# What this is about This piece explains a practical operating model for using generative AI in regulatory-change work without letting the model make legal conclusions. The objective is to accelerate mechanical tasks—collecting authoritative source metadata, extracting obligation elements, surfacing missing facts, and producing remediation plans—while keeping applicability, interpretation, regulator communication, and risk acceptance inside explicit human authority boundaries.
# Why source-state matters
- Issuing authority (who produced the material)
- Instrument type (statute, rule, guidance, order, decision)
- Legal status (proposed, final, delayed, superseded)
- Publication date
- Effective date
- Version or amendment state
- Official source status (authoritative vs. convenience copy)
- Pinpoint citation
- Verification date
- Language
# The evidence-pipeline workflow
- 1Ingest and validate the source record with the metadata above.
- 2Extract provisions and decompose each into discrete obligation records.
- 3For each obligation, create an applicability record that lists the triggers (e.g., revenue threshold, customer-location test) and which organizational facts are required to evaluate them.
- 4Identify unresolved applicability facts and surface them as explicit data gaps—do not fill them.
- 5Map confirmed obligations to controls, tests, evidence, owners, and remediation tasks.
- 6Produce an implementation plan with owners, deadlines, and evidence requirements.
The model's role is structuring and surfacing uncertainty: it should not invent missing numbers, assume applicability, or conflate guidance with binding law.
# Roles and decision boundaries Define responsibilities so the system never substitutes for legal judgment: counsel resolves legal interpretation and communications with regulators. Compliance confirms applicability after human fact verification. Technical and product owners convert confirmed requirements into controls, tests, and monitored implementation work. Risk acceptance, certification, and regulator negotiation remain explicit human actions.
# Practical prompt outputs you should expect
- A validated source record including all metadata fields above.
- A list of decomposed obligation records with unique IDs and citations back to the source record.
- Applicability records per obligation that enumerate required organizational facts and flag missing items.
- A control-mapping table: obligation ID → control ID → owner → test → evidence needed.
- A remediation task list with owners, estimated effort, dependencies, and compliance or effective dates.
- Audit trail entries showing when and by whom each fact or interpretation was verified.
# Bottom line Use AI to automate traceability, decomposition, and implementation planning. Require the AI to surface gaps and retain uncertainty. Keep legal applicability, interpretation, regulator engagement, and risk acceptance explicitly human-led and auditable. This preserves defensibility while reducing the mechanical burden of regulatory-change work.