Frequently asked questions

Clear answers on how Rule26 reviews vendors, evaluates and tests AI systems, closes prototype-to-production gaps, supports approved AI adoption, and what GhostCite does.

Working with Rule26

What does Rule26 AI do?

Rule26 provides independent technical review, AI evaluation and testing, implementation leadership, and defined technical delivery. We examine vendors and systems, test how AI behaves in practice, close prototype-to-production gaps, and help establish supported AI adoption.

When should Rule26 be brought in?

Before selecting or accepting an AI vendor or architecture, when an internally built or configured system needs evaluation, when a prototype needs to become production-ready, or when unmanaged AI use needs an approved alternative and an adoption program.

Does Rule26 replace our internal technology team or implementation vendor?

No. We work alongside them while keeping an independent client-side view. Depending on scope we can lead a defined workstream, coordinate with vendors and internal teams, and provide temporary implementation leadership. We do not supply every specialty an engagement needs.

What is the Initial Technical Review?

A focused review of up to 60 minutes on one defined technical question or vendor proposal. You get direct technical analysis with enterprise engineering leadership, three prioritized risk and evidence observations, and a concise executive follow-up document. The fixed fee is $500. Detailed solution design and implementation planning are completed as part of a paid engagement. It is an initial technical perspective, not a comprehensive assessment.

What does Rule26 not provide?

Legal, clinical, cybersecurity, insurance and regulatory advice, formal compliance determinations, certifications, and attestations. CIPP/US and AIGP inform the questions we ask; they do not make Rule26 a certifying authority. We examine privacy-relevant data movement and vendor boundaries, leaving formal conclusions to qualified professionals.

Evaluation and Technical Delivery

What does an AI Vendor and Architecture Review examine?

Vendor claims and the evidence behind them, architecture and integrations, data and model boundaries, testing, logging and human review, ownership, dependencies and unresolved risks, and pilot or acceptance criteria where appropriate. The result supports your decision. It is not a contract review or a security certification.

What does AI evaluation and testing involve?

Depending on scope: defining intended uses and unacceptable failures, building or reviewing representative evaluation datasets, testing grounding, retrieval, permissions, exceptions and human review, classifying failures by severity, setting thresholds and regression tests, and assessing what the evidence does and does not demonstrate.

See the evaluation engagement →

Is evaluation only for systems approaching release?

No. Evaluation can support a vendor pilot, an internal workflow, a release decision, a system already deployed, a significant change, an observed failure, or continuing regression testing.

How is evaluation different from productization?

Evaluation determines how the system behaves and what the evidence shows. Productization closes the engineering and operational gaps so the system can be integrated, operated, monitored, supported, and handed over responsibly.

What can AI Productization and Technical Delivery include?

Target architecture and integrations, authentication and authorization, logging, observability and auditability, evaluation and regression infrastructure, human-review and exception workflows, and deployment, rollback, escalation, ownership and handoff. Scope depends on the system and the specialist expertise required.

See the delivery engagement →

Approved AI Adoption and Shadow AI

What is Shadow AI?

Employees or teams using AI outside the organization’s approved environment, usually because they need capabilities existing tools do not provide. The concern is sensitive data, vendor boundaries, retention, unreliable output, inconsistent review, and limited organizational visibility.

What does the Approved AI Adoption and Shadow AI Reduction program include?

Five stages. Discover current use, needs and workflows. Select and evaluate tools against real work. Define practical use and data boundaries. Enable people through role-based training, scenarios, job aids and rollout. Measure feedback, adoption, exceptions and improvements needed.

See the adoption program →

Does training alone solve Shadow AI?

No. Training is one part of the program. Durable adoption also needs approved tools that fit the work, practical boundaries, leadership support, workflow integration and follow-up measurement. It involves your leadership, IT, HR, privacy, legal, risk, security and business owners.

Does Rule26 discover every undisclosed AI tool employees use?

No. We document disclosed workflows, interview users, evaluate needs, and help design an approved environment. Comprehensive technical discovery may require endpoint, network, identity, browser or SaaS-management capabilities supplied by your organization or by specialized providers.

GhostCite

What does GhostCite verify?

GhostCite checks supported legal citations and quoted language against public court-record sources. It does not verify every legal proposition, provide good-law treatment, evaluate overall legal reasoning, or replace attorney review.

Open GhostCite →

Does GhostCite use AI for verification?

No. The verification step uses defined, rule-based checks against CourtListener public court-record data. No generative model decides whether a citation or quotation is supported. Optional semantic search is a clearly labeled fallback for locating a source, not a verification result.

Does GhostCite replace Shepardizing, KeyCite, or attorney supervision?

No. GhostCite confirms that a citation exists and that quoted language matches the record. It does not tell you whether a case is still good law, and it does not replace attorney review or professional judgment.

What happens to text submitted to GhostCite?

Submitted text is used to perform the check and is not used to train an AI model. Follow your organization’s data-handling rules when deciding what to paste into any external tool.

Still have questions?

Discuss Your Project