← all posts
Regulatory AIDocument processing

A Regulation is not a bag of embeddings

Tracfox treats a Regulation as structured source. It uses Pi to process that structure, then compiles it into grounded obligations and related control best practices.

There is a familiar pattern in handling documents using AI. Split a document into chunks. Turn each chunk into an embedding, which is a numeric representation used to compare meaning. Put those embeddings in a vector database. When someone asks a question, retrieve the chunks that look closest and ask a model to write the answer.

I understand the appeal. It is a quick way to show that a model can find relevant language in a large collection. It is also useful. We should keep it.

A Regulation is different. It behaves more like source code than a collection of passages. Its hierarchy sets scope. Definitions bind terms. Exceptions change which requirements apply. Cross-references connect one provision to another.

That is why Tracfox chose Pi, a coding agent, for regulatory document processing. Pi can work with the document as structured source instead of reducing it to unrelated chunks.

Tracfox compiles that source into grounded obligations and related control best practices. Definitions, exceptions, cross-references and citations stay connected to the obligation. Compliance teams receive organised work with evidence attached, rather than another answer whose context must be rebuilt.

What we mean by compile

A compiler does not search source code for the line that looks most similar. It reads the structure, follows the relationships and produces a defined output. We use that as a practical analogy for regulatory processing.

The Regulation is the source. A grounded obligation is the first output. Related control best practices follow after the obligation passes its checks. The obligation remains linked to the regulatory text, so the source of the requirement stays clear.

Search locates. Processing compiles.

Vector search is good at narrowing a large corpus. A search for “fees charged before closing” can find passages that use different words. That is much better than asking a person to open every document.

The problem starts when the highest-ranked chunk is treated as the regulatory record. Chunking removes text from its original neighbourhood. Anthropic describes the same limitation in traditional retrieval-augmented generation: a chunk can lose the context needed to retrieve or use it correctly.

For compliance work, I use a simple distinction. Retrieval answers where should we look? Processing answers what does the provision require when read in context?

Regulatory structure is part of the requirement

Regulations are organised documents. In the CFR, for example, text descends from Titles and Parts into Sections and several levels of paragraphs. The National Archives guide to CFR structure shows why a citation can point to a very specific place in that hierarchy.

The hierarchy is not decoration. It tells us which heading governs a paragraph, which list items share a condition and where an exception ends. Definitions and cross-references add links across that hierarchy.

An embedding can help locate one node. It does not compile the relationships around that node into an obligation. Tracfox preserves those relationships before asking a model to reason about the requirement.

Why Tracfox chose a coding agent

Regulatory sources do not arrive in one dependable shape. A heading may become bold text. A table may hold conditions that disappear during conversion. A cross-reference may be a link in one source and plain text in another.

Pi can inspect the original document, use tools, write and run a small program, and compare the processed result with the source. For one document, that might mean recovering a table. For another, it might mean rebuilding the heading hierarchy or identifying cross-references.

Each task defines the expected output and the checks it must pass. If a check finds a missing row, heading or reference, Pi receives that finding and corrects the program. Tracfox runs the checks again on the corrected output.

Tracfox chose Pi because of its compact size and effective tool-calling capabilities. Pi handles the code-driven document work. Claude or Grok reasons over the prepared regulatory text. Tracfox owns the compilation: Regulation in, grounded obligations and related control best practices out.

This is not one enormous prompt

We do not trade chunking for one huge prompt. Long context is useful, but it does not guarantee reliable attention. The Lost in the Middle study found that model performance can change depending on where relevant information appears in a long input.

Tracfox keeps the hierarchy, brings in the references needed for the task and carries the citation with the extracted text. The model works on a bounded Section or document unit without losing its connection to the Regulation.

The output has to be gradable

The approach is useful only when the output can be checked against the input. Every obligation Tracfox produces must point back to the regulatory text that supports it.

The result has to pass gradable checks:

  • Grounding: does the source support the statement?
  • Correctness: does the statement keep the right meaning in context?
  • Completeness: are the scope, conditions, exceptions, thresholds and timing still present?
  • Cross-references: have the definitions and referenced provisions needed to understand the requirement been resolved?

The point of these checks is to reduce review, not recreate it. Routine obligations move on. Failed, uncertain and high-risk items reach the right SME with the source and the question attached.

From structured Regulation to compliance work
Regulation as source
Conditionwho and when
Requirementwhat must happen
Exceptionwhere it does not apply
Cross-referencelinked definition or provision
Grounded obligation
Applicabilityretained
Required actionstated in context
Qualificationsexceptions retained
Evidencecitation attached
Accepted obligationrelated control best practices

What this changes for compliance teams

Compliance teams do not need another list of passages to interpret. They need the Regulation converted into work they can use without losing the source, scope or qualifications.

Tracfox provides grounded obligations and related control best practices with definitions, exceptions, cross-references and citations carried forward. Compliance teams can see what applies, why it applies and how related controls could put the obligation into practice.

Vector search is useful for finding likely passages, but a passage is not a complete regulatory requirement. The Tracfox approach is better suited to compliance work because it preserves the scope, definitions, exceptions, cross-references and citation while compiling the provision. The result is a grounded obligation and related control best practices that can be checked, traced and acted on. Search shows where to look. Tracfox preserves the context needed to understand what the Regulation requires.

Notes and further reading
Anthropic · Contextual Retrieval and context lost during chunking ↗ National Archives · How the CFR is structured ↗ Liu et al. · Lost in the Middle ↗ Pi · Coding agent reference ↗

Bring us a Regulation. See Tracfox compile it into grounded obligations and related control best practices →