Skip to content
SIRETO

AI + Regulatory Engineering

Turn regulation into machine-readable, executable knowledge.

Sireto builds Regulatory Engineering technology that transforms legislation, regulation and policy into structured, traceable and executable knowledge for compliance, decision support and AI systems.

At the centre is NormLogic, our platform for machine-readable and executable regulation.

From regulation to executable rulesA regulation provision, Article 12 paragraph 3 exception, flows into NormLogic, which produces connected regulatory knowledge nodes for requirement, obligation, condition, exception and provision, and from those executable rules, compliance checks, agent constraints and an audit trail.RegulationNormLogicRegulatory knowledgeOutputsRegulation (EU) 2024/…Article 12paragraph 3exceptionNormLogicRequirementObligationConditionExceptionProvisionExecutable rulesCompliance checkAgent constraintsAudit trail
  • Machine-readable regulation
  • Machine-executable rules
  • Automated regulatory compliance
  • Auditable AI
  • Regulatory digital twins
The problem

Regulation was written for humans.
Modern systems need more.

Regulatory requirements usually stay where they were published: in documents that people can read and software cannot use.

Requirements stay trapped in

  • PDFs
  • legal text
  • standards documents
  • policy documents
  • guidance
  • manually maintained compliance rules

Which produces

  • duplicated interpretation
  • slow regulatory updates
  • inconsistent implementation
  • opaque AI reasoning
  • weak traceability

AI can help interpret regulatory text. But probabilistic interpretation alone is insufficient for high-trust systems.

The missing layer is structured, machine-readable and executable regulatory knowledge.

Sireto builds that layer.

NormLogic

From regulation to executable rules.

NormLogic is Sireto’s platform for transforming legislation, regulation, standards and policy into structured, machine-readable and executable regulatory knowledge.

  1. 1

    Source

    • Legislation
    • Regulation
    • Standards
    • Policy
    • Guidance
  2. 2

    Structure

    • Documents
    • Provisions
    • Concepts
    • Relationships
  3. 3

    Regulatory knowledge

    • Requirements
    • Obligations
    • Permissions
    • Prohibitions
    • Conditions
    • Exceptions
  4. 4

    Execution

    • Machine-readable rules
    • Regulatory reasoning
    • Compliance checks
  5. 5

    Evidence

    • Provenance
    • Explanation
    • Audit trail

Key concepts

  • source-to-decision traceability
  • regulatory knowledge representation
  • provenance-aware reasoning
  • machine-executable rules
  • deterministic validation around probabilistic AI

NormLogic is a Regulatory Engineering platform developed by Sireto B.V., a Netherlands-based AI and software technology company.

NormLogic combines AI-assisted extraction, regulatory knowledge modelling, provenance and formal rule representations, with interoperability support for standards such as LegalRuleML and Akoma Ntoso.

Automated regulatory compliance

The first application, and a core competency

The NormLogic compliance checker reads an organisation’s policies, procedures and controls and evaluates them against the structured requirements of regulations such as DORA, MiCA and PSD2. It reports coverage and gaps per obligation, attaches the source provision to every finding, and hands results to existing GRC tooling.

The discipline

What is Regulatory Engineering?

Regulatory Engineering is the design and development of systems that transform regulatory requirements into structured, machine-readable, testable and executable representations that software and AI systems can use.

It is the infrastructure between human-readable regulation and machine-operable systems. Sireto builds that infrastructure. The discipline has seven elements.

  1. Structured legal sourcesdocuments, provisions and identifiers in machine-readable form
  2. Knowledge representationregulatory knowledge graphs of requirements, concepts and relationships
  3. Formal rulesobligations, permissions and conditions that software can evaluate
  4. Provenanceevery assertion traceable to the provision that justifies it
  5. Regulatory reasoningwhat applies, to whom, under which conditions, and what takes precedence
  6. Automated compliancepolicies, controls and data evaluated against the rules
  7. Interoperable standardsrepresentations that can be exchanged and validated across systems
Approach

AI with evidence, structure and control.

We use AI where probabilistic reasoning is useful, and formal systems where determinism, validation and auditability are required.

  1. AIextraction, classification, interpretation, assistance
  2. Structured regulatory modelsvalidation, consistency, provenance
  3. Formal rulesdeterministic execution
  4. Evidencesource-level traceability

AI extracts and assists. Structured models validate. Formal rules execute.

LLM-only systems

Good at interpreting text. Probabilistic, and difficult to audit deterministically: the same question can get a different answer, and no answer cites a provision.

Traditional rule engines

Deterministic, but the rules are expensive to author, expensive to update, and disconnected from the regulation they implement.

NormLogic

AI-assisted extraction, plus structured regulatory knowledge, plus formal machine-executable rules, plus provenance and auditability. Each layer does what it is good at.

Products

Two products, one principle.

Use AI where it helps. Put contracts, validation and evidence around it where trust is required. NormLogic applies that to regulation; openapi.ai applies it to the interface between an organisation and the models it uses.

NormLogic

Regulatory Engineering platform

Transforms legislation, regulation, standards and policy into structured, machine-readable and executable regulatory knowledge, with automated compliance checking as its first application.

  • Machine-readable regulation
  • Machine-executable rules
  • Compliance checks with provenance
  • Regulatory change management

openapi.ai

AI infrastructure, under contract

Versioned, schema-frozen capability contracts enforced by the platform on an OpenAI-compatible gateway for every model. Inputs and outputs validated, failures typed, published versions immutable, data governance over which providers process your data.

  • Capability contracts
  • Unified gateway with failover
  • Data governance and audit
  • Self-hosted community edition
Applied AI engineering

We build the infrastructure around intelligent systems.

NormLogic grows out of Sireto’s broader work in AI engineering and regulatory knowledge infrastructure.

  • Automated regulatory compliance

    Compliance checking systems that evaluate policies, controls and evidence against structured regulatory requirements, with the source provision attached to every finding.

  • Regulation as code

    Legislation, standards and internal policies transformed into structured, machine-executable rules with provenance.

  • Agentic systems

    Multi-agent architectures for research, extraction, validation and operational workflows.

  • Regulatory knowledge engineering

    Regulatory ontologies, knowledge graphs, semantic models and domain knowledge representation.

  • LLM engineering

    Structured generation, model routing, evaluation, prompt optimisation and model-independent architectures.

  • AI evaluation

    Datasets, benchmarks and systematic testing for extraction, reasoning and domain-specific AI systems.

  • AI infrastructure

    APIs, observability, authentication, orchestration and production infrastructure for AI applications, including our own gateway and contract platform, openapi.ai.

  • Secure enterprise integration

    Connecting AI systems with existing identity, data and operational environments without turning critical business processes into opaque black boxes.

Use cases

Where machine-executable regulation pays off.

Six problems that start with regulation written for people and end with systems that need it as data.

  • Regulatory compliance

    Translate regulatory requirements into structured rules that software systems can evaluate, with a traceable finding for every gap.

  • Regulatory change management

    Identify affected rules, obligations, policies and systems when legislation changes, from the model rather than by reading.

  • Public administration

    Support transparent and interoperable digital implementation of legislation and policy, with open representations.

  • AI governance

    Provide AI systems and agents with structured regulatory constraints linked to authoritative sources.

  • Regulatory digital twins

    Create computable representations of regulatory environments that can be queried, tested and updated.

  • Decision support

    Generate reasoning paths with traceability back to the relevant regulatory source, for people and for systems.

Standards and interoperability

Interoperable by design.

NormLogic enables interoperable representations of regulatory requirements that can be exchanged, validated and executed across systems and organisations.

Semantic, legal and technical interoperability matter for public-sector digitalisation and cross-border digital services as much as for enterprises. We build on open standards rather than proprietary formats so regulatory data stays reusable.

LegalRuleML
OASIS standard for formal representation of legal rules and normative statements.
Akoma Ntoso
OASIS standard for structured legislative and legal documents.
W3C PROV
Provenance data model for recording how an assertion was derived, by whom and from what.
prEN 18286
Emerging European work on interoperable, machine-readable regulatory information.
Knowledge graphs and ontologies
Graph-based representation of regulatory concepts, relationships and provenance.
Formal rules and DSLs
Rule representations and domain-specific languages for deterministic execution; policy-as-code patterns where they fit.
Europe

Built for Europe’s regulatory digital future.

Europe is moving toward interoperable digital services, trustworthy AI and data-driven regulatory compliance. Sireto develops the technical infrastructure needed to represent regulatory requirements in forms that software and AI systems can understand, validate and execute.

Sireto B.V. is based in the Netherlands and works with enterprises, public-sector organisations, research partners and technology partners across Europe. Our representations are built on open standards so regulatory knowledge can be exchanged, validated and executed across systems, organisations and borders.

Themes we build for

  • Trustworthy AI
  • Semantic and legal interoperability
  • Regulatory data
  • Public-sector digitalisation
  • Open standards
  • Source-to-decision traceability
  • Digital sovereignty
  • Privacy
  • Auditable systems
Technical credibility

Research that ships.

Sireto operates at the intersection of six fields. We explore emerging ideas, build reference implementations and turn the approaches that work into production technology.

The objective is not AI experimentation for its own sake.

It is to build systems that can be understood, tested and trusted.

  • Artificial Intelligence
  • Software Engineering
  • Knowledge Representation
  • Legal Informatics
  • Formal Methods
  • Distributed Systems
Questions

Frequently asked questions

Direct answers to the questions we are asked most, for people and for the systems that answer on their behalf.

What does Sireto do?

Sireto is a Dutch AI and Regulatory Engineering company building infrastructure that transforms legislation, regulation and policy into structured, machine-readable and executable regulatory knowledge.

What is Regulatory Engineering?

Regulatory Engineering is the design and development of systems that transform regulatory requirements into structured, machine-readable, testable and executable representations that software and AI systems can use. It combines structured legal sources, knowledge representation, formal rules, provenance, regulatory reasoning, automated compliance and interoperable standards.

What is NormLogic?

NormLogic is Sireto’s platform for transforming legislation, regulation, standards and policy into structured, machine-readable and executable regulatory knowledge. NormLogic is a Regulatory Engineering platform developed by Sireto B.V., a Netherlands-based AI and software technology company. Its first application is automated regulatory compliance: checking an organisation’s policies and controls against the regulations that apply.

How does NormLogic work?

In five stages. 1. Source: legislation, regulation, standards, policy and guidance are ingested. 2. Structure: documents, provisions, concepts and relationships are identified with AI assistance. 3. Regulatory knowledge: requirements, obligations, permissions, prohibitions, conditions and exceptions are modelled and reviewed. 4. Execution: formal, machine-executable rules evaluate situations deterministically. 5. Evidence: provenance, explanation and an audit trail connect every decision to its source.

What is the difference between machine-readable and machine-executable regulation?

Machine-readable regulation structures the text so software can find and link provisions, concepts and requirements. Machine-executable regulation expresses those requirements as formal rules software can evaluate deterministically against data. NormLogic produces both and keeps the executable rule connected to its readable source.

How does AI support regulatory compliance?

AI is used where interpretation is needed: extracting requirements from regulatory text and mapping policies to them. Structured regulatory models validate the result and formal rules execute the checks deterministically, so every finding is reproducible and cites its source provision. AI assists; it does not decide, and it makes no legal claims.

What if regulation were software-readable by default?

We are building the infrastructure to make that possible. If you work on regulation, compliance, public-sector digital services, AI governance or knowledge-intensive AI systems, we would like to hear from you.