Onspring vs Regology: how they compare in 2026
These two can sit in the same stack rather than compete for the same budget. Onspring is a no code governance, risk and compliance platform a team configures without developers, and Regology is a regulatory intelligence layer that deliberately does not replace one, naming ServiceNow, Archer and Hyperproof as systems it sits beside and stating that no rip and replace is required. Regology reaches the top two bands on six of fifteen axes and Onspring on five, and the pair produces a neat symmetry. Onspring names the provider behind its AI outright, stating that Onspring AI runs on Anthropic's Claude family, and does not name the firm that audited its SOC 2. Regology names its auditor, BARR Advisory, and states the scope of the examination, and names no model or provider at all. Each publishes the fact the other withholds, and neither publishes a customer agreement, a liability position or a hosting region.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The clearest case on the index of AI as an addition rather than a foundation, and the vendor says so itself. Onspring is a no code GRC platform that existed and sold for years before any AI shipped. Onspring AI launched October 2025 as an optional add on module that customers enable and configure, extended July 2026 into agentic operation. The vendor's own framing is that customers have total control over when and how it is used, which is a sound commercial position and also an admission that the product works without it. Removing the model layer removes an efficiency layer over data entry, documentation drafting, duplicate detection and record linking, and leaves the entire platform standing. Graded below Everlaw and Relativity at B, where the model layer is bundled into the core product rather than licensed separately. The AI is real, shipped, documented and dated, which is why this is C and not lower. The brief flagged this vendor to check the AI bar and it clears it comfortably; centrality is a different question from existence.
The models are the engine of a core capability layered on an asset that has value without them. The Smart Law Library is a curated, continuously updated corpus of United States federal law, all fifty states and international jurisdictions, and a law library with search and change tracking is a usable product in its own right; the vendor sells the ability to import a customer's existing library into it, which underlines that the corpus is a distinct asset. What the models drive is substantial rather than peripheral, which is why this is not a C: three named AI agents covering Regulatory Change, Compliance and Research determine which laws apply to an organisation, assess the impact of incoming changes, and generate obligations, risks, controls and policies mapped to source law. Applicability analysis at that scale is not achievable by search alone. Distinguished from Norm Ai in the same category, graded A, where the agents execute encoded regulations and no separable data asset stands behind them.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Nothing published. Onspring AI generates and revises long form content, creates records from prompts, completes text predictively, and reads and summarises uploaded documents such as SOC 2 reports to populate fields. Every one of those is a generation task where a wrong output lands in a compliance record, and none carries a published grounding claim, source citation behaviour, accuracy figure, precision or recall measure for duplicate detection or field extraction, hallucination rate, evaluation, or statement of what the assistant does when it has no answer. Searched the Onspring AI announcements of October 2025 and July 2026, the regulatory change management product page, the security page, the platform pages and the corporate counsel solution page on 29 Aug 2026. The gap is sharper here than the grade alone conveys: the assistant is documented as able to answer from every record and application in a customer's GRC program, and nothing states how those answers are grounded in the underlying records.
Grounding is real, architecturally enforced and stated as a design goal, short of published measurement. The vendor's central claim on this axis is traceability rather than accuracy: every alert, assignment, decision, approval, rejection and policy update is timestamped and traceable to a source law, which the vendor frames as producing defensible documentation for auditors. So an obligation or control generated by the platform can be followed back to the specific provision it derives from, and the corpus it derives from is the vendor's own maintained library rather than an open web retrieval. That is grounding by construction. Searched the platform pages, the company blog, the published llms-txt file and the news announcements on 29 Aug 2026 and located no accuracy figure, no error rate for applicability determination, no test set, no published evaluation methodology and no independent benchmark participation. For a product whose core function is deciding which laws apply to a business, an applicability error rate is the figure a buyer would most want and it is not published.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The strongest autonomy disclosure located in this category, and the only one on the index where the boundary is a configurable customer artifact rather than a vendor assurance. The July 2026 release is explicit that administrators define the rules that prompt agent action, that automation operates within the boundaries set by the system administrator, and that the design intent is a governed assistant that keeps users in control. The module is opt in and configurable to organisational standards, and an internal AI governance council is named as the oversight body. That gives a buyer three separate levers a compliance function can actually evidence to an examiner: whether the module is on, what rules trigger action, and who governs it. Held at B because none of the mechanics are published. No rule syntax, no scope limits, no statement of what an agent may never do, no escalation or human confirmation behaviour, and no description of what the audit trail captures when an agent rather than a person acts. Better positioned than Regology and Norm Ai, both of which describe oversight without a customer set boundary.
A real published commitment with a documented decision record, short of thresholds. The oversight structure is visible in what the platform records: assignments, decisions, approvals and rejections are all captured and timestamped, which means a human accepts or rejects the agents' output and the acceptance is itself part of the record. Rejection being explicitly logged is notable, since it evidences that disagreeing with the system is an expected path rather than an exception. The agents are described as automating repetitive manual processes and anticipating changes, with compliance teams acting on the output. Not located as of 29 Aug 2026: any threshold at which an agent defers, what the system does when applicability is genuinely uncertain, what proportion of determinations are expected to be reviewed, and what the vendor commits to when an output is wrong.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Customers are named, which most of this category does not do. American Family Insurance for IT risk and GRC program management, Warner Bros. Discovery for GRC management, Memorial Hermann Health System for audit, and Northgate Resorts with a stated saving of 200 compliance hours from a single integration. The vendor also publishes an annual GRC Benchmarking Report carrying survey findings, including that 70 percent of GRC practitioners see simplifying repeatable administrative work as the largest AI opportunity, which is industry research rather than product evidence but is dated and attributable. Held at B rather than A because the named customers are described at use case level without published outcome methodology, the 200 hours figure carries no baseline or period, and none of the named accounts is a legal department, so the evidence supports the GRC product rather than the corporate counsel solution this index is grading it for.
Described deployments without named customers. The vendor publishes two customer situations with stated outcomes, a regional bank achieving automated impact analysis, faster assessment of regulatory changes and improved audit documentation, and a global social media and technology company managing compliance across multiple jurisdictions at scale. Those describe the shape of a deployment usefully but name no organisation, carry no figures and are undated. Founder credibility is published and relevant, the company having been founded by former PwC compliance professionals with seven years implementing regulatory programmes at large financial institutions, which speaks to domain competence rather than to deployment outcome. Searched the platform pages, the blog, the news section and the llms-txt file on 29 Aug 2026 and located no named customer paired with figures and a date, and no case study with an assessable method.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
General confidentiality is claimed and evidenced; legal specific confidentiality is not addressed at all. The vendor publishes a SOC 2 Type II attestation covering security, availability and confidentiality, and states that information privacy, security and risk management policies are documented with defined roles, responsibilities, policies and procedures protecting stored data. That is a real confidentiality position for a platform generally. What does not exist: any treatment of legal privilege or attorney work product, any statement about the confidentiality of matter records held in the Corporate Counsel solution, and any acknowledgement that a legal department's records on the platform differ in kind from an IT risk register. Checked the security page, the corporate counsel solution page, the platform pages and the AI announcements on 29 Aug 2026. This matters more than usual here because the same platform holds both the legal department's matters and the business units those matters concern.
Confidentiality rests on certification with the specific commitments unaddressed. Published: SOC 2 Type II certification, with earlier announcements stating the examination covered security, availability and confidentiality and naming the auditing firm. That is a real attestation covering the confidentiality trust services criterion, which is more than a bare security claim. Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026 and located no statement on whether customer content may be used to train or improve models, no retention or deletion terms, no segregation model between customers, and no treatment of privilege or work product. The material at issue is a customer's own obligations, controls, policies and compliance decisions, including records of what was rejected, which is sensitive in a different way from client documents but sensitive nonetheless. No trust centre or security page was located, so there was no obvious place these terms would sit.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Not addressed. The Corporate Counsel solution holds legal opinions, legal research and a clause library whose clauses are automatically selected by contract type, and Onspring AI can generate and revise long form field content across the platform. Generated or auto selected contract language reaching a business user without a lawyer in the path is the shape this axis exists to examine, and nothing addresses it. No statement that output is not legal advice, no positioning on the role of the reviewing lawyer, no professional responsibility material of any kind. Checked the corporate counsel solution page, the AI announcements, the platform pages and the resource material on 29 Aug 2026.
The audience is stated precisely and the position is not. The vendor names its users as compliance, legal and risk teams, which places lawyers among the buyers rather than as the only buyer, and the product identifies applicable law and generates obligations, which is analysis a lawyer would otherwise perform. Searched the platform pages, the blog, the news section and the llms-txt file on 29 Aug 2026 and located no published position on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits, notwithstanding that the platform spans United States federal law, fifty states and international jurisdictions where the rules governing who may advise on law differ materially. Recorded at C because the position is inferable from the buyer set rather than published.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A governance body is named and nothing it produces is published. Onspring AI is stated to operate under the oversight of the company's AI governance council, and the module is configurable by customers against their own organisational standards and compliance requirements. Naming an internal governance body at all puts this ahead of most of the roster, where governance disclosure covers security rather than model behaviour. What is missing is everything the council would produce: no AI policy, no model evaluation, no bias testing or fairness assessment, no accuracy monitoring, no drift or regression statement, no model card, no ISO 42001, and no description of what the council reviews or when. A named committee with no published output is a claim rather than evidence, which is the definition of this band. Checked the October 2025 and July 2026 announcements, the security page and the platform pages on 29 Aug 2026.
Searched the platform pages, the company blog, the news announcements and the published llms-txt file on 29 Aug 2026. No governance position for model behaviour was located: no AI principles or framework, no named owner of model governance, no pre release testing regime, no AI management certification such as ISO 42001, and nothing on uneven output across jurisdictions, industries or organisation types. The full audit trail is a governance artifact in the compliance sense, recording what was decided and by whom, but it governs the customer's compliance process rather than the model's behaviour, and the two were not conflated. The absence has a specific edge here: applicability determination decides which laws a business is told it must follow, and differential performance across jurisdictions or business types would be invisible to a customer who has no independent view of what should have been flagged.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Platform stewardship is evidenced and AI specific stewardship is not. The SOC 2 Type II attestation covers security, availability and confidentiality, documented privacy, security and risk management policies are stated, and SecurityScorecard is cited as awarding a 100 out of 100 score. Nothing addresses what happens to customer content once it passes into the AI layer: no statement on whether customer records, policies or uploaded documents are used to train or improve any model, no retention position for prompts or generated output, and no description of how data flows to the model provider and back. That last gap is notable because the provider is named, so the vendor has already disclosed the harder fact and stopped short of the easier one. Checked the security page, both AI announcements and the platform pages on 29 Aug 2026. Security certification is graded separately and is not double counted here.
Certification is published and the operational detail is not. Real and stated: SOC 2 Type II certification, described in company announcements as an examination by an accredited third party auditor covering security, availability and confidentiality, with the vendor stating a continuing commitment to maintaining it. Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026 and located no retention period, no deletion control, no encryption specifics, no access control detail, no named subprocessor list, no hosting provider or region, and no incident or breach notification practice. No trust centre or dedicated security page was reached. Recorded at C on the strength of the attestation alone.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
No published position. Nothing was located on liability for AI output, indemnity, warranty, service levels, or remedy where a generated field value, an auto populated record or an agent action is wrong. The agentic release makes this a live question rather than a theoretical one, since an agent acting on administrator defined rules can write to compliance records that an examiner later reads. The vendor's answer to that risk is architectural, in the form of administrator boundaries and opt in configuration, rather than contractual, and no contractual position is public. Checked the July 2026 agentic announcement, the October 2025 launch announcement, the security page, the platform pages and the site footer on 29 Aug 2026.
Searched the platform pages, the company blog, the news announcements and the published llms-txt file on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer terms of service was located as published on the property. Recorded as a pure absence on the surfaces reached. The exposure shape matches Norm Ai in the same category and is worth restating: this product tells an organisation which laws apply to it and what obligations follow, so a missed applicability determination surfaces as a regulatory breach by the customer rather than as a bad draft. Nothing published addresses who carries that.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integrations are named rather than gestured at, and an open API is documented as the extension path. Named: DocuSign, Microsoft 365, Google Drive and Slack, with the vendor stating that further systems connect through the Onspring API. A published customer account credits a single integration with saving 200 compliance hours, which is integration evidence rather than an integration list. Held at B, and the reason matters for a legal index: not one named integration is a legal practice system. No iManage, no NetDocuments, no SharePoint matter workspace, no e-billing or matter management connector, and nothing that would let the Corporate Counsel solution sit inside a legal department's existing document estate. The integrations are the business software a GRC platform needs. Compare Regology at B for naming ServiceNow, Archer and Hyperproof, which is the same shape: real named integrations aimed at the adjacent stack rather than the legal one.
Real integrations exist, are named individually, and the positioning around them is unusually clear. The vendor states it works alongside existing governance risk and compliance investments rather than replacing them, naming ServiceNow, Archer and Hyperproof specifically, and describes itself as a regulatory intelligence and data layer on top of that infrastructure. Explicitly stating that no rip and replace is required, and naming the incumbent systems it sits beside, is a positioning choice that tells a buyer where the product fits in an existing stack. Migration in is also addressed: customers can upload existing law libraries from spreadsheets and PDFs so the platform is operational without rebuilding from scratch. Not located as of 29 Aug 2026: an integrations index page, per integration documentation describing what moves in which direction and what an administrator configures, and any API documentation.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Nothing located from the vendor. Third party software directories describe the platform as cloud deployment supporting Windows and macOS with no mobile application, and that is directory material rather than vendor disclosure, so it is recorded here as context and not credited. From Onspring's own pages, located nothing on hosting provider, region, data residency commitment, single tenant or dedicated instance options, or where customer data is processed and stored. Checked the security page, the platform pages, the corporate counsel solution page and the site footer on 29 Aug 2026. Research limitation stated rather than hidden: the security page was reached through search result content rather than a full page render, so a residency statement lower on that page would not have been seen. Flagged as a correction candidate on that basis.
Searched the platform pages, the company blog, the news announcements and the published llms-txt file on 29 Aug 2026. Nothing was located on the deployment model: no hosting provider, no named regions, no customer selectable residency, no tenancy model, and no statement of where processing happens as distinct from where data is stored. Earlier company material describes the product as a cloud based regulatory intelligence solution, which establishes cloud delivery and nothing further. The absence carries weight given the vendor's own coverage claim: a platform serving international jurisdictions and marketed to multinational organisations will meet customers for whom data location is a supervisory requirement.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
A named attestation with its scope stated and its currency addressed, published on the vendor's own security page. Onspring states an annual SOC 2 Type II attestation prepared in accordance with AICPA standards, and names the trust services criteria covered as security, availability and confidentiality. Naming which criteria are in scope is the detail most vendors omit and it is the difference between a claim and a checkable one, since a SOC 2 covering security alone is a materially narrower report. Annual renewal addresses currency. Also cited: a SecurityScorecard rating of 100 out of 100, which is an external scanner score rather than an audit and is treated as supporting rather than load bearing. Held at B on three gaps: the auditing firm is not named, the examination period is not stated, and no trust centre or self serve request route for the report was located, so under the three tier test the artifact itself is sales gated. Consistent with Regology at B, which names its auditor but not its currency; Onspring names its currency and scope but not its auditor.
Certification is real, named, scoped and attributed to a named auditor, short of a current date and an evidence route. SOC 2 Type II certification is stated by the vendor, and its announcements identify the auditing firm as BARR Advisory and describe the examination scope as covering security and availability, later stated as security, confidentiality and availability. Naming the audit firm is something only a handful of records on this index do, and the vendor also states a continuing commitment to maintaining the certification rather than treating it as a one time achievement. Two things hold this at B. The announcements naming the auditor and scope date from earlier certification cycles, and no current report date, coverage period or renewal announcement was located, so currency rests on the standing claim rather than on a dated artifact. And no trust centre, security page or published request route for the report was located, the vendor's material inviting interested customers to get in touch.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The best model supply chain disclosure located in this pull, and the first record to name its provider outright. Onspring states in dated public announcements that Onspring AI is powered by Anthropic's Claude family of generative AI models, repeated across the October 2025 launch and the July 2026 agentic release and carried in independent trade coverage of both. Naming the provider is the single fact a regulated buyer's own supervisor is most likely to ask for, and it is the fact almost every vendor on this index withholds. Held at B rather than A because the disclosure stops at the family name. No specific model or version is identified, no subprocessor list exists, nothing states whether the provider is engaged through an enterprise agreement or what contractual terms govern data sent to it, no data flow description is published, and no statement addresses what happens if the provider is changed. A buyer knows who, and nothing else.
Searched the platform pages, the company blog, the news announcements and the published llms-txt file on 29 Aug 2026. No model, model provider, hosting location for model processing, or subprocessor was located, and no commitment to notify customers of supply chain changes. The vendor names its three AI agents individually and describes using the industry's most advanced AI without identifying what any of it is. A buyer cannot determine from published material whether their regulatory obligations, control mappings and policy documents are processed by a third party model provider, which is the first question a security review of an AI platform would ask.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The pricing structure is discoverable and no figure is. Subscription pricing is structured by number of users and by modules selected, with annual and multi year licensing options, additional modules incurring incremental cost, and implementation services included with the GRC Suite under some licensing models. Onspring AI is separately licensed as an add on. Knowing that price scales on seats and modules, and that the AI costs extra, tells a buyer how the bill will grow, which is more than most of this roster discloses. Held at C because no price, range or entry point is published at any level, every route is a quote request, and the vendor's own licensing model is described by third parties as complex, which is a signal in itself. Source basis recorded as Third Party Estimated rather than Vendor Published: the structural detail comes from an independent review platform's product summary, not from an Onspring pricing page, and no vendor pricing page was located on 29 Aug 2026.
Checked the platform pages, the company blog, the news section and the published llms-txt file on 29 Aug 2026. No pricing page was located, no rate is published, no unit of charge is stated and no tier structure appears. Commercial paths located terminate in a demo request or a published telephone number. No free trial or self serve entry point was located, and no third party pricing figure was located either. Consistent with the enterprise sales model implied by a buyer set of multinational compliance functions.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is broad across compliance domains and thin across legal ones. Governance frameworks are named at ISO, NIST and CMMC, and the platform spans risk, audit, vendor and third party risk, IT risk, policy, ESG, and business continuity, with named deployments across insurance, media and healthcare. Legal coverage is a single Corporate Counsel solution positioned within business operations, describing matter tracking, requests, opinions, research, a clause library and cost tracking. That is one in house legal use case, not practice coverage: nothing addresses practice areas, jurisdictions, matter types beyond the generic, or any distinction between a legal department's work and the adjacent compliance work the platform was built for. Held at C because the legal offering is real and documented but shallow relative to the platform around it, and because the corporate counsel material carries no visible recent update while the GRC and AI material is refreshed continuously.
Jurisdictional coverage is enumerated precisely and the industry position is stated as a deliberate choice. Coverage spans United States federal law, all fifty states and international jurisdictions, with earlier material citing regulations across twenty countries, and the corpus is described as continuously updated rather than periodically refreshed. Industry scope is stated as an explicit differentiator: one platform covering all industries and jurisdictions, not siloed by vertical or geography, which is a positioning claim against competitors that specialise. Buyer functions are named as compliance, legal and risk teams. Not located as of 29 Aug 2026: a current enumerated list of the international jurisdictions covered, any completeness or lag statement per jurisdiction, organisation size segmentation, and any statement of what the platform is not built for. Naming twenty countries in older material without a current list is the gap between this and an A.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Terms are silent. The security page describes what the SOC 2 attestation validates, quoted here, and that scope is about safeguarding data rather than about model training. No statement was located anywhere addressing whether customer records, uploaded documents or prompts are used to train or improve any model, in either direction. The gap is pointed because the vendor already names Anthropic's Claude as the model provider, so it has disclosed the harder fact and left the simpler one unanswered. Checked the security page, the October 2025 and July 2026 AI announcements, the platform pages and the site footer on 29 Aug 2026. Recorded as silent, not as a negative commitment.
Searched the platform pages, the company blog, the news announcements and the published llms-txt file on 29 Aug 2026. No located material states whether customer content may be used to train or improve models, either way, and no model provider is identified so no provider side commitment could be located either. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction. The question is live because customers upload their own existing law libraries and the platform records their obligations, control mappings, policy decisions and rejections, which is a corpus of one organisation's compliance judgement that would be commercially valuable across others.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Not addressed. No retention period is published for prompts, assistant conversations, generated field content or agent actions, and nothing indicates whether retention is configurable or can be set to zero. The platform is explicitly a system of record that retains GRC data by design, but that is record retention rather than AI interaction retention, and the two are not the same question. Nothing states whether an administrator can see or purge what users asked the assistant. Checked the security page, both AI announcements and the platform pages on 29 Aug 2026.
Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026. No public material states how long records are retained, whether a customer controls the window, or whether deletion is available. Retention is nonetheless inherent to the product's stated value: the vendor's central claim is a full audit trail in which every alert, assignment, decision, approval, rejection and policy update is timestamped and traceable, and defensible documentation for auditors only works if it persists. So the product is designed to retain indefinitely and no published terms govern it, which is a sharper version of this gap than a silence would normally be.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Claimed and not documented, and the AI release raises the stakes on it. The vendor states clearly defined roles, responsibilities, policies and procedures protecting stored data, so an access model exists and is asserted. Nothing documents its granularity or whether it constrains the AI layer: the July 2026 assistant is described as living on every screen and answering from every record and application in the GRC program, and no published statement says those answers respect the asking user's record permissions. For a platform holding both a legal department's matters and the business units those matters concern, that is the segregation question, and it is unanswered. No document management system exists to inherit permissions from, so the second model shape is the only applicable one. Checked the security page and both AI announcements on 29 Aug 2026.
Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026. No vendor material addresses segregation between customers, users or business units. The product assigns work and records approvals and rejections, which implies a user and role model exists, but nothing describes it. The question has some weight for a multinational customer running compliance across business units with different regulatory perimeters, where visibility of one unit's obligations and failures to another is a governance question rather than a preference. No document management integration was located whose permissions could be inherited.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Not addressed. No government or law enforcement request clause, no commitment to notify a customer before producing their data, and no transparency report were located. Checked the security page, the platform pages and the site footer on 29 Aug 2026.
Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026, and no published customer agreement, terms of service or data processing agreement was reached. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The exposure mirrors Norm Ai in the same category: the platform holds a timestamped record of what a regulated organisation decided about its own obligations, including what it rejected, which is material a regulator or plaintiff would seek, and nothing published addresses what the vendor would do on receiving a demand for it.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Not addressed, and largely not applicable in the usual sense. This product has no primary law corpus: the AI operates over the customer's own GRC records, policies, controls and uploaded documents rather than over published legislation or case law. The one adjacent disclosure is that governance frameworks including ISO, NIST and CMMC are supported and mapped to controls, which names standards bodies rather than a regulatory corpus with sources, jurisdictions and update lag. Regulatory change management is sold as a module, and nothing published names which regulatory sources feed it, which jurisdictions are covered, how current the feed is, or on what licence basis any of it is obtained. That last part is a real gap rather than an inapplicable one. Checked the regulatory change management product page and the platform pages on 29 Aug 2026.
The corpus is named as a product asset, its jurisdictional scope is enumerated, and its currency is described, which together make this one of the stronger provenance positions in the index for a non case law product. The Smart Law Library is the vendor's proprietary corpus, covering United States federal law, all fifty states and international jurisdictions, with earlier material citing regulations across twenty countries. Currency is a core claim rather than a footnote: the platform tracks bills, laws, regulations and agency updates in real time, and the library is described as continuously updated. Provenance is inherently identifiable because the underlying material is primary law published by legislatures and agencies, so the licensing question this signal exists to probe does not arise in the way it would for a proprietary secondary corpus. Recorded at named sources with the basis unstated because no licence or sourcing statement is published, no per jurisdiction completeness statement was located, and no current enumerated list of the international jurisdictions was located.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Not addressed. The regulatory change management module monitors regulatory changes and aligns controls with evolving requirements, and Onspring AI can surface related regulatory controls and suggest which analyst to assign a new control to. That is change routing rather than a currency signal: nothing indicates whether the product flags that a regulation a control relies on has been superseded, withdrawn or amended, and no citator or treatment source is named. Checked the regulatory change management page, both AI announcements and the platform pages on 29 Aug 2026.
Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this product's corpus is legislation and regulation rather than case law, so a citator in the conventional sense is outside its design. The functional equivalent for a regulatory product is whether the rule in the library is the rule currently in force, and the vendor addresses that directly through real time tracking of bills, laws, regulations and agency updates and a continuously updated library. That is a currency mechanism for its own corpus rather than a treatment signal on cited authority, and the two were not conflated.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Not addressed. No explicit no answer path, abstention behaviour, confidence score or uncertainty signal is documented for either the assistant or the agentic features. The July 2026 release describes an assistant making contextualised decisions across workflows and answering from every record in the program, and says nothing about what it does when the records do not support an answer. The published control is the administrator defined boundary on what an agent may act on, which limits scope rather than describing behaviour under uncertainty. Checked both AI announcements, the platform pages and the security page on 29 Aug 2026.
Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026. No published material describes what the agents do when applicability is genuinely uncertain or when a regulatory change does not map cleanly to an existing obligation, and no explicit no answer path or confidence signal exposed to the user was located. The audit trail records rejections, which shows that a human disagreeing with a determination is an expected path, but that is a record of the human's judgement rather than a description of the system flagging its own uncertainty. For a product whose core output is a determination that a law does or does not apply, how it handles the ambiguous case is a live question and is unaddressed.
Fabricated Citation Record
Does a public court record exist involving output from this product?
None located, with the instrument stated so the finding is worth what the search is worth. General web searches combining the vendor and product names with court, opinion, sanction, enforcement and disciplinary terms returned nothing on 29 Aug 2026. No named docket database or court record tracker was searched for this record. Exposure shape is low relative to a research or drafting product: the AI generates internal compliance documentation and populates records rather than producing citations to authority for filing. Recorded as a statement about what was found, not as a clearance.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note the characteristic failure here would be a missed or wrongly asserted applicability determination surfacing as a regulatory breach by the customer rather than a fabricated citation in a filing, and such a matter would name the regulated organisation rather than the software.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Not addressed. No named ethics opinion, no ABA Formal Opinion 512, no state bar guidance and no engagement with professional responsibility material of any kind was located, including on the Corporate Counsel solution page where it would be most expected. The vendor publishes extensively on compliance obligations owed by its customers' organisations and nothing on the professional duties of lawyers using the legal solution. Checked the corporate counsel solution page, the resource and report material, both AI announcements and the platform pages on 29 Aug 2026.
Searched the platform pages, the company blog, the news announcements and the llms-txt file on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512 and state bar guidance. The vendor publishes research including an annual state of regulatory compliance survey, which addresses practitioner sentiment and compliance operations rather than the professional responsibility obligations binding the lawyers among its stated buyer set of compliance, legal and risk teams.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Savings claims only. Published customer material states 200 compliance hours saved from a single integration, and the AI positioning rests on reducing repetitive administrative work, supported by a benchmarking finding that 70 percent of GRC practitioners see simplifying repeatable administrative work as the biggest AI opportunity. All of that describes the customer's internal time. Nothing appears on the client's side of the equation: the Corporate Counsel solution tracks legal costs and budgets as a feature, and no position is published on billing for AI assisted time or on producing a record a department could disclose. Checked the corporate counsel solution page, the customer stories and both AI announcements on 29 Aug 2026.
Savings are claimed in general terms with nothing published on the client's side of the equation. The vendor's framing is that its AI and agents automate repetitive, labour intensive manual processes that inundate compliance teams and drain resources and time, and a published customer situation cites faster assessment of regulatory changes. Those are efficiency claims without figures attached. Searched the platform pages, the blog, the news announcements and the llms-txt file on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment. Noted for context: the buyer is a corporate compliance or legal function that does not bill a client by the hour, so this signal reads as internal cost rather than billable time for this segment.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
Not addressed, with one genuine component present that the value set cannot express. The model provider is named outright, Anthropic's Claude family, in dated announcements, which is the single hardest element of such a pack and one almost no vendor on this index publishes. Everything around it is missing: no subprocessor list, no data processing agreement, no trust centre, and no self serve route to the SOC 2 report, which is stated to exist but is not reachable without a sales conversation. A department could forward the model provider name and nothing else. Recorded as not addressed because no forwardable disclosure pack or request route exists, with the model provider disclosure noted here so it is not lost. Checked the security page, both AI announcements, the platform pages and the site footer on 29 Aug 2026.
Searched the platform pages, the company blog, the news announcements and the llms-txt file on 29 Aug 2026, and no trust centre or security page was reached. The vendor states SOC 2 Type II certification and its announcements name the auditing firm and the examination scope, and invite interested current and prospective customers to make contact, which is a route of a kind though not a published request flow. Not located: a subprocessor list, any statement naming which model providers see customer content, a published data processing agreement, and any client facing consent or notification material. Recorded as not addressed because no assembled diligence material and no published request mechanism exists to point to.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Partial record. The platform is built to evidence compliance to auditors and examiners: control authoring, attestations and documentation, evidence capture, task tracking with automated notifications, real time reporting, and framework to control mapping across ISO, NIST and CMMC. A customer can produce what was required, who was assigned, what was done and when. The AI dimension is where it stops short. Nothing indicates that a record carries which fields were AI generated, which model produced them, what sources the assistant drew on, or whether a human confirmed the output before it was saved. With agentic action now writing into records under administrator rules, the distinction between a human entry and an agent entry is exactly what an examiner would probe, and no published export or audit view addresses it. Checked both AI announcements, the regulatory change management page and the platform pages on 29 Aug 2026.
Among the strongest defensibility records on the index, and the vendor states that purpose explicitly rather than leaving it to be inferred. Published: every alert, assignment, decision, approval, rejection and policy update is timestamped and traceable to a source law, which the vendor describes as creating defensible documentation for auditors. That covers what was decided, who decided it, when, what the decision rested on, and crucially what was rejected, which is the element most audit trails omit and the one an examiner is most likely to probe. Two elements are missing and keep this at partial record: no per document export combining that trail with the model used was located, and no model is identified in published material so the model used could not be stated. Noted for context: the relevant forum for this product is a regulatory examination or an internal audit rather than a court, and for that demand this record is well positioned.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- AI Liability and Recourse
- Deployment Model and Data Residency
- Prompt and Output Retention
- Third Party Request and Subpoena Notice
- Good Law Verification
- Refusal and Uncertainty Behaviour
- Bar Guidance Alignment
- Outside Counsel Guideline Readiness
Which one fits
Choose Onspring if
- You want to build the programme rather than buy someone else's shape. Onspring is a no code platform where business users configure applications, workflows, surveys, dashboards and reports through the interface, spanning risk, regulatory change, internal audit, policy authoring, control and framework mapping, third party risk, IT risk, ESG and business continuity, with ISO, NIST and CMMC frameworks mapped to controls and a separate corporate counsel solution covering request intake, matter tracking, a clause library and legal cost tracking.
- You want to know whose model it is and where it stops. Onspring states that Onspring AI runs on Anthropic's Claude family, and its July 2026 agentic release provides that administrators define the rules that prompt agent action and that automation operates within the boundaries the administrator sets, with the module opt in and an internal AI governance council named as the oversight body.
- You want an attestation whose scope is stated and customers you can name. Onspring publishes an annual SOC 2 Type II attestation and names the trust services criteria covered as security, availability and confidentiality, and names American Family Insurance, Warner Bros. Discovery and Memorial Hermann Health System among its customers, with one published account crediting a single integration with saving 200 compliance hours.
Choose Regology if
- The question is which laws apply to you. Regology identifies applicable law rather than serving a library of it, monitoring bills, laws, regulations and agency updates in real time across United States federal law, all fifty states and international jurisdictions, and generating obligations, risks, controls and policies mapped back to the source law.
- Your auditor will ask you to show your working. Regology timestamps every alert, assignment, decision, approval, rejection and policy update and makes each traceable to the source law it derives from, which the vendor frames as defensible documentation, and rejection being logged as explicitly as approval means disagreeing with the system is a recorded path rather than an exception.
- You are not replacing your GRC investment. Regology positions itself as an intelligence and data layer working alongside existing systems and names ServiceNow, Archer and Hyperproof specifically, states that no rip and replace is required, lets customers import existing law libraries from spreadsheets and PDFs, and publishes its SOC 2 Type II with the auditing firm named as BARR Advisory and the examination scope stated.
In summary
Onspring
Onspring is a no code governance, risk and compliance platform used to build and run programmes without developer involvement, spanning risk, regulatory change, internal audit, policy authoring, control and framework mapping, third party and IT risk, ESG and business continuity, with a separate corporate counsel solution for in house legal departments. Onspring AI is an optional add on module extended into agentic operation in July 2026 under administrator defined rules. The AI Legal Index grades it in the top two bands on five of fifteen capability axes. It names Anthropic's Claude family as the models behind its AI, which few vendors do. As of 29 August 2026 the index located no customer agreement, no liability position and no residency statement.
Regology
Regology is an AI powered regulatory intelligence platform for compliance, legal and risk teams, built around a proprietary law library and three named agents covering regulatory change, compliance and research, identifying which laws apply to an organisation, monitoring bills, laws and agency updates in real time, and generating obligations, risks, controls and policies mapped to the source law across United States federal, all fifty states and international jurisdictions. The AI Legal Index grades it in the top two bands on six of fifteen capability axes. Every alert, decision, approval and rejection is timestamped and traceable to source, and its SOC 2 Type II names BARR Advisory as auditor. As of 29 August 2026 the index located no customer agreement, no named model provider and no residency statement.
Questions buyers ask
Do you need one of these or both?
Possibly both. Onspring is the system of record a team configures for its own programme, and Regology is deliberately not one, positioning itself as an intelligence layer that sits alongside existing GRC investments and naming ServiceNow, Archer and Hyperproof as systems it works with. The AI Legal Index places Regology in the top two bands on six of fifteen capability axes and Onspring on five, and the two are more naturally read as layers in one stack than as alternatives.
Who names what?
Each names what the other withholds. Onspring states that its AI runs on Anthropic's Claude family, which few vendors in this index do, and does not name the firm behind its SOC 2. Regology names BARR Advisory as its auditor and states the examination scope, and names no model, provider or hosting arrangement anywhere. A buyer running a vendor risk process will get half its answers from each. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What can you read before signing?
On neither. No terms of service, master agreement or data processing agreement was located on either property, so no liability cap, indemnity, warranty or training commitment is readable in advance, and the entire allocation of risk sits in a signed contract. Both publish a SOC 2 Type II attestation, and on neither is the report itself downloadable or offered through a stated request route. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What happens if a law is missed?
Nothing published on either record says. Both products decide which laws and obligations apply to an organisation, and the consequence of a miss falls on the customer as a regulatory breach rather than appearing as a visible error in a document. Neither publishes an applicability error rate, an evaluation or a test set, and neither publishes a liability position addressing who carries the loss. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What do Onspring and Regology both leave unpublished?
Neither publishes a price, though Onspring's structure is discoverable as scaling on users and modules with the AI licensed separately. Neither publishes a residency or tenancy statement. Neither publishes an AI governance position with any output behind it, or any evaluation of uneven performance across jurisdictions, industries or organisation types, which on an applicability engine is the question that decides whether a gap is systematic or random. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
The pair produces a symmetry worth naming: Onspring names the provider behind its AI and not the firm that audited it, while Regology names its auditor and its examination scope and no model or provider at all. Beyond that the gaps match. Neither publishes a customer agreement, so on neither record can a buyer read a liability position, an indemnity, a warranty on output or a training commitment before signing. Neither states a hosting provider, a region, a residency option or a tenancy model. Neither publishes an error rate for the task each is bought to perform, which on these products is applicability: the failure that matters is a law or an obligation that never surfaces, and a customer with no independent view of what should have been flagged cannot detect it. Onspring names an internal AI governance council and publishes nothing it produces; on Regology no governance position was located at all. Both records were verified on 29 August 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.