AI Agent for Internal Policy Review
Policies are written one at a time and read as a set, which is why they contradict each other. This agent reads the whole estate together, finds where two documents tell an employee different things, which obligations nothing implements, and which policies are past their review date.
What is an AI policy review agent?
An AI policy review agent is a governed software worker that reviews an organisation’s internal policy estate for internal consistency and coverage. It groups statements by subject to locate contradictions, traces obligations to the policy text implementing them, identifies uncovered requirements, and reports documents past their stated review date.
What it does
What it is not
Three documents, three different retention periods
A policy estate grows by addition. Each document is written by a team solving their own problem, approved on its own merits, and never read against the others — so an employee looking for the retention period finds three answers, and the one they follow is whichever they found first.
Policies contradict each other
Two approved documents give different instructions on the same situation and both remain in force because nobody compared them.
Obligations map to nothing
A regulatory requirement is assumed to be covered by an existing policy, and it turns out no document actually addresses it.
Reviews lapse invisibly
A document states an annual review cycle, the owner changed roles, and the last approval was three years ago.
Language differs for the same rule
The same control is described four ways across four documents, so employees cannot tell whether it is one rule or four.
The policy set, read as one document
Consistency
Where Two Policies Disagree
Both passages, side by side.
Statements about the same subject are gathered across the estate and compared, so a conflict on retention, approval thresholds or access rules is reported with both passages quoted and the documents they come from named.
- Statements grouped by subject, not document
- Both conflicting passages quoted
- Distinguishes conflict from mere overlap
- Ranked by how often the rule is relied on
Both passages shown
Coverage
Which Obligations Nothing Implements
Traced requirement to document.
Obligations from regulation, contract or a control framework are traced to the policy text that implements them, and anything with no corresponding provision is reported as an uncovered obligation rather than assumed to be handled elsewhere.
To policy text
Currency
What Is Past Its Review Date
And who was supposed to do it.
Review cycles, approval dates and owners are extracted from the documents themselves and checked against the calendar, producing a list of lapsed reviews with the named owner and how long each has been overdue.
With named owner
How the AI Policy Review Agent runs a task
- STEP 01
Assemble the estate
Every policy, standard and procedure in scope is collected with its stated owner, approval date and review cycle, because a review of part of the estate cannot find the conflicts that live between its documents.
Document collectionMetadata extraction - STEP 02
Group statements by subject
Rather than reading document by document, provisions are gathered by what they govern — retention, approval thresholds, access, escalation — so every rule about a subject sits together regardless of where it was written.
Subject clusteringProvision extraction - STEP 03
Test for contradiction
Grouped statements are compared for genuine incompatibility as against harmless overlap, and each conflict is reported with both passages quoted and the practical question an employee could not answer.
Conflict detectionPassage quoting - STEP 04
Trace the obligations
Each item in the obligation register is matched to the policy text that implements it, and anything unmatched is reported as uncovered rather than assumed to be addressed by a document somewhere in the set.
Obligation mappingGap listing - STEP 05
Route to the owners
Findings are grouped by the owner recorded on each document, with proposed reconciling wording attached as a draft, and the decision to change any policy is left to the owner and the approving body.
Owner groupingDraft wordingGovernance handover
Systems the AI Policy Review Agent connects to
Document sources
Analysis
Inputs, outputs and runtime
- Ingests
- Policy and standard documentsObligation registerControl frameworkOwner and review metadataApproval history
- Produces
- Conflict report with passagesObligation coverage mapUncovered requirement listOverdue review listProposed reconciling wording
- Triggered by
- Annual governance cycleNew regulation adoptedPost-merger integration
- Human oversight
- Policy owners approve every amendment
- Models
- Open-weight LLMs you host — Llama, Qwen or Mistral class
- Typical latency
- Hours for a full estate review
- Deployment
- On-premise or sovereign cloud with egress control
- Data residency
- Policy text stays inside your environment
Where the Policy Review Agent pays back
Annual Policy Health Check
Review the whole estate for conflicts, gaps and overdue documents ahead of the yearly governance cycle.
Post-Merger Harmonisation
Compare two acquired policy sets and identify where they instruct employees differently on the same matter.
New Regulation Mapping
Trace each obligation of an incoming regulation to the policy that implements it and list what is uncovered.
Audit Preparation
Assemble the evidence that each control in a framework is supported by an approved and current policy.
Policy Rationalisation
Find documents that overlap enough to be merged and those that no longer reference anything in force.
Plain-Language Consistency
Identify the same rule expressed four different ways so a single wording can be agreed.
AI Policy Review Agent vs chatbots and SaaS copilots
A policy estate is one of the few corpora where the interesting property is not what any document says but whether the documents agree, and that is precisely the question nobody can answer by reading them individually.
| Generic chatbot | SaaS copilot | VDF AI | |
|---|---|---|---|
| Unit of review | One document | One document | The estate as a set |
| Contradictions | Cannot see them | Cannot see them | Located with both passages |
| Obligation coverage | Assumed | Manual mapping | Traced to implementing text |
| Review currency | Unknown | Unknown | Checked against stated cycle |
| Proposed changes | Rewrites the policy | Edits the file | Drafted as a proposal only |
| Approval | Not applicable | Not applicable | Owner and governance body |
| Where policies are read | Vendor service | Vendor tenancy | Inside your own network |
Governance and controls
Policy documents carry approval authority, so the one thing an agent must never do here is change a published text, because an unapproved amendment in circulation is indistinguishable from an approved one.
No published text changed
Wording is proposed, never applied
Approval path preserved
Changes follow the governance route
Findings cite both passages
Every conflict shows its evidence
Restricted policies respected
Limited-access documents stay limited
Owner attribution
Each finding names the responsible owner
Coverage gaps not assumed away
Unmatched obligations are reported
Evidence it leaves behind
What changes after rollout
Who runs the AI Policy Review Agent
Head of governance
Runs the annual cycle from a list of specific contradictions and uncovered obligations instead of asking each owner whether their document is still accurate and receiving the answer yes.
Compliance manager
Can show an auditor a mapping from each framework control to the policy text implementing it, and a dated record of the gaps that were identified and what happened to them.
Policy owner in a business unit
Receives only the findings attached to their own documents, with the conflicting passage from the other policy quoted, which turns an abstract review request into a specific decision to make.
Questions about the AI Policy Review Agent
What is an AI policy review agent?
It is an agent that reviews an internal policy estate as a whole: grouping statements by subject to find contradictions, tracing obligations to the policy text that implements them, and reporting documents that are past their stated review date.
How is an AI policy review agent different from a generic chatbot?
A chatbot can summarise one policy at a time. This agent compares the whole set against itself and against your obligation register, which is where contradictions and coverage gaps actually live.
Can an AI policy review agent run on-premise on internal policy data?
Yes. Policies describe your controls, thresholds and escalation paths in detail, which is a useful document for an attacker and a poor one to hand to a hosted service.
What does an AI policy review agent produce, and in what format?
A conflict report with both passages quoted, an obligation coverage map with uncovered items listed, an overdue review list with named owners, and proposed wording marked as a draft.
Where does an AI policy review agent fit in a governed AI programme?
It reviews rather than approves. Amending a policy, resolving a conflict and approving the result remain governance decisions taken by the owner and the approving body.
Can it amend a policy directly?
No. It drafts proposed wording and routes it to the owner, and any change goes through your normal approval path. Published policies derive their force from having been approved by a body with the authority to approve them; a document that was edited by a process outside that path is not a policy, whatever it says at the top of the page.
How does it tell a real contradiction from documents that simply overlap?
By testing whether the two statements could both be followed. Two policies mentioning retention are overlapping; two policies specifying different retention periods for the same record class are contradictory, because an employee cannot comply with both. Findings are framed as the practical question that cannot be answered, which is also what makes them straightforward for an owner to resolve.
Does it decide whether we are compliant with a regulation?
No. It reports whether a policy exists that addresses each obligation, which is a documentary question. Whether that policy is adequate, and whether the organisation actually operates in line with it, are questions of legal judgement and control testing respectively. Conflating documentary coverage with compliance is a well-known way to fail an audit while holding a complete policy set.
What if our policies are scattered across several systems?
It reads from wherever they live, and the first output is usually an inventory that surprises people: documents in a wiki that were superseded by ones in a document management system, and versions in a shared drive that nobody realised were still being cited. Establishing the authoritative version of each policy is often the most valuable part of the first run.
How does this relate to the compliance and governance agents?
The EU AI Act governance agents work on a specific regulatory regime and its artefacts. This agent works on your internal policy estate whatever the subject: expenses, access, retention, conduct, security. Where the obligation register includes AI Act requirements, the coverage mapping treats them like any other obligation, and the specialist governance agents handle the substance behind them.
Read the policy estate as one document
See the AI Policy Review Agent find the contradictions and coverage gaps in your policies.