# Rule26 AI > Technical leadership for AI systems that must work in the real world, for healthcare and legal organizations. Know what the architecture, vendor proposal, or delivery plan may be overlooking before you commit, deploy, or accept the system. Rule26 AI reviews architecture, integration, data handling, verification, implementation risk and vendor claims, and can continue into client-side oversight or delivery of a defined technical workstream. Rule26 AI is led by Salma Saad: nearly 30 years in enterprise software and engineering leadership, including engineering leadership in a HIPAA-regulated healthcare environment, with additional software experience across finance, publishing, consumer, professional services and legal AI. CIPP/US and AIGP certified. Fatima Hussain supports research, workflow analysis, program coordination, training, client enablement, documentation, and adoption feedback according to engagement scope. ## What Rule26 AI does Technical leadership and independent judgment on consequential AI and software implementations, most often for healthcare and legal organizations. In plain terms: AI architecture review, AI vendor assessment, technical due diligence for AI systems, AI testing and verification, AI risk assessment, responsible-AI implementation support, and client-side AI implementation oversight. The work covers architecture and integration review, data-flow analysis, verification and testing strategy, privacy and regulated-data considerations, and implementation oversight. Depending on what an organization needs, Rule26 AI can independently assess the technical risk, provide client-side vendor and implementation oversight, or deliver a clearly defined technical workstream. The role and accountability are agreed for each engagement. Rule26 AI does not provide legal, clinical, cybersecurity, insurance or regulatory advice. ## Who Rule26 supports - Regulated organizations - Enterprise software companies - Consultancies and professional-services firms - Corporate technology, privacy, legal, risk and operational teams ## Engagement types - **Decide, AI Vendor and Architecture Review**, independent examination of vendor claims and supporting evidence, architecture and integrations, data and model boundaries, privacy and access assumptions, testing and verification, human review, operational ownership, and unresolved implementation risks. Useful for vendor selection, architecture approval, pilot decisions, contract renewal, and deployment or acceptance decisions. Rule26 AI informs the decision; the organization makes it. - **Evaluate, AI Evaluation, Testing and Assurance**, for a workflow an organization has built or configured itself: intended uses, unacceptable failures and testable acceptance criteria, representative evaluation datasets, failure categories and severity levels, testing of grounding, unsupported claims, retrieval, permissions and workflow exceptions, whether human review and exception handling work as intended, release thresholds and repeatable regression tests, and documentation of what the available evidence does and does not demonstrate. Rule26 AI assesses agreed technical criteria and evidence; the organization and appropriately qualified specialists make formal acceptance, clinical, regulatory, legal, security and compliance determinations. - **Deliver, AI Productization and Technical Delivery**, for a prototype or MVP that shows value but is not yet supportable: the gap between the prototype and its intended production environment, production architecture, integrations, data and model boundaries and operational ownership, authentication, authorization, user-level auditability, logging, traceability and exception handling, evaluation and regression testing, human-review workflows, release criteria, rollback expectations and escalation paths, and delivery of an agreed bounded workstream or temporary implementation leadership through a defined milestone. Scope depends on the system and the expertise available; Rule26 AI does not replace specialized clinical, EHR, medical-device, security or regulatory professionals. - **Adopt, Approved AI Adoption and Shadow AI Reduction**, for organizations where employees already use AI but approved tools, data boundaries and practical guidance are not yet in place: disclosed AI-enabled workflows and employee needs, relevant data categories, vendor boundaries, retention considerations, access requirements and human-review needs, business and technical requirements for approved tools, comparison of candidate tools against real workflows, permitted, conditional and prohibited use patterns, role-based training using realistic scenarios, and support for rollout, feedback collection and an agreed adoption follow-up. Lasting change also depends on leadership, management, HR, communications, IT, privacy, risk and security. Comprehensive discovery of undisclosed technology may require endpoint, network, SaaS-management or cybersecurity capabilities outside Rule26 AI's role; Rule26 AI does not perform endpoint forensics, network surveillance, penetration testing or managed security services. Scope, depth and duration are agreed for each engagement, and an engagement can stay advisory or continue into oversight and delivery. Rule26 AI does not sell standardized implementation packages. ## Initial Technical Review A focused review of up to 60 minutes on one defined technical question or vendor proposal: a proposed system, a vendor decision, an implementation concern or a technical-evidence gap. You get up to 60 minutes of direct technical analysis with enterprise engineering leadership, three prioritized risk and evidence observations, and a concise executive follow-up document. $500 fixed fee. Detailed solution design and implementation planning are completed as part of a paid engagement. It is an initial technical perspective, not a complete architecture, security, compliance, evidence or governance assessment. ## Experience and credentials Salma Saad has nearly 30 years in enterprise software: roughly twenty years as a developer and ten in engineering leadership, spanning delivery, reliability, security, interoperability and cross-functional coordination, including engineering leadership in a HIPAA-regulated healthcare environment. CIPP/US informs the questions asked about sensitive-data handling and AIGP the questions asked about reliability, bias, human review and accountability; neither credential makes Rule26 a lawyer, auditor, regulator or cybersecurity consultancy. Prior roles include senior engineering leadership at the American College of Surgeons (2019–2024), enterprise software consulting at Home Chef (2018–2019), and engineering management and delivery leadership at Datalogics (2015–2017), plus earlier software engineering and technical leadership across healthcare, financial services, publishing, consumer and professional-service environments. These reflect prior employment and consulting experience; they are not Rule26 AI clients or endorsements. A public LinkedIn recommendation from Jack King, MBA, Chief Information Officer at the American College of Surgeons, describes Salma's prior enterprise work there. It is a personal professional recommendation, not a Rule26 AI client testimonial and not an endorsement by the American College of Surgeons. Credentials: CIPP/US, AIGP, B.S. Mathematics. ## What Rule26 AI does not do Rule26 AI does not certify systems, issue attestations or audit opinions, or make compliance determinations. It is not a law firm, clinical adviser, HIPAA compliance auditor, cybersecurity consultancy, or certification body. CIPP/US informs the questions asked about sensitive-data handling and AIGP the questions asked about reliability, bias, human review and accountability; neither credential confers regulatory or certifying authority. Technical assurance also differs from AI governance consulting: governance work produces policies, frameworks and controls, while Rule26 AI examines the system itself and the engineering decisions behind it. ## GhostCite GhostCite is a Rule26 AI legal-domain verification tool that checks supported legal citations and quotations against public court-record sources without using a generative model as the verification authority. It runs defined, rule-based checks against CourtListener data. It does not provide good-law treatment or subsequent history, and it does not verify healthcare or general enterprise AI outputs. Free to use: https://app.rule26ai.com/citation-checker/ ## Legal AI specialization Legal AI is Rule26 AI's most developed domain specialization, particularly where confidential or privileged information, source verification, professional judgment and implementation evidence intersect. Typical technical questions include privileged-data boundaries, citation and source verification, document-system integrations, attorney supervision, and what evidence of review should be retained. Rule26 AI does not provide legal advice. ## Healthcare experience Salma Saad has prior enterprise software and engineering-leadership experience in a HIPAA-regulated healthcare environment. Rule26 AI does not claim completed healthcare-AI consulting engagements or provide clinical or HIPAA compliance determinations. ## Current primary pages - [Home](https://rule26ai.com/): positioning, how AI can fail differently from conventional software, when independent technical judgment matters, the four services, the adoption program, and the GhostCite demonstration - [Services](https://rule26ai.com/services/): four stages and four services (decide: vendor and architecture review; evaluate: evaluation, testing and assurance; deliver: productization and technical delivery; adopt: approved AI adoption and Shadow AI reduction, a five-step program), the Initial Technical Review, method, and example scopes - [Credentials](https://rule26ai.com/credentials/): enterprise experience, applied work, professional perspectives - [FAQ](https://rule26ai.com/faq/): working with Rule26, evaluation and technical delivery, approved AI adoption and Shadow AI, and GhostCite - [Blog](https://rule26ai.com/blog/): writing on verification, legal AI and implementation risk. Older articles were written for a litigation audience and use legal-sector framing - [Privacy](https://rule26ai.com/privacy/) · [Terms](https://rule26ai.com/terms/) ## How to start Every initial conversation begins the same way: "Discuss Your Project", a short call to work out whether Rule26 is relevant to what you are building. The Initial Technical Review above is the paid engagement where substantive analysis happens. ## Legal entity Rule26 AI is operated by Pixel Rise Labs LLC, a Texas limited liability company. "Rule26 AI" is the trading name, not a separate incorporated entity. ## Contact hello@rule26ai.com · https://rule26ai.com/ Last updated: 2026-09-02