Humanbound website
Compliance

Test your AI agents against the obligations you already carry

Add your regulatory requirements to an agent's scope and Humanbound attacks them with the same multi-turn engine it uses for security, scores each violation by what is at stake in your domain, and keeps every conversation as evidence you can put in front of an auditor.

Regulatory rules, attacked like security rules

Every requirement you add becomes a restricted intent that the engine tries to break over several turns of conversation, using the same techniques it turns against security boundaries.

Templates for regulated domains

Start from scope templates for banking and finance, insurance, healthcare, legal services, and e-commerce, with an add-on for agents deployed in the EU that covers Articles 9, 13, and 14 of the EU AI Act.

Evidence built for submission

Reports record the scope each agent was tested against and the full conversation behind every verdict, and they print to PDF for auditors and for frameworks such as DORA, NIS2, and ISO/IEC 42001.

The rules you follow already apply to your AI agents

Your compliance work was scoped before agents reached production, so it never tested how an agent behaves when someone sets out to talk it past a rule. A regulatory rule gives way under pressure exactly like a security control.

List what the agent must not do as restricted intents, and the engine attacks each one over several adaptive turns. There is no separate mode: you run a normal test with regulatory and security restrictions in one scope, and an independent judge checks both.

Start from the rules your sector already follows

Turning a regulation into a precise list of things an agent must never do is where gaps appear. Each template pairs security restrictions with your sector’s rules, plus the domain context the judge uses to weigh severity. Copy it, set the permitted intents, and run.

Banking and finance
FCA COBS 9, PRIN 6, SYSC 3.2. No investment recommendations without a suitability assessment.
Insurance
IDD and Solvency II. No recommendations without assessing the customer’s demands and needs.
Healthcare
HIPAA Privacy and Security Rules. No specific diagnoses or treatment recommendations.
Legal services
SRA and ABA Model Rules. No specific legal advice on individual cases.
E-commerce
Consumer Rights Act 2015 and FTC Act. No urgency or scarcity claims not based on actual stock.
EU AI Act add-on
Articles 9, 13 and 14, for agents deployed in the EU. Must disclose that it is an AI when asked.

From one conversation to one obligation

Follow one case through the banking and finance template. It shows how the mapping works; it is not a real test, result or customer.

The boundary

A retail banking agent must not recommend investment products without a suitability assessment. The scope cites FCA COBS 9 and marks the domain high-stakes.

The finding is a security result first; the regulation behind it is what makes it urgent for compliance teams and the board.

Evidence for the frameworks you report against

Reviewers want to see what was tested, how, and what happened. Humanbound reports are built for submission to auditors and to DORA, PCI-DSS, ISO/IEC 42001, NIS2 and the EU AI Act, and save to PDF from the browser.

Project report
The scope tested and the monitoring record.
Assessment report
The full conversation behind every verdict.
Experiment report
The methodology of one run.

The Evidence page covers the report levels, finding retests, and the posture score in more detail.

Put your regulatory boundaries under test

Start from the scope template for your domain, add the policies your organisation already follows, and run your first compliance-scoped test with the open-source engine or on the platform.