Skip to main content
Regurai
Legal & transparency
Home
Public transparency documentVersion 1.0Last updated: 13 June 2026

Regurai AI Policy

Version: 1.0 | Last updated: 13 June 2026


1. Regurai Public AI Policy

(Trust-Focused, Human Readable, Marketing Safe)

1.1 What Regurai is

Regurai is an Enterprise AI Governance and Operational Intelligence platform designed for regulated organisations operating in complex, high-assurance environments.

We help organisations govern, deploy, and scale artificial intelligence with confidence, control, and accountability—transforming governance from a compliance obligation into a strategic capability.

Our platform brings together:

  • AI governance
  • Compliance automation
  • Operational risk intelligence
  • Audit-grade oversight

into one integrated control environment.

1.2 How AI is used in Regurai

Regurai uses AI in limited, controlled ways to support governance workflows.

AI Assistant (Regur)

Regur is an AI assistant that:

  • explains governance and compliance concepts
  • supports training and onboarding
  • helps users understand regulatory frameworks

It does not:

  • make legal, financial, or regulatory decisions
  • access live production systems or customer transactions
  • replace human judgement

All responses are advisory and must be verified by authorised users.

Customer-connected AI systems

Customers may connect their own AI models to Regurai to:

  • monitor decisions
  • track risk signals
  • support governance and audit workflows

Regurai does not control these models. The customer is responsible for:

  • lawful use
  • model accuracy
  • decision-making outcomes

Regurai provides oversight tools, not automated decision authority.

1.3 Human oversight

All meaningful decisions must involve human review.

Regurai does not replace human judgement in:

  • compliance decisions
  • risk decisions
  • regulatory reporting
  • operational approvals

AI outputs are always subject to review by authorised personnel.

1.4 Data protection and privacy

We follow strict data protection principles:

  • data minimisation — only required data is processed
  • encryption in transit and at rest
  • tenant isolation — no cross-customer access
  • role-based access controls

Regurai does not sell personal data or use it for advertising.

1.5 Transparency and limitations

AI systems may:

  • produce incorrect or incomplete outputs
  • reflect limitations in underlying data
  • require human verification before use

Regurai is designed to support decision-making — not replace it.

1.6 User rights

Depending on applicable law, individuals may:

  • access their data
  • request correction or deletion
  • object to certain processing
  • request human review of decisions

Requests can be submitted via the relevant organisation using Regurai.

1.7 Updates

This policy is reviewed regularly and may change as the platform evolves.


2. Regurai Legal AI Governance Policy

(Operational, Compliance, Audit, Procurement Version)

2.1 System classification

Regurai is an AI governance and operational intelligence system supporting regulated decision environments.

It is classified as:

  • Limited-risk AI system (Regur Assistant)
  • High-assurance governance support system (customer decision monitoring)
  • Operational risk intelligence platform (anomaly and audit workflows)

Regurai does not operate fully autonomous decision-making systems with legal or similarly significant effects.

2.2 System architecture and AI components

2.2.1 Regur Assistant

  • Provider: Google Gemini (via AI Gateway)
  • Purpose: informational support only
  • Restrictions:
    • no live system access
    • no decision authority
    • no autonomous action capability

2.2.2 Customer AI Integration Layer

Regurai ingests:

  • model outputs
  • decision logs
  • risk scores
  • audit metadata

Regurai does not:

  • validate model correctness
  • override customer models
  • determine legal basis for processing

2.2.3 Anomaly & risk intelligence

Outputs are:

  • probabilistic indicators
  • advisory signals only
  • subject to mandatory human review before action

2.3 Data protection roles

Controller / Processor model

  • Customer = Data Controller (default for operational data)
  • Regurai = Data Processor (for customer data processing)
  • Regurai = Independent Controller (for platform security and account data)

All processing is governed by a Data Processing Agreement (DPA).

2.4 Prohibited AI use

Regurai prohibits use of its platform for:

  • fully automated legal or financial decisions without human oversight
  • behavioural manipulation or social scoring
  • unlawful profiling or discrimination
  • biometric inference without lawful basis
  • covert inference of sensitive attributes

2.5 Human oversight requirements

All high-impact workflows must include:

  • documented human reviewer
  • ability to override AI output
  • recorded rationale for decisions
  • segregation of duties

AI outputs are advisory and must not be used as sole decision basis.

2.6 Model governance framework

All AI systems must be recorded in a Model Governance Register including:

  • model name and version
  • provider (e.g. Google Gemini)
  • purpose and intended use
  • risk classification
  • data categories processed
  • approval status
  • monitoring owner
  • audit history

No model may be deployed without governance approval.

2.7 Data handling and retention

Data is:

  • encrypted in transit and at rest
  • logically isolated per tenant
  • access-controlled via RBAC

Retention periods:

  • defined per deployment contract
  • enforced via retention policies and deletion workflows

No default retention period is implied unless contractually agreed.

2.8 Incident management

Regurai maintains a formal AI incident response framework.

Incident types

  • data breach
  • model failure or drift
  • unsafe or incorrect AI output
  • prompt injection or exploitation
  • cross-tenant data leakage

Response process

  • detection
  • containment
  • investigation
  • notification (where required)
  • remediation and rollback

Regulatory notification timelines apply where legally required.

2.9 Monitoring and assurance

Regurai monitors:

  • model performance drift
  • override rates
  • fairness indicators (where applicable)
  • system latency and availability
  • security guardrail events

Material changes require re-approval before deployment.

2.10 Compliance mapping

This policy supports alignment with:

  • UK GDPR & Data Protection Act 2018
  • EU AI Act (risk-based classification approach)
  • ISO 27001 (information security controls)
  • ISO 42001 (AI management system principles)
  • NIST AI Risk Management Framework
  • UK ICO AI guidance

This is not a certification statement.

2.11 Governance accountability

Roles

  • Product Owner: responsible for system design and intended use
  • Security Owner: responsible for security controls and monitoring
  • Data Protection Officer: responsible for privacy compliance
  • Customer Owner: responsible for model usage and decisions
  • Human Reviewer: responsible for all consequential decisions

2.12 Policy enforcement

  • All AI systems must be approved before deployment
  • All changes require re-assessment
  • Policy is version-controlled and auditable
  • Non-compliant use must be suspended immediately