Agent-Based Controls for Verifying Regulatory Compliance
The LexAlign project automates EU AI Act obligation checks, but verifying compliance remains manual. This thesis explores using autonomous agents to automatically gather proof and assess legal obligations.
Contact persons
What the project is about
The LexAlign project at SINTEF Digital formalizes EU AI Act regulations into executable decision flows to automatically derive legal obligations for AI systems. However, proving that derived obligations are actually fulfilled relies on manually gathering evidence across code repositories, issue trackers, model registries, and monitoring logs.
Research topic focus
This thesis investigates attaching autonomous agents ("controls") to individual legal obligations to identify required proof, retrieve the corresponding software artifacts, and present traceable evidence to auditors. The primary research question explores the boundary between agent autonomy and deterministic, computed legal judgment.
Expected results and learning outcomes
- System Design & Prototype: Architect and implement a multi-agent prototype integrated with the LexAlign framework to automate artifact retrieval.
- Evaluation & Benchmarks: Assess the agent system's accuracy, traceability, and defensibility when evaluated against sample AI system compliance cases.
- Core Competencies: Gain practical experience combining multi-agent architectures, formal specification tools, and regulatory technology (RegTech).
Desired qualifications
- Strong background in Computer Science, Software Engineering, or Artificial Intelligence.
- Proficiency in Python or general software development (e.g., interacting with APIs, Git repositories, or CI/CD pipelines).
- Knowledge of or interest in Multi-Agent Systems, Formal Methods, or Legal/Regulatory Technology.
- Ability to work independently on open research questions.