Stanford's RegLab Turns AI Loose on America's 3 Billion Words of Law

Government & Regulation
A Stanford lab pointed AI at every federal, state, and municipal statute on the books. The audit it ran on government is the audit waiting inside your own compliance library.
By Shashi Bellamkonda · August 20, 2026
3B+
Words of U.S. legal code, federal, state, and municipal (Ho, The Washington Post; 2026)
400%
Growth in California reporting requirements, 2000 to 2025 (Ho, The Washington Post; 2026)
30%
Recurring California reports that appear never to have been filed (Ho, The Washington Post; 2026)
$870K
Staff cost of a single California report, 3,500 hours (Ho, The Washington Post; 2026)
A Stanford research team read the entire body of American law with AI and priced what it costs to keep obsolete reporting mandates on the books. Reporting rules in California grew 400 percent since 2000 while staffing stayed flat, and a third of the state's recurring reports never get filed at all.

Every year, the Federal Reserve's board of governors sends Congress a report on the Presidential $1 Coin Program. The coins stopped circulating in 2011. The report hasn't. The Fed has asked to be relieved of the exercise every year since, without success, because nobody in Congress owns the job of repealing a reporting mandate once it's law.

Daniel Ho calls that pattern policy sludge, obsolete requirements that accumulate because writing a new law is a legislator's job and deleting an old one is nobody's. Ho directs Stanford's Regulation, Evaluation, and Governance Lab, and the scale of the problem kept it unfixable by hand until AI could take it on. More than three billion words of federal, state, and municipal code sit on the books. A team at the Social Security Administration once spent four months, fifty employees, just to document its own printing operations. Reading American law to find what's obsolete has never been a matter of will. It's a matter of throughput.

RegLab Built an AI System That Reads the Entire Code, Not a Sample

Ho's team built a system capable of scanning federal, state, and municipal law in full and flagging what's outdated, redundant, or unconstitutional. Some of what it surfaces is dead weight from another era. San Francisco's public health code still authorizes the health director to examine anyone suspected of carrying a "venereal disease," language that predates the constitutional protections that would bar enforcing it. New York still requires its board of regents to report on disciplinary action against teachers found to hold "subversive" views, a Red Scare provision courts struck down in 1967.

Symbolic cleanup isn't the finding that matters. Reporting mandates are.

Reporting Rules Outgrew the Staff Meant to Handle Them

California's reporting requirements grew roughly 400 percent between 2000 and 2025. Staffing didn't follow. In Maryland, RegLab estimates that reading every report the legislature ordered in fiscal 2023 would take a single legislator fourteen weeks. The session runs thirteen.

Most of that volume goes unread, and some of it goes unwritten. Around 30 percent of California's recurring reports appear never to have been filed. When San Francisco published a housing report in July 2025 that overstated evictions by 40 percent, almost nobody noticed, because almost nobody reads the report to begin with. A mandate that produces a document nobody checks isn't oversight. It's a line item.

Cost varies by an order of magnitude depending on what an agency is asked to produce. One California report consumed 3,500 hours of staff time and more than $870,000 before it was done. Others take a few hours and get downloaded thousands of times. When Maryland agencies reviewed their own obligations against RegLab's findings, they flagged about 20 percent as candidates for elimination or consolidation. Civil servants aren't defending this system. They're trapped inside it.

Civil servants are not defending this system. They are trapped inside it.

The Sludge Isn't a Partisan Story, and That's the Part Worth Noting

Reporting requirements run somewhat higher in Democratic-led states even after controlling for the size of government, which is the finding "abundance" critics point to when they blame blue-state bureaucracy. RegLab's data confirm the direction, not the magnitude. The gap is small. Sludge accumulates under any legislature that rewards writing new rules and offers no credit for repealing old ones, regardless of party.

Governments that have seen RegLab's output are starting to act on it. San Francisco ran a consultative process and passed legislation cutting more than a third of its reporting requirements. New York Governor Kathy Hochul issued a "Regulatory Reset" executive order directing agencies to identify and eliminate obsolete rules. AI made the discovery cheap. Cutting the rule still takes a legislature, an agency, and someone willing to own the decision.

RegLab's Real Lesson Is About Task, Not Technology

Ho's team hasn't published which models power the system, but it draws from the same class of large language model behind the copilots and chatbots most enterprises spent 2024 and 2025 piloting. What's different is the job. Reading three billion words to classify, extract, and cross-reference against a fixed body of law is an analytical task. You can check the output against the statute itself and know whether the system got it right. Drafting a memo or answering an open-ended customer question is a generative task, and there's no fixed corpus to check it against, which is exactly where hallucination hides.

Most enterprise AI budget has gone to the generative side, because that's the demo that plays well in a board meeting. The ROI in this story comes from the other side: an extraction and classification job run at a scale nobody thought was checkable by hand, against a corpus large enough that sampling used to be the only option.

You already have that corpus. Every enterprise with more than one compliance function has its own version of the Presidential $1 Coin Program report, a policy, an audit trail requirement, a vendor reporting obligation that a predecessor stood up under pressure and that nobody has the standing to kill. RegLab's demonstration is proof that reading all of it at once, instead of sampling it every audit cycle, works at a scale that used to require a multi-year project and a headcount request that never cleared budget.

The method that found $870,000 buried in one California report is an analytical task with a checkable answer, not a generative one. The question for a CIO isn't whether AI can read a compliance library end to end. It's whether anyone in the organization has the authority to act on what it finds.
CIO/CTO Viability Question
Stanford priced obsolete reporting mandates with an analytical read of three billion words, not a generative one. Before you commission the same scan against your own policy library and vendor reporting obligations, name who inside your organization owns the authority to kill what it finds.
Ho, Daniel E. "America Has 3 Billion Words of Legal Code Riddled with 'Policy Sludge.'" The Washington Post, 19 Aug. 2026, washingtonpost.com.
Stanford University. "Regulation, Evaluation, and Governance Lab." Stanford Law School, 2026, law.stanford.edu.
Disclaimer: This blog reflects my personal views only. Content does not represent the views of my employer, Info-Tech Research Group. AI tools may have been used for brevity, structure, or research support. Please independently verify any information before relying on it.