Inspiration

In 2023, a lawyer submitted a court brief written with ChatGPT — citing six cases that were completely invented. He was sanctioned. Now imagine the same failure mode, but the invented text is a paragraph of the GDPR. An AI tells your team "Article 27 requires this," and nobody checks. In compliance work, a hallucinated citation isn't embarrassing — it's a fine.

That's the gap every generic "AI compliance copilot" leaves open: they rely on the model promising to behave, with nothing actually enforcing it.

We set out to build the opposite: an agent that cannot save a non-compliant report in the first place. Not better prompting. Not a disclaimer buried in the output. A structural guarantee.

Who it's for: privacy officers and DPOs running GDPR vendor reviews, compliance leads handling HIPAA security assessments, small legal teams facing CCPA data-rights requests, and engineering teams who need agent behavior they can audit — not hope for.

What It Does

ComplianceCopilot is a single Strands agent on Amazon Bedrock, running Claude Sonnet 4.6 on AgentCore, that analyzes documents against GDPR, HIPAA, and CCPA checklists and drafts a structured compliance report. The difference: it cannot save a non-compliant report.

A request is one prompt plus the document itself, sent inline — nothing leaves your control to a third party. The prompt carries three parts: which document, which rules, what action (e.g. "Analyze this vendor agreement for GDPR Article 28 processor obligations, and save a report.").

Inside the agent loop:

Locate — the agent's search_clauses tool scans the document for candidate clauses using keywords drawn from the applicable regulation. Know — load_skills pulls the matching regulation's checklist on demand (a markdown skill file with exact article/section citations) — GDPR, HIPAA, or CCPA, whichever the request calls for. Judge — Claude compares each flagged clause against the checklist, mapping conflicts to a citation and a severity level (HIGH / MEDIUM / LOW) that's encoded directly in the skill file. Report — findings are compiled into a structured report (clause → quote → citation → risk → fix) with a compliance score and a "decision support, not legal advice" disclaimer.

Sitting on top of save_report are two deterministic gates — CitationGate and DisclaimerGate — implemented as Strands hooks. If the model tries to save a report with a fabricated citation or a missing disclaimer, the save is blocked, the violation is returned to the model as an error, and the agent self-corrects and retries automatically — same invocation, no human required. What lands on disk is a clean report plus a machine-readable .gates.json stamp: a timestamped audit trail proving both gates passed.

How We Built It Agent Orchestration: Built on the Strands Agents SDK, defining an agent loop over four modular Python @tool functions — read_document, search_clauses, load_skills, and save_report. Foundation Model: Amazon Bedrock running Anthropic Claude Sonnet 4.6, handling multi-step reasoning: locating clauses, applying the regulation's judgment rubric, and self-correcting when a gate rejects its output.

Deterministic Gates: ComplianceGates — a CitationGate and a DisclaimerGate — hook directly into save_report. They don't ask the model to be careful; they regex- and rule-check the actual output and refuse to persist anything that fails, forcing a block → fix → retry loop. Regulatory Knowledge: Three regulations as three swappable markdown skill files (skills/gdpr/SKILL.md, skills/hipaa/SKILL.md, skills/ccpa/SKILL.md), each a checklist of requirements with exact citations and severity mappings. Adding a fourth regulation is one new file — no code changes.

Runtime: The same agent runs locally and in the cloud via Amazon Bedrock AgentCore Runtime, with skills, gates, and tools packaged into the container so there are no external dependencies at inference time.

Evaluation Harness: A two-layer eval suite — 7 gate unit tests (evals/test_gates) that check the gates in isolation, and 4 end-to-end evals that seed a synthetic contract with known, deliberately planted violations and grade the agent's findings blind, using an independent LLM judge against an answer key. Stack: Strands Agents SDK · Amazon Bedrock (Claude Sonnet 4.6) · Amazon Bedrock AgentCore Runtime · Python.

Challenges We Ran Into Making misbehavior structurally impossible, not just less likely. It's easy to prompt a model to "always cite real articles and always add a disclaimer." It's much harder to guarantee it — so we moved the guarantee out of the prompt and into a deterministic gate the model cannot talk its way past. Designing a self-correction loop, not just a rejection. A gate that only blocks is a dead end. We had to feed the violation back to the model as a structured error it could act on, so the same invocation could drop the fake citation, add the missing disclaimer, and retry — without a human in the loop. Proving the judgment, not just the plumbing. Blocking a hallucinated citation is one thing; correctly identifying real violations across three differently-structured regulations (GDPR's numbered articles, HIPAA's named rules, CCPA's section symbols) is another. We built an eval harness with seeded, known violations and an independent LLM judge specifically so the accuracy claim wasn't the agent grading its own homework.

Keeping the architecture generalizable. We didn't want "add a regulation" to mean "write more code." Encoding each law's checklist and severity logic entirely inside a markdown skill file — rather than in the agent's Python — was what made GDPR, HIPAA, and CCPA feel like three instances of the same pattern instead of three special cases.

Accomplishments That We're Proud Of A gate that would rather block than be wrong. save_report BLOCKED on a fabricated GDPR Article 99 and CCPA §1798.999 citation, with zero hallucinated citations ever reaching disk — that's the whole thesis made concrete.

A self-correcting agent, not just a rejecting one. The same invocation drops the bad citation, adds the disclaimer, and retries automatically — no human intervention needed to recover from its own mistake. An eval-gated build. 7/7 gate unit tests and 4/4 end-to-end evals passing, with the end-to-end grade coming from an independent judge scoring against seeded, known violations — not the agent's own confidence.

A real audit trail. Every saved report ships with a timestamped .gates.json proving which checks passed, so "the agent said it was compliant" is backed by evidence, not just an assertion. One architecture, three regulations, zero code changes. GDPR, HIPAA, and CCPA all run through the same locate → know → judge → report pipeline, differing only in their skill file. What We Learned

Building ComplianceCopilot reinforced that the hardest part of a trustworthy agent isn't getting a foundation model to reason well — Claude Sonnet 4.6 already does that. It's building the machinery around the model that turns "probably behaves correctly" into "cannot misbehave." A deterministic gate the model has to satisfy, rather than a well-worded instruction it's asked to follow, is what actually earns a human's signature on the output. We also learned that self-correction only works if the failure is fed back as something actionable — a bare rejection just moves the problem, while a structured error lets the same agent loop fix itself in place.

What's Next for ComplianceCopilot Orchestrator + per-regulation specialist agents (agents-as-tools) — splitting the single agent into an orchestrator that routes to specialist sub-agents for each regulation, for deeper per-framework reasoning.

S3 document storage — moving from inline document payloads to durable, referenceable storage for larger document sets and repeat analyses. More regulatory frameworks — extending beyond GDPR, HIPAA, and CCPA by adding new skill files, proving the "one architecture, many regulations" claim at scale. Built With

Strands Agents SDK · Amazon Bedrock · Amazon Bedrock AgentCore · Anthropic Claude Sonnet 4.6 · Python

Built With

  • amazonbedrock
  • amazonbedrockagent
  • anthropicclaudesonnet4.6
  • python
  • strandsagentssdk
Share this project:

Updates

Submission history