Norm Ai vs Regology: how they compare in 2026

Norm Ai profileRegology profile
Last verifiedSeptember 2, 2026

Norm Ai and Regology both turn regulation into something a compliance team can act on, and they arrive from different directions: Norm Ai encodes rules as executable agents, Regology maintains a law library and layers agents over it. The grid is level at six of fifteen axes each. Norm Ai takes the higher grade on AI centrality, because regulations are compiled through its own domain specific language into human readable decision trees that an agent traverses to reach a determination, and it answers the advice line question structurally, having launched a separate law firm in 2026 while the software delivers analysis. Regology takes the higher grades on what a procurement review asks for, naming BARR Advisory as the auditor behind its SOC 2 Type II examination with the scope stated, and naming ServiceNow, Archer and Hyperproof as the systems it sits alongside rather than replaces. Neither publishes a customer agreement, so neither states a liability position, a training position or a retention period.

At a glance

Category
Norm AiRegulatory & Compliance Counsel
RegologyRegulatory & Compliance Counsel
Founded
Norm Ai2023
Regology2017
Headquarters
Norm AiNew York, New York, United States
RegologyPalo Alto, California, United States
Last verified
Norm AiAug 29, 2026
RegologyAug 29, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Norm Ai
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

The artificial intelligence is the product and the company is organised around building it. Regulations are converted into executable AI agents through a proprietary domain specific language, agents traverse decision trees to reach compliance determinations, and the entire platform, LEAP, exists to build, evaluate and deploy those agents. The vendor describes itself as the Regulatory AI agent company. Remove the models and nothing remains but a representation of regulations with no ability to apply them. Notable in structure as well as capability: the company created a job function, Legal Engineer, specifically to build AI agents, staffed by former attorneys given intensive language model training, which is an organisational commitment to the model layer rather than a feature investment.

Regology
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models are the engine of a core capability layered on an asset that has value without them. The Smart Law Library is a curated, continuously updated corpus of United States federal law, all fifty states and international jurisdictions, and a law library with search and change tracking is a usable product in its own right; the vendor sells the ability to import a customer's existing library into it, which underlines that the corpus is a distinct asset. What the models drive is substantial rather than peripheral, which is why this is not a C: three named AI agents covering Regulatory Change, Compliance and Research determine which laws apply to an organisation, assess the impact of incoming changes, and generate obligations, risks, controls and policies mapped to source law. Applicability analysis at that scale is not achievable by search alone. Distinguished from Norm Ai in the same category, graded A, where the agents execute encoded regulations and no separable data asset stands behind them.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Norm Ai
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is real, architecturally enforced and documented, short of published measurement. The mechanism is unusual and specific: regulations are encoded through a proprietary domain specific language into decision trees that a human can read and a machine can execute, and an agent traverses that tree step by step to reach a determination rather than generating an answer from model memory. The vendor states every determination carries an explanation, identifying what may be problematic and under which regulation, so a compliance team can see the legal basis for the outcome and what would need to change. Because the reasoning path is the encoded regulation itself, the output is traceable to a provision rather than to a retrieved passage, which is a different and arguably stronger form of grounding than citation. LEAP is stated to include automated evaluation pipelines, so evaluation is built into the deployment process. What is missing is the result: searched the platform pages, the resources section, the company blog and the trust centre on 29 Aug 2026 and located no accuracy figure, no error rate, no test set, no published evaluation methodology and no independent benchmark participation, notwithstanding that the founder co authored a widely used legal reasoning benchmark.

Regology
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is real, architecturally enforced and stated as a design goal, short of published measurement. The vendor's central claim on this axis is traceability rather than accuracy: every alert, assignment, decision, approval, rejection and policy update is timestamped and traceable to a source law, which the vendor frames as producing defensible documentation for auditors. So an obligation or control generated by the platform can be followed back to the specific provision it derives from, and the corpus it derives from is the vendor's own maintained library rather than an open web retrieval. That is grounding by construction. Searched the platform pages, the company blog, the published llms-txt file and the news announcements on 29 Aug 2026 and located no accuracy figure, no error rate for applicability determination, no test set, no published evaluation methodology and no independent benchmark participation. For a product whose core function is deciding which laws apply to a business, an applicability error rate is the figure a buyer would most want and it is not published.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Norm Ai
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

A real published commitment with a described division of labour, short of thresholds. The vendor states the operating model plainly: an agent conducts the initial compliance review of, for example, marketing communications against SEC or FINRA rules, and a human professional then reviews the findings and completes the determination. That allocates the decision rather than asserting human involvement. Supporting surfaces are described: explanations attached to every determination, and collaboration tooling through which teams tag each other, review AI judgments and centralise decision history. Oversight is also a staffing structure, with Legal Engineers building and supervising the agents and adjusting them to client specific guidelines. The vendor is separately building supervisory agents that monitor other AI systems for compliance, which is an oversight product rather than an oversight policy. Not located as of 29 Aug 2026: any threshold at which an agent defers, what it does when a determination is genuinely ambiguous, and what the vendor commits to when a determination is wrong.

Regology
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

A real published commitment with a documented decision record, short of thresholds. The oversight structure is visible in what the platform records: assignments, decisions, approvals and rejections are all captured and timestamped, which means a human accepts or rejects the agents' output and the acceptance is itself part of the record. Rejection being explicitly logged is notable, since it evidences that disagreeing with the system is an expected path rather than an exception. The agents are described as automating repetitive manual processes and anticipating changes, with compliance teams acting on the output. Not located as of 29 Aug 2026: any threshold at which an agent defers, what the system does when applicability is genuinely uncertain, what proportion of determinations are expected to be reviewed, and what the vendor commits to when an output is wrong.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Norm Ai
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Institutional signals stand in for deployment evidence. The vendor references a client meeting with a top ten global asset manager in published material describing a Legal Engineer's working day, and states a focus on Fortune 100 customers, but no customer is named. Investor composition is unusually informative for this market and is recorded as context rather than evidence: Vanguard, Blackstone, Citi and TIAA are strategic investors from the regulated industries the product serves, which indicates institutional validation without demonstrating a deployment. Searched the platform pages, the resources section, the company blog and the news announcements on 29 Aug 2026 and located no named customer paired with figures and a date, no case study with an assessable method, and no adoption count.

Regology
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Described deployments without named customers. The vendor publishes two customer situations with stated outcomes, a regional bank achieving automated impact analysis, faster assessment of regulatory changes and improved audit documentation, and a global social media and technology company managing compliance across multiple jurisdictions at scale. Those describe the shape of a deployment usefully but name no organisation, carry no figures and are undated. Founder credibility is published and relevant, the company having been founded by former PwC compliance professionals with seven years implementing regulatory programmes at large financial institutions, which speaks to domain competence rather than to deployment outcome. Searched the platform pages, the blog, the news section and the llms-txt file on 29 Aug 2026 and located no named customer paired with figures and a date, and no case study with an assessable method.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Norm Ai
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Confidentiality is asserted through a trust programme without the specific commitments this axis tests being reached. Published on the trust centre: a stated commitment to rigorous security practices including SOC 2 compliance, continuous monitoring, and a company wide culture of data protection. That is a general assurance rather than a set of terms. Searched the trust centre, the platform pages, the resources section and the company blog on 29 Aug 2026 and located no statement on whether customer content may be used to train or improve models, no retention or deletion terms, no segregation model between customers, and no treatment of privilege or work product. The material at issue is unusually sensitive even by this index's standards: the platform reviews internal communications, draft marketing and investor materials, and agreements before they are issued, so it sees regulated firms' content at the point where a compliance problem would still be undisclosed. The trust centre renders client side and its control detail was not retrieved in this pass, which is where these terms would sit if published.

Regology
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Confidentiality rests on certification with the specific commitments unaddressed. Published: SOC 2 Type II certification, with earlier announcements stating the examination covered security, availability and confidentiality and naming the auditing firm. That is a real attestation covering the confidentiality trust services criterion, which is more than a bare security claim. Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026 and located no statement on whether customer content may be used to train or improve models, no retention or deletion terms, no segregation model between customers, and no treatment of privilege or work product. The material at issue is a customer's own obligations, controls, policies and compliance decisions, including records of what was rejected, which is sensitive in a different way from client documents but sensitive nonetheless. No trust centre or security page was located, so there was no obvious place these terms would sit.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Norm Ai
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

The most structurally distinctive answer to this axis on the index, though not a written position. The vendor addresses the boundary between software and legal advice by building on both sides of it: the platform performs compliance analysis for enterprises, and in 2026 the company launched Norm Law, which it describes as the first fully AI native law firm for institutional clients, chaired by the former chairman of Sidley Austin and recruiting partners. Legal advice is therefore delivered by a law firm with admitted attorneys while the software delivers analysis, which is a real separation rather than a disclaimer. The operating model reinforces it: an agent performs initial review and a human professional completes the determination, and in the law firm context an experienced attorney decides what happens next. The team includes former regulators including a former SEC Commissioner. Short of an A because none of this is published as a position on the advice line: searched the platform pages, the resources section and the company site on 29 Aug 2026 and located no statement on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits. The structure answers the question; the vendor does not.

Regology
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

The audience is stated precisely and the position is not. The vendor names its users as compliance, legal and risk teams, which places lawyers among the buyers rather than as the only buyer, and the product identifies applicable law and generates obligations, which is analysis a lawyer would otherwise perform. Searched the platform pages, the blog, the news section and the llms-txt file on 29 Aug 2026 and located no published position on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits, notwithstanding that the platform spans United States federal law, fifty states and international jurisdictions where the rules governing who may advise on law differ materially. Recorded at C because the position is inferable from the buyer set rather than published.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Norm Ai
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

A governance framework with real substance embedded in how the product is built, short of certification, published results and bias disclosure. Several elements are genuine mechanisms rather than principles. LEAP is stated to include automated evaluation pipelines as part of taking agents into production, so evaluation is a gate rather than an afterthought. Every determination carries an explanation, and the decision tree representation is human readable, so an agent's reasoning is auditable by a lawyer without reading code, which is a design decision with governance consequences. Legal Engineers build and supervise agents and maintain them as regulations change. The company also builds supervisory agents to monitor other AI systems against laws and policies, and convenes a forum on AI, law and policy involving legislators and regulators. Not located as of 29 Aug 2026: an AI management certification such as ISO 42001, a named accountable owner for model governance, published evaluation results as distinct from the existence of pipelines, and any disclosure about uneven output across firms, content types or populations.

Regology
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

Searched the platform pages, the company blog, the news announcements and the published llms-txt file on 29 Aug 2026. No governance position for model behaviour was located: no AI principles or framework, no named owner of model governance, no pre release testing regime, no AI management certification such as ISO 42001, and nothing on uneven output across jurisdictions, industries or organisation types. The full audit trail is a governance artifact in the compliance sense, recording what was decided and by whom, but it governs the customer's compliance process rather than the model's behaviour, and the two were not conflated. The absence has a specific edge here: applicability determination decides which laws a business is told it must follow, and differential performance across jurisdictions or business types would be invisible to a customer who has no independent view of what should have been flagged.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Norm Ai
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

A general security posture is stated without operational detail being reached. Published on the trust centre: SOC 2 compliance, continuous monitoring, and a company wide culture of data protection and integrity. A trust centre exists at a stable URL on a recognised compliance platform, which is a self serve route. Searched the trust centre, the platform pages and the company site on 29 Aug 2026 and located no retention period, no deletion control, no encryption specifics, no access control detail, no named subprocessor list, no hosting provider or region, and no incident or breach notification practice. Recorded at C on the stated certification and monitoring rather than lower. The trust centre renders its contents client side and they were not retrieved in this pass, so this row is rebuttable and the portal is the single place to look.

Regology
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

Certification is published and the operational detail is not. Real and stated: SOC 2 Type II certification, described in company announcements as an examination by an accredited third party auditor covering security, availability and confidentiality, with the vendor stating a continuing commitment to maintaining it. Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026 and located no retention period, no deletion control, no encryption specifics, no access control detail, no named subprocessor list, no hosting provider or region, and no incident or breach notification practice. No trust centre or dedicated security page was reached. Recorded at C on the strength of the attestation alone.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Norm Ai
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

Searched the platform pages, the resources section, the company blog, the news announcements and the trust centre on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer terms of service was located as published on the property. Recorded as a pure absence on the surfaces reached. The shape is worth naming because it is unusual: this product makes compliance determinations about content a regulated firm is about to publish, so a wrong determination can result in a regulatory finding against the customer rather than merely a bad draft. That is a materially different exposure from most records on this index, and nothing published addresses who carries it. Note also that the adjacent law firm entity would carry professional liability of its own, which the software vendor's silence does not cover.

Regology
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

Searched the platform pages, the company blog, the news announcements and the published llms-txt file on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer terms of service was located as published on the property. Recorded as a pure absence on the surfaces reached. The exposure shape matches Norm Ai in the same category and is worth restating: this product tells an organisation which laws apply to it and what obligations follow, so a missed applicability determination surfaces as a regulatory breach by the customer rather than as a bad draft. Nothing published addresses who carries that.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Norm Ai
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

Integration is described at workflow level without named connectors. The vendor's stated design is compliant by design, embedding compliance checks into business activities rather than running them separately, covering AI generated content, internal communications, agreements, marketing content and sales materials, and the platform is described as monitoring workflows and alerting when something drifts out of compliance. That implies connection into the systems where those artifacts are produced. Searched the platform pages, the resources section and the company site on 29 Aug 2026 and located no integrations page, no named connector for content management, communications archiving, document management or customer relationship systems, and no API documentation. For a product whose value depends on intercepting content before it is published, the absence of a named integration surface is the notable gap.

Regology
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Real integrations exist, are named individually, and the positioning around them is unusually clear. The vendor states it works alongside existing governance risk and compliance investments rather than replacing them, naming ServiceNow, Archer and Hyperproof specifically, and describes itself as a regulatory intelligence and data layer on top of that infrastructure. Explicitly stating that no rip and replace is required, and naming the incumbent systems it sits beside, is a positioning choice that tells a buyer where the product fits in an existing stack. Migration in is also addressed: customers can upload existing law libraries from spreadsheets and PDFs so the platform is operational without rebuilding from scratch. Not located as of 29 Aug 2026: an integrations index page, per integration documentation describing what moves in which direction and what an administrator configures, and any API documentation.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Norm Ai
DD on Deployment Model and Data ResidencyNothing published on where the software runs or where client data sits.

Searched the platform pages, the resources section, the company site and the trust centre on 29 Aug 2026. Nothing was located on the deployment model: no hosting provider, no named regions, no customer selectable residency, no tenancy model, and no statement of where processing happens as distinct from where data is stored. The product is evidently cloud delivered, which is inference from how it is sold and earns nothing on this axis. The absence carries weight for this buyer specifically, since the customer base is regulated financial institutions for whom data location is frequently a supervisory requirement rather than a preference.

Regology
DD on Deployment Model and Data ResidencyNothing published on where the software runs or where client data sits.

Searched the platform pages, the company blog, the news announcements and the published llms-txt file on 29 Aug 2026. Nothing was located on the deployment model: no hosting provider, no named regions, no customer selectable residency, no tenancy model, and no statement of where processing happens as distinct from where data is stored. Earlier company material describes the product as a cloud based regulatory intelligence solution, which establishes cloud delivery and nothing further. The absence carries weight given the vendor's own coverage claim: a platform serving international jurisdictions and marketed to multinational organisations will meet customers for whom data location is a supervisory requirement.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Norm Ai
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

A trust centre exists and the certification is claimed without scope or evidence. Published: a trust centre at a stable URL on a recognised compliance automation platform, stating a commitment to rigorous security practices including SOC 2 compliance and continuous monitoring. Existence of the portal is a real self serve route and is more than several records here offer. What was not located as of 29 Aug 2026: whether the SOC 2 is Type 1 or Type 2, any coverage period, any audit scope, any report date, any named auditing firm, any other certification, and any published request flow for the report. The trust centre renders its contents client side and they were not retrieved in this pass, which is a limitation of the research method rather than a finding about the vendor, and is recorded as such. Rebuttable in one step by reading the portal contents.

Regology
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Certification is real, named, scoped and attributed to a named auditor, short of a current date and an evidence route. SOC 2 Type II certification is stated by the vendor, and its announcements identify the auditing firm as BARR Advisory and describe the examination scope as covering security and availability, later stated as security, confidentiality and availability. Naming the audit firm is something only a handful of records on this index do, and the vendor also states a continuing commitment to maintaining the certification rather than treating it as a one time achievement. Two things hold this at B. The announcements naming the auditor and scope date from earlier certification cycles, and no current report date, coverage period or renewal announcement was located, so currency rests on the standing claim rather than on a dated artifact. And no trust centre, security page or published request route for the report was located, the vendor's material inviting interested customers to get in touch.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Norm Ai
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The architecture is described in detail and the model layer is not identified. Published: agents are described as language model driven, traversing decision trees encoded in the vendor's proprietary domain specific language, with proprietary prompt optimisation and structured reasoning frameworks in LEAP. A buyer therefore understands that the regulatory logic is the vendor's own and that a general purpose model executes against it, which is a clearer architectural picture than most records provide. Searched the platform pages, the resources section, the company blog and the trust centre on 29 Aug 2026 and located no named model or model provider, no statement of where models run, no subprocessor list, and no commitment to notify customers when the model supply chain changes.

Regology
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

Searched the platform pages, the company blog, the news announcements and the published llms-txt file on 29 Aug 2026. No model, model provider, hosting location for model processing, or subprocessor was located, and no commitment to notify customers of supply chain changes. The vendor names its three AI agents individually and describes using the industry's most advanced AI without identifying what any of it is. A buyer cannot determine from published material whether their regulatory obligations, control mappings and policy documents are processed by a third party model provider, which is the first question a security review of an AI platform would ask.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Norm Ai
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Checked the platform pages, the solutions pages, the resources section and the company site on 29 Aug 2026. No pricing page was located, no rate is published, no unit of charge is stated and no tier structure appears. Every commercial path located terminates in a request for a personalised demo. No free trial or self serve entry point was located, and no third party pricing figure was located either. Consistent with the enterprise sales model implied by a customer base of large regulated institutions, and consistent with the pattern across this index for vendors selling to that segment.

Regology
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Checked the platform pages, the company blog, the news section and the published llms-txt file on 29 Aug 2026. No pricing page was located, no rate is published, no unit of charge is stated and no tier structure appears. Commercial paths located terminate in a demo request or a published telephone number. No free trial or self serve entry point was located, and no third party pricing figure was located either. Consistent with the enterprise sales model implied by a buyer set of multinational compliance functions.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Norm Ai
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Coverage is described with substance and the regulatory focus is named at source level. Regulatory scope is stated concretely through the regimes the Legal Engineers track and encode: SEC, FINRA and CFPB, with GDPR referenced in comparison material, and the vendor states the approach generalises to anything a company is subject to rather than being limited to those regimes. The buyer is the large regulated enterprise, with chief compliance officers named as the primary role and financial services the evident concentration given the investor base and the named regimes. Functional coverage is enumerated by workflow: regulated content review across marketing, investor relations and internal communications, questionnaire and information request completion, contract review, and supervision of other AI systems. Not located as of 29 Aug 2026: an enumerated industry list beyond financial services, organisation size segmentation, jurisdictional coverage outside the United States, and any statement of what the platform is not built for.

Regology
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Jurisdictional coverage is enumerated precisely and the industry position is stated as a deliberate choice. Coverage spans United States federal law, all fifty states and international jurisdictions, with earlier material citing regulations across twenty countries, and the corpus is described as continuously updated rather than periodically refreshed. Industry scope is stated as an explicit differentiator: one platform covering all industries and jurisdictions, not siloed by vertical or geography, which is a positioning claim against competitors that specialise. Buyer functions are named as compliance, legal and risk teams. Not located as of 29 Aug 2026: a current enumerated list of the international jurisdictions covered, any completeness or lag statement per jurisdiction, organisation size segmentation, and any statement of what the platform is not built for. Naming twenty countries in older material without a current list is the gap between this and an A.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Norm Ai
Terms silent

Searched the trust centre, the platform pages, the resources section and the company blog on 29 Aug 2026. No located material states whether customer content may be used to train or improve models, either way. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction. The question has particular weight here because the vendor describes LEAP as creating a compounding layer of institutional judgment that captures firm specific standards and continuously improves how those standards are applied, which is a learning claim about firm specific material without a statement of whether that learning is confined to the firm it came from. The trust centre renders client side and was not retrieved in this pass; it is the most likely location of a training position.

Regology
Terms silent

Searched the platform pages, the company blog, the news announcements and the published llms-txt file on 29 Aug 2026. No located material states whether customer content may be used to train or improve models, either way, and no model provider is identified so no provider side commitment could be located either. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction. The question is live because customers upload their own existing law libraries and the platform records their obligations, control mappings, policy decisions and rejections, which is a corpus of one organisation's compliance judgement that would be commercially valuable across others.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Norm Ai
Not addressed

Searched the trust centre, the platform pages, the resources section and the company site on 29 Aug 2026. No public material states how long submitted content, compliance determinations, explanations or decision history are retained, whether a customer controls the window, or whether deletion is available. The product centralises decision history as a feature, so accumulation is by design rather than incidental, and the retained record includes determinations that content was non compliant before it was corrected, which is exactly the material a regulated firm would want governed by explicit terms.

Regology
Not addressed

Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026. No public material states how long records are retained, whether a customer controls the window, or whether deletion is available. Retention is nonetheless inherent to the product's stated value: the vendor's central claim is a full audit trail in which every alert, assignment, decision, approval, rejection and policy update is timestamped and traceable, and defensible documentation for auditors only works if it persists. So the product is designed to retain indefinitely and no published terms govern it, which is a sharper version of this gap than a silence would normally be.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Norm Ai
Not addressed

Searched the trust centre, the platform pages, the resources section and the company site on 29 Aug 2026. No vendor material addresses segregation between customers, users or business units. The question is live for this buyer type: a large financial institution operates information barriers between deal teams, research and trading as a regulatory requirement rather than a preference, and this platform reviews internal communications and investor materials across the firm. Nothing located states whether agents, determinations or decision history respect those barriers. Collaboration tooling is described in terms of teams tagging each other and centralising decision history, which points toward shared visibility rather than compartmentalisation, though nothing states either.

Regology
Not addressed

Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026. No vendor material addresses segregation between customers, users or business units. The product assigns work and records approvals and rejections, which implies a user and role model exists, but nothing describes it. The question has some weight for a multinational customer running compliance across business units with different regulatory perimeters, where visibility of one unit's obligations and failures to another is a governance question rather than a preference. No document management integration was located whose permissions could be inherited.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Norm Ai
Not addressed

Searched the trust centre, the platform pages, the resources section and the company site on 29 Aug 2026, and no published customer agreement or data processing agreement was reached. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The exposure is distinctive: this platform holds records of compliance determinations, including determinations that a regulated firm's content failed a rule before it was fixed, which is precisely the material a regulator or plaintiff would seek. Nothing published addresses what the vendor would do on receiving such a demand.

Regology
Not addressed

Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026, and no published customer agreement, terms of service or data processing agreement was reached. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The exposure mirrors Norm Ai in the same category: the platform holds a timestamped record of what a regulated organisation decided about its own obligations, including what it rejected, which is material a regulator or plaintiff would seek, and nothing published addresses what the vendor would do on receiving a demand for it.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Norm Ai
Sources named, basis unstated

Sources are named at regulator level and the maintenance process is described, which is more than most records manage, though no licence basis is stated. The corpus is the body of regulation itself, and the vendor names where it comes from: Legal Engineers review regulatory updates from sources including the SEC, FINRA and CFPB and identify relevant changes for the agents, with regulatory logic built and maintained inside LEAP as laws change. That is a named source set plus a described currency process, and the currency process is staffed rather than automated, which is unusual. What is not stated is the rights basis, though United States federal regulations are public domain so the licence question that this signal exists to probe largely does not arise. Also not located: a jurisdiction by jurisdiction coverage list, a completeness statement for any regime, or a stated lag between a rule change and the agent being updated.

Regology
Sources named, basis unstated

The corpus is named as a product asset, its jurisdictional scope is enumerated, and its currency is described, which together make this one of the stronger provenance positions in the index for a non case law product. The Smart Law Library is the vendor's proprietary corpus, covering United States federal law, all fifty states and international jurisdictions, with earlier material citing regulations across twenty countries. Currency is a core claim rather than a footnote: the platform tracks bills, laws, regulations and agency updates in real time, and the library is described as continuously updated. Provenance is inherently identifiable because the underlying material is primary law published by legislatures and agencies, so the licensing question this signal exists to probe does not arise in the way it would for a proprietary secondary corpus. Recorded at named sources with the basis unstated because no licence or sourcing statement is published, no per jurisdiction completeness statement was located, and no current enumerated list of the international jurisdictions was located.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Norm Ai
Not addressed

Searched the platform pages, the resources section and the company blog on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this product's corpus is regulation rather than case law, so a citator in the conventional sense is outside its design. The functional equivalent for a regulatory product is whether the encoded rule is current, and the vendor does address that, describing Legal Engineers reviewing regulatory updates and maintaining the decision trees as laws change. That is a currency mechanism for its own corpus rather than a treatment signal on cited authority, and the two were not conflated.

Regology
Not addressed

Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this product's corpus is legislation and regulation rather than case law, so a citator in the conventional sense is outside its design. The functional equivalent for a regulatory product is whether the rule in the library is the rule currently in force, and the vendor addresses that directly through real time tracking of bills, laws, regulations and agency updates and a continuously updated library. That is a currency mechanism for its own corpus rather than a treatment signal on cited authority, and the two were not conflated.

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Norm Ai
Not addressed

Searched the platform pages, the resources section, the company blog and the trust centre on 29 Aug 2026. No published material describes what an agent does when a determination is genuinely ambiguous or when the encoded rule does not reach the situation presented, and no explicit no answer path or confidence signal exposed to the user was located. The decision tree architecture makes this a sharper question than usual rather than a softer one: traversal is designed to terminate in a compliance determination, so what happens at a node the tree does not anticipate is a real design question. The published human review step, where a professional completes the determination, is where such a case would presumably surface, but nothing states that the agent flags uncertainty rather than resolving it.

Regology
Not addressed

Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026. No published material describes what the agents do when applicability is genuinely uncertain or when a regulatory change does not map cleanly to an existing obligation, and no explicit no answer path or confidence signal exposed to the user was located. The audit trail records rejections, which shows that a human disagreeing with a determination is an expected path, but that is a record of the human's judgement rather than a description of the system flagging its own uncertainty. For a product whose core output is a determination that a law does or does not apply, how it handles the ambiguous case is a live question and is unaddressed.

Fabricated Citation Record

Does a public court record exist involving output from this product?

Norm Ai
None located

No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note the characteristic failure here would not be a fabricated citation but a wrong compliance determination on content that was then published, which would surface as a regulatory enforcement matter rather than in a hallucination database, and would in most cases name the regulated firm rather than the software.

Regology
None located

No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note the characteristic failure here would be a missed or wrongly asserted applicability determination surfacing as a regulatory breach by the customer rather than a fabricated citation in a filing, and such a matter would name the regulated organisation rather than the software.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Norm Ai
Not addressed

Searched the platform pages, the resources section, the company blog and the news announcements on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512 and state bar guidance. Recorded as an absence with an unusual qualification: this company launched a law firm in 2026, describing it as the first fully AI native law firm for institutional clients and appointing a former Sidley Austin chairman to lead it. A law firm is directly bound by the professional conduct rules this signal asks about, so the question moves from whether the vendor engages with guidance to whether an entity subject to it publishes its position. Nothing located does. Also recorded: the company convenes a forum on AI, law and policy involving legislators and regulators, which engages with policy formation rather than with the existing conduct rules binding its users.

Regology
Not addressed

Searched the platform pages, the company blog, the news announcements and the llms-txt file on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512 and state bar guidance. The vendor publishes research including an annual state of regulatory compliance survey, which addresses practitioner sentiment and compliance operations rather than the professional responsibility obligations binding the lawyers among its stated buyer set of compliance, legal and risk teams.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Norm Ai
Not addressed

Searched the platform pages, the solutions pages, the resources section and the company blog on 29 Aug 2026. No per matter record of AI assisted work intended for fee purposes was located, and no guidance on billing, fee or client disclosure treatment was located. No quantified time or cost savings claim was located either, the vendor's published framing being coverage and speed of compliance analysis rather than hours displaced, so there is no savings claim to weigh against a client's side of the equation. Recorded as not addressed rather than at the savings claims value for that reason. Noted for a future pass: the adjacent law firm entity bills institutional clients directly, and how AI assisted work is treated in those fees is a live question that no located material addresses.

Regology
Savings claims only

Savings are claimed in general terms with nothing published on the client's side of the equation. The vendor's framing is that its AI and agents automate repetitive, labour intensive manual processes that inundate compliance teams and drain resources and time, and a published customer situation cites faster assessment of regulatory changes. Those are efficiency claims without figures attached. Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment. Noted for context: the buyer is a corporate compliance or legal function that does not bill a client by the hour, so this signal reads as internal cost rather than billable time for this segment.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Norm Ai
On request only

A trust centre exists at a stable URL on a recognised compliance platform, stating SOC 2 compliance and continuous monitoring, which is a real self serve route to whatever diligence material sits behind it. Searched the trust centre entry point, the platform pages and the company site on 29 Aug 2026 and located no subprocessor list, no statement naming which model providers see customer content, no published data processing agreement, and no client facing consent or notification material. Recorded at on request on the strength of the portal existing rather than at the subprocessor value, because the portal renders its contents client side and they were not retrieved in this pass, so what a requester would actually receive is unestablished.

Regology
Not addressed

Searched the platform pages, the company blog, the news announcements and the llms-txt file on 29 Aug 2026, and no trust centre or security page was reached. The vendor states SOC 2 Type II certification and its announcements name the auditing firm and the examination scope, and invite interested current and prospective customers to make contact, which is a route of a kind though not a published request flow. Not located: a subprocessor list, any statement naming which model providers see customer content, a published data processing agreement, and any client facing consent or notification material. Recorded as not addressed because no assembled diligence material and no published request mechanism exists to point to.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Norm Ai
Partial record

Substantial elements of a defensibility record exist and are central to the product rather than incidental. Every determination carries an explanation identifying what is problematic and under which regulation, the decision tree encoding each rule is human readable so the reasoning path itself is inspectable by a lawyer without reading code, and decision history is centralised with human review recorded through the collaboration tooling. A regulated firm asked by a supervisor to justify why content was cleared would have the rule applied, the path taken, the explanation given and the human who signed off. Two elements are missing: no single per document export combining those with the model used was located, and no model is identified in published material so the model used could not be stated. Recorded at partial record. Noted for context: the relevant forum here is a regulatory examination rather than a court, and this is among the better positioned records on the index for that particular demand.

Regology
Partial record

Among the strongest defensibility records on the index, and the vendor states that purpose explicitly rather than leaving it to be inferred. Published: every alert, assignment, decision, approval, rejection and policy update is timestamped and traceable to a source law, which the vendor describes as creating defensible documentation for auditors. That covers what was decided, who decided it, when, what the decision rested on, and crucially what was rejected, which is the element most audit trails omit and the one an examiner is most likely to probe. Two elements are missing and keep this at partial record: no per document export combining that trail with the model used was located, and no model is identified in published material so the model used could not be stated. Noted for context: the relevant forum for this product is a regulatory examination or an internal audit rather than a court, and for that demand this record is well positioned.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • AI Liability and Recourse
  • Deployment Model and Data Residency
  • Commercial Transparency
Signals neither addresses in public material
  • Prompt and Output Retention
  • Ethical Walls and Matter Segregation
  • Third Party Request and Subpoena Notice
  • Good Law Verification
  • Refusal and Uncertainty Behaviour
  • Bar Guidance Alignment

Which one fits

Choose Norm Ai if

  • You have to show a supervisor why content was cleared. Norm Ai encodes regulations through a proprietary domain specific language into decision trees a human can read, an agent traverses the tree rather than answering from model memory, and every determination carries an explanation naming what is problematic and under which provision.
  • You want the division of labour stated rather than implied. Norm Ai publishes an operating model in which an agent conducts the initial compliance review of material such as marketing communications against SEC or FINRA rules and a human professional then reviews the findings and completes the determination, with Legal Engineers building and supervising the agents.
  • The advice line matters to your risk committee. Norm Ai answers it structurally rather than with a disclaimer, having launched Norm Law in 2026 as a separate law firm for institutional clients chaired by a former Sidley Austin chairman, so admitted attorneys deliver legal advice while the software delivers analysis.

Choose Regology if

  • You need the auditor named in a diligence response. Regology states SOC 2 Type II certification and its announcements identify BARR Advisory as the auditing firm, with the examination scope stated as covering security, confidentiality and availability, which few vendors in this market publish at all.
  • You are not replacing your GRC stack. Regology positions itself as a regulatory intelligence and data layer sitting alongside existing investments, naming ServiceNow, Archer and Hyperproof specifically, and lets customers import existing law libraries from spreadsheets and PDFs rather than rebuilding from scratch.
  • Your auditor will ask what you rejected, not just what you approved. Regology timestamps every alert, assignment, decision, approval, rejection and policy update and traces each to the source law, across United States federal law, all fifty states and international jurisdictions.

In summary

Norm Ai

Norm Ai converts laws, regulations and corporate policies into executable compliance agents for large regulated enterprises, with a concentration in financial services covering SEC, FINRA and CFPB rules. The AI Legal Index grades it in the top two bands on six of fifteen capability axes, with an A on AI centrality: regulations are encoded through a proprietary domain specific language into decision trees a human can read and a machine can execute, and an agent traverses the tree and states which provision drove its determination. Agents are built by Legal Engineers, former attorneys given intensive language model training, on a platform whose deployment path includes automated evaluation pipelines. As of 29 August 2026 the index located no customer agreement, no named model or provider, no retention position and no pricing.

Source: AI Legal Index, 2026

Regology

Regology is a regulatory intelligence platform for compliance, legal and risk teams, built on a proprietary Smart Law Library covering United States federal law, all fifty states and international jurisdictions, with three named agents covering regulatory change, compliance and research. The AI Legal Index grades it in the top two bands on six of fifteen capability axes, with a B on security certifications: it states SOC 2 Type II certification and names BARR Advisory as the auditing firm, with the examination scope stated. Every alert, assignment, decision, approval, rejection and policy update is timestamped and traceable to the source law, which the vendor frames as defensible documentation for auditors. As of 29 August 2026 the index located no customer agreement, no model or provider named, no retention position and no pricing.

Source: AI Legal Index, 2026

Questions buyers ask

Norm Ai vs Regology: which is better for regulatory compliance?

The AI Legal Index places both in the top two bands on six of fifteen capability axes, so the grid does not separate them. Norm Ai takes the higher grade on AI centrality and publishes more about how a determination is reached and reviewed. Regology publishes more of what a procurement review asks for, naming its auditor and the systems it sits alongside. Neither publishes a customer agreement, so on liability and training the records are equally empty.

How does Norm Ai ground its compliance determinations?

By construction rather than by retrieval. Norm Ai encodes regulations through its own domain specific language into decision trees that a human can read and a machine can execute, so an agent traverses the encoded rule and reaches a determination rather than generating one from model memory, and every determination carries an explanation identifying the provision behind it. No accuracy figure, error rate or test set is published, so the grounding mechanism is documented and its performance is not. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.

Does Regology replace an existing GRC system?

It says it does not. Regology positions itself as a regulatory intelligence and data layer working alongside existing governance, risk and compliance investments, naming ServiceNow, Archer and Hyperproof, and states that no rip and replace is required. Customers can import existing law libraries from spreadsheets and PDFs. What the AI Legal Index did not locate is an integrations index, per integration documentation describing what moves in which direction, or any API documentation.

Does either vendor name the auditor behind its security certification?

Regology does. It states SOC 2 Type II certification and names BARR Advisory as the auditing firm, with the examination scope stated. Norm Ai states SOC 2 compliance on a trust centre hosted on a recognised compliance platform without saying whether it is Type 1 or Type 2, and names no auditor, coverage period or report date. The trust centre renders client side, so its contents were not retrieved during research. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.

What do Norm Ai and Regology both leave unpublished?

Neither publishes a customer agreement, so neither states an indemnity, a liability cap, a warranty on output or an insurance position, which matters because both products tell a regulated firm what its obligations are. Neither names a model or a provider. Neither states a retention period, a deletion route or a position on training. Neither publishes a price or a unit of charge. And neither describes what happens when applicability is genuinely uncertain. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.

Disclosure

Two limits belong on this page. Norm Ai's trust centre exists at a stable URL and renders its contents client side, so they were not retrieved during research: several of its middle grades, including security certifications and data stewardship, would move if the portal were read, and they record a limit on this reading rather than an absence on the vendor's part. On Regology, the announcements naming BARR Advisory and the examination scope come from earlier certification cycles and no current report date or coverage period was located, so currency rests on a standing claim. Neither vendor states whether customer content trains its models, and neither publishes an agreement in which such a term could sit. Both records were verified on 29 August 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 2, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746