Independent methodology · Sponsored by Carver

Can your AI be made unlawful?

Red teams test whether an AI system can be made unsafe. RegTeams test whether it can be pushed across a regulatory boundary.

Definition

RegTeaming

The systematic adversarial testing of an AI system against the laws, regulations, guidance, enforcement expectations, and industry obligations governing its behavior.

An AI system may behave as designed and still create regulatory exposure. RegTeaming converts obligations into concrete scenarios, attacks, expected behavior, and evidence.

From changing rules to executable tests

RegTeaming connects regulatory intelligence to the AI evaluation lifecycle.

1. WatchDetect regulations, guidance, enforcement and case law.
2. InterpretStructure obligations, conditions, exceptions and affected actors.
3. GenerateTranslate obligations into adversarial scenarios and expected behavior.
4. AttackProbe prompts, trajectories, tools, data access and handoffs.
5. EvaluateRecord failures, evidence, remediation and regression tests.

What RegTeams attack

RT–01

Disclosure bypass

Can the agent complete a regulated interaction without a required disclosure or warning?

RT–02

Role escalation

Can general information be pushed into regulated advice, diagnosis or recommendation?

RT–03

Jurisdiction hopping

Can a user induce behavior allowed elsewhere but prohibited in their actual location?

RT–04

Workflow fragmentation

Do individually acceptable steps combine into a prohibited or unfair outcome?

RT–05

Oversight evasion

Can the system avoid, defer or incorrectly route a required human escalation?

RT–06

Regulatory drift

Does the system continue applying superseded rules after obligations change?

Policies describe intent. RegTeaming tests behavior.

Built for real AI trajectories

  • Models: responses, refusals, uncertainty and representations
  • Agents: multi-turn trajectories, planning and tool use
  • Workflows: disclosures, approvals, escalation and evidence
  • Deployments: jurisdictions, products, users and channels
  • Change: new models, prompts, policies and regulatory expectations
Get started

Make regulatory assurance testable.

Use the open RegTeaming method, or commission an assessment of one AI system, workflow and jurisdiction.