Regulatory drift
What this page is — the capability that flags where a document has fallen behind the current law and standards of its jurisdiction, with a confidence score on every finding.
What it is for — because documents age quietly, and the template you have been reusing for four years is the one most likely to reference a statute that has been replaced.
The problem it solves — a reused template keeps citing replaced law, and nobody notices until it matters.
Route: /org/papers/documents/<document>/ai → Comply → Regulatory drift ·
Permission: Use AI drafting/extraction/Q&A for documents. ·
Utility: papers_regulatory_drift · Cost: 450 credits estimated, 1,800 maximum.
1. What it is
It reads the document against the jurisdiction it belongs to and flags four kinds of ageing:
| Drift | Example |
|---|---|
| Superseded references | A statute renumbered, or replaced by a newer act |
| Clauses a newer law now demands be different | A data-protection rule that has tightened |
| Mandatory provisions now missing | A newer law requires a clause the document never had |
| Deprecated terminology or thresholds | A notice period or monetary threshold that has moved |
The distinguishing output is confidence, which exists on every finding alongside severity:
confidence | Means | How to treat it |
|---|---|---|
high | It is citing a rule it knows | A finding — verify and act |
medium | Reasonably grounded | A finding — verify carefully |
low | Inferring a likely change rather than citing a rule | A lead to check, not a finding |
Severity tells you how much it would matter if true. Confidence tells you how likely it is to be true. They are independent, and reading only the first is how this capability gets misused.
Every flag is a prompt to check a primary source — the current statute, rule or regulator guidance — not a ruling. It never changes the document.
2. Why you would use it
Nothing in a contract management system tells you that the law underneath a document has moved. The document is unchanged, correctly filed, fully executed, and progressively wrong.
- It finds the template that has aged. Run it on the type you reuse most and the finding applies to every document ever generated from it — the highest-leverage run in the module.
- It catches renumbering, which nothing else does. A clause citing a repealed act is not wrong on its face and reads perfectly well.
current_expectationstates what the rule now wants. Not just "this is out of date" but what compliant would look like.confidencemakes it safe to run broadly. You can sweep a portfolio and triage by confidence, rather than treating every output as requiring a lawyer.- It is how a periodic review becomes tractable. Reviewing two hundred agreements against current
law is not a task anyone schedules; reviewing the twelve that came back
high/highis.
3. What you provide
| Input | Required | Notes |
|---|---|---|
| Jurisdiction override | Optional | Name the jurisdiction to assess against. Otherwise inferred from the document's fields and text |
Nothing is required. Set the override when the document's jurisdiction is ambiguous — a cross-border agreement, or one whose governing-law clause is silent.
| Example | |
|---|---|
India | National |
England & Wales | The correct granularity — not "UK" |
Every finding is relative to a body of law. Assessed against the wrong one, the output is not
slightly off — it is answering a different question. jurisdiction_assessed in the result tells you
which one it used, and states its assumption when it was unclear. Read that field first.
4. What it reads automatically
| Read from the document | Used for |
|---|---|
| Document text — the full rendered body | Finding the references and provisions |
| Title & family — e.g. "MSA" | What regulation applies to this kind of document |
| Party names — everyone named | Which entity's regulatory environment matters |
| Field summary — filled schema fields | Thresholds and dates that may have moved |
| Jurisdiction hints — signals from the document's fields | Inferring jurisdiction, when you give no override |
5. What you get back
drifts[] — one entry per issue.
| Field | Type | Values | Means |
|---|---|---|---|
provision | string | — | The clause or topic affected |
issue | string | — | What has drifted |
current_expectation | string | — | What the current rule now expects |
severity | enum | high, medium, low | How much it matters if true |
recommendation | string | — | The concrete change to make |
confidence | enum | high, medium, low | low = inferring rather than citing |
Plus jurisdiction_assessed — the jurisdiction or jurisdictions assessed against, stating the
assumption if it was unclear. And summary — 2–3 sentences on the document's overall
regulatory freshness. And disclaimer.
6. Worked example
A compliance manager runs Regulatory drift over an MSA template that has been in use since 2021.
Input: no override — the governing-law clause names India.
One entry from drifts[]:
provision: "Cl. 14 — Data Protection" issue: "References the 2000 IT rules; India's DPDP Act 2023 now governs personal data." current_expectation: "Consent, breach-notice and data-fiduciary obligations under DPDP Act 2023." severity:
high· confidence:mediumrecommendation: "Rewrite cl. 14 to the DPDP Act 2023 framework."
How the manager reads it. high severity with medium confidence is the combination that
warrants a specialist's time but not yet a rewrite: the framework change is real and well known, and
the precise obligations under it are what a lawyer must confirm against the current text.
current_expectation names the three things the replacement clause must cover, so the instruction to
counsel is specific rather than "clause 14 may be out of date".
What makes this the highest-value run available. The finding is on a template, not a document. Every agreement generated from it since 2021 carries the same clause 14. One run, one finding, and the remediation scope is the whole portfolio.
7. Running it
- Open the document in Orbit Papers.
- Open the AI Assistant drawer, or go to the document's AI workspace.
- Choose Regulatory drift under Comply.
- Optionally name a jurisdiction override.
- The assessment appears in a result tab and is saved to the document.
Read jurisdiction_assessed before the findings, then triage by confidence before severity.
Verify each retained finding against a primary source.
Available for auto-run from the type's AI Config tab. Unlike most capabilities, the useful cadence here is not per-document but periodic: law moves on its own timetable, so a document that was current at finalize may not be a year later. A saved result is a snapshot of the law on the day it ran, and nothing tells you when it went stale.
See AI configuration.
8. The admin contract
| Must be true | Where | What happens if it is not |
|---|---|---|
| Your role holds Use AI drafting/extraction/Q&A for documents. | Role editor | The AI Assistant button does not appear |
The papers_regulatory_drift utility is active | Orbit AI Flow → utilities | "This utility is currently disabled" |
| The utility is enabled for your organisation | /org/ai-utilities | Absent from Comply, with no error |
papers.ai_monthly_credit_cap not yet reached | System Config | "monthly AI credit cap reached: n of n credits used this month" |
| The type carries a governing-law or jurisdiction field | Field schema | Jurisdiction is guessed from body text, and jurisdiction_assessed may state an assumption you did not intend |
| Someone owns verifying findings against primary sources | Your process | Advisory output is treated as fact, which is the specific misuse this capability invites |
For a confidential document, auto-run is default-denied — a platform administrator must set
papers.ai_confidential_cloud to the literal allow, and the block appears only in the server log.
A manual press still works, and where a local model key is configured the run is forced on-prem and
audited on the timeline as ai_local_routed.
9. Don't confuse this with…
| Compliance & policy check | Measures against your policy. This measures against the law |
| Regional annexures | Adds jurisdiction-specific documents that are missing. This fixes wording that has aged |
| Missing clauses | Professional expectation, timeless. This is specifically about change over time |
| Retention advice | Also cites statute, but about how long to keep the record |
10. Troubleshooting
| Symptom | Cause |
|---|---|
| The findings relate to the wrong country | Jurisdiction was inferred wrongly. Read jurisdiction_assessed, then set the override (§3) |
Everything came back confidence: low | The jurisdiction is unclear, or the document's subject is outside well-charted regulation. Treat as leads (§1) |
A high severity finding turned out to be wrong | Severity is not confidence. Read both — and verify against a primary source before acting (§1) |
| No drift on a document I know is dated | The ageing may be in a jurisdiction it was not assessed against |
| The result is a year old | It is cached with the document. A drift result is a snapshot of the law on the day it ran (§7) |
| It cited a statute that does not exist | Advisory output can misattribute. This is exactly what confidence and the disclaimer are warning about |
| The capability is missing from Comply | Role lacks Use AI drafting/extraction/Q&A for documents., or the utility is off for the organisation (§8). The document type does not gate it — AI Config controls auto-run only |