Norm Ai
Regulatory AI agent company converting laws, regulations and corporate policies into executable compliance agents for large regulated enterprises, with a concentration in financial services covering SEC, FINRA and CFPB rules. Regulations are represented through a proprietary Norm Regulatory AI Domain Specific Language as decision trees that a human can read and a machine can execute, so an agent traverses the tree, reaches a compliance determination and states which provision drove it. Built on LEAP, the Legal Engineering Automation Platform, a no code environment in which Legal Engineers, former attorneys given intensive LLM training, build, evaluate and deploy agents without software engineers, alongside structured reasoning frameworks, proprietary prompt optimisation and automated evaluation pipelines. Use cases cover regulated content review across marketing, investor relations and internal communications, questionnaire and information request completion grounded in approved firm content, contract review, and supervisory agents that monitor other AI systems such as chatbots and content generators for compliance. Founded by John Nay, previously at Stanford's Center for Legal Informatics and a co author of the LegalBench benchmark. Backed by Vanguard, Blackstone, Bain Capital, Citi, TIAA and Coatue, with $267m raised. In 2026 the company launched Norm Law, which it describes as the first fully AI native law firm for institutional clients, chaired by the former chairman of Sidley Austin.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The artificial intelligence is the product and the company is organised around building it. Regulations are converted into executable AI agents through a proprietary domain specific language, agents traverse decision trees to reach compliance determinations, and the entire platform, LEAP, exists to build, evaluate and deploy those agents. The vendor describes itself as the Regulatory AI agent company. Remove the models and nothing remains but a representation of regulations with no ability to apply them. Notable in structure as well as capability: the company created a job function, Legal Engineer, specifically to build AI agents, staffed by former attorneys given intensive language model training, which is an organisational commitment to the model layer rather than a feature investment.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real, architecturally enforced and documented, short of published measurement. The mechanism is unusual and specific: regulations are encoded through a proprietary domain specific language into decision trees that a human can read and a machine can execute, and an agent traverses that tree step by step to reach a determination rather than generating an answer from model memory. The vendor states every determination carries an explanation, identifying what may be problematic and under which regulation, so a compliance team can see the legal basis for the outcome and what would need to change. Because the reasoning path is the encoded regulation itself, the output is traceable to a provision rather than to a retrieved passage, which is a different and arguably stronger form of grounding than citation. LEAP is stated to include automated evaluation pipelines, so evaluation is built into the deployment process. What is missing is the result: searched the platform pages, the resources section, the company blog and the trust centre on 29 Aug 2026 and located no accuracy figure, no error rate, no test set, no published evaluation methodology and no independent benchmark participation, notwithstanding that the founder co authored a widely used legal reasoning benchmark.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A real published commitment with a described division of labour, short of thresholds. The vendor states the operating model plainly: an agent conducts the initial compliance review of, for example, marketing communications against SEC or FINRA rules, and a human professional then reviews the findings and completes the determination. That allocates the decision rather than asserting human involvement. Supporting surfaces are described: explanations attached to every determination, and collaboration tooling through which teams tag each other, review AI judgments and centralise decision history. Oversight is also a staffing structure, with Legal Engineers building and supervising the agents and adjusting them to client specific guidelines. The vendor is separately building supervisory agents that monitor other AI systems for compliance, which is an oversight product rather than an oversight policy. Not located as of 29 Aug 2026: any threshold at which an agent defers, what it does when a determination is genuinely ambiguous, and what the vendor commits to when a determination is wrong.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Institutional signals stand in for deployment evidence. The vendor references a client meeting with a top ten global asset manager in published material describing a Legal Engineer's working day, and states a focus on Fortune 100 customers, but no customer is named. Investor composition is unusually informative for this market and is recorded as context rather than evidence: Vanguard, Blackstone, Citi and TIAA are strategic investors from the regulated industries the product serves, which indicates institutional validation without demonstrating a deployment. Searched the platform pages, the resources section, the company blog and the news announcements on 29 Aug 2026 and located no named customer paired with figures and a date, no case study with an assessable method, and no adoption count.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Confidentiality is asserted through a trust programme without the specific commitments this axis tests being reached. Published on the trust centre: a stated commitment to rigorous security practices including SOC 2 compliance, continuous monitoring, and a company wide culture of data protection. That is a general assurance rather than a set of terms. Searched the trust centre, the platform pages, the resources section and the company blog on 29 Aug 2026 and located no statement on whether customer content may be used to train or improve models, no retention or deletion terms, no segregation model between customers, and no treatment of privilege or work product. The material at issue is unusually sensitive even by this index's standards: the platform reviews internal communications, draft marketing and investor materials, and agreements before they are issued, so it sees regulated firms' content at the point where a compliance problem would still be undisclosed. The trust centre renders client side and its control detail was not retrieved in this pass, which is where these terms would sit if published.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The most structurally distinctive answer to this axis on the index, though not a written position. The vendor addresses the boundary between software and legal advice by building on both sides of it: the platform performs compliance analysis for enterprises, and in 2026 the company launched Norm Law, which it describes as the first fully AI native law firm for institutional clients, chaired by the former chairman of Sidley Austin and recruiting partners. Legal advice is therefore delivered by a law firm with admitted attorneys while the software delivers analysis, which is a real separation rather than a disclaimer. The operating model reinforces it: an agent performs initial review and a human professional completes the determination, and in the law firm context an experienced attorney decides what happens next. The team includes former regulators including a former SEC Commissioner. Short of an A because none of this is published as a position on the advice line: searched the platform pages, the resources section and the company site on 29 Aug 2026 and located no statement on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits. The structure answers the question; the vendor does not.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A governance framework with real substance embedded in how the product is built, short of certification, published results and bias disclosure. Several elements are genuine mechanisms rather than principles. LEAP is stated to include automated evaluation pipelines as part of taking agents into production, so evaluation is a gate rather than an afterthought. Every determination carries an explanation, and the decision tree representation is human readable, so an agent's reasoning is auditable by a lawyer without reading code, which is a design decision with governance consequences. Legal Engineers build and supervise agents and maintain them as regulations change. The company also builds supervisory agents to monitor other AI systems against laws and policies, and convenes a forum on AI, law and policy involving legislators and regulators. Not located as of 29 Aug 2026: an AI management certification such as ISO 42001, a named accountable owner for model governance, published evaluation results as distinct from the existence of pipelines, and any disclosure about uneven output across firms, content types or populations.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
A general security posture is stated without operational detail being reached. Published on the trust centre: SOC 2 compliance, continuous monitoring, and a company wide culture of data protection and integrity. A trust centre exists at a stable URL on a recognised compliance platform, which is a self serve route. Searched the trust centre, the platform pages and the company site on 29 Aug 2026 and located no retention period, no deletion control, no encryption specifics, no access control detail, no named subprocessor list, no hosting provider or region, and no incident or breach notification practice. Recorded at C on the stated certification and monitoring rather than lower. The trust centre renders its contents client side and they were not retrieved in this pass, so this row is rebuttable and the portal is the single place to look.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Searched the platform pages, the resources section, the company blog, the news announcements and the trust centre on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer terms of service was located as published on the property. Recorded as a pure absence on the surfaces reached. The shape is worth naming because it is unusual: this product makes compliance determinations about content a regulated firm is about to publish, so a wrong determination can result in a regulatory finding against the customer rather than merely a bad draft. That is a materially different exposure from most records on this index, and nothing published addresses who carries it. Note also that the adjacent law firm entity would carry professional liability of its own, which the software vendor's silence does not cover.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integration is described at workflow level without named connectors. The vendor's stated design is compliant by design, embedding compliance checks into business activities rather than running them separately, covering AI generated content, internal communications, agreements, marketing content and sales materials, and the platform is described as monitoring workflows and alerting when something drifts out of compliance. That implies connection into the systems where those artifacts are produced. Searched the platform pages, the resources section and the company site on 29 Aug 2026 and located no integrations page, no named connector for content management, communications archiving, document management or customer relationship systems, and no API documentation. For a product whose value depends on intercepting content before it is published, the absence of a named integration surface is the notable gap.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Searched the platform pages, the resources section, the company site and the trust centre on 29 Aug 2026. Nothing was located on the deployment model: no hosting provider, no named regions, no customer selectable residency, no tenancy model, and no statement of where processing happens as distinct from where data is stored. The product is evidently cloud delivered, which is inference from how it is sold and earns nothing on this axis. The absence carries weight for this buyer specifically, since the customer base is regulated financial institutions for whom data location is frequently a supervisory requirement rather than a preference.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
A trust centre exists and the certification is claimed without scope or evidence. Published: a trust centre at a stable URL on a recognised compliance automation platform, stating a commitment to rigorous security practices including SOC 2 compliance and continuous monitoring. Existence of the portal is a real self serve route and is more than several records here offer. What was not located as of 29 Aug 2026: whether the SOC 2 is Type 1 or Type 2, any coverage period, any audit scope, any report date, any named auditing firm, any other certification, and any published request flow for the report. The trust centre renders its contents client side and they were not retrieved in this pass, which is a limitation of the research method rather than a finding about the vendor, and is recorded as such. Rebuttable in one step by reading the portal contents.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The architecture is described in detail and the model layer is not identified. Published: agents are described as language model driven, traversing decision trees encoded in the vendor's proprietary domain specific language, with proprietary prompt optimisation and structured reasoning frameworks in LEAP. A buyer therefore understands that the regulatory logic is the vendor's own and that a general purpose model executes against it, which is a clearer architectural picture than most records provide. Searched the platform pages, the resources section, the company blog and the trust centre on 29 Aug 2026 and located no named model or model provider, no statement of where models run, no subprocessor list, and no commitment to notify customers when the model supply chain changes.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the platform pages, the solutions pages, the resources section and the company site on 29 Aug 2026. No pricing page was located, no rate is published, no unit of charge is stated and no tier structure appears. Every commercial path located terminates in a request for a personalised demo. No free trial or self serve entry point was located, and no third party pricing figure was located either. Consistent with the enterprise sales model implied by a customer base of large regulated institutions, and consistent with the pattern across this index for vendors selling to that segment.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described with substance and the regulatory focus is named at source level. Regulatory scope is stated concretely through the regimes the Legal Engineers track and encode: SEC, FINRA and CFPB, with GDPR referenced in comparison material, and the vendor states the approach generalises to anything a company is subject to rather than being limited to those regimes. The buyer is the large regulated enterprise, with chief compliance officers named as the primary role and financial services the evident concentration given the investor base and the named regimes. Functional coverage is enumerated by workflow: regulated content review across marketing, investor relations and internal communications, questionnaire and information request completion, contract review, and supervision of other AI systems. Not located as of 29 Aug 2026: an enumerated industry list beyond financial services, organisation size segmentation, jurisdictional coverage outside the United States, and any statement of what the platform is not built for.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way.
Searched the trust centre, the platform pages, the resources section and the company blog on 29 Aug 2026. No located material states whether customer content may be used to train or improve models, either way. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction. The question has particular weight here because the vendor describes LEAP as creating a compounding layer of institutional judgment that captures firm specific standards and continuously improves how those standards are applied, which is a learning claim about firm specific material without a statement of whether that learning is confined to the firm it came from. The trust centre renders client side and was not retrieved in this pass; it is the most likely location of a training position.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
Searched the trust centre, the platform pages, the resources section and the company site on 29 Aug 2026. No public material states how long submitted content, compliance determinations, explanations or decision history are retained, whether a customer controls the window, or whether deletion is available. The product centralises decision history as a feature, so accumulation is by design rather than incidental, and the retained record includes determinations that content was non compliant before it was corrected, which is exactly the material a regulated firm would want governed by explicit terms.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
Searched the trust centre, the platform pages, the resources section and the company site on 29 Aug 2026. No vendor material addresses segregation between customers, users or business units. The question is live for this buyer type: a large financial institution operates information barriers between deal teams, research and trading as a regulatory requirement rather than a preference, and this platform reviews internal communications and investor materials across the firm. Nothing located states whether agents, determinations or decision history respect those barriers. Collaboration tooling is described in terms of teams tagging each other and centralising decision history, which points toward shared visibility rather than compartmentalisation, though nothing states either.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data.
Searched the trust centre, the platform pages, the resources section and the company site on 29 Aug 2026, and no published customer agreement or data processing agreement was reached. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The exposure is distinctive: this platform holds records of compliance determinations, including determinations that a regulated firm's content failed a rule before it was fixed, which is precisely the material a regulator or plaintiff would seek. Nothing published addresses what the vendor would do on receiving such a demand.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the licence or rights basis.
Sources are named at regulator level and the maintenance process is described, which is more than most records manage, though no licence basis is stated. The corpus is the body of regulation itself, and the vendor names where it comes from: Legal Engineers review regulatory updates from sources including the SEC, FINRA and CFPB and identify relevant changes for the agents, with regulatory logic built and maintained inside LEAP as laws change. That is a named source set plus a described currency process, and the currency process is staffed rather than automated, which is unusual. What is not stated is the rights basis, though United States federal regulations are public domain so the licence question that this signal exists to probe largely does not arise. Also not located: a jurisdiction by jurisdiction coverage list, a completeness statement for any regime, or a stated lag between a rule change and the agent being updated.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Searched the platform pages, the resources section and the company blog on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this product's corpus is regulation rather than case law, so a citator in the conventional sense is outside its design. The functional equivalent for a regulatory product is whether the encoded rule is current, and the vendor does address that, describing Legal Engineers reviewing regulatory updates and maintaining the decision trees as laws change. That is a currency mechanism for its own corpus rather than a treatment signal on cited authority, and the two were not conflated.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Searched the platform pages, the resources section, the company blog and the trust centre on 29 Aug 2026. No published material describes what an agent does when a determination is genuinely ambiguous or when the encoded rule does not reach the situation presented, and no explicit no answer path or confidence signal exposed to the user was located. The decision tree architecture makes this a sharper question than usual rather than a softer one: traversal is designed to terminate in a compliance determination, so what happens at a node the tree does not anticipate is a real design question. The published human review step, where a professional completes the determination, is where such a case would presumably surface, but nothing states that the agent flags uncertainty rather than resolving it.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note the characteristic failure here would not be a fabricated citation but a wrong compliance determination on content that was then published, which would surface as a regulatory enforcement matter rather than in a hallucination database, and would in most cases name the regulated firm rather than the software.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
Searched the platform pages, the resources section, the company blog and the news announcements on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512 and state bar guidance. Recorded as an absence with an unusual qualification: this company launched a law firm in 2026, describing it as the first fully AI native law firm for institutional clients and appointing a former Sidley Austin chairman to lead it. A law firm is directly bound by the professional conduct rules this signal asks about, so the question moves from whether the vendor engages with guidance to whether an entity subject to it publishes its position. Nothing located does. Also recorded: the company convenes a forum on AI, law and policy involving legislators and regulators, which engages with policy formation rather than with the existing conduct rules binding its users.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
No located public material addresses billing, fee or disclosure treatment.
Searched the platform pages, the solutions pages, the resources section and the company blog on 29 Aug 2026. No per matter record of AI assisted work intended for fee purposes was located, and no guidance on billing, fee or client disclosure treatment was located. No quantified time or cost savings claim was located either, the vendor's published framing being coverage and speed of compliance analysis rather than hours displaced, so there is no savings claim to weigh against a client's side of the equation. Recorded as not addressed rather than at the savings claims value for that reason. Noted for a future pass: the adjacent law firm entity bills institutional clients directly, and how AI assisted work is treated in those fees is a live question that no located material addresses.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The material exists behind a sales conversation or an executed agreement.
A trust centre exists at a stable URL on a recognised compliance platform, stating SOC 2 compliance and continuous monitoring, which is a real self serve route to whatever diligence material sits behind it. Searched the trust centre entry point, the platform pages and the company site on 29 Aug 2026 and located no subprocessor list, no statement naming which model providers see customer content, no published data processing agreement, and no client facing consent or notification material. Recorded at on request on the strength of the portal existing rather than at the subprocessor value, because the portal renders its contents client side and they were not retrieved in this pass, so what a requester would actually receive is unestablished.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Substantial elements of a defensibility record exist and are central to the product rather than incidental. Every determination carries an explanation identifying what is problematic and under which regulation, the decision tree encoding each rule is human readable so the reasoning path itself is inspectable by a lawyer without reading code, and decision history is centralised with human review recorded through the collaboration tooling. A regulated firm asked by a supervisor to justify why content was cleared would have the rule applied, the path taken, the explanation given and the human who signed off. Two elements are missing: no single per document export combining those with the model used was located, and no model is identified in published material so the model used could not be stated. Recorded at partial record. Noted for context: the relevant forum here is a regulatory examination rather than a court, and this is among the better positioned records on the index for that particular demand.