Regulatory

Built against the regulatory horizon.

We do not ask desks to take a young vendor on faith, and we do not hand out our technology to prove ourselves. What we show instead is where the rules are going and what the system already implements for each. The full mapping is available as a memo, and the architecture is reviewed live with the firm's security function under NDA.

I.

Three frameworks, three implementations.

EU AI ACT Regulation (EU) 2024/1689 · high risk obligations phasing in from August 2026
What the framework asks: risk management, logging, transparency to deployers, human oversight, and record keeping for AI systems that touch consequential decisions. What the system implements: append only logs of every model interaction that produces a supervisory artifact, a human decision maker on every trade by design, full in tenant auditability of the engine's predictions and their grades, and documentation written for the deployer's own conformity work.
SEC RECORD KEEPING Exchange Act Rule 17a-4 as modernized October 2022 · Advisers Act Rule 204-2(a)(7)
What the rules ask: electronic records preserved in systems that permit viewing, download, and audit, and preservation of communications relating to recommendations and advice, a perimeter enforcement has been widening since 2022. What the system implements: sealed, exportable evidence chains for every decision, retained inside the firm's own storage under the firm's retention policy, in a format built for examination rather than reconstructed for it.
ALLOCATOR ODD AIMA DDQ standard · AI governance now on most institutional checklists (industry ODD analyses, 2025)
What allocators ask: whether the manager holds a formal policy on AI usage within the investment process, and how that usage is governed and evidenced. What the system provides: the answer as an artifact. A documented governance posture, role separated oversight surfaces, and a contemporaneous record of supervised decision making that no other layer of the stack can produce.

Bloomberg and Charles River do not publish their internals, and neither do we. What a serious vendor owes a serious counterparty is not source code. It is evidence of understanding the obligations the counterparty actually carries, and a system already shaped to them.

II.

The horizon, and the question behind it.

FROM THE RESEARCH FILERECORDS OF DECISIONS, GOVERNANCE OF AI
OCT 2022The SEC adopts amendments modernizing electronic recordkeeping under Exchange Act Rule 17a-4: records must be preserved in systems that permit viewing, download, and audit.
2022 ONWARDThe off channel communications sweep begins: eleven orders in September 2022, billions in penalties across the industry since. Advisers Act Rule 204-2(a)(7) requires preserving communications relating to recommendations and advice. Enforcement has made the perimeter of a record of advice a board level question.
AUG 2024The EU AI Act, Regulation 2024/1689, enters into force: the first comprehensive horizontal framework for AI, with logging, transparency, human oversight, and record keeping obligations phased in by risk tier.
AUG 2026High risk obligations under Annex III become applicable (a delay to late 2027 has been proposed but not enacted, as of September 2026). Firms deploying AI that touches consequential decisions face documentation, oversight, and logging duties either way.

The direction is singular: regulators increasingly expect a record of how decisions are made, not only of what was executed, and governance of any AI that touches those decisions. An intent stage record, generated and retained inside the firm's own walls, is built for exactly this trajectory.

SOURCES · U.S. SEC, Electronic Recordkeeping Requirements adopting release, October 12, 2022 · Advisers Act Rule 204-2(a)(7) · SEC recordkeeping enforcement orders, September 2022 onward · Regulation (EU) 2024/1689 and the European Commission's published implementation timeline.

B / C
III.

Six questions. Each answered here with an artifact.

Where does your record of the decision begin?

The register: observations at the intent stage, before order entry, with the committed plan and the figure attached.

Can anything in the record be edited or deleted?

The acknowledge ledger: append-only, with officer and time. There is no route to edit or remove an entry.

What leaves our tenant, exactly?

The egress manifest, generated from the same registry the runtime enforces, and the flow-log verification run against the tenant's own logs.

Can the vendor see our trades?

The architecture: sealed single tenant, no vendor endpoint. The plane-denial report and the flow-log verification are reviewed live under NDA.

What happens when the system cannot measure something?

The attestation row that says “not measured, so it is not a pass”, and the mandate proposal that arrives as not expressible instead of a guessed number.

How is the AI's own output governed?

The forecast board scored against the record, tiers withheld on small populations, and audit-stamped PDFs that name their scope.

IV.

The regulatory alignment memo.

The full mapping, in a document your compliance function can file. Available in advance of a briefing.