CUBE
CUBE sells automated regulatory intelligence and regulatory change management to financial institutions. Its RegBrain engine, and the RegAI framework built on it, capture, classify and interpret laws, rules and regulations across a stated 10,000 issuing bodies, 750 jurisdictions and 80 languages, then map each change to the policies, controls and teams it affects inside a customer's own framework.
Delivery runs through RegPlatform Enterprise for tier one institutions, RegPlatform Intel for mid market banks, wealth managers and asset managers, and RegAssure for lean compliance teams, with RegBrain also exposed through APIs so a customer can run the same summarisation, classification and enrichment stack over its own content. Roughly 250 in house regulatory specialists review machine output, a step the company markets as human in the loop assurance.
The group has grown largely by acquisition, absorbing Reg-Room and the Thomson Reuters Regulatory Intelligence and Oden businesses in 2024, then the operational risk controls network Acin in 2025, which is listed separately in this index and still ships under its own name.
Capability Axes
Capability grades
15 of 15 axes rated · 6 graded A or B
Machine learning and natural language processing carry the capture, classification, ontological mapping and translation work across 750 jurisdictions and 80 languages, a footprint no human team could maintain, and the RegAI framework is described as trained exclusively on regulatory data. It sits at B rather than A because of what remains when the models are removed.
The company employs roughly 250 in house regulatory subject matter experts who curate and validate output, and it acquired an established human curated regulatory content business in 2024. Strip the models and a saleable regulatory content library remains, staffed by specialists. Peer anchored before grading against the regulatory intelligence cohort already in this index, all of which sit at A on this axis: Ascent, Norm Ai, Hadrius and Acin. In each of those cases nothing sellable survives the removal test, which is the distinction.
Earned on a structural human step the company publishes and markets rather than a claim of safety: roughly 250 in house regulatory subject matter experts review and curate machine output before it reaches customers, described as human in the loop assurance and positioned as a deliberate differentiator against pure automation. Held at B because none of the mechanics are stated.
No sampling rate, no review threshold, no rule for which machine outputs reach a specialist and which pass through, and no escalation path. The recently added agentic capability inside the API widens the surface further, since a customer can apply the stack to its own content with no oversight model described for that path.
The central claim is measurable and unmeasured. Filtering out irrelevant updates, false positives and missed obligations is a classification claim that can be tested against a known corpus and reported as precision and recall, and the platform also advertises regulatory change prediction, which is directly checkable against what regulators subsequently published. No accuracy figure, benchmark, error rate or validation method was located for any of it.
This is the standard applied to Blue Fire AI and bondIT: a product making predictive or classification claims to regulated buyers carries an obligation to publish a hit rate. The asymmetry is the sharp part, since a false positive costs an analyst minutes while a missed obligation surfaces as a supervisory finding at the customer.
Around 1,000 customers across banking, insurance, asset and investment management and payments, including an 800 strong mid market community, roughly 700 employees across 20 countries, and majority backing from a specialist software investor since 2024. Five global banks are named publicly as supporters of a compliance and risk collaboration initiative the company leads: Barclays, BNP Paribas, Citi, JPMorganChase and Lloyds Banking Group. Held at B rather than A on two grounds.
Those banks appear as backers of an initiative rather than as customers reporting a measured result, and the single strongest quantified outcome, a tier one bank restandardising more than 20,000 controls in one week against an estimated 7,500 days of manual effort, is published in a cloud partner's customer story with the bank unnamed, and attaches to the acquired Acin tool rather than to the regulatory intelligence platform. An earlier account of a United States bank reporting a 50 percent efficiency gain is also unnamed.
No boundary statement was located on whether content a customer submits informs anything served to another customer. The question is live rather than theoretical for this group. Customers are direct competitors, the platform holds their internal control frameworks and policy libraries, and the acquired Acin network is explicitly a cross institution benchmarking mechanism where peer comparison is the product. Acin publishes an anonymisation claim for its own network. Nothing equivalent was found covering content processed through the regulatory intelligence platform or the customer facing API.
No privacy posture, retention policy or customer content handling statement was located in this pass. The gap matters more than usual because of what the product ingests. Mapping regulatory change to a customer's own policies, controls and teams requires holding that institution's internal control framework, and the RegBrain interface invites customers to run the vendor's stack over their own content.
That is confidential institutional material rather than consumer financial data, so the consumer privacy regimes bite less directly here than for a retail facing vendor, but the absence of any published statement on handling, retention or segregation is the finding.
No certification, audit report, trust centre or report request route was located across the company site, product pages and third party sources in this pass. Recorded as an absence found rather than a proven absence, and it should be rechecked, since the lesson from the 73 Strings correction is that product and use case pages carry compliance claims that security pages do not.
The absence is conspicuous at this scale: tier one banks and roughly 1,000 regulated customers put this platform inside their compliance operations, and a peer in the same category has published an independently audited AI management system certification, which shows the disclosure is achievable in this market.
No licence, registration, supervisory programme or sandbox participation was located. The company sells into supervised firms without being supervised itself, which is the ordinary position in this index. Worth recording as an available benchmark rather than a criticism: CleverChain earns an A on this axis for a live test of its AI product under financial regulator oversight, and a vendor whose output feeds regulated firms' compliance records has an obvious route to the same evidence. The industry collaboration initiative this company leads is convened with banks, not with a supervisor.
Six stated core principles underpin the proprietary AI, with a commitment to transparent and ethical technology. That is assertion rather than testing, which is where the C sits. The product specific exposure is not protected class discrimination but coverage tilt, and it is worth reusing for any relevance filtering product: the platform markets its ability to filter out irrelevant updates so a compliance team sees only what matters, which means an obligation the filter suppresses is invisible by construction to the team responsible for it.
Coverage across 750 jurisdictions and 80 languages will not be uniform in quality, and the thinnest treatment will fall on smaller jurisdictions and less represented languages, which is where a firm is least able to check the machine independently. No precision or recall figures by jurisdiction or language are published.
No accuracy warranty, service commitment or remedy was located. The consequence structure is worth stating plainly because it recurs across every compliance intelligence vendor in this index: responsibility for identifying and meeting a regulatory obligation stays with the regulated firm, so when a change is missed or misclassified the supervisory finding, the remediation cost and the reputational damage land entirely on the customer, while the vendor's output was the input the customer relied on. The firm cannot transfer the duty and, on the published record, cannot recover against the tool either.
Above the index norm and earned on a named provider rather than a generic claim. The company publicly announced a partnership with a major cloud and model provider in September 2025 and its agentic control rewrite capability is documented as built on that provider's hosted models, while its own regulatory AI framework is described as proprietary and trained exclusively on regulatory data.
Naming the upstream provider matters here because a customer inheriting classifications of its own obligations is inheriting another firm's model behaviour. Not an A because the boundary is never drawn: nothing states which functions run on the third party foundation models, which run on the proprietary framework, or which of those a customer's own submitted content passes through.
Integration is into the right system of record for this buyer. The platform maps external regulatory change onto internal policies and control frameworks and pushes into governance, risk and compliance systems, and third party market analysis lists the company among the regulatory content partners of a major enterprise GRC platform.
The stronger and less common feature is that the AI engine is exposed through APIs so a customer can run the same summarisation, classification and enrichment over its own content, which makes the vendor's stack addressable by the buyer's systems rather than only through the vendor's screen. Held at B because only one named platform partnership was located and it appeared in third party material rather than the company's own integration documentation.
Cloud software as a service is the evident model and the hyperscaler is publicly identified through an announced partnership, which is more than many disclose. What is missing is everything a bank's third party risk function asks next: no region selection, no residency commitment, no tenancy model, no statement on where customer control frameworks are stored or processed.
For a vendor whose customer base spans Europe, North America, Asia and Australia and whose European customers sit under an operational resilience regime with explicit location requirements, the absence is material.
No rate card, no unit of consumption and no billing basis published on any product page. Every route to a number runs through a demo request. Third party analysis of the regulatory change management market places bank tier contracts in the low six figures at the entry end, scaling substantially for multinationals, but that is an outside estimate rather than vendor disclosure and cannot be graded as one.
Note the structural gap this leaves: the company sells a distinct mid market product to regional and community banks, the segment least able to absorb a procurement cycle to discover a price, and publishes no pricing shape for it.
Genuine breadth on both dimensions the axis measures. Buyer types run from tier one global institutions through regional and community banks, wealth managers, asset and investment managers, insurers and payments firms, with a separate product line built for each end of that range. Operations span Europe, North America, Canada, Asia and Australia, and regulatory coverage is stated at 750 jurisdictions and 80 languages.
The company also reports expansion into adjacent regulated sectors including insurance, healthcare and energy. Few vendors in this index address both a global systemically important bank and a community bank with named products for each.
What Changed
Material product, regulatory, evidence and commercial changes at CUBE, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.
CUBE added three agentic coworkers to RegPlatform: a Priorities Coworker that scores regulatory updates for relevance, an Analysis Coworker for natural language querying of regulations, and an Enforcements Coworker that consolidates enforcement actions across jurisdictions.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to CUBE
The closest documented capability profiles to CUBE in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Model Risk Management and Transparency where CUBE does not
Documents Regulatory Status and Licensure where CUBE does not
Documents Regulatory Status and Licensure where CUBE does not
Documents Regulatory Status and Licensure where CUBE does not
Documents Regulatory Status and Licensure and Deployment Model and Data Residency where CUBE does not
Documents Regulatory Status and Licensure where CUBE does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.