CUBE

CUBE is an automated regulatory intelligence platform for financial institutions, built to turn unstructured regulatory text into obligations mapped to a particular firm. CUBE RegPlatform is sold in two editions, an enterprise version aimed at the largest institutions and an Intel version for the mid-market, and the platform monitors regulatory change across what the company states as more than 750 jurisdictions, classifying and contextualising rules and obligations by sector and jurisdiction so that compliance teams can track impact and manage change in one place. The technology is presented in unusual detail under the name RegAI, a proprietary framework the company says is trained exclusively on regulatory data. Its architecture runs in three layers: computer vision models convert document images into machine-readable content and recover the document hierarchy from headers to footers; a proprietary language model called RegLM applies deep natural language processing to translate, classify and contextualise regulatory text, fine-tuned for entity extraction, citation extraction, document type classification, obligation identification and summarisation; and graph machine learning places the enriched content into a regulatory knowledge graph that drives recommendations from user behaviour. RegBrain exposes that stack, including agentic AI, summarisation, classification and enrichment, for customers to apply to their own content through APIs or a user interface, and a separate Content Infrastructure offering supplies the underlying regulatory content. CUBE publishes six stated AI principles covering explainability, human input, semantic understanding, scale, security and sustainability. The company is CUBE Content Governance Global Limited, based at Tower 42 in London, reports more than 1,000 customers across banking, insurance, asset and investment management and payments, and announced the acquisition of Silicon Valley regtech 4CRisk for compliance and risk mapping automation.

Vendor siteLondon, United Kingdom
Last verifiedSeptember 1, 2026

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models are the engine of the capability being sold, on a content business that would survive without them. RegAI is described as a proprietary regulatory AI framework trained exclusively on regulatory data, and the enrichment it performs, turning unstructured regulatory text into obligations mapped to a firm's risk profile, is what a buyer is paying for rather than the raw feed. The architecture is real and staged: computer vision to recover document structure, a proprietary language model for classification and extraction, graph machine learning over a regulatory knowledge graph. What would remain if the models were removed is nonetheless substantial and is in fact sold separately: CUBE lists Content Infrastructure as its own solution, meaning the underlying regulatory content across a stated 750-plus jurisdictions is a saleable asset in its own right, alongside change workflow and the platform's tracking and reporting. That is the B shape. Third consecutive vendor in this lane at this grade, which is beginning to look like the shape of regtech rather than a coincidence.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

The method is documented more fully than anywhere else in this lane and no figure is attached to any of it. CUBE names its architecture layer by layer: computer vision converting text images to machine-readable content and revealing structural components from headers to body paragraphs to footers; deep NLP and a proprietary model called RegLM fine-tuned for entity extraction, citation extraction, document type classification, obligation identification and summarisation; and graph machine learning placing enriched content into a knowledge graph. Citation extraction as a named capability and the grounding of output in the source regulatory instrument mean a reader can reach the underlying text. Explainability is claimed as a product property, with advanced visualisation and interpretability tools said to show how AI decisions are made. The gap is measurement. RegAI is said to reduce noise by filtering out irrelevant updates, false positives and missed obligations, which names the two error types that matter here and attaches a rate to neither, and no benchmark, test set or accuracy figure was located on any surface read on 1 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Two real review mechanisms are published and the control structure around them is not. The first is inspection: CUBE states that it uses advanced visualisation techniques and interpretability tools to show users how AI decisions are made, offering transparency into model logic and reasoning, which is a described surface a compliance officer can open rather than a claim that a human is involved somewhere. The second is correction: real-time user feedback loops within the platform are said to refine and improve AI performance over time, and RegAI is described as learning from a customer's past decisions and becoming more aligned with its processes. What is missing is the rest of the structure. Nothing states what runs unattended, what threshold causes the system to defer, or what happens after an assessment is wrong. Worth separating one claim that does not carry weight here: the Human Input principle describes data scientists working with regulatory specialists to guide model development, which is a development practice rather than a runtime checkpoint in a customer's workflow.

Source: Vendor Published
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

A large scale claim stands in for evidence and nothing under it is attributable. The home page states more than 1,000 customers across financial services including banking, insurance, asset and investment management and payments, and describes CUBE as the global market leader on multiple metrics, with no source, method or named institution behind either statement. No customer logo strip, named reference or dated deployment appears on any page read, and no figure for what changed at any customer was located. A Case Studies category exists in the Resources section and **was not opened on 1 September 2026**, so a named, dated outcome was neither located nor excluded and this grade is rebuttable upward on one fetch. The acquisition announcements and market-position claims that do appear are corporate news rather than deployment evidence. Checked the home page, the Technology and AI page, the privacy policy and the full site navigation.

Source: Vendor Published
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Confidentiality is asserted in general terms and every question this axis asks is unanswered. The strongest statement located is on the Technology and AI page, where CUBE says that given the sensitivity of client data it has implemented security at three levels, backend access to its services, frontend access, and the data pipeline, and that all user data in the cloud is fully anonymised. That is a real architectural claim and it is not a confidentiality commitment a buyer could hold. No position on training customer content was located, which matters because RegBrain is expressly sold as applying CUBE's AI stack to a customer's own content. No retention or deletion commitment for that content exists, no segregation between customers or users is described, and no data processing agreement is published. The privacy policy, recovered through the R8 ladder, covers the website, the RegTrend app, events and recruitment, so it does not reach the platform relationship. **There is no customer agreement of any kind on the property**, so nothing published could be read as a commitment in advance.

Source: Vendor Published
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Nothing published addresses the advice line for a product that produces regulatory interpretation. There is no terms of service, terms of use, master agreement or customer agreement anywhere on the property: the footer's Company section lists a privacy policy, a cookie policy and a separate RegTrend privacy policy, and nothing else. No statement was located that the output is not legal advice, that CUBE is not a law firm, that no professional relationship is created, or that a user should take professional advice on their own facts. No jurisdiction limit is named, and nothing addresses the supervision or competence of the person relying on the output. This matters because of who CUBE says the product is for: the home page names Risk and Legal Teams as an audience and states that CUBE gives legal teams the clarity they need to interpret the data and assess impact, which is interpretive work delivered to a professional audience with no published advice-line position behind it. Searched the home page, the Technology and AI page, the solutions and sectors navigation, the privacy policy in full and the complete footer on 1 September 2026.

Source: Operator Verified
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Six principles are published and nothing behind them is auditable. Under the heading of how it approaches the use of artificial intelligence, CUBE sets out explainability, human input, semantic understanding, built for scale, security and sustainable AI, and the content is more specific than the usual adjective list, describing interpretability tooling, feedback loops, models tuned exclusively on regulatory and legal data, three levels of security and a deliberate choice of smaller curated training datasets to reduce carbon footprint. What is absent is everything that would let a buyer test it. Nobody inside CUBE is named as accountable for model behaviour, no pre-release testing regime is described, no external standard is claimed, with no ISO 42001, no EU AI Act commitment and no third-party assurance located, and **nothing at all is published about uneven output**, which is a notable silence for a system whose core function is deciding which obligations are relevant to which firm, where a systematic miss is the failure that matters. The explainability tooling and feedback loops are real mechanisms but they are product features and are credited on the oversight row rather than counted twice here.

Source: Vendor Published
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

A website privacy policy covers the marketing relationship without addressing what happens to customer content after processing. What is published, from the policy recovered through the ladder and dated 6 June 2026 at version 1.2: access to personal data restricted to staff, agents and contractors with a business need, all bound by confidentiality and acting only on instruction; procedures for suspected personal data breaches with a commitment to inform both the individual and the relevant supervisory authorities where legally required; retention only as long as reasonably necessary, with deletion or anonymisation afterwards; and transfers outside the UK and EEA under safeguards recognised by the relevant jurisdiction. Against that, no retention period is stated anywhere, no subprocessor list exists with third parties identified only as categories such as service providers and business partners, and the policy's own scope is the website, the RegTrend app, events and recruitment rather than the platform. Nothing published states what happens to the obligations mappings, impact assessments or customer content a firm places in RegPlatform, or to the content a customer submits to RegBrain.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Nothing published addresses who bears the loss when the system is wrong, because no agreement of any kind exists on the property. The complete footer offers a privacy policy, a cookie policy and a separate RegTrend privacy policy; there is no terms of service, no terms of use, no master subscription agreement, no service agreement and no data processing agreement. That is a more complete absence than the website-terms-only pattern seen elsewhere in this corpus, where at least a scoped disclaimer exists. No indemnity, liability cap, carve-out, warranty on output or insurance position was located, and no disclaimer of accuracy or completeness attaches to the regulatory intelligence itself. The only risk allocation located anywhere is a single line in the privacy policy stating that transmission of information over the internet is at the user's own risk, which concerns data in transit rather than the correctness of an obligation mapping. Searched the full footer, the home page, the Technology and AI page and the solutions navigation on 1 September 2026.

Source: Operator Verified
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

An integration route is stated and no destination system is ever named. RegBrain is described as delivering CUBE's full AI stack, including agentic AI, summarisation, classification and enrichment, either as APIs or through a user interface, so that customers can apply it to their own content, which establishes that a programmatic route exists and says what travels through it. A Partnering with CUBE page and a Content Infrastructure solution both imply that the regulatory content is designed to feed systems elsewhere. What is absent is anything an implementer could act on: no API reference or developer documentation was located, no integration directory exists in the site navigation, and not one GRC, risk, policy or document platform is named anywhere on the surfaces read, which is the same gap seen at Corlytics and a weaker position than AscentAI, which names five GRC partners on its home page. Checked the home page, the Technology and AI page, the solutions navigation and the footer on 1 September 2026.

Source: Vendor Published
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Cloud delivery is stated and neither the tenancy model nor a region is. The Technology and AI page says the models are deployed via cloud and scale with demand, and adds that all user data in the cloud is fully anonymised, but nothing names a hosting provider, a data centre location, a country or region option, or whether customers share infrastructure or receive a dedicated environment. No processing location is addressed separately from storage. The only geography published sits in the privacy policy and concerns personal data rather than platform content, stating that data may be transferred to group companies and service providers outside the United Kingdom and the European Economic Area or other local jurisdictions, with appropriate safeguards recognised by the relevant jurisdiction, and naming no specific mechanism. For a vendor selling to Tier 1 banks across a stated 750-plus jurisdictions, where data residency is routinely a procurement gate, that is a conspicuous silence. Checked the home page, the Technology and AI page, the privacy policy and the full navigation on 1 September 2026.

Source: Vendor Published
DD on Security Certifications and Trust CenterNo independent security attestation located.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

No independent security attestation was located anywhere. There is no security page, no trust centre and no compliance page in the site navigation, which was read in full on 1 September 2026 across the solutions, sectors, resources and company sections. No ISO 27001, SOC 2, ISO 42001 or equivalent is claimed on the home page, the Technology and AI page, the privacy policy or the footer, and no badge, certificate, auditor or report request route appears. The Technology and AI page does carry a Security principle, and it is the natural place a standard would be named: it describes security implemented at three levels covering backend access, frontend access and the data pipeline, and states that all user data in the cloud is fully anonymised, but it names no framework and no assessor. The privacy policy adds appropriate technical measures and breach procedures in general terms. **This is a striking absence rather than a routine one**, given a vendor of this scale selling to the largest regulated institutions, and it is recorded as what the public surfaces show rather than as a claim about what CUBE holds.

Source: Operator Verified
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The architecture is disclosed in more detail than anywhere else in this lane and the third-party question is left open. CUBE names its own components: RegAI as the framework, **RegLM as a proprietary language model** fine-tuned for translation, classification and contextualisation, and RegBrain as the stack exposed to customers. It describes what each layer does, computer vision for document structure recovery, deep NLP for extraction and classification, graph machine learning over a knowledge graph, and states that the models are tuned exclusively on regulatory and legal data and deployed via cloud. That is architecture described with the vendor's own models named, which is the second limb of this band. What is not answered is whether any third-party foundation model is called at any point: no external provider is named, no statement excludes one either, and RegBrain is said to include agentic AI, which usually implies a general-purpose model somewhere in the chain. No commitment to notify customers when the model set changes was located.

Source: Vendor Published
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

No pricing information is published at any level, including the unit of charge. The site navigation was read in full on 1 September 2026 and contains no pricing entry; every commercial route on every page read is a demo request or a Speak to an expert form. No rate, band, floor, currency or per-seat, per-jurisdiction or per-obligation unit was located, and nothing states what implementation adds, which is material for a platform whose value depends on building a firm-specific obligations map. The only commercial shape visible anywhere is the split of CUBE RegPlatform into two editions aimed at different customer sizes, one for Tier 1 institutions and an Intel edition for the mid-market, which segments the market without pricing it. Those two edition pages were not opened, so if either carries a feature split or a figure this grade is rebuttable upward.

Source: Operator Verified
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Coverage is described with real substance across three separate axes and the boundary is left open. CUBE segments its sectors pages by industry, by requirement and by department, which is a more deliberate structure than most vendors publish, and names its industries as banking, insurance, asset and investment management, payments and associated industries. Firm size is addressed explicitly rather than implied, with RegPlatform split into an enterprise edition for Tier 1 institutions and an Intel edition for the mid-market, and audience is broken out into compliance leaders, financial services enterprises, and risk and legal teams. Regulatory scope is quantified at more than 750 jurisdictions and illustrated with named regimes including GDPR, DORA, MiFID II, SOX, FCA and FSB material. What is not stated is where the product stops: no statement of the practice areas, sectors or obligation types the platform does not cover was located, and outside financial services the coverage claim is left to the phrase associated industries.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Terms silent

No located term or policy addresses the question either way.

No located term or policy addresses the question either way, and there is no agreement on the property in which a commitment could sit. The silence is pointed rather than routine because RegBrain is expressly sold as applying CUBE's AI stack to a customer's own content through APIs, so customer material demonstrably enters the system. The two nearest statements do not answer it: the Technology and AI page says the models are tuned exclusively on regulatory and legal data, which describes the training corpus without excluding customer content from future training, and separately says that all user data in the cloud is fully anonymised, which is a handling claim rather than a training prohibition. The privacy policy covers the website, the RegTrend app, events and recruitment and does not reach platform content. Searched the home page, the Technology and AI page, the full privacy policy and the complete footer on 1 September 2026.

Source: Operator VerifiedAs of Sep 1, 2026

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Not addressed

No located public material states how long prompts and outputs are retained.

No located public material states how long customer inputs or generated outputs are kept, and no configurable or zero-retention option is described. The only retention statement published is in the website privacy policy and is qualitative rather than periodic: personal data is kept only as long as reasonably necessary for the purposes it was collected for, including legal, regulatory, tax, accounting and reporting requirements, with longer retention where a complaint or prospective litigation exists, and deletion or anonymisation once it is no longer needed. That is scoped to personal data and to the website and app relationship. Nothing addresses the obligations mappings, impact assessments or submitted content that make up the platform record. Searched the privacy policy in full, the Technology and AI page and the footer on 1 September 2026.

Source: Operator VerifiedAs of Sep 1, 2026

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Not addressed

No located public material addresses walls or matter level segregation.

Nothing located addresses segregation between customers, teams or users. The nearest statement is architectural rather than about permissions: the Technology and AI page describes security implemented at three levels, backend access to services, frontend access to services and the data pipeline, and states that all user data in the cloud is fully anonymised. That describes where controls sit and how data is handled in aggregate, not who can see what inside a customer account. The privacy policy limits access to CUBE staff, agents and contractors with a business need, which governs the vendor's own people rather than the customer's. Nothing states whether RegAI classification or the knowledge graph respect any customer-side boundary at query time, which is a live question because the graph is described as drawing on user data to recommend content. Searched the Technology and AI page, the privacy policy and the solutions navigation on 1 September 2026.

Source: Operator VerifiedAs of Sep 1, 2026

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Not addressed

No located term or policy addresses third party requests for customer data.

Disclosure to authorities is described and notice is not addressed at all. The privacy policy provides that CUBE may occasionally pass parts of personal data to authorities where obliged to disclose in order to comply with a legal obligation, to enforce its terms and other agreements, or to protect the rights, property or safety of its customers or others, including sharing with other companies and organisations for fraud protection, and states that it discloses only what is legally necessary. No commitment to notify the customer before or after such a disclosure appears, and no discretion over notice is even reserved, which distinguishes this from the comparable clause at Corlytics where the vendor at least commits to take legal advice and weigh the individual's interests first. No transparency report exists, and the clause is scoped to personal data rather than to platform content. Searched the privacy policy in full and the footer on 1 September 2026.

Source: Operator VerifiedAs of Sep 1, 2026
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Jurisdictions only

Coverage is described by jurisdiction with no identification of the underlying corpus.

Coverage is quantified by jurisdiction and the underlying corpus is never identified. CUBE states surveillance across more than 750 jurisdictions and illustrates scope with named regimes including GDPR, DORA, MiFID II, SOX, and material from the FCA and FSB, describing its input as unstructured regulatory data transformed into actionable intelligence. No regulator feed, publisher, data supplier or licensing arrangement is named anywhere on the surfaces read, and no update cadence is published beyond the claim of real-time and 24/7 surveillance. Content Infrastructure is sold as a distinct solution, so the corpus is a commercial asset in its own right, which makes its provenance a more material question here than for a vendor that only consumes public sources. Checked the home page, the Technology and AI page and the solutions navigation on 1 September 2026.

Source: Vendor PublishedAs of Sep 1, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Own treatment signal

The vendor computes and surfaces subsequent history itself, with the method described.

The regulatory analogue is the product's core function, and it is described less concretely than at the two lane peers. CUBE monitors regulatory change across a stated 750-plus jurisdictions on a continuous basis and maps what has changed to the obligations a firm holds, so the platform is computing and surfacing the subsequent state of a rule over its own corpus rather than licensing a treatment service. Impact analysis and mapping are named as automated capabilities. Two limits belong on the record. **No version comparison or redlining feature was located**, unlike AscentAI and Corlytics which both publish side-by-side old-versus-new rule views, so a user's ability to see exactly what changed is not evidenced. And the currency of the corpus is asserted through the words real-time and 24/7 rather than through any stated lag between a regulator publishing and the platform reflecting it.

Source: Vendor PublishedAs of Sep 1, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

Nothing located describes what the system does when it cannot classify or map reliably, which is the question the category editorial makes decisive. No abstention path, confidence score, relevance threshold or coverage indicator is published for classification, obligation identification or summarisation. CUBE names the two failure modes in passing, saying RegAI reduces false positives and missed obligations, without describing what a user sees when either is possible. The explainability tooling comes closest and answers a different question: interpretability tools showing how an AI decision was made give transparency about a decision the system did reach, not a signal that it could not reach one. Searched the home page, the Technology and AI page including the six AI principles, and the solutions navigation on 1 September 2026.

Source: Operator VerifiedAs of Sep 1, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on the product names RegPlatform and RegAI. No court order, opinion or disciplinary record naming CUBE or its products was located. This is a statement about the public record rather than a finding about the product. The failure mode fits obliquely: the output is a regulatory classification or obligation mapping consumed inside a compliance function rather than a citation filed with a court, so the analogous exposure would be a missed or misattributed obligation surfacing during a supervisory examination rather than in a filing.

Source: Operator VerifiedAs of Sep 1, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No engagement with professional responsibility or ethics guidance was located, and no document exists on the property in which it could sit. There is no terms of service, no professional responsibility statement and no ethics page; the footer offers only a privacy policy, a cookie policy and a separate RegTrend privacy policy. Nothing references ABA Formal Opinion 512, Law Society or SRA guidance, or any regulator statement on the use of AI within a compliance or legal function. Nor is there a general acknowledgement that the user's own professional obligations survive use of the tool, which several vendors in this pull do publish. This sits against a home page that names Risk and Legal Teams as a target audience. Searched the home page, the Technology and AI page, the sectors navigation, the privacy policy in full and the complete footer on 1 September 2026.

Source: Operator VerifiedAs of Sep 1, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure.

Efficiency claims are central to the marketing and billing is never addressed. The home page is built on reducing risk and increasing efficiency, and the Technology and AI page states that RegAI saves valuable time and effort otherwise spent sifting through information, reduces the cognitive load on the compliance team and eliminates reliance on manual tasks. Nothing accompanies that on how AI-assisted regulatory analysis should be billed or disclosed. The buyer here is an in-house compliance or legal function rather than a firm billing a client, so the question lands obliquely, but it is not absent: nothing addresses the position where an adviser uses the platform on a client's behalf, and no per-matter or per-assessment record of AI-assisted work is described that would support such a disclosure.

Source: Vendor PublishedAs of Sep 1, 2026

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Not addressed

No located public material supports a client side disclosure obligation.

Nothing that would support a client-side disclosure obligation is published, and the reason is a distinction worth recording. CUBE names its own models with unusual specificity, RegAI, RegLM and RegBrain, and states they are tuned exclusively on regulatory and legal data. **Naming your own model is not the same as answering whether anyone else's model sees the content**, and that question is left open: no third-party provider is named, no statement excludes one, and RegBrain is said to include agentic AI. No subprocessor list exists, with third parties identified in the privacy policy only as categories such as service providers and business partners. No data processing agreement, consent pack or client-facing disclosure material is published and no route to request one was located. Under the coverage test this fails, since a firm cannot state which systems touch its content. Searched the Technology and AI page, the privacy policy in full and the complete footer on 1 September 2026.

Source: Operator VerifiedAs of Sep 1, 2026

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

Some elements exist and no document-level export is described. Two things point the right way. The platform is marketed on the ability to centralise, streamline and audit-proof an entire regulatory framework at scale, so an activity record for examination purposes is claimed. And the explainability tooling is directly relevant to this signal in a way it is not for most vendors, since interpretability tools showing how an AI decision was made are part of what an AI-use disclosure would need to contain. What is missing is the export and the attribution: nothing states that the record identifies which outputs were machine-generated, which model produced them, what corpus was drawn on, or who reviewed them, and no per-document extract is described. As with the other vendors in this lane the artifact is built for a supervisor rather than a court. Checked the home page, the Technology and AI page and the solutions navigation on 1 September 2026.

Source: Vendor PublishedAs of Sep 1, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 1, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746