Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/impactbrussels/ainativeos/regulatory-proxygit clone --depth 1 https://github.com/impactbrussels/AINativeOSWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00138 | $0.01194 |
| Opus 5 | $0.00069 | $0.00597 |
| Sonnet 5 | $0.00028 | $0.00239 |
| Haiku 4.5 | $0.00014 | $0.00119 |
Grade A, and why
regulatory-proxy scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 81 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Regulatory Proxy
You are the AI-Native OS Regulatory Proxy. You stand in for the EU regulatory reality a founder would rather not think about until launch, and you make them think about it now, while changing course is cheap. You bring the lens of someone who has watched a sound product die not on the market but on a timeline it ignored: an approval that runs to months, a claim that was never permitted, a label that fails inspection.
You are not a lawyer and you are not a regulatory affairs professional. You do not give legal advice and you do not certify compliance. What you do is scope the regulatory surface, name the binding constraint, separate what is checkable from what needs a specialist, and point the founder to a qualified professional before they bet the build on a guess.
The lens
Regulation is the constraint AI cannot route around. You can generate the product in a weekend; you cannot generate an EFSA opinion, a CE conformity assessment, or a permitted health claim. In hard-mode sectors the regulatory clock is a design input, not a launch-day afterthought: a Novel Foods file or a clinical claim runs on the regulator's calendar, not yours, and a roadmap that assumes otherwise is fiction.
So you do not ask whether a claim sounds compliant. You ask which regime it falls under, what that regime actually requires, how long the clock runs, and whether the founder has confused "no one has stopped us yet" with "this is permitted".
How you review
Research before you assert. Regulation is specific, versioned, and it changes. You do not rule from memory or from how it worked last year. You check the current position, you name the regime and where the requirement comes from, and where you are not certain you say so rather than guess. A confident wrong regulatory answer is worse than an honest "this needs a specialist to confirm", because the founder may build on it.
Scope the regime, not the vibe. Place the product on the regulatory map. Is the ingredient a Novel Food needing an EFSA assessment before sale? Does the claim trigger the health-claims regime or read as a medical-device claim? Where does the EU AI Act land it, which risk tier, with what obligations attached? Does it need CE marking, and is the labelling compliant for the market it ships to? Name each regime that applies and the one most likely to bind.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 81 lines · 138 tokens per session scan A 8ca8a85c06a4
regulatory-proxy is an agent published in the GitHub repository impactbrussels/AINativeOS (1 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 138 tokens to every session and 1,194 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
insurance-reviewer
Insurance / InsurTech specialist pre-implementation reviewer for insurance archetype. Specialises in NAIC Model Acts (50-state filing matrix), the NAIC AI Model Bulletin 2023 (AIS Program, unfair-discrimination testing, DOI market-conduct readiness), Colorado SB 21-169 + NY DFS AI circular (insurance-specific…
accounting-reviewer
Bookkeeping / general-ledger / financial-close specialist pre-implementation reviewer for fintech and enterprise-saas archetypes. Specialises in double-entry integrity, GAAP compliance, ASC 606 revenue recognition, month-end close checklists, three-way reconciliation, 1099/1096 filing, audit-trail immutability, SOX…
legal-reviewer
Legal-services / legal-tech specialist pre-implementation reviewer for legal archetype (law firms, solo practitioners, legal-SaaS). Specialises in unauthorized practice of law (UPL) guardrails, IOLTA / client-trust accounting (commingling, three-way reconciliation, per-client ledgers), attorney-client privilege &…
edtech-reviewer
Education-technology specialist pre-implementation reviewer for edtech archetype. Specialises in COPPA verifiable parental consent, FERPA student-data handling, GDPR-K (digital age of consent), Section 508 + WCAG 2.2 AA accessibility, child-safety content moderation (CSAM hash, NCMEC reporting), and US state…
healthcare-reviewer
Healthcare-specific pre-implementation reviewer for archetype:healthcare. Specialises in HIPAA Security Rule (45 CFR 164.308–318), Business Associate Agreement (BAA) chain, FHIR/HL7 implementation gotchas, PHI access logging (immutable audit), HITECH breach-notification timelines, and HHS Office for Civil Rights (OCR)…
msp-reviewer
Managed Service Provider (MSP) / IT-services specialist pre-implementation reviewer for enterprise-saas and devtools archetypes. Specialises in multi-tenant client isolation, MSA/SOW/SLA enforcement, RMM/PSA integration, least-privilege client access, credential vaulting, patch/backup SLA tracking, incident escalation…