Key facts
| Core jobs | Map controls, collect evidence, draft responses, flag gaps |
| Grounding | Retrieval over policy and regulation corpora with citations |
| Boundaries | Read-only by default; no autonomous filings or attestations |
| Human review | Draft-first output signed off by the compliance owner |
| Audit | Every retrieval, draft and edit logged with trace IDs |
| Residency | Region choice plus VPC, on-prem and air-gapped deployment |
| Access | Scoped keys and RBAC so the agent sees only what it should |
| Status | Embeddings, RAG, function calling and audit logs are live |
TL;DR
- Draft, map and flag — never file, attest or delete autonomously.
- Ground every statement in a cited source; uncited output is a defect.
- Read-only access to evidence stores, with scoped keys and RBAC.
- Log retrievals, drafts and reviewer edits so the trail is audit-ready.
- Keep the corpus fresh; stale policy text produces confident wrong answers.
How it works, step by step
- Define the frameworks, policies and control sets the agent must work against.
- Index authoritative sources with version and date metadata, and a re-index process.
- Expose read-only tools: control lookup, evidence search, document retrieval and gap listing.
- Require citations for every mapping or claim, and separate quoted text from interpretation.
- Draft outputs — gap reports, evidence summaries, response drafts — for human sign-off.
- Log every retrieval, draft and edit with trace IDs, and store drafts with their sources.
- Measure accuracy against a labelled control set before the agent touches real reviews.
Try it yourself
Open the EU AI Act compliance checker →
What a compliance agent should and should not do
Compliance work is largely reading, mapping and documenting, which is exactly what a grounded agent does well. It can search a regulation, locate the matching internal policy, point at the evidence and draft the paragraph. That removes hours of manual cross-referencing per control.
What it must not do is act as the accountable party. It should not submit filings, attest to accuracy, approve exceptions or delete records. Those remain with named humans. Making this boundary explicit in the design — read-only tools, draft-only outputs — is what makes the agent acceptable to auditors rather than risky.
Architecture: grounded, cited, read-only
- Corpus: regulations, standards, internal policies and past audit responses, versioned and dated.
- Retrieval: hybrid search over the corpus with metadata filters by framework and jurisdiction.
- Mapping tools: structured lookups of controls, owners and existing evidence.
- Citations: every claim returns source IDs and quoted spans the reviewer can open.
- Permissions: the agent's identity can read evidence, never write or approve.
- Output contract: structured drafts with gaps and open questions clearly marked.
Treat the corpus as the source of truth. If a document is not indexed with a version and date, the agent should say so rather than improvise.
Review, evidence and audit trails
The reviewer's workflow matters as much as the agent's. A useful draft reduces review to verification: each statement links to a source, gaps are listed explicitly, and uncertainty is flagged rather than smoothed over. Track how often reviewers change drafts and feed those edits back into prompts and retrieval settings.
For regulated and sovereign environments, the entire pipeline benefits from staying inside a controlled boundary. Plugsky provides region-locked deployment plus VPC, on-prem and air-gapped options, with scoped keys, RBAC and audit logging on the live API, and embeddings, RAG and function calling for grounded retrieval. 30+ models behind one OpenAI-compatible key let you use a strong model for interpretation and a cheap one for extraction. Plans are on the live pricing page; files and batch endpoints are coming soon.
Honest comparison
| Task | Agent role | Human role | Risk if automated |
|---|---|---|---|
| Control mapping | Draft mapping with citations | Verify and approve | Misclassification |
| Evidence collection | Locate and summarise | Confirm validity | Stale or wrong evidence |
| Gap analysis | Flag likely gaps | Prioritise and own | Missed nuance |
| Response drafting | Produce a cited draft | Edit and sign | Inaccurate attestation |
| Filing and attestation | Must not act | Accountable owner | Legal and regulatory exposure |
Frequently asked questions
Can a compliance agent replace auditors?
No. It accelerates evidence gathering, mapping and drafting. Accountability, judgement and sign-off stay with qualified people.
How do I prevent hallucinated citations?
Return source IDs and quoted spans from retrieval, require citations for every claim, and make the evaluation set penalise uncited statements. If retrieval finds nothing, the agent must say so.
What data should the agent reach?
Only the evidence, policies and documents needed for the task, under a read-only scoped identity. It should never have write access to the compliance system itself.
How do I keep the corpus current?
Version documents at ingestion, store effective dates, re-index on change, and let the agent filter by date. Surface the document date in every citation.
Is this acceptable for auditors?
A read-only, cited, logged pipeline with human sign-off is materially easier to defend than ad-hoc research. Keep traces of what the agent retrieved and what reviewers changed.
Can it run in a sovereign environment?
Yes. Plugsky supports region choice, VPC, on-prem and air-gapped deployment, so policy and evidence data can stay inside the required jurisdiction.
How do I measure quality?
Build a labelled set of controls with known correct mappings and evidence, and score retrieval precision, citation validity and reviewer edit rate.