System 04 AI / regulated systems
AI for regulated operations
Turning rules into executable systems: rules as data, data as controls, controls as evidence, AI where the output is checkable.
- Principle
- Regulation should become executable.
- Context
- Regulated companies
Governance
AI ActModel scopeHuman reviewTraceabilityProblem
In a regulated company, an obligation lives in prose and the product lives in code. The gap between them is filled by people, spreadsheets and memory.
That gap is where control failures happen: not because nobody knew the rule, but because nothing in the system was responsible for it.
The work here is to close the gap in one direction only. Regulation becomes executable; the system never becomes the interpreter of the law.
Regulation as data
Regulation should become executable.
An obligation is decomposed into its testable parts: what must be true, of what object, at what moment, and what evidence demonstrates it. Those parts are data with an owner and a version, not paragraphs in a document.
Governance
AI ActModel scopeHuman reviewTraceabilityRules
A rule references the data it needs, states the condition, and names the consequence. Because it is data, it can be listed, diffed, tested and dated, which is what makes an internal control system reviewable at all.
- Versioned
- Owned
- Testable
- Dated
- Traceable to a source
Controls
A control is a rule that runs. It runs on a schedule or on an event, it produces a result, and the result is stored with the inputs that produced it.
Evidence
Controls should produce evidence.
Evidence that is assembled at the end of a quarter is not evidence, it is reconstruction. When a control produces its own record, an audit becomes a query rather than a project.
AI in the loop
Where a model is allowed to decide, and where it is only allowed to draft.
LLMs and agents are used where the output is checkable: extracting structure from documents, drafting a procedure, mapping a text to existing rules, preparing a report, summarising a case for a human decision.
They are not used as the authority on a regulated outcome. Anything with a consequence keeps a human decision and a recorded reason.
| Task | AI role | Human role |
|---|---|---|
| Document analysis | Extraction and structuring. | Validation |
| Rule mapping | Proposes candidate rules from a text. | Approval |
| Documentation | Drafts and keeps it current. | Ownership |
| Reporting | Assembles and checks consistency. | Sign-off |
| Regulated decision | None. | Decides and records why |
Governance and the AI Act
The EU AI Act is read as a system specification: scope, classification, documentation, human oversight, logging and traceability.
Read that way, most of it is architecture rather than paperwork, which is the point of the second Blackgrade principle.
- Scope
- Classification
- Documentation
- Human oversight
- Logging
- Traceability
Automation and reporting
Once rules, controls and evidence share one data structure, reporting is a projection of it. The same structure answers a supervisor, an auditor and an internal review without producing three versions of the truth.
Limits
Stated plainly, because they matter more than the capabilities.
- A model is not a legal interpretation
- Automation cannot fix an ambiguous obligation
- Evidence without a schema is just storage
- A control nobody owns will silently rot
Lessons learned
The systems that hold up are the ones where a rule, its control and its evidence are the same object seen from three angles.
Contact
Turning rules into systems?
Fintech, regulated infrastructure, AI, cryptography or complex digital platforms.