as a backend service, but nothing located names a hosting provider, a data centre region, or whether customers receive a dedicated or shared environment. The only geography published sits in the privacy policy, recovered through search after the page would not fetch directly, which states that the company primarily stores data about customers in the United States and that to facilitate global operations it may transfer and access such information from around the world. That is a description of where data tends to sit rather than a residency commitment, it offers the customer no choice, and it is framed around personal data rather than the obligations inventories and policy mappings the platform holds. No processing location is addressed separately from storage. Checked the home page, the RLM Platform page, the security page, the terms of service and the privacy policy on 1 September 2026.

FinregE
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

The hosting platform is named and nothing beyond it is. The vendor states hosting on Microsoft Azure, single sign on, role based access control and a four to twelve week implementation. No region or data residency commitment was located, which is a live question for a London vendor selling to Tier 1 banks, insurers and regulators subject to UK and EU data localisation expectations. No single tenant, private instance or in perimeter deployment option is described, and nothing states where regulatory data or customer policy libraries are physically processed. Checked the home page, the horizon scanning page, the automated compliance solutions page and the company page on 29 Aug 2026. Naming the cloud provider is a real disclosure and earns the C; residency is the artifact that would move it.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

AscentAI
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

The attestation is real, named, and stated with a candour worth recording: AscentAI publishes that it maintains a SOC 2 **Type I** attestation, which is the design-at-a-point-in-time report rather than the Type II examination of operating effectiveness over a period that most vendors lead with. Naming the weaker of the two rather than blurring them is a disclosure choice in the buyer's favour. A trust centre exists at trust.ascentregtech.com and the security page states the attestation is available there, so a route to the report is published. The security programme is additionally described as aligned to the NIST Cybersecurity Framework, and the page is current, last modified April 2026. What holds this below the top band is that none of the confirming detail is on the readable surface: no auditor or certification body is named, no examination date or period appears, and no scope statement identifies which entities or systems the attestation covers. The trust centre itself was not opened on 1 September 2026, so whether its access flow is self-serve or sales-gated could not be established, and the lower tier was taken for that reason.

FinregE
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

Three credentials are named and none is evidenced. Named: ISO/IEC 27001:2022 with the standard version stated and a dated announcement carrying a quote from the named COO, Cyber Essentials Plus, and FSQS registration. Naming the 2022 revision rather than the withdrawn 2013 one is a real signal and better than several records on this index. Held at C rather than B because nothing behind the claims is reachable: no auditor or certification body is named, no certificate number, scope statement or expiry date is published, no SOC 2 of any type is claimed, and there is no trust centre, security page or documentation request route of any kind. Under the three tier test the artifact is neither open nor self serve request; it is absent. The certifications appear on the home page as badge images rather than as text a reader can verify. Checked the home page badge row, the ISO certification announcement, the company page and the full site footer on 29 Aug 2026. Compare Regology at B in this same category, which names BARR Advisory as the auditing firm and states the examination scope; FinregE names neither, so B here would sit inconsistently against a record already on the roster.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

AscentAI
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The vendor refers to its own proprietary technology and identifies nothing underneath it. A 2022 first-party announcement describes patented AI and natural language processing technology, and the product pages refer throughout to AI-powered automation, AI-generated summaries and AI-driven impact assessment without naming a model, a model family, a provider, or an architecture. No statement identifies whether any third-party foundation model is called at any point, which is the question a financial services customer's own vendor risk process will ask about a system processing its obligations inventory. Where inference runs is not stated. No commitment to notify customers when the model set changes was located. Checked the home page, the RLM Platform page, the Compliance page, the security page and the terms of service on 1 September 2026. The dedicated page at /our-difference/ascentai/ could not be retrieved and is the surface most likely to carry this, so the grade is rebuttable on it; nothing has been graded against the vendor for that retrieval failure, since C rests on what the readable surfaces do say rather than on what could not be read.

FinregE
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

Nothing located. No foundation model provider is named anywhere in public material, no statement distinguishes proprietary models from third party models, and no subprocessor list exists. The vendor describes machine learning and natural language processing built since 2018 and an Imperial College research collaboration, which implies meaningful in house model work, but implication is not disclosure and the platform's generative and question answering features are not attributed to any named model. Checked the home page, the AI Regulatory Expert page, the company page, the site footer and the Terms of Use on 29 Aug 2026. For a buyer in a regulated institution, the identity of the model provider is a subprocessor question their own regulator may ask, and it cannot be answered from public sources.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

AscentAI
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing information is published at any level, including the unit of charge. There is no pricing page and no pricing entry anywhere in the site navigation, which was read in full on 1 September 2026 and covers the platform, difference, buyer, partner, resource and company sections. Every commercial route on the property is a contact form or a request to talk. The terms of service confirm that a priced self-service route exists without publishing any part of it: a user signs up for a duration of their choice ranging from one month to three years and pays by credit card, with pricing terms and procedures deferred entirely to a separate Individual Service Agreement, and recurring ACH debit authorised against charges described in that agreement. The only figure published anywhere is a 25 dollar fee for a transaction returned for insufficient funds, which is a penalty rather than a price. Neither a rate, a band, a tier name, a per-seat or per-obligation unit, nor a statement of what implementation adds was located.

FinregE
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing at any level of abstraction. No price, no range, no tier structure, no unit of charge, and no statement of what drives cost, whether that is users, jurisdictions monitored, modules licensed or regulatory sources ingested. Every commercial route on the site is a demo request or a booking link to a calendar. The one adjacent figure published is a case study claiming a 60 percent cost reduction at a UK bank, which describes the customer's savings rather than the vendor's price and is not transparency about what the product costs. Checked the home page, the sign up page, the contact page and the company page on 29 Aug 2026. Common for enterprise RegTech and still an absence a buyer cannot work around.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

AscentAI
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Coverage is documented with real precision on two of the three dimensions and left open on the third. Segment coverage is unusually specific and is expressed as regulatory scope rather than as a logo wall: depository institutions including banks and credit unions, non-depository institutions covering mortgage services, consumer finance and fintech platforms, electronic payments and money services, then securities and commodities covering investment advisers, broker-dealers and funds, crypto and digital asset businesses, and market infrastructure including exchanges, clearing and settlement organisations and repositories. Practice coverage is named by regulatory topic across consumer protection, consumer privacy, anti-money laundering, counter-financial terrorism and ESG, against a stated 98 countries and 1,000 data sources. The boundary is implicit rather than stated: the coverage list makes clear this is a financial services product, but nothing states firm size, obligation volume, or where the product stops. The gap worth naming is the buyer: the Who We Serve section offers pages for Compliance, Risk and Digital Transformation and none for Legal, even though the platform page positions the product to legal teams and the rebrand announcement does the same.

FinregE
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Coverage is stated with unusual specificity for this category, at the level of named regulators and named regimes rather than a jurisdiction count alone. Regulators named include the PRA, ECB, EBA, Basel Committee, SEC, FCA and CFPB. Regimes named include MiFID II, AIFMD, Solvency II, PSD2, MiCA, DORA, AMLD6 and Consumer Duty. Regulatory themes are enumerated across prudential regulation and conduct, AML, sanctions, data protection and information security, operational resilience, consumer protection, competition, health and safety, tax and reporting, and ESG. Sector coverage is set out for banking, payments, insurance, asset and wealth management, fintech and digital assets, lending and credit, accounting and tax, healthcare and pharma, public sector and development finance, energy, aerospace and defence, and automotive and transport. Scale is stated in the ISO certification announcement as more than three million regulatory data points from over 2,000 sources across more than 160 jurisdictions. Held at B rather than A because the jurisdiction list itself is not published: a buyer can read that 160 plus jurisdictions are covered and cannot check whether their own is among them, and no update lag or refresh frequency is stated for any source.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

AscentAI
Terms silent

No located term or policy addresses the question either way. The terms of service govern the Site and the Solutions, run to roughly twenty sections covering warranties, liability, indemnification, service rules and payment, and contain no provision on the use of customer content for model training or improvement. The security page describes encryption, secret management and identity controls and is silent on it. No data processing agreement is published anywhere on the property. The nearest adjacent statement runs the other way and concerns a different subject: the terms provide that as between the parties the customer owns and retains all right, title and interest in its Account Information, which is a statement about ownership rather than about training use. Searched the terms of service, the security page, the privacy policy, the home page, the RLM Platform page and the Compliance page on 1 September 2026.

FinregE
Terms silent

Terms are silent. No agreement addressing customer content was located, and the only published legal document is a website Terms of Use whose scope is the marketing site, as the quoted phrase shows. It says nothing about the platform, customer uploads, or model training. No privacy policy and no data processing agreement exist on the site. Checked the site navigation, the full footer, the company page, the contact page, the sitemap page and the Terms of Use on 29 Aug 2026. Recorded as silent rather than as a negative commitment: a vendor that does not say it trains on client data has not said it does not.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

AscentAI
Not addressed

No located public material states how long customer inputs or generated outputs are retained, and no zero-retention or customer-configurable option is described. The privacy policy addresses website visitor data rather than platform content. One clause touches the subject obliquely and is worth recording because it cuts against the product's own audit-trail marketing: the History Views section of the terms provides that where new information changes Ascent's assessment of a customer's history of rules and documents, the prior history may not be accessible to the customer and may be replaced by an updated view. That describes a presentation policy rather than a retention window, and it means the record a customer sees is not guaranteed to persist unchanged. Searched the terms of service, the security page, the privacy policy and the platform pages on 1 September 2026.

FinregE
Not addressed

Not addressed. No retention period is stated for AI prompts, generated summaries, extracted obligations or question answering exchanges, and nothing indicates whether a customer can configure or zero retention. The platform does publish that it retains a permanent audit trail of assessments and decisions, which is a deliberate retention commitment in the opposite direction and is a product feature rather than a privacy disclosure. What is missing is any statement about the AI interaction layer itself. Checked the home page, the horizon scanning page, the workflows page, the site footer and the Terms of Use on 29 Aug 2026.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

AscentAI
Claimed, not documented

A permission model is asserted and nowhere described. The Information Sharing section of the terms states that Ascent enables users with appropriate permissions to share access to their accounts, giving a law firm working on the customer's behalf as its worked example, and makes the customer responsible for the use and content of anyone they share access with. That establishes that per-user permissions exist and that cross-organisation sharing is a supported flow, without publishing anything about how the model is enforced, what granularity it operates at, or whether shared access can be scoped below the account. The role-based access controls described on the security page govern AscentAI employees rather than customer users. Nothing addresses walls or segregation between teams or matters inside a customer account, which is the question that matters given the sharing feature points outward to external advisers.

FinregE
Claimed, not documented

Claimed and not documented. The vendor names role based access control and single sign on as platform capabilities, and describes routing assessments to specific stakeholders with assigned ownership, so an access model exists and is asserted. Nothing documents how it works: no permission granularity, no statement of whether access is enforced at query time against the AI layer as well as the record layer, and no description of segregation between business units within a single institution. This product has no document management system to inherit permissions from, so the inherits value does not apply and a second model is the only available shape. Checked the home page, the horizon scanning page and the workflows page on 29 Aug 2026.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

AscentAI
Not addressed

No commitment to notify the customer of a third-party request for their data was located, in the terms of service, the privacy policy or the security page. There is no confidentiality section in the terms in the usual sense, so the clause that ordinarily carries this obligation does not exist. One provision addresses disclosure to authorities and contains no notice undertaking: the terms state that user activity may be monitored, that users expressly consent to such monitoring, and that if monitoring reveals possible criminal activity security staff may provide the evidence to law enforcement officials. That is a disclosure route without a notice commitment attached, though it concerns monitoring of system use rather than a subpoena for customer content. No transparency report exists. Searched on 1 September 2026.

FinregE
Not addressed

Not addressed. No government or law enforcement request clause was located, no commitment to notify a customer before producing their data, and no transparency report. The website Terms of Use contains no such clause because it governs the site rather than the service. Checked the site footer, the Terms of Use, the company page and the sitemap page on 29 Aug 2026. Worth noting for a later reader that this vendor holds regulator relationships, including hosting the FCA Handbook website, which makes the question of what it does with a customer's compliance record when asked by an authority more pointed than usual rather than less.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

AscentAI
Jurisdictions only

Coverage is quantified and geographic, and the underlying corpus is not identified. The home page states 98 countries, roughly 1,000 data sources and 400,000 obligations, and the platform page breaks coverage down by segment and by cross-segment regulatory topic including consumer protection, consumer privacy, anti-money laundering, counter-financial terrorism and ESG. None of the 1,000 sources is named, no regulator, publisher or feed is identified, and no licence or rights basis is stated for any of it. The terms confirm that third parties are involved without naming them, describing the Content as relating to and provided by Ascent Technologies Inc. and its third party content providers. No update cadence is published, although the product is marketed on near-real-time capture. Checked the home page, the RLM Platform page, the Compliance page and the terms of service on 1 September 2026.

FinregE
Sources named, basis unstated

Sources are named at regulator and regime level with no licence basis stated. Named regulators include the PRA, ECB, EBA, Basel Committee, SEC, FCA and CFPB, and named regimes include MiFID II, AIFMD, Solvency II, PSD2, MiCA, DORA and AMLD6. Scale is stated as more than three million regulatory data points from over 2,000 sources across more than 160 jurisdictions. Most of this corpus is government published regulatory text, where a licence question is less loaded than for case law, but the vendor never says so: no licence, no public domain basis, no source list a buyer can open, and no update lag or refresh frequency for any source. The full jurisdiction list is not published, so a buyer cannot confirm their own is covered.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

AscentAI
Own treatment signal

The regulatory analogue of a citator is a shipped feature here, which is unusual for this signal. Rule Compare presents the new and former versions of a rule side by side with the changes redlined, and the change management engine identifies in near real time when a rule the customer is tracking has moved and which of their obligations it affects, with auto-generated summaries of what changed. That is the vendor computing and surfacing subsequent history for its own corpus rather than licensing a treatment service, and the method is described at least at the level of what the user sees. Two limits belong on the record. The currency of the underlying corpus is asserted rather than evidenced, and the terms state that Content may not reflect the most current regulatory developments. And the History Views clause provides that a prior version of a customer's rule history may cease to be accessible and be replaced by an updated view, which weakens the historical trail the feature otherwise builds.

FinregE
Own treatment signal

Own treatment signal, operating on regulatory text rather than case law. The vendor states that mappings are dynamic and that when a regulation changes the system automatically flags the affected policies and controls for review, and describes version history maintained against regulatory requirements so governance documents stay traceable as rules move. That is the regulatory equivalent of a currency check: it tells a user that the authority underneath their policy has moved. It is the vendor's own mechanism rather than a licensed commercial citator, and no accuracy or completeness measure is published for change detection.

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

AscentAI
Not addressed

Nothing located describes what the system does when a question or a rule falls outside its scope, which is the decisive question the index editorial sets for this category. No abstention path, confidence score, coverage indicator or low-certainty flag is published for the applicability assessment or for the generated summaries, and no statement describes what a user sees when the platform cannot determine whether a change affects them. The terms answer the question contractually instead, telling the user that if their specific problem is too complex to be addressed by Ascent and its Solutions they should consult a Compliance Professional in their area. That places the escalation duty on the reader rather than describing a behaviour of the system, and it is the customer who must notice that the threshold has been crossed. Searched the home page, the RLM Platform page, the Compliance page, the security page and the terms on 1 September 2026.

FinregE
Not addressed

Not addressed. Nothing describes what the system does when it cannot find support for an answer, and no explicit no answer path, abstention behaviour or confidence score is documented anywhere in public material. The vendor states that AI operates within controlled workflows and that output is source cited, which bounds the output without describing the uncertainty case. Checked the home page, the AI Regulatory Expert page, the horizon scanning page and the blog index on 29 Aug 2026. Research limitation recorded: the home page FAQ entry asking whether the AI is suitable for regulated environments renders client side and did not load, so its answer is unread and may bear on this signal.

Fabricated Citation Record

Does a public court record exist involving output from this product?

AscentAI
None located

Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on both the current brand AscentAI and the former corporate name Ascent Technologies. No court order, opinion or disciplinary record naming either was located. This is a statement about the public record rather than a finding about the product. The failure mode this signal tracks fits imperfectly, since the platform's output is a regulatory obligation assessment consumed inside a compliance function rather than a citation filed with a court, though the same underlying risk exists in a different forum: a fabricated or misattributed regulatory citation reaching an examiner rather than a judge.

FinregE
None located

None located, and the instrument used is stated so the finding is worth what the search is worth. General web searches on the vendor name combined with court, opinion, sanction and enforcement terms returned nothing on 29 Aug 2026. No named docket database or court record tracker was searched for this record. This is a UK vendor selling compliance tooling to institutions rather than a litigation product filing into courts, so the exposure shape differs from a research or drafting tool. Recorded as a statement about what was found, not as a clearance, and a named tracker search would strengthen it.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

AscentAI
Generic reference

Professional responsibility is engaged repeatedly and in substance, and no guidance is ever named. The terms state that Ascent is not a law firm, attorney and does not dispense legal advice, that no attorney-client relationship is created or implied, that any privileges related to such a relationship may only be formed between the customer and their own attorney, that Ascent is not a law or compliance firm and may not perform the services of a Compliance Professional, and that use of its forms is neither legal advice nor the practice of law. That is a fuller engagement with the professional line than most vendors in this pull publish. What is absent is any named source: no reference to ABA Formal Opinion 512, to any state bar opinion, or to regulator guidance on the use of AI in compliance functions was located on any surface read on 1 September 2026.

FinregE
Not addressed

Not addressed. No named ethics opinion, no ABA Formal Opinion 512, no Solicitors Regulation Authority or Law Society guidance, and no bar guidance engagement of any kind was located. The vendor addresses Legal and General Counsel as a named stakeholder audience and produces drafted policy language and regulatory interpretations, so professional guidance is relevant to how that output is used. The vendor writes extensively about regulatory obligations owed by its customers and nothing about the professional duties of the lawyers using it. Checked the home page, the company page, the stakeholder sections, the blog index and the news index on 29 Aug 2026.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

AscentAI
Savings claims only

Cost savings are claimed and no billing or disclosure treatment is addressed. The home page markets reduced costs through eliminating manual processes, and the Compliance page states that automation reduces the need for incremental full-time employees and outside services to monitor and act on regulatory change. That is a headcount and outside-spend saving aimed at an in-house compliance function rather than an hours claim aimed at a firm billing a client, so the fee-disclosure question this signal was written for lands differently in this category. Nothing published addresses how AI-assisted regulatory analysis should be disclosed where the work is performed by an adviser and billed on, which is a live question given the terms expressly contemplate a law firm being granted shared access to a customer's account. No per-matter record of AI-assisted work is described.

FinregE
Savings claims only

Savings claims only. The published case study claims a 60 percent reduction in cost and a 100 percent reduction in risk at a UK bank, and the wider positioning is built on eliminating manual effort and duplicative work. Nothing appears on the client's side of the equation: no statement about billing for AI assisted time, no record a firm could disclose to its own client, and no fee posture of any kind. The 100 percent risk reduction figure is the unfalsifiable absolute shape this index does not credit as evidence, and it is recorded here as the claim it is.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

AscentAI
Not addressed

Nothing that would support a client-side disclosure obligation was located. No subprocessor list is published anywhere on the property. No model provider is identified, and the AI is described only as Ascent's own patented artificial intelligence and natural language processing, so a customer cannot say whether any third-party model sees its content. No data processing agreement, consent pack or client-facing disclosure material exists, and no route to request any of it was found beyond a general contact form. The terms disclose that third party content providers exist without naming them. The trust centre at trust.ascentregtech.com is stated to carry the SOC 2 attestation and was not opened, so it is possible a subprocessor register sits there; on the surfaces read there is nothing. Searched the terms of service, the security page, the privacy policy and the full site navigation on 1 September 2026.

FinregE
Not addressed

Not addressed. No subprocessor list, no model provider disclosure, no data processing agreement, no trust centre and no security documentation request route were located. A firm could not forward anything to its own client without opening a sales conversation. The vendor does publish ISO/IEC 27001:2022, Cyber Essentials Plus and FSQS registration, which is the raw material for such a pack, but names no auditor, scope or certificate and provides no route to the underlying documents. Checked the home page badge row, the ISO certification announcement, the company page, the full site footer and the Terms of Use on 29 Aug 2026.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

AscentAI
Partial record

Part of the record exists and it was built for a different forum. The platform markets comprehensive audit trails with automatic tracking of every activity, end-to-end traceability for audit readiness, and support for documentation to prepare for regulatory audits and examinations, so a customer can evidence what was reviewed, when, and by whom. That is a real and exportable-sounding activity record, and in this category the relevant tribunal is an examiner rather than a judge. What it does not do is identify the AI's contribution: nothing states that the record captures which assessments or summaries were machine-generated, what corpus they drew on, or who verified them, so a user could not produce an AI-use disclosure from it. The History Views clause cuts against it further, providing that a prior history may become inaccessible and be replaced by an updated view.

FinregE
Partial record

Partial record, and strong for its actual forum, which is a regulatory examination or an internal audit rather than a court. The vendor states an immutable audit trail recording who assessed a change, what changed, when it changed, why it was actioned, the evidence supporting the decision and the workflow routing history, and states that this exists to demonstrate compliance to regulators, auditors and boards. Rule applied, path taken, human sign off and evidence are all recorded and exportable into board ready reports. Held at partial rather than exportable record because the model used for a given AI output is never named and no per document export of model, sources retrieved and human verification is described. Same shape as Regology, and the second record in this category to make defensibility of the trail its central claim.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • AI Governance and Bias Disclosure
  • Commercial Transparency
Signals neither addresses in public material
  • Prompt and Output Retention
  • Third Party Request and Subpoena Notice
  • Refusal and Uncertainty Behaviour
  • Outside Counsel Guideline Readiness

Which one fits

Choose AscentAI if

  • You want a register of your own obligations rather than a library of the rules. AscentAI builds and maintains the obligations inventory itself, identifies gaps and duplicates in it, then automatically assesses which incoming regulatory changes affect which obligations, with rule comparison showing old and new versions side by side and changes redlined, across a stated 98 countries, roughly 1,000 sources and 400,000 obligations.
  • You want the professional boundaries stated. AscentAI's terms state that it is not a law firm or an attorney and does not dispense legal advice, that no attorney client relationship is created or implied and that privilege can arise only between the user and their own attorney under that firm's engagement and conflict procedures, that it is not a compliance firm and is not a substitute for one, and that the subject matter varies between jurisdictions and regulators.
  • The obligations have to reach your GRC system. AscentAI names five integration partners in MCO, LogicGate, Onspring, Resolver and Corestream, with obligations flowing out of the register so that policy and control records reflect current requirements, and publishes a detailed security page covering AES-256 at rest with FIPS 140-2 validated hardware security modules, TLS 1.2 or 1.3 in transit, annual penetration testing and a programme aligned to the NIST Cybersecurity Framework.

Choose FinregE if

  • You want to know who else relies on it. The Financial Conduct Authority selected FinregE to redesign, host and manage the FCA Handbook website, which is a regulator adopting the product to publish its own rulebook rather than a customer logo, alongside a strategic investment from Moody's Corporation, FSQS registration, an Innovate UK AI grant and a natural language processing research collaboration with Imperial College.
  • Every assessment has to survive examination. FinregE states that every AI output is source cited for audit defensibility and that the platform preserves an immutable audit trail recording who assessed a change, what changed, when, why it was actioned, the evidence supporting the decision and the workflow routing history, with mappings that are dynamic so a regulatory change flags the affected policies and controls for review.
  • Your coverage question is about named regimes rather than a jurisdiction count. FinregE names the regulators it tracks, including the PRA, ECB, EBA, Basel Committee, SEC, FCA and CFPB, and the regimes, including MiFID II, AIFMD, Solvency II, PSD2, MiCA, DORA and AMLD6, across a stated three million regulatory data points from over 2,000 sources in more than 160 jurisdictions, and holds ISO/IEC 27001:2022 with Cyber Essentials Plus.

In summary

AscentAI

AscentAI is a regulatory lifecycle management platform for financial institutions, built around holding a register of the obligations that apply to a particular firm rather than a library of the rules at large, with global horizon scanning filtered to declared interests, an obligations inventory that identifies gaps and duplicates, automatic assessment of which changes affect which obligations, rule comparison with redlined versions and an audit trail. The AI Legal Index grades it in the top two bands on five of fifteen capability axes. Its terms carry the most developed professional responsibility position in this category, and it names its attestation candidly as SOC 2 Type I. As of 1 September 2026 the index located no named model provider, no accuracy figure and no published price.

Source: AI Legal Index, 2026

FinregE

FinregE is an AI powered regulatory compliance platform for regulated institutions, sold as seven modules spanning horizon scanning, a machine readable rules library, mapping rules to internal policies and controls, impact assessment workflows, policy governance, regulatory project management and control testing, with an AI engine that classifies, summarises, extracts obligations and maps them to controls while highlighting gaps. The AI Legal Index grades it in the top two bands on four of fifteen capability axes. The Financial Conduct Authority selected it to redesign, host and manage the FCA Handbook website. As of 29 August 2026 the index located no privacy policy, no data processing agreement, no security page and no published price.

Source: AI Legal Index, 2026

Questions buyers ask

AscentAI vs FinregE: which is better for regulatory change?

The AI Legal Index places AscentAI in the top two bands on five of fifteen capability axes and FinregE on four, so the grid barely separates them. AscentAI publishes its terms, including the most developed professional responsibility position in this lane, and names its integrations and its security controls. FinregE publishes who relies on it, including a regulator that chose it to publish its own handbook, and names the regulators and regimes it covers.

What can you read before signing?

On AscentAI, a full terms of service covering the professional boundaries, liability caps at the annual fee paid, warranty disclaimers and the informational purposes limitation, plus a security page and a trust centre route to its attestation. On FinregE, a website terms of use and nothing else: no privacy policy, no data processing agreement and no security page was located, so the confidentiality and liability position sits entirely in a signed contract. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Who else relies on each of them?

FinregE publishes the stronger answer. The Financial Conduct Authority selected it to redesign, host and manage the FCA Handbook website, and it holds a strategic investment from Moody's. On AscentAI no customer is named anywhere on the surfaces read, and the logos that appear are its GRC integration partners rather than customers, with a single testimonial attributed only to a compliance executive at a large financial services firm. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Do either publish an accuracy figure?

Neither does. FinregE states that every AI output is source cited and AscentAI shows old and new rule versions side by side with changes redlined, both of which let a user check a claim against the regulatory text. Neither publishes an accuracy figure, a precision or recall number for obligation extraction, a test set or an evaluation, on a task where the failure mode is an obligation that never surfaces rather than a visible error. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What do AscentAI and FinregE both leave unpublished?

Neither publishes a price, a unit of charge or what drives cost, whether that is users, jurisdictions monitored or modules licensed. Neither names the model or provider behind its AI, which in a regulated institution is a subprocessor question the customer's own regulator may ask. Neither publishes an AI governance position, a named owner of model behaviour or any evaluation of uneven output across jurisdictions or obligation types. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Disclosure

AscentAI's marketing and its agreement describe the same product differently and a buyer should read both. The product pages promise a single enterprise wide source of regulatory truth, a rock solid inventory of corporate obligations and that a user will never miss a regulatory update. The terms of service state that all content is for informational purposes only, may not reflect the most current regulatory developments and is not guaranteed to be correct, complete or up to date, and the history views clause describes the register as reflecting Ascent's best guess of the rules applicable to the customer. The agreement governs. On FinregE, the only legal document published anywhere is a website terms of use covering the marketing site, and no privacy policy, data processing agreement or security page was located, so a buyer cannot read a confidentiality, retention or liability position in advance. Neither vendor names the model provider behind its AI. AscentAI was verified on 1 September 2026 and FinregE on 29 August 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 2, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746