CUBE vs Vixio: how they compare in 2026

CUBE profileVixio profile
Last verifiedSeptember 3, 2026

CUBE and Vixio both sell regulatory intelligence and they disagree about who should make it. CUBE's corpus is machine made: computer vision recovers document structure, a proprietary language model it calls RegLM classifies and extracts obligations, and graph machine learning places the result in a knowledge graph. Vixio's is analyst made, written and validated by domain specialists before publication, with its assistant retrieving over that material in a closed box that never touches the open web and citing every claim back to the source text or the analyst report behind it. They tie at five of fifteen axes each. Vixio holds the only A between them, on professional responsibility: its terms state that the materials are not a definitive statement of the law and do not constitute legal advice, the product carries a standing instruction to verify critical information against official sources, and its published FAQ asks whether the assistant replaces a legal team and answers no.

At a glance

Category
CUBERegulatory & Compliance Counsel
VixioRegulatory & Compliance Counsel
Founded
CUBENot published
Vixio2006
Headquarters
CUBELondon, United Kingdom
VixioLondon, United Kingdom
Last verified
CUBESep 1, 2026
VixioSep 1, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

CUBE
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models are the engine of the capability being sold, on a content business that would survive without them. RegAI is described as a proprietary regulatory AI framework trained exclusively on regulatory data, and the enrichment it performs, turning unstructured regulatory text into obligations mapped to a firm's risk profile, is what a buyer is paying for rather than the raw feed. The architecture is real and staged: computer vision to recover document structure, a proprietary language model for classification and extraction, graph machine learning over a regulatory knowledge graph. What would remain if the models were removed is nonetheless substantial and is in fact sold separately: CUBE lists Content Infrastructure as its own solution, meaning the underlying regulatory content across a stated 750-plus jurisdictions is a saleable asset in its own right, alongside change workflow and the platform's tracking and reporting. That is the B shape. Third consecutive vendor in this lane at this grade, which is beginning to look like the shape of regtech rather than a coincidence.

Vixio
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

The models sit on top of a twenty-year content business rather than constituting it, and Vixio says so in its own framing, describing the offering as expert-led data combined with AI-powered tools and counting more than twenty domain specialist analysts among its assets. The corpus is analyst-written and analyst-validated: humans validate and enrich high-value updates before publication, and the regulatory intelligence graph holds more than 90,000 pieces of verified content. VIQ is a retrieval and drafting assistant over that material, and it is described as flagship rather than foundational. Remove the models and the business that existed from 2006 remains entirely saleable, with jurisdiction reports, regulatory analysis, an obligations library, horizon scanning and the task and audit workflow all intact. This is a lower grade than the three regtech peers in this lane took, and the reason is structural rather than a matter of degree: at those vendors machine learning performs the classification and enrichment of the corpus itself, whereas here the corpus is human-made and the AI queries it.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

CUBE
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

The method is documented more fully than anywhere else in this lane and no figure is attached to any of it. CUBE names its architecture layer by layer: computer vision converting text images to machine-readable content and revealing structural components from headers to body paragraphs to footers; deep NLP and a proprietary model called RegLM fine-tuned for entity extraction, citation extraction, document type classification, obligation identification and summarisation; and graph machine learning placing enriched content into a knowledge graph. Citation extraction as a named capability and the grounding of output in the source regulatory instrument mean a reader can reach the underlying text. Explainability is claimed as a product property, with advanced visualisation and interpretability tools said to show how AI decisions are made. The gap is measurement. RegAI is said to reduce noise by filtering out irrelevant updates, false positives and missed obligations, which names the two error types that matter here and attaches a rate to neither, and no benchmark, test set or accuracy figure was located on any surface read on 1 September 2026.

Vixio
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is real, documented and architecturally enforced, and no figure is attached to any of it. VIQ is described as operating in a closed-box environment over Vixio's own analyst-verified data and never the open web, drawing on more than 6,200 curated sources and 20,000 regulatory documents. Traceability is the strongest in this lane: every claim carries a direct citation back to the original source text or to the Vixio analyst report behind it, with signposts into deeper analysis, and the company frames this as full explainability to a regulator. The retrieval method is described rather than gestured at, through a regulatory intelligence graph connecting content by intent rather than keyword. The gap is measurement: no accuracy rate, benchmark, test set or error analysis was located. **One internal tension belongs on the record**: the section heading claims grounded research with zero hallucinations, while the body copy on the same page says the design minimises and reduces hallucination risk, which is the more defensible of the two claims and the one the rest of the page supports.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

CUBE
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Two real review mechanisms are published and the control structure around them is not. The first is inspection: CUBE states that it uses advanced visualisation techniques and interpretability tools to show users how AI decisions are made, offering transparency into model logic and reasoning, which is a described surface a compliance officer can open rather than a claim that a human is involved somewhere. The second is correction: real-time user feedback loops within the platform are said to refine and improve AI performance over time, and RegAI is described as learning from a customer's past decisions and becoming more aligned with its processes. What is missing is the rest of the structure. Nothing states what runs unattended, what threshold causes the system to defer, or what happens after an assessment is wrong. Worth separating one claim that does not carry weight here: the Human Input principle describes data scientists working with regulatory specialists to guide model development, which is a development practice rather than a runtime checkpoint in a customer's workflow.

Vixio
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Three distinct review mechanisms are published, which is more than any other vendor in this lane, and the control structure around them is still incomplete. First, oversight of the corpus before it reaches a user: human-in-the-loop is named as a design pillar, with AI scanning roughly 8,000 daily sources for scale and analysts validating and enriching high-value updates before publishing. Second, oversight of the output at the point of use: the product carries a standing notice that VIQ uses AI across Vixio's proprietary data only and that critical information should always be verified against official sources, and citation traceability makes that verification actually possible. Third, behaviour at the boundary, addressed below on the refusal signal. What is missing is the rest of the structure. The analyst validation applies to high-value updates without defining which those are, so validation coverage is undisclosed; no confidence threshold is described for VIQ itself; and nothing states what happens after an answer is wrong or how a correction propagates to other users who relied on it.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

CUBE
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

A large scale claim stands in for evidence and nothing under it is attributable. The home page states more than 1,000 customers across financial services including banking, insurance, asset and investment management and payments, and describes CUBE as the global market leader on multiple metrics, with no source, method or named institution behind either statement. No customer logo strip, named reference or dated deployment appears on any page read, and no figure for what changed at any customer was located. A Case Studies category exists in the Resources section and **was not opened on 1 September 2026**, so a named, dated outcome was neither located nor excluded and this grade is rebuttable upward on one fetch. The acquisition announcements and market-position claims that do appear are corporate news rather than deployment evidence. Checked the home page, the Technology and AI page, the privacy policy and the full site navigation.

Vixio
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Two named customers, two named individuals with senior titles, and figures that describe the customer rather than the change. Inpay is named with a quote from Camila Witt, Chief Risk and Compliance Officer, describing daily use as part of the firm's risk management, alongside figures of more than 45 countries represented and a 99.6 per cent transaction success rate. Bally's Corporation is named with a quote from Christine Scicluna, International Legal Director of Regulatory and Governance, alongside 17,700 slot machines and 20 casinos across the US and UK. Both link to full case studies. The limitation is precise: those numbers size the customer's business, not what using Vixio changed, and the testimony itself is qualitative. The only outcome figure located anywhere is a marketing claim that research time is cut by 90 per cent, which carries no source or method. Neither case study was opened on 1 September 2026, and no date was located on either.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

CUBE
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Confidentiality is asserted in general terms and every question this axis asks is unanswered. The strongest statement located is on the Technology and AI page, where CUBE says that given the sensitivity of client data it has implemented security at three levels, backend access to its services, frontend access, and the data pipeline, and that all user data in the cloud is fully anonymised. That is a real architectural claim and it is not a confidentiality commitment a buyer could hold. No position on training customer content was located, which matters because RegBrain is expressly sold as applying CUBE's AI stack to a customer's own content. No retention or deletion commitment for that content exists, no segregation between customers or users is described, and no data processing agreement is published. The privacy policy, recovered through the R8 ladder, covers the website, the RegTrend app, events and recruitment, so it does not reach the platform relationship. **There is no customer agreement of any kind on the property**, so nothing published could be read as a commitment in advance.

Vixio
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Almost nothing addresses what happens to customer content, and the one structural fact that is published explains why. Clause 14 of the terms records that for data protection purposes **Vixio is the controller of personal data provided to it**, not a processor acting on customer instructions, and sets out its reasons including that it determines what data is required, how it is used and how long it is retained. That is an unusual position for a platform sold to compliance functions and it is the reason no data processing agreement exists anywhere on the property. Beyond it: no training position on VIQ queries, no retention or deletion commitment for customer content, no segregation description, and no security page. The single located term is narrow and sits in clause 6.3, covering only information submitted to the self-assessment tool, which Vixio may use in perpetuity **on an anonymous basis** to improve its business and services. The privacy policy was not opened on 1 September 2026 and is the remaining surface where a confidentiality position could sit.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

CUBE
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Nothing published addresses the advice line for a product that produces regulatory interpretation. There is no terms of service, terms of use, master agreement or customer agreement anywhere on the property: the footer's Company section lists a privacy policy, a cookie policy and a separate RegTrend privacy policy, and nothing else. No statement was located that the output is not legal advice, that CUBE is not a law firm, that no professional relationship is created, or that a user should take professional advice on their own facts. No jurisdiction limit is named, and nothing addresses the supervision or competence of the person relying on the output. This matters because of who CUBE says the product is for: the home page names Risk and Legal Teams as an audience and states that CUBE gives legal teams the clarity they need to interpret the data and assess impact, which is interpretive work delivered to a professional audience with no published advice-line position behind it. Searched the home page, the Technology and AI page, the solutions and sectors navigation, the privacy policy in full and the complete footer on 1 September 2026.

Vixio
AA on UPL and Professional Responsibility PostureThe vendor states plainly what the product is and is not, who may use it, and how it supports a lawyer’s competence and supervision duties. Jurisdiction limits are named and any consumer facing surface carries a clear disclosure.

**The most complete professional responsibility posture located in this pull**, and it is stated in three places that reinforce each other. In the agreement, clause 11 provides that commentary and materials are not intended to amount to advice on which reliance should be placed, and specifically that they are not to be relied on as a definitive or complete statement of the law nor to constitute legal or expert advice or recommendations; clause 6.2 repeats it for self-assessment reports, which are for information only and not to be relied on as legal, financial or other advice. In the product, VIQ carries a standing notice that it uses AI across Vixio's proprietary data only and that critical information should always be verified against official sources, and citation-to-source traceability is what makes that instruction executable rather than decorative. And on the question this axis exists for, the published FAQ asks directly whether VIQ replaces a legal team or compliance officers and answers no, stating that it is built for augmentation rather than replacement and handles research, summaries and drafting so that human experts can focus on high-stakes judgment. **Jurisdiction limits are named**: clause 10.2 warrants nothing about whether the materials are permitted under the laws of any jurisdiction outside the UK and puts that check on the user. The one caveat worth recording is that the terms were last updated in October 2023 and therefore predate VIQ, so the AI-specific statements rest on the product page and FAQ rather than the contract.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

CUBE
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

Six principles are published and nothing behind them is auditable. Under the heading of how it approaches the use of artificial intelligence, CUBE sets out explainability, human input, semantic understanding, built for scale, security and sustainable AI, and the content is more specific than the usual adjective list, describing interpretability tooling, feedback loops, models tuned exclusively on regulatory and legal data, three levels of security and a deliberate choice of smaller curated training datasets to reduce carbon footprint. What is absent is everything that would let a buyer test it. Nobody inside CUBE is named as accountable for model behaviour, no pre-release testing regime is described, no external standard is claimed, with no ISO 42001, no EU AI Act commitment and no third-party assurance located, and **nothing at all is published about uneven output**, which is a notable silence for a system whose core function is deciding which obligations are relevant to which firm, where a systematic miss is the failure that matters. The explainability tooling and feedback loops are real mechanisms but they are product features and are credited on the oversight row rather than counted twice here.

Vixio
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

Nothing published addresses governance of Vixio's own AI, and the contrast with what the company publishes about the subject is sharp. Vixio has produced its own research on it, publishing The State of AI Trust in Regulatory Compliance 2026 and a press release reporting that 65 per cent of compliance leaders distrust generic AI for regulatory decisions, and it markets VIQ as designed to satisfy strict internal AI governance committees. All of that is about the market's governance expectations and how VIQ meets a buyer's, not about Vixio's own framework. No responsible-AI page, AI policy, ethics statement, governance committee, named accountable owner, pre-release testing regime or bias evaluation was located. The site navigation and the full footer were read on 1 September 2026 across platform, industries, resources, about and legal sections and contain no such surface, the legal set comprising terms, privacy, cookies, a disclaimer, anti-slavery and accessibility. The design commitments that do exist, closed-box grounding, analyst validation and citation traceability, are product properties and are credited on the accuracy and oversight rows rather than counted twice here.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

CUBE
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

A website privacy policy covers the marketing relationship without addressing what happens to customer content after processing. What is published, from the policy recovered through the ladder and dated 6 June 2026 at version 1.2: access to personal data restricted to staff, agents and contractors with a business need, all bound by confidentiality and acting only on instruction; procedures for suspected personal data breaches with a commitment to inform both the individual and the relevant supervisory authorities where legally required; retention only as long as reasonably necessary, with deletion or anonymisation afterwards; and transfers outside the UK and EEA under safeguards recognised by the relevant jurisdiction. Against that, no retention period is stated anywhere, no subprocessor list exists with third parties identified only as categories such as service providers and business partners, and the policy's own scope is the website, the RegTrend app, events and recruitment rather than the platform. Nothing published states what happens to the obligations mappings, impact assessments or customer content a firm places in RegPlatform, or to the content a customer submits to RegBrain.

Vixio
DD on AI Safety and Data StewardshipNothing published on retention, deletion or access for a system that holds client documents.

Nothing is published on any limb this axis asks about, and one published fact explains the shape of the absence. **There is no security page anywhere in the navigation or footer**, which were read in full on 1 September 2026. No retention period, deletion route, subprocessor list, incident or breach notification commitment, or encryption statement was located for customer content. No data processing agreement exists, and clause 14 of the terms explains why: Vixio positions itself as the **controller** of personal data provided to it rather than as a processor, on the stated basis that it determines what data is required, how it is used within the platform, whether third parties process it and how long it is retained. A buyer therefore has no processor commitments to read, by design rather than by oversight. The privacy policy was not opened and is the one remaining surface that could carry retention or sharing detail, so this grade rests on the absence of a security or trust surface rather than on an exhaustive reading of every legal page.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

CUBE
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

Nothing published addresses who bears the loss when the system is wrong, because no agreement of any kind exists on the property. The complete footer offers a privacy policy, a cookie policy and a separate RegTrend privacy policy; there is no terms of service, no terms of use, no master subscription agreement, no service agreement and no data processing agreement. That is a more complete absence than the website-terms-only pattern seen elsewhere in this corpus, where at least a scoped disclaimer exists. No indemnity, liability cap, carve-out, warranty on output or insurance position was located, and no disclaimer of accuracy or completeness attaches to the regulatory intelligence itself. The only risk allocation located anywhere is a single line in the privacy policy stating that transmission of information over the internet is at the user's own risk, which concerns data in transit rather than the correctness of an obligation mapping. Searched the full footer, the home page, the Technology and AI page and the solutions navigation on 1 September 2026.

Vixio
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

The allocation of loss is published and readable in advance, entirely through a standard limitation clause, and the agreement carrying it predates the AI product it now governs. The cap at clause 10.10 limits liability to the price paid for the particular services in the twelve months before the claim. Clause 10.4 is broader than most, excluding **direct** as well as indirect, special and consequential losses, along with lost profits, savings, business, opportunity, goodwill, data, contract, use and management time. Clause 10.3 preserves the mandatory carve-outs for death or personal injury caused by negligence, fraud and anything not lawfully excludable. Materials are supplied as-is with all other warranties excluded at clauses 10.1 and 10.9. One real protection runs the customer's way: clause 12.3 obliges Vixio, at its own expense, to defend third-party intellectual property infringement claims arising from the website or materials and to pay resulting judgments or settlements, subject to standard conduct conditions. There is no insurance position, no warranty on output, and nothing addressing an AI answer being wrong. **The terms were last updated 12 October 2023**, so the agreement governing VIQ was written before VIQ existed.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

CUBE
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

An integration route is stated and no destination system is ever named. RegBrain is described as delivering CUBE's full AI stack, including agentic AI, summarisation, classification and enrichment, either as APIs or through a user interface, so that customers can apply it to their own content, which establishes that a programmatic route exists and says what travels through it. A Partnering with CUBE page and a Content Infrastructure solution both imply that the regulatory content is designed to feed systems elsewhere. What is absent is anything an implementer could act on: no API reference or developer documentation was located, no integration directory exists in the site navigation, and not one GRC, risk, policy or document platform is named anywhere on the surfaces read, which is the same gap seen at Corlytics and a weaker position than AscentAI, which names five GRC partners on its home page. Checked the home page, the Technology and AI page, the solutions navigation and the footer on 1 September 2026.

Vixio
DD on Practice Systems Integration DepthNo integration into practice systems located, or the product stands alone and requires work to move to it.

Nothing published addresses connecting Vixio to anything else. The site navigation and full footer were read on 1 September 2026 and contain no integrations page, no API reference, no developer documentation and no connector directory, and no third-party system of any kind is named as an integration target. Every workflow tool listed is internal to the platform: task management, project tracking, reporting, the obligations library and the document store all operate inside Vixio rather than pushing obligations or tasks into a customer's GRC, policy or document management estate. The nearest thing to an outbound flow is the ability to generate reports and share them by URL, which is document distribution rather than integration. The architecture points the other way as well, with the two services delivered through separate login domains for gambling and payments rather than a single environment. For a product whose output is meant to end in changed controls and updated policies inside other systems, this is a substantive gap rather than a missing marketing page.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

CUBE
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Cloud delivery is stated and neither the tenancy model nor a region is. The Technology and AI page says the models are deployed via cloud and scale with demand, and adds that all user data in the cloud is fully anonymised, but nothing names a hosting provider, a data centre location, a country or region option, or whether customers share infrastructure or receive a dedicated environment. No processing location is addressed separately from storage. The only geography published sits in the privacy policy and concerns personal data rather than platform content, stating that data may be transferred to group companies and service providers outside the United Kingdom and the European Economic Area or other local jurisdictions, with appropriate safeguards recognised by the relevant jurisdiction, and naming no specific mechanism. For a vendor selling to Tier 1 banks across a stated 750-plus jurisdictions, where data residency is routinely a procurement gate, that is a conspicuous silence. Checked the home page, the Technology and AI page, the privacy policy and the full navigation on 1 September 2026.

Vixio
DD on Deployment Model and Data ResidencyNothing published on where the software runs or where client data sits.

Nothing published addresses deployment or residency. No hosting provider, data centre location, region option, tenancy model or processing location was located on any surface read on 1 September 2026, and there is no security page in which such detail would ordinarily sit. What can be established is limited to the delivery shape and the corporate footing: the services are browser-delivered through two hosted environments at gc.vixio.com and pc.vixio.com, a status page is published at status.vixio.com, and the contracting entity is Compliance Online Limited, registered in England and Wales with company number 05706431 at St Clare House, 30 Minories, London, with the terms governed by English law and subject to the exclusive jurisdiction of the English courts. That tells a buyer which legal system applies and nothing about where its data sits or who runs the infrastructure. The privacy policy was not opened and is the remaining surface that might address international transfers.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

CUBE
DD on Security Certifications and Trust CenterNo independent security attestation located.

No independent security attestation was located anywhere. There is no security page, no trust centre and no compliance page in the site navigation, which was read in full on 1 September 2026 across the solutions, sectors, resources and company sections. No ISO 27001, SOC 2, ISO 42001 or equivalent is claimed on the home page, the Technology and AI page, the privacy policy or the footer, and no badge, certificate, auditor or report request route appears. The Technology and AI page does carry a Security principle, and it is the natural place a standard would be named: it describes security implemented at three levels covering backend access, frontend access and the data pipeline, and states that all user data in the cloud is fully anonymised, but it names no framework and no assessor. The privacy policy adds appropriate technical measures and breach procedures in general terms. **This is a striking absence rather than a routine one**, given a vendor of this scale selling to the largest regulated institutions, and it is recorded as what the public surfaces show rather than as a claim about what CUBE holds.

Vixio
DD on Security Certifications and Trust CenterNo independent security attestation located.

No independent security attestation is claimed anywhere. No SOC 2, ISO 27001, ISO 27701 or equivalent appears on the home page, the VIQ product page, the terms or the footer, and there is no security page, trust centre or compliance page in the navigation, all of which were read in full on 1 September 2026. No auditor, certification body, penetration test, scope statement or report request route was located, and no badge or certification mark appears anywhere on the property. The only assurance-adjacent artifacts published are a service status page and the two industry awards displayed in the footer, neither of which is a security attestation. This is a notable absence rather than a routine one for a subscription platform sold to banks, payment institutions, licensed gambling operators and regulators, all of which run third-party assurance processes as a matter of course, and it is recorded as what the public surfaces show rather than as a claim about what Vixio holds internally.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

CUBE
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

The architecture is disclosed in more detail than anywhere else in this lane and the third-party question is left open. CUBE names its own components: RegAI as the framework, **RegLM as a proprietary language model** fine-tuned for translation, classification and contextualisation, and RegBrain as the stack exposed to customers. It describes what each layer does, computer vision for document structure recovery, deep NLP for extraction and classification, graph machine learning over a knowledge graph, and states that the models are tuned exclusively on regulatory and legal data and deployed via cloud. That is architecture described with the vendor's own models named, which is the second limb of this band. What is not answered is whether any third-party foundation model is called at any point: no external provider is named, no statement excludes one either, and RegBrain is said to include agentic AI, which usually implies a general-purpose model somewhere in the chain. No commitment to notify customers when the model set changes was located.

Vixio
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The data boundary is described with unusual precision and the model behind it is never identified. What Vixio publishes is a retrieval architecture rather than a model stack: a regulatory intelligence graph of more than 90,000 verified content items connected by intent rather than keyword, drawing on more than 6,200 curated sources, with VIQ described as operating in a closed-box environment across Vixio's proprietary data only and explicitly never the open web. That answers where the knowledge comes from, which is the question a compliance buyer asks first, and leaves the vendor risk question open. No model, model family, provider or hosting arrangement is named anywhere, nothing states whether a third-party foundation model performs the generation, and nothing excludes one. No commitment to notify customers when the model set changes was located. A customer quote on the same page underlines what the disclosure is doing, praising VIQ for never touching the open web, which is a statement about the corpus rather than about whose model reads it.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

CUBE
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing information is published at any level, including the unit of charge. The site navigation was read in full on 1 September 2026 and contains no pricing entry; every commercial route on every page read is a demo request or a Speak to an expert form. No rate, band, floor, currency or per-seat, per-jurisdiction or per-obligation unit was located, and nothing states what implementation adds, which is material for a platform whose value depends on building a firm-specific obligations map. The only commercial shape visible anywhere is the split of CUBE RegPlatform into two editions aimed at different customer sizes, one for Tier 1 institutions and an Intel edition for the mid-market, which segments the market without pricing it. Those two edition pages were not opened, so if either carries a feature split or a figure this grade is rebuttable upward.

Vixio
CC on Commercial TransparencyPricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not.

No rate is published and more of the commercial shape is readable than at most vendors in this lane, all of it from the terms rather than from a pricing page, which does not exist. The unit of charge is stated: a subscriber licence is either for a fixed number of users or for an unlimited number of users, with login details issued per user and Vixio reserving audit rights over whether passwords have been shared. Payment structure for bespoke work is published in full, with 50 per cent of the price due up front as a deposit and the balance on delivery, and additional fees agreed in advance where research goes beyond the agreed scope. Renewal is customer-favourable and specified: a renewal reminder issues one month before expiry setting out the price, and renewal requires positive written confirmation rather than defaulting on, with the caveat that unlimited-user licences are likely to reprice upward after a merger or acquisition. Late payment carries interest at 5 per cent above the Bank of England base rate. Clause 8.1 implies some prices are set out on the website for one-off reports, and no figure was located on any page read on 1 September 2026.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

CUBE
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Coverage is described with real substance across three separate axes and the boundary is left open. CUBE segments its sectors pages by industry, by requirement and by department, which is a more deliberate structure than most vendors publish, and names its industries as banking, insurance, asset and investment management, payments and associated industries. Firm size is addressed explicitly rather than implied, with RegPlatform split into an enterprise edition for Tier 1 institutions and an Intel edition for the mid-market, and audience is broken out into compliance leaders, financial services enterprises, and risk and legal teams. Regulatory scope is quantified at more than 750 jurisdictions and illustrated with named regimes including GDPR, DORA, MiFID II, SOX, FCA and FSB material. What is not stated is where the product stops: no statement of the practice areas, sectors or obligation types the platform does not cover was located, and outside financial services the coverage claim is left to the phrase associated industries.

Vixio
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

The buyer picture is the most precisely segmented in this lane and the coverage figures contradict each other. Two industries are addressed, each with a hub and five named buyer segments: in financial services, payment services, retail banking, digital assets, regulators and **law firms**; in gambling, online operators, suppliers, payment service providers, regulators and **law firms**. Addressing regulators and law firms as distinct buyers alongside the regulated firms themselves is unusual and is backed by separate pages rather than a mention. The boundary is stated rather than left open, with the platform described as purpose-built for financial services and gambling, which most vendors in this corpus decline to do. Regulatory scope is illustrated with named regimes including AML, GDPR, MiFID II, MiCA, PSD2, FATF, UKGC, MGA and AGCO. **What keeps this below the top band is precision**: the home page states more than 200 jurisdictions and more than 1,400 regulatory authorities, while the VIQ page states over 1,600 regulators across more than 246 jurisdictions, and nothing reconciles the two or indicates which jurisdictions receive analyst depth rather than monitoring alone.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

CUBE
Terms silent

No located term or policy addresses the question either way, and there is no agreement on the property in which a commitment could sit. The silence is pointed rather than routine because RegBrain is expressly sold as applying CUBE's AI stack to a customer's own content through APIs, so customer material demonstrably enters the system. The two nearest statements do not answer it: the Technology and AI page says the models are tuned exclusively on regulatory and legal data, which describes the training corpus without excluding customer content from future training, and separately says that all user data in the cloud is fully anonymised, which is a handling claim rather than a training prohibition. The privacy policy covers the website, the RegTrend app, events and recruitment and does not reach platform content. Searched the home page, the Technology and AI page, the full privacy policy and the complete footer on 1 September 2026.

Vixio
Terms silent

No located term addresses whether queries put to VIQ, or any other customer content, are used to train or improve models. The terms were last updated 12 October 2023 and predate the assistant, which is the likeliest explanation for the silence. One adjacent term exists and is narrower than it first appears: clause 6.3 gives Vixio the right in perpetuity to use information a customer submits to the self-assessment tool, **on an anonymous basis**, for its reasonable business purposes including creating its own analysis and improving its business and services. That is scoped to a single tool, is expressly anonymised, and says nothing about model training. No data processing agreement exists in which a training commitment could otherwise sit, and clause 14 records that Vixio acts as controller rather than processor. Searched the home page, the VIQ product page, the terms in full and the footer legal set on 1 September 2026.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

CUBE
Not addressed

No located public material states how long customer inputs or generated outputs are kept, and no configurable or zero-retention option is described. The only retention statement published is in the website privacy policy and is qualitative rather than periodic: personal data is kept only as long as reasonably necessary for the purposes it was collected for, including legal, regulatory, tax, accounting and reporting requirements, with longer retention where a complaint or prospective litigation exists, and deletion or anonymisation once it is no longer needed. That is scoped to personal data and to the website and app relationship. Nothing addresses the obligations mappings, impact assessments or submitted content that make up the platform record. Searched the privacy policy in full, the Technology and AI page and the footer on 1 September 2026.

Vixio
Not addressed

No located public material states how long customer inputs or generated outputs are retained, and no configurable or zero-retention option is described. Nothing distinguishes VIQ queries, generated board reports or self-assessment submissions from customer data generally. The one statement bearing on retention is a governance claim rather than a period: clause 14 of the terms records that Vixio determines how long personal data is retained, in the course of explaining why it is a controller rather than a processor, which tells a buyer who decides without telling them what was decided. The privacy policy was not opened on 1 September 2026 and is the remaining surface where a period might appear. Searched the terms in full, the VIQ page, the home page and the footer legal set.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

CUBE
Not addressed

Nothing located addresses segregation between customers, teams or users. The nearest statement is architectural rather than about permissions: the Technology and AI page describes security implemented at three levels, backend access to services, frontend access to services and the data pipeline, and states that all user data in the cloud is fully anonymised. That describes where controls sit and how data is handled in aggregate, not who can see what inside a customer account. The privacy policy limits access to CUBE staff, agents and contractors with a business need, which governs the vendor's own people rather than the customer's. Nothing states whether RegAI classification or the knowledge graph respect any customer-side boundary at query time, which is a live question because the graph is described as drawing on user data to recommend content. Searched the Technology and AI page, the privacy policy and the solutions navigation on 1 September 2026.

Vixio
Not addressed

Nothing located addresses segregation between customers, teams or matters. The access model is described only at the level of licensing and credentials: a subscriber licence covers either a fixed or an unlimited number of users, each user receives individual login details, the customer must ensure no unauthorised person uses them, and Vixio reserves the right to audit whether passwords have been shared with non-users. Those are licence-compliance controls rather than a described permission model, and they govern who may log in rather than what any user can see once inside. Nothing states whether one customer's self-assessment submissions, saved queries or generated reports are isolated from another's, and there is no security page in which such a statement would sit. Searched the terms in full, the VIQ page and the full navigation on 1 September 2026.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

CUBE
Not addressed

Disclosure to authorities is described and notice is not addressed at all. The privacy policy provides that CUBE may occasionally pass parts of personal data to authorities where obliged to disclose in order to comply with a legal obligation, to enforce its terms and other agreements, or to protect the rights, property or safety of its customers or others, including sharing with other companies and organisations for fraud protection, and states that it discloses only what is legally necessary. No commitment to notify the customer before or after such a disclosure appears, and no discretion over notice is even reserved, which distinguishes this from the comparable clause at Corlytics where the vendor at least commits to take legal advice and weigh the individual's interests first. No transparency report exists, and the clause is scoped to personal data rather than to platform content. Searched the privacy policy in full and the footer on 1 September 2026.

Vixio
Not addressed

No commitment to notify a customer of a third-party request for its data was located, and no clause addresses law enforcement, regulator or court demands at all. The terms contain no confidentiality section in the usual two-way sense: confidentiality obligations run from the customer to Vixio over passwords and access codes, and the intellectual property provisions protect Vixio's materials, but nothing protects customer-submitted information or governs its disclosure. That absence is consistent with the controller position at clause 14, since a vendor that does not hold itself out as processing on customer instructions has no processor notice obligation to give. No transparency report exists. The privacy policy was not opened on 1 September 2026 and is the remaining surface. Searched the terms in full and the footer legal set.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

CUBE
Jurisdictions only

Coverage is quantified by jurisdiction and the underlying corpus is never identified. CUBE states surveillance across more than 750 jurisdictions and illustrates scope with named regimes including GDPR, DORA, MiFID II, SOX, and material from the FCA and FSB, describing its input as unstructured regulatory data transformed into actionable intelligence. No regulator feed, publisher, data supplier or licensing arrangement is named anywhere on the surfaces read, and no update cadence is published beyond the claim of real-time and 24/7 surveillance. Content Infrastructure is sold as a distinct solution, so the corpus is a commercial asset in its own right, which makes its provenance a more material question here than for a vendor that only consumes public sources. Checked the home page, the Technology and AI page and the solutions navigation on 1 September 2026.

Vixio
Jurisdictions only

The corpus is quantified in unusual detail and no individual source is named. Vixio publishes counts at every level: more than 6,200 curated sources, over 20,000 regulatory documents, a graph of more than 90,000 verified content items, roughly 8,000 daily sources scanned, and coverage stated as more than 200 jurisdictions and 1,400 regulatory authorities on the home page against over 1,600 regulators and more than 246 jurisdictions on the VIQ page, a discrepancy nothing reconciles. Named regimes appear as illustration, including AML, GDPR, MiFID II, MiCA, PSD2, FATF, UKGC, MGA and AGCO. What is absent is identification and rights: no regulator feed, publisher or data supplier is named, and no licence or public-domain basis is stated for any of it. Update cadence is described qualitatively, with the graph continuously updated by the analyst team as new legislation lands, and part of the corpus is Vixio's own analyst commentary rather than primary material.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

CUBE
Own treatment signal

The regulatory analogue is the product's core function, and it is described less concretely than at the two lane peers. CUBE monitors regulatory change across a stated 750-plus jurisdictions on a continuous basis and maps what has changed to the obligations a firm holds, so the platform is computing and surfacing the subsequent state of a rule over its own corpus rather than licensing a treatment service. Impact analysis and mapping are named as automated capabilities. Two limits belong on the record. **No version comparison or redlining feature was located**, unlike AscentAI and Corlytics which both publish side-by-side old-versus-new rule views, so a user's ability to see exactly what changed is not evidenced. And the currency of the corpus is asserted through the words real-time and 24/7 rather than through any stated lag between a regulator publishing and the platform reflecting it.

Vixio
Own treatment signal

The regulatory analogue is a shipped capability and the method behind it is described more concretely than at any peer in this lane, because the method is people. Vixio maintains an obligations library, a regulatory document store and continuous monitoring, and states that as new legislation lands the VIQ data graph is continuously updated by its analyst team, with human analysts validating and enriching high-value updates before publication. That is the vendor computing and maintaining the current state of its own corpus rather than licensing a treatment service, and every claim VIQ makes traces back to the source text or the analyst report behind it, so a user can check what the current position rests on. Two limits belong on the record: no version comparison or redline view between a superseded and a current rule was located, and no stated lag exists between a regulator publishing and the change reaching the platform.

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

CUBE
Not addressed

Nothing located describes what the system does when it cannot classify or map reliably, which is the question the category editorial makes decisive. No abstention path, confidence score, relevance threshold or coverage indicator is published for classification, obligation identification or summarisation. CUBE names the two failure modes in passing, saying RegAI reduces false positives and missed obligations, without describing what a user sees when either is possible. The explainability tooling comes closest and answers a different question: interpretability tools showing how an AI decision was made give transparency about a decision the system did reach, not a signal that it could not reach one. Searched the home page, the Technology and AI page including the six AI principles, and the solutions navigation on 1 September 2026.

Vixio
Documented

**The only documented refusal behaviour located in this lane.** The published FAQ, answering how VIQ differs from general-purpose assistants, states that it operates in a closed-box environment over Vixio's analyst-verified data, cites every claim, and explicitly says it does not know rather than making up an answer. That is a described behaviour at the boundary of the corpus rather than a confidence score or a disclaimer, and it is the behaviour the category editorial treats as decisive, since the failure that matters is a confident answer about a jurisdiction the vendor does not actually cover. Two things keep this at documented rather than higher: no demonstration, evaluation or example of the refusal is published that an outsider could test, and no threshold or coverage indicator is described, so a user cannot tell in advance which jurisdictions or questions sit inside the boundary.

Fabricated Citation Record

Does a public court record exist involving output from this product?

CUBE
None located

Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on the product names RegPlatform and RegAI. No court order, opinion or disciplinary record naming CUBE or its products was located. This is a statement about the public record rather than a finding about the product. The failure mode fits obliquely: the output is a regulatory classification or obligation mapping consumed inside a compliance function rather than a citation filed with a court, so the analogous exposure would be a missed or misattributed obligation surfacing during a supervisory examination rather than in a filing.

Vixio
None located

Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on both service names, GamblingCompliance and PaymentsCompliance. No court order, opinion or disciplinary record naming Vixio or either service was located. This is a statement about the public record rather than a finding about the product. The failure mode is more directly analogous here than at most vendors in this lane, because Vixio sells to law firms in both industries and markets defensible advice as the outcome, so a fabricated or misattributed regulatory citation could in principle reach a client advice note or a licensing submission rather than only an internal compliance file.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

CUBE
Not addressed

No engagement with professional responsibility or ethics guidance was located, and no document exists on the property in which it could sit. There is no terms of service, no professional responsibility statement and no ethics page; the footer offers only a privacy policy, a cookie policy and a separate RegTrend privacy policy. Nothing references ABA Formal Opinion 512, Law Society or SRA guidance, or any regulator statement on the use of AI within a compliance or legal function. Nor is there a general acknowledgement that the user's own professional obligations survive use of the tool, which several vendors in this pull do publish. This sits against a home page that names Risk and Legal Teams as a target audience. Searched the home page, the Technology and AI page, the sectors navigation, the privacy policy in full and the complete footer on 1 September 2026.

Vixio
Generic reference

Professional responsibility is engaged directly and repeatedly, and no guidance is ever named. The terms state that materials are not intended to amount to advice on which reliance should be placed, are not a definitive or complete statement of the law, and do not constitute legal or expert advice or recommendations, and clause 6.2 repeats the point for self-assessment reports. The VIQ FAQ states that the assistant is built for augmentation rather than replacement of a legal team or compliance officers. That is a fuller engagement with the professional line than most vendors publish, and it is entirely self-referential: nothing cites ABA Formal Opinion 512, Solicitors Regulation Authority or Law Society guidance, or any regulator or bar statement on the use of AI in legal or compliance work. The absence carries more weight here than at the in-house-only vendors in this lane, because Vixio publishes dedicated law firm pages for both industries.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

CUBE
Savings claims only

Efficiency claims are central to the marketing and billing is never addressed. The home page is built on reducing risk and increasing efficiency, and the Technology and AI page states that RegAI saves valuable time and effort otherwise spent sifting through information, reduces the cognitive load on the compliance team and eliminates reliance on manual tasks. Nothing accompanies that on how AI-assisted regulatory analysis should be billed or disclosed. The buyer here is an in-house compliance or legal function rather than a firm billing a client, so the question lands obliquely, but it is not absent: nothing addresses the position where an adviser uses the platform on a client's behalf, and no per-matter or per-assessment record of AI-assisted work is described that would support such a disclosure.

Vixio
Savings claims only

Time-saving claims are quantified and nothing addresses billing or disclosure, which matters more here than elsewhere in this lane. Vixio markets a 90 per cent reduction in research time and cites a figure that the average compliance professional loses 70 per cent of their time to reactive paperwork and manual website trawling. **This is the only vendor in the lane with law firms as a named buyer segment**, addressed on dedicated pages in both the financial services and gambling verticals and sold on delivering defensible advice and fast answers for clients, so the question this signal was written for applies squarely rather than obliquely: a firm using VIQ to research a client matter faces a live question about how that assistance is disclosed and billed. Nothing published addresses it, and no per-matter record of AI-assisted work is described for that purpose, although VIQ's citation traceability would support one.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

CUBE
Not addressed

Nothing that would support a client-side disclosure obligation is published, and the reason is a distinction worth recording. CUBE names its own models with unusual specificity, RegAI, RegLM and RegBrain, and states they are tuned exclusively on regulatory and legal data. **Naming your own model is not the same as answering whether anyone else's model sees the content**, and that question is left open: no third-party provider is named, no statement excludes one, and RegBrain is said to include agentic AI. No subprocessor list exists, with third parties identified in the privacy policy only as categories such as service providers and business partners. No data processing agreement, consent pack or client-facing disclosure material is published and no route to request one was located. Under the coverage test this fails, since a firm cannot state which systems touch its content. Searched the Technology and AI page, the privacy policy in full and the complete footer on 1 September 2026.

Vixio
Not addressed

Nothing that would support a client-side disclosure obligation is published. No subprocessor list exists anywhere, and no third party of any kind is identified beyond a general acknowledgement in clause 10.7 that Vixio relies on third-party providers to make the website and materials available, and a reference to third-party payment handlers. **No model provider is named** and nothing states whether a third-party foundation model generates VIQ's answers, so under the coverage test neither the infrastructure nor the model side is answered. No data processing agreement, consent pack or client-facing disclosure material exists, which follows from the controller position at clause 14 rather than being an oversight, and no route to request any of it was located. **Tenth data point on this signal and the weakest**, since the vendor most likely to face a client AI clause in this lane, the one selling to law firms, publishes the least material to answer it with.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

CUBE
Partial record

Some elements exist and no document-level export is described. Two things point the right way. The platform is marketed on the ability to centralise, streamline and audit-proof an entire regulatory framework at scale, so an activity record for examination purposes is claimed. And the explainability tooling is directly relevant to this signal in a way it is not for most vendors, since interpretability tools showing how an AI decision was made are part of what an AI-use disclosure would need to contain. What is missing is the export and the attribution: nothing states that the record identifies which outputs were machine-generated, which model produced them, what corpus was drawn on, or who reviewed them, and no per-document extract is described. As with the other vendors in this lane the artifact is built for a supervisor rather than a court. Checked the home page, the Technology and AI page and the solutions navigation on 1 September 2026.

Vixio
Partial record

The strongest traceability in this lane, aimed at a regulator, and still short of an AI-use record. Vixio builds an audit trail as a product stage in its own right: the track and audit phase maintains a centralised, time-stamped record of actions taken to give internal audit a clear trail of compliance and accountability, supported by reporting and the obligations library. VIQ adds provenance to that, with every claim carrying a direct citation back to the original source text or the analyst report behind it, which the company describes as full explainability to regulators, and outputs are exportable as board reports and shareable by URL. What is missing is the machine-attribution layer: nothing states that the record distinguishes VIQ-generated material from analyst-written material, identifies which model produced an output, or captures who verified it, so a user could evidence what a claim rests on without being able to evidence how it was produced.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • Security Certifications and Trust Center
Signals neither addresses in public material
  • Prompt and Output Retention
  • Ethical Walls and Matter Segregation
  • Third Party Request and Subpoena Notice
  • Outside Counsel Guideline Readiness

Which one fits

Choose CUBE if

  • You want the machinery described rather than asserted. CUBE publishes its architecture layer by layer: computer vision converting document images into machine readable content and recovering structure from headers to footers, a proprietary language model it calls RegLM fine tuned for entity extraction, citation extraction, document type classification, obligation identification and summarisation, and graph machine learning placing the enriched content into a regulatory knowledge graph, with interpretability tools stated to show users how AI decisions are made.
  • Your obligations should be yours rather than a rules library. CUBE turns unstructured regulatory text into obligations mapped by sector and jurisdiction to a particular firm, across a stated 750 plus jurisdictions, and describes its filtering in terms of the two errors that matter, removing irrelevant updates and false positives while reducing missed obligations.
  • You want the stack pointed at your own content. RegBrain exposes CUBE's AI including agentic capability, summarisation, classification and enrichment through APIs or a user interface so a customer can apply it to its own material, with the underlying regulatory content sold separately as Content Infrastructure, and the platform offered in an enterprise edition for the largest institutions and an Intel edition for the mid market.

Choose Vixio if

  • You want a person to have read it before you do. Vixio's corpus is written and validated by its own domain specialists, with analysts enriching high value updates before publication across more than 6,200 curated sources, and VIQ operating in a closed box over that verified material rather than the open web, tracing every claim back to the original source text or the analyst report behind it and stating that it does not know rather than answering when it cannot.
  • You want the vendor to say what it is not. Vixio's terms state that its commentary and materials are not to be relied on as a definitive or complete statement of the law and do not constitute legal or expert advice, its self assessment reports are stated to be for information only, the product carries a standing instruction to verify critical information against official sources, and its published FAQ asks whether the assistant replaces a legal team or compliance officers and answers no.
  • Your firm is a regulator or a law firm rather than the regulated entity. Vixio addresses five buyer segments in each of its two industries, and in both cases regulators and law firms are named as distinct buyers alongside the operators, with the boundary stated plainly, since the platform is described as purpose built for financial services and gambling rather than for regulated industry generally.

In summary

CUBE

CUBE is an automated regulatory intelligence platform for financial institutions built to turn unstructured regulatory text into obligations mapped to a particular firm, monitoring change across a stated 750 plus jurisdictions and sold in an enterprise edition and a mid market edition, with its RegAI framework described in three layers covering computer vision, a proprietary language model called RegLM and graph machine learning over a regulatory knowledge graph. The AI Legal Index grades it in the top two bands on five of fifteen capability axes. Its architecture disclosure is the most detailed in this category. As of 1 September 2026 the index located no customer agreement, no security page, no certification and no published price.

Source: AI Legal Index, 2026

Vixio

Vixio is a regulatory intelligence business built around analyst written coverage of financial services and gambling, following a five stage change lifecycle from horizon monitoring through applicability, impact assessment, implementation and audit, with jurisdiction reports, an obligations library and a document store, and VIQ as an assistant grounded exclusively in its own analyst verified data that cites every claim and states that it does not know rather than answering. The AI Legal Index grades it in the top two bands on five of fifteen capability axes, with an A on professional responsibility posture. As of 1 September 2026 the index located no security page, no certification, no data processing agreement and no residency statement.

Source: AI Legal Index, 2026

Questions buyers ask

CUBE vs Vixio: which is better for regulatory intelligence?

The AI Legal Index places both in the top two bands on five of fifteen capability axes, so the grid ties them, and they disagree about something more basic than features. CUBE's regulatory corpus is machine made, with computer vision, a proprietary language model and graph machine learning building it. Vixio's is analyst made, written and validated by people before publication, with the AI retrieving over it. Everything else about the two records follows from that difference.

Who writes the regulatory intelligence?

That is the difference between them. CUBE describes a three layer pipeline that converts document images to structured content, classifies and extracts obligations with its own model, and places the result in a knowledge graph. Vixio employs domain specialist analysts who validate and enrich high value updates before publication, and its assistant answers only from that verified material, never the open web, with a citation back to the source or the analyst report for every claim. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What can you read before signing?

On Vixio, a full set of terms covering the advice line, a liability cap, an intellectual property indemnity running to the customer, the licensing unit and the renewal process, though they predate the AI product. On CUBE, nothing: no terms of service, master agreement or data processing agreement exists on the property, so the entire allocation of risk sits in a signed contract a prospect cannot see. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Does either say what it is not?

Vixio does, in three places that reinforce each other: the agreement, a standing product notice telling users to verify critical information against official sources, and an FAQ answering directly that the assistant is built for augmentation rather than replacement. On CUBE nothing of the kind was located, which matters because its home page names risk and legal teams as an audience and says it gives legal teams the clarity to interpret the data and assess impact. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What do CUBE and Vixio both leave unpublished?

Neither publishes a price, a rate or a unit a buyer could budget against. Neither publishes an accuracy figure for the obligation identification each depends on, where the failure that matters is an obligation that never surfaces. Neither publishes an AI governance position with an accountable owner or any evaluation of uneven output, which on CUBE means nothing addresses whether its filtering misses systematically in some jurisdictions, and on Vixio means nothing addresses which updates its analysts validate. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Disclosure

Neither vendor publishes a security attestation, and neither publishes a security page at all, on platforms sold to banks, payment institutions, licensed operators and regulators, all of which run third party assurance as a matter of course. CUBE publishes no customer agreement of any kind either: its footer carries a privacy policy, a cookie policy and a separate app privacy policy, so no liability position, indemnity, warranty or training commitment can be read in advance. Vixio's terms were last updated in October 2023 and therefore predate its AI assistant, so the AI statements sit on product pages rather than in the contract, and clause 14 records that Vixio is the controller of personal data provided to it rather than a processor, which is why no data processing agreement exists. Vixio's own pages also disagree on coverage, giving more than 200 jurisdictions and 1,400 authorities in one place and more than 246 and 1,600 in another. Both records were verified on 1 September 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 2, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746