RegOps
RegOps is a secure multi-agent system that turns regulatory changes into evidence-backed findings, approved actions, deterministic revalidation, and complete audit trails on Google Cloud.
The problem
When a regulation changes, organizations rarely have one clean system for understanding its operational impact. Teams must read the new document, identify obligations, search through policies and cases, determine what may be affected, propose corrective work, obtain approval, and later prove what was changed.
This process is slow, fragmented, and difficult to audit. Giving an AI agent unrestricted authority would create a different problem: uncertain findings could lead directly to consequential actions.
RegOps addresses both sides of this challenge. It automates the investigative workflow while keeping evidence, deterministic verification, policy controls, and human approval at the center.
RegOps does not make legal determinations. It identifies potential operational conflicts and prepares them for qualified human review.
What RegOps does
A user submits a synthetic regulatory PDF. RegOps creates a durable processing run and moves it through a controlled state machine covering intake, extraction, mapping, verification, approval, execution, revalidation, completion, and recovery.
Specialized agents perform separate responsibilities:
- The Regulation Analyst extracts structured obligations and connects every material claim to evidence in the source document.
- The Impact Investigator compares verified obligations with a synthetic organizational corpus containing contracts, policies, and cases.
- A deterministic verification layer checks identifiers, citations, bindings, severity inputs, and evidence integrity before findings become authoritative.
- The Action Controller applies a strict allowlist and decides whether a finding should create a review task, apply a controlled tag, or prepare a draft amendment.
The analytical agents cannot approve decisions, mutate authoritative records, or execute amendments.
Consequential amendments pause at a human-approval checkpoint. Before approval, RegOps runs the proposed action against an isolated shadow state and shows which findings would be resolved, which would remain, and whether new conflicts would appear.
If the amendment is approved, RegOps executes it only in the controlled shadow environment and performs deterministic revalidation before completing the run. If it is rejected, the run completes without execution, the original finding remains open, and the rejected action is excluded from completed and executed-action records.
Main features
- Multimodal regulatory PDF intake
- Exact SHA-256 change detection
- Evidence-linked obligation extraction
- Synthetic contract, policy, and case investigation
- Severity-ranked findings with transparent score components
- Strict separation between analytical agents and action authority
- Allowlisted actions only
- Human approval for consequential amendments
- Shadow-state counterfactual previews
- Direct, non-executing rejection path
- Deterministic post-action revalidation
- Durable checkpoints and recoverable failures
- Idempotency protection against repeated actions
- Authoritative transition history
- Downloadable audit reporting
- Accessible, responsive interface with keyboard navigation, live status regions, reduced-motion support, and text-plus-icon status indicators
How we built it
The frontend uses React, TypeScript, Vite, and a contract-aligned API layer. It provides run monitoring, finding exploration, evidence inspection, approval controls, counterfactual results, recovery information, and audit reporting.
The backend uses Python and FastAPI with strict request validation and a frozen OpenAPI contract. Firestore stores authoritative workflow state, transitions, checkpoints, findings, approvals, actions, idempotency claims, and audit records. Cloud Storage keeps source documents and audit packages private. Google Workflows coordinates durable long-running execution.
The system uses atomic transactions for intake metadata, approval-required action creation, approval decisions, and pending-approval enforcement. Reviewer identity is assigned by the backend rather than accepted from the client.
[VERIFY BEFORE SUBMISSION: The deployed worker uses the Agent Development Kit and Google GenAI SDK with Gemini 3.5 Flash. It runs through Google Agent Runtime and is registered through Agent Registry. Agent Identity limits access, Model Armor inspects untrusted inputs and model outputs, and content-safe observability records operational traces without storing source text or model reasoning.]
Data sources
The demonstration uses an explicitly synthetic regulatory-change scenario based on overseas-recruitment fee controls.
Its corpus contains:
- A synthetic regulatory PDF
- Synthetic obligations extracted from that document
- Synthetic contracts
- Synthetic organizational policies
- Synthetic worker cases
- Synthetic findings, proposed actions, and approval records
No real worker records, private customer documents, personal information, or production legal decisions are used. Shared corpus records remain immutable; proposed amendments operate on isolated shadow copies.
Security and reliability
RegOps was designed to fail closed.
Model-generated output is treated as a candidate, not authoritative state. Deterministic services verify it before persistence. The frontend cannot supply reviewer identity. Analytical agents receive no mutation or approval tools. Actions must match an explicit allowlist, and duplicate execution is prevented through deterministic idempotency claims.
The workflow records every transition and supports checkpoint-based recovery from sanitized failures. Source documents remain private, signed audit links are short-lived, and sensitive URLs and document contents are excluded from logs.
Challenges
The hardest part was not generating text with an AI model. It was deciding where model authority must end.
We had to design clear boundaries between probabilistic analysis and deterministic operations, preserve exact relationships across runs, prevent duplicate actions, ensure a rejected amendment never appears as executed, and make recovery possible without repeating completed work.
Another challenge was keeping the frontend demonstration realistic while preserving the same identities, lifecycle rules, and approval semantics used by the persistent backend.
What we learned
Long-running agents need more than prompts and tools. They need authoritative state, checkpoints, idempotency, transaction boundaries, ownership rules, and a clear recovery model.
Human approval is also more than an Approve button. The reviewer must see the exact finding, proposed action, evidence, and counterfactual result associated with the decision. If those bindings cannot be verified, the interface must disable the decision.
We also learned that model output becomes safer and more useful when it is narrow, structured, evidence-linked, and checked by deterministic code before it can affect a workflow.
What we are proud of
RegOps demonstrates an end-to-end agent workflow rather than a chatbot interface. It can detect change, investigate impact, recommend controlled work, pause for authorization, preview consequences, recover from failure, prevent duplicate execution, and produce an audit trail.
The same state and safety rules apply across the interface, API, persistence layer, orchestration system, and agent boundary.
What comes next
Future work includes expanding the evaluation corpus, measuring citation precision and finding recall, adding trusted production reviewer authentication, testing recovery under larger workloads, and adapting the evidence-verification framework to additional regulatory domains.
Built With
- adk
- ai
- armor
- artifact
- build
- cloud
- fastapi
- firestore
- gemini
- genai
- iam
- model
- playwright
- pydantic
- python
- react
- registry
- run
- sdk
- storage
- typescript
- vercel
- vertex
- workflows
Log in or sign up for Devpost to join the conversation.