4
4CRisk.ai
4CRisk.ai is a regulatory and compliance AI platform from 4CRisk.ai, Inc., founded in 2020 and acquired by CUBE in February 2026; its site says it is proud to join CUBE and continues to sell under its own name. Built on what it calls specialized language models trained on curated regulatory content, its products cover regulatory research across federal, state and international sources including the Federal Register, regulatory change management that scans more than 2,400 sources and flags affected obligations, policies and controls, Compliance Map, which maps policies and controls to obligations and finds duplicates, HorizonScan, and Ask ARIA, a copilot that answers compliance questions from regulations and a firm's own policies with links to highlighted source passages and a confidence score.
It serves chief compliance officers, regulatory affairs and legal professionals, and risk and security teams in banking, insurance, fintech, retail and technology. 4CRisk says customer data is not used to train its models, that its cloud environments are certified for SOC 2, and that it can run multi tenant, in a dedicated environment or in a customer's private cloud. Its terms of service are published; pricing is not.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The language models drive the core functions of a compliance platform built around regulatory content and workflow. 4CRisk describes specialized language models trained on curated regulatory and governance content, and the products run on them: regulatory research that builds rulebooks and obligations from authoritative sources, regulatory change management that scans more than 2,400 sources and recommends which policies and controls to review, Compliance Map, which maps internal policies and controls to obligations and finds duplicates, HorizonScan, and Ask ARIA, a copilot answering compliance questions.
Around the models sit rulebooks, obligation registers, impact assessment workflows, exports to PDF and Excel and review by subject matter experts, which would still organize compliance work without them. CUBE, which acquired 4CRisk in February 2026, describes the business as compliance and risk mapping automation. The models are the engine of the core capabilities rather than the whole product.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Answers and obligations are tied to their sources, and accuracy is asserted rather than measured. The Ask ARIA page says each answer is supported by clickable links to the source documents, presents the source with the relevant section highlighted, and shows a confidence score. The regulatory research page says rulebooks and obligations carry an audit trail to the original sources, and the change management page gives a confidence rating on what is or is not mapped.
The SLM page says the specialized models are less prone to the errors of general language models, and the platform page claims tasks performed up to 50 times faster than a human, with no test set, error rate or method behind either statement. Nothing describes how the currency of a cited rule is shown in an answer or how often mapping misses an obligation. A compliance lawyer can open the source behind an answer, and cannot test the accuracy claims.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Human review is built into the workflows, short of a stated control structure. The platform page says subject matter experts can review and override model predictions; the regulatory research page describes collaborative work in which experts identify and create the requirements; the change management page says the product supports an expert's judgment of criticality, priority and due date in the AI generated impact analysis; and Ask ARIA lets users review and vote on responses.
Confidence scores are shown on answers and mappings. What is not published is the threshold at which the system defers to a person, what the AI may not do unreviewed, or what happens after a mapping or answer is shown to be wrong. Section 8.2 of the terms leaves the client solely responsible for conclusions drawn from use of the services.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Awards and unattributed figures stand in for customer evidence. The about page says 4CRisk serves leading organizations in financial services, insurance, retail, telecom and other regulated industries, without naming one, and lists recognitions: RegTech100 for a second year, AIFinTech100, a Globee award, a Banking Tech Awards shortlisting in 2025, a Bank Automation News list of AI start ups to watch in 2025 and a Chartis Research best of breed placing in 2026.
The platform page claims 75% effectiveness in risk reduction, 85% efficiency improvement and 60% faster deployment, and the who we serve page claims 90% research time savings, with no customer, period or method. CUBE's acquisition release names no 4CRisk customer. No case study with a named customer is published.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Confidentiality is in the agreement and a no training statement is published, alongside a broad improvement license. Section 7 of the terms of service binds the parties to protect each other's confidential information. The platform page says customer data is not used to train 4CRisk's language models, and Ask ARIA is described as a closed domain knowledge base with role based retrieval. The SLM page says the platform keeps sensitive data within the enterprise and can be deployed in a customer's infrastructure or private cloud.
Against that, the terms grant 4CRisk an irrevocable, transferable, sublicensable, royalty free license to use, copy, store, modify and display user content, including to provide, maintain and improve the services, and the no training commitment is not in the terms. Privilege and work product are not addressed.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
A responsibility clause sits in the terms while the product is marketed as giving reliable answers to compliance questions. Section 8.2 of the terms of service says the client assumes sole responsibility for conclusions drawn from use of the services, and the services are provided as is. No statement that output is not legal advice, no eligibility rule and no supervision guidance is published. Ask ARIA is described as giving immediate, reliable answers to complex compliance questions and accurate, up to date information, and the product is addressed to regulatory affairs and legal professionals, compliance officers and front line staff.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance position on the AI is published. Checked the home, platform, SLM, Ask ARIA, regulatory research, change management, who we serve and about pages and the terms: none names a person accountable for model behavior, describes testing before release, publishes evaluation results, or sets out principles. The SLM page explains why specialized models are chosen and claims fewer errors than general models, which is a design rationale rather than governance.
Uneven output is a live question for models mapping obligations across federal, state and international regimes and several industries, and nothing published addresses it.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Security practices are described in general terms, and retention, deletion and subprocessors are not. The SLM page describes zero trust principles, penetration testing and SOC 2 for 4CRisk's private cloud deployments, the platform page says the cloud environments are certified for SOC 2, and Ask ARIA uses role based retrieval in a closed domain knowledge base. The terms require the client to stop use and return materials on termination and say nothing about deletion of customer data.
The privacy policy covers the website and keeps personal data as long as needed. No retention period for uploaded policies, prompts or outputs, no subprocessor list and no breach notice commitment is published.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A vendor indemnity and a mutual cap are published, and output risk sits with the client. The terms of service provide in section 10.2 that 4CRisk defends the client against third party claims that the services infringe intellectual property rights and pays resulting costs and attorneys' fees, and in section 11 cap either party's aggregate liability at the fees paid in the twelve months before the claim. Section 8.1 provides the services as is without warranty, section 8.2 makes the client solely responsible for conclusions drawn from use, and section 10.1 has the client indemnify 4CRisk for third party claims.
California law governs. Nothing allocates the loss when a missed obligation or a wrong answer leads to a compliance failure.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integration capability is described without naming a system. The platform page says the platform supports integration with business systems, content providers and third parties through a REST API architecture, and supports standard exports to PDF and Excel. No GRC platform, document management system, policy management tool or other named connection is published on the home, platform, products, regulatory research, change management or Ask ARIA pages read, and no API documentation is public.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The tenancy options are stated and no region is. The platform page says the platform can run in a multi tenant environment, in a dedicated environment or in the customer's private cloud, and names AWS and Google Cloud among the clouds it says it is certified on. The SLM page says the specialized models can be deployed within a company's infrastructure or a private cloud. The privacy policy says personal data may be transferred to and kept in the United States.
What is not stated is the region of the multi tenant service, where the models run in that service, or whether customers can choose a country.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
SOC 2 is stated without type, auditor, date or a route to the report. The home page lists AICPA SOC 2 certification, the platform page says 4CRisk's cloud environments are certified for SOC 2, and the SLM page mentions SOC 2, penetration testing and zero trust principles for private cloud deployments. No report type, period, auditor or request route is published, and no trust center is published on the home, platform, SLM or about pages read. A buyer has a named standard to ask about and must ask for the evidence.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The models are described as 4CRisk's own and nothing is said about what sits underneath. The SLM page describes specialized language models trained on curated regulatory content and governance data from the public domain, deployable within a customer's infrastructure, and the platform page says customer data is not used to train them. No base model, model provider, version or change notice is named on the SLM, platform, Ask ARIA or about pages, and no third party model provider is mentioned on any page read. A firm cannot tell whether a foundation model from another provider underlies the specialized models.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level. Checked the home, free evaluation, holiday offer and products pages and the terms: no price, plan, tier or unit of charge appears. The terms say fees are paid in advance monthly, quarterly or yearly, which describes billing frequency rather than what is charged. The free evaluation covers Regulatory Research, Compliance Map and Regulatory Change Management after a registration review, with no stated length or price after it.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Who 4CRisk serves is described with substance, and the boundaries are not. The who we serve page addresses chief compliance officers, regulatory affairs and legal professionals, chief risk officers, security and IT risk teams and front line staff, in banking, insurance, fintech, retail and high tech and telecom. Regulatory research covers US state and federal bodies, including the Federal Register, and international bodies, and change management scans more than 2,400 sources across more than 50 document types.
CUBE's release adds corporate compliance areas including cyber, AI, privacy, labor law and ESG. What is not stated is which countries and regulators outside the United States are covered, and which regulatory domains are deep and which are thin.
8 public documents
The public pages on file for 4CRisk.ai, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.
-
4crisk.ai/aria-platform2 signals
Client Data in Training, Outside Counsel Guideline Readiness
Read Oct 2, 2026
-
4crisk.ai/ask-aria2 signals
Ethical Walls and Matter Segregation, Refusal and Uncertainty Behavior
Read Oct 2, 2026
-
4crisk.ai/regulatory-research2 signals
Primary Law Corpus Provenance, Court Disclosure Support
Read Oct 2, 2026
-
4crisk.ai/terms-and-conditions2 signals
Prompt and Output Retention, Bar Guidance Alignment
Read Oct 2, 2026
-
4crisk.ai/privacy-policy1 signal
Third Party Request and Subpoena Notice
Read Oct 2, 2026
-
Good Law Verification
Read Oct 2, 2026
-
4crisk.ai/who-we-serve1 signal
Billing and Fee Posture
Read Oct 2, 2026
-
Fabricated Citation Record
Read Oct 2, 2026
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A public policy or trust page states no training on customer content, with no matching term located in the published agreement.
The platform page states that customer data is not used to train 4CRisk's language models. The terms of service do not name training; they grant 4CRisk an irrevocable, transferable, sublicensable license to use, copy, store, modify and display user content to provide, maintain and improve the services, so the no training position sits in a product page rather than the agreement.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
No located material states how long uploaded policies, questions or AI outputs are kept or when they are deleted. The terms require the client to return materials on termination and say nothing on deletion, and the privacy policy covers website personal data. Checked the terms, the privacy policy and the platform pages on 2 October 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is asserted in public materials with no published detail on how it is enforced.
Ask ARIA is described as using a role based information retrieval system in a closed domain knowledge base, and the SLM page says the platform keeps sensitive data within the enterprise and restricts data sharing through configuration. No published detail describes how roles map to business units, matters or teams or how retrieval enforces them.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data.
The privacy policy, which covers the website, says 4CRisk may disclose personal data in the good faith belief that it is necessary to comply with a legal obligation, with no notice commitment. The terms of service do not address legal demands for customer content. Checked the terms and the privacy policy on 2 October 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the license or rights basis.
Sources are described by issuer and count. The regulatory research page names the Federal Register among US state, federal and international bodies, the change management page says more than 2,400 sources of rules, regulations and laws are scanned, and the SLM page says the models learn from regulations, rules, laws and standards in the public domain. No full list of sources is published and the basis for any content beyond public domain material is not stated.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
The vendor computes and surfaces subsequent history itself, with the method described.
Currency is tracked by the product itself. The change management page says it captures changes to laws, regulations, rules and standards across more than 50 document types from alerts and authoritative sources, scans more than 2,400 sources, maps applicability to the organization and recommends which policies and controls to review. How an answer in Ask ARIA shows that a cited rule has changed is not described.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
The product exposes a confidence or grounding score without an explicit abstention path.
Ask ARIA shows a confidence score with each response, and change management gives a confidence rating on what is or is not mapped. No located material describes an explicit path where the system declines to answer or says its sources do not cover a question.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.
No court order, opinion or disciplinary record naming 4CRisk as the source of fabricated authority was located as of 2 October 2026. The AI Hallucination Cases database maintained by Damien Charlotin returned no cases for 4CRisk.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No located material refers to professional responsibility, bar guidance or ethics opinions. Section 8.2 of the terms makes the client responsible for conclusions drawn from use, without reference to legal or professional duties. Checked the home, who we serve, Ask ARIA and platform pages and the terms on 2 October 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.
4CRisk is sold to compliance, risk and legal teams inside regulated companies for their own obligations, so no lawyer to client fee is in the loop. Its savings claims, including 90% research time savings for Ask ARIA, are aimed at the buyer's own cost.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
No subprocessor list, model provider disclosure or client facing security pack is published, and the SOC 2 report is not offered on any page read. Checked the home, platform, SLM and privacy pages and the terms on 2 October 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Some elements of a record exist for regulatory work. The regulatory research page describes an audit trail from obligations to the original sources, Ask ARIA links each answer to highlighted source passages with a confidence score, and experts can review and override model predictions. No record of which model produced an output and no export documenting AI use and human verification for a regulator or court is described.