John Nay

Founder and CEO of Norm Ai, a New York City regulatory AI agent platform for compliance; previously founding CEO of Brooklyn Investment Group and an AI and law researcher at Stanford

Overview

John Nay is Founder and CEO of Norm Ai, a regulatory AI agent platform based in New York City focused on compliance[1]. Nay previously served as Founding CEO of Brooklyn Investment Group, which was acquired by TIAA Nuveen[3]. Nay maintains a professional presence on LinkedIn[2] and X[4].

Profile introduction
Source excerptLinkedIn [6]

Founder & CEO of Norm Ai, backed by $260M+ from Khosla Ventures, Blackstone, Coatue, Bain Capital, Craft Ventures, Vanguard, New York Life, TIAA, Citi, Henry R. Kravis, Tony James, Marc Benioff, etc. Combined assets under management across clients is more than $35 trillion. Founding CEO of Brooklyn Artificial Intelligence, Inc. and Brooklyn Investment Group, an AI-powered investment software platform and wholly-owned SEC Registered Investment Advisor. Brooklyn manages billions of dollars and was acquired by TIAA Nuveen, one of the world's largest asset managers, with $1.3 trillion in assets…

Career history

  1. Founder & CEOJul 2023 to presentNorm Ai
  2. Fellow, AI & Law2022 to presentCodeX, The Stanford Center for Legal Informatics
  3. Visiting Scholar in AI & LawSep 2023 to presentVanderbilt University Law School
  4. ChairmanJan 2017 to Jul 2025Brooklyn Investment Group
  5. Founding CEOJan 2017 to Jun 2023Brooklyn Investment Group
  6. Adjunct Professor of Law2018 to 2021New York University
  7. Affiliate, 2017-2018 Cohort2017 to 2018Berkman Klein Center for Internet & Society at Harvard University

Education

  1. Post-doctoral Research FellowshipNew York University

Insights & ideas

The through-line

Everything John Nay argues starts from one idea: law can be turned into code that runs. He calls it agentic law, and defines it plainly as "embedding law into AI agents to put it really simply" [1]. That has two sides. One is automation, bringing machine speed to the first pass of legal and regulatory work [1][2]. The other is governance, because once the core economic activity itself is agentic, "generating marketing or talking directly to a client or giving investment advice as an AI agent to a client" [1], the deterministic guardrails that were good enough for earlier systems stop working, and you need other AI agents to check them from a legal, regulatory and compliance perspective [1]. Building law into agents unlocks both sides at once [1].

The vision has been consistent from the start rather than discovered along the way. He says the goal was always framed around AI agents, "systems that can take more than one step at a time to accomplish an economically useful task without a human fully in the loop" [2], and around the recognition that once such agents are genuinely deployed they will be subject to many laws and regulations that exist for good reason [2]. What changed was capability: large language models reached "that inflection point in the broader world of large language models being able to understand law and policy in a really real way" [2], which is what made him leave the founding CEO seat at his first company to start Norm Ai. His path there ran through two threads, roughly a decade of research on how machine learning systems and neural networks can understand law, policy and legal standards, and the practical work of running a compliance program at a company with a wholly owned SEC registered investment adviser subsidiary [2].

On agents versus co-pilots

The distinction he draws hardest is between AI as a co-pilot and AI as an agent working autonomously in the background [1][3]. A co-pilot is an efficiency booster, but the value evaporates: "it's sort of like throwaway work," high quality, the client is happy, and the next time you do that work you get no compounding benefit [1]. An agent doing a fuller pass lets the learnings be embedded back in naturally, so each matter improves the next [1]. Made concrete on a deal: with a co-pilot a lawyer checks incoming documents against a form, a playbook and a term sheet by prompting. In the agentic version the documents were already analysed before a human stepped in, possibly overnight, "the docs could have came in at midnight and that was running from midnight to 12:35 a.m." [1], removing the human bottleneck on the first pass and allowing parallel processing [1].

The second advantage is epistemic. With a co-pilot the AI is "sort of like fully merged into the human," so it is unclear what it can and cannot do, which makes it harder to trust and harder to offload anything cognitively without rechecking all of it [1]. An agent has an observable "jagged edge of capabilities" that you can benchmark and study systematically, offline and online, and then deliberately push outward by giving it more context where it falls short [1].

On turning regulation into a decision process

Norm Ai converts regulations and firm policies into regulatory AI agents that "automatically assess compliance for first pass review in a live workflow" [2]. The method is one rule at a time: take a public policy, a firm rule or an industry standard and build out in detail the compliance decision process for determining whether you are in compliance with it [2]. Crucially, the output is not a single universal reading of the rule, since interpretation depends heavily on the firm, so the process is further aligned to the client's interpretation and to how they would deploy it inside the enterprise [2]. The concrete case he returns to is consumer-facing content, a large risk surface governed by many regulations. Analysing that content far upstream in the production process lets business people get feedback early and lets compliance professionals catch that "we forgot to add a disclosure there," or that a subtle disclosure of product details is owed to the consumer [2]. Where the volume of things needing review is high, converting the regulation into code and putting it in the workflow is where the value shows up [2].

On legal engineers building the product themselves

The staffing model is deliberate. Norm Ai created a career it calls legal engineer, hiring attorneys mostly around the fifth-year associate level from other law firms, almost none of whom had written much code before, and turning them into software engineers [1]. They do not practise law; their full-time job is building, refining, testing, validating and deploying AI agents [1][2]. They are internally certified in the process of creating regulatory AI agents, and part of the software engineering organisation exists purely to build the tooling they use to analyse agent outputs [2]. The point of putting domain experts at the keyboard is directness: "they literally build the product. So the domain experts are the ones that are the builders of the product," which removes any loss in translation between the expert and the code [2]. Alongside them sit software and AI engineers building production-grade harnesses and infrastructure, and, at Norm Law, practising attorneys ranging from senior associates to very senior partners with decades of experience at other top firms [1]. Legal engineer and partner collaborate daily to embed decades of partner judgment into agents [1].

On the client overlay and the digital associate

The architecture is layered. There is a base agent for a matter type that could apply to anybody, and then a client overlay built from that client's precedent, past deals and past contracts [1]. As more work is done, "the agent overlay on the client level can get thicker and thicker" [1], capturing the client's preferences and proclivities, the terms they push on and the ones they care less about [1]. This is how a new entrant can start from something other than a blank slate, and it produces an asset a law firm cannot easily match. When a human associate who has been implicitly trained on a client leaves, that knowledge is gone; a digital associate that the client and the attorney have done the hard work to train "is there and it's not gonna leave," which he argues strengthens the long-term relationship [1].

On supervision, trust and oversight

He is unambiguous that humans remain on top of the stack. There is building, testing and validating on the front and back ends, and supervision above: Norm Ai builds the agents, those agents power much of the work behind the scenes at Norm Law, Norm Law attorneys supervise it, and "nothing goes out the door without that human supervision by a barred attorney" [1]. On the compliance side, at minimum the human is carefully supervising the process, with the ability to dig into very interpretable explanations of exactly what the agent did [2]. The internal validation rule is that at least one certified lawyer must analyse output in a system built for that purpose, which is how trust is established internally before it is asked of clients [2]. Oversight also comes from outside the building: former SEC commissioners are involved in the compliance testing and legal oversight applied to high-stakes applications such as investment advisory services [1], Troy Parades was added as a senior adviser [2], and a regulatory advisory board including people from firms like New York Life and TIA feeds high-level input into the regulatory roadmap and down into what the legal engineers do each day [2]. He names Blackstone and CO2 among clients, large private equity firms and leading hedge funds and investment firms [1]. Part of what attracts senior legal and regulatory talent, in his telling, is that this is "immediately impactful" AI rather than talk, and a chance to help define what regulatory AI means [2].

On pricing without the billable hour

Norm Law does not price by billable human hours [1]. Pricing is by outcome, with the unit of analysis being a deal or an agreement to be reviewed, agreed with the client in advance and often anchored to what they historically paid for that work [1]. The effect on both sides is deliberate: the client does not worry about the firm devoting a lot of time or being highly available, because there is no extra charge for it, and the firm is incentivised to lean in and improve the service with technology as well as people [1]. He does not pretend this is easy. Setting a price up front for work that may meander into more or less complicated territory is "a fundamentally really hard thing to solve," and it is AI arriving that forced everyone to reckon with it because the hourly model no longer aligns with the actual business [1]. His practical response is to narrow scope and lengthen relationships: matters where neither side can understand the likely work ahead of time are off the table for now, and the model tilts toward big long-term relationships with larger clients where volume averages out the harder and easier matters and both sides gain clarity [1].

On whether agents replace compliance officers

He rejects the replacement framing, and says clients do not hold it either [2]. The dominant pattern is doing more: getting work back to the business faster from a legal and compliance review perspective without sacrificing review quality, so a firm can generate more revenue and build faster rather than cut headcount [2]. The second argument is structural. As AI generates more proposed actions and content subject to regulation, manual review will not keep up with the volume, so agents become the only scalable way to review agents, with humans supervising [2]. That shifts what compliance people spend time on, toward acting as managers of AI agents and handling the nuanced work, brand new situations, and the internal politics and stakeholder navigation of the business [2]. He also notes the operational edge that agents run around the clock, which otherwise requires globally distributed teams that are difficult to staff and awkward for fast turnarounds, and that a risk-based approach lets the first pass sort what genuinely needs a deeper dive [2].

On advice to institutions and to founders

For a large institution about to deploy AI agents in a high-risk surface such as customer service, his test is a translation exercise: work out how a human doing that same role or task would have been governed from a regulatory and compliance perspective, then ask how you will achieve that when the actor is an agent operating at far greater scale and across more risk area [2]. That question is precisely where he positions the company, as the regulatory AI infrastructure sitting across from deployed agents [2]. For founders, his advice is about timing rather than conviction. Use cases that sit just below the capability threshold are being unlocked within two to three months, so the discipline is to index into measured capability increases across different evals and keep optionality open for the use cases that become possible every couple of quarters [2].

On using AI for his own thinking

He applies the same logic to himself. Research is the use that interests him most, and it is the only way he can stay involved in the Legal AGI Lab the company launched, using AI to develop research hypotheses and think through how to carry the work forward [1]. He enjoys the recursion: "it's sort of like a meta AI legal AI because it's legal is using AI to help to research legal AI" [1].

Takeaways

  • Agentic law means "embedding law into AI agents" [1], which serves two purposes at once: automating first-pass legal and regulatory work, and giving you the means to check other AI agents that are generating marketing, advising clients or making investment recommendations [1].
  • Co-pilot output is "throwaway work" with no compounding value, while an agent doing a full pass lets learnings be embedded back in and gives you a benchmarkable "jagged edge of capabilities" you can deliberately push outward [1].
  • Regulations become software by building a detailed compliance decision process per rule, then aligning it to the individual client's interpretation and deployment context rather than assuming one universal reading [2].
  • Attorneys hired around the fifth-year associate level are retrained as legal engineers who stop practising law and build the agents themselves, so there is no loss in translation between the domain expert and the code [1][2].
  • Nothing reaches a client without human sign-off: "nothing goes out the door without that human supervision by a barred attorney" [1], and internally at least one certified lawyer must review agent output in purpose-built tooling [2].
  • A client-specific agent overlay grows thicker with every matter and, unlike a trained human associate, "it's not gonna leave" [1].
  • Norm Law prices by outcome agreed in advance, often anchored to what the client historically paid, which pushes it toward long-term relationships and away from matters whose scope neither side can predict [1].
  • The scaling argument against replacement fears: manual review cannot keep pace with AI-generated content and decisions, so compliance staff become managers of agents and focus on nuance and stakeholder navigation [2].
  • Before deploying agents in a high-risk function, ask how a human in that role would have been governed, then design for that at agent scale [2].

Media & appearances

  • AI and the Future of LawApple Podcasts
    What Is an AI-Native Law Firm? John Nay on Norm AI and Norm LawWhat is an AI-native law firm? In this episode, Jen Leonard and Bridget McCormack are joined by John Nay, founder and CEO of Norm AI and Norm Law, for a conversation about agentic law, AI-native legal services, and what it means to build legal work arou
  • AI and the Future of Law PodcastYouTube
    What Is an AI-Native Law Firm? John Nay on Norm AI and Norm LawJohn Nay discusses agentic law, which he defines as embedding law into AI agents to automate legal and regulatory operations and govern AI systems. He explains how Norm AI uses AI agents autonomously in the background for legal processes, distinguishing this from AI co-pilots, and describes how the company applies compliance testing and legal oversight—including involvement of former SEC commissioners—to high-stakes applications like investment advisory services.
  • BenzingaYouTube
    Interview with Norm AI CEO John Nay: Building Compliance AI in FinanceJohn Nay discusses how Norm AI turns regulations and firm policies into regulatory AI agents that automatically assess compliance for first-pass review in live workflows. He explains that the company converts detailed regulatory processes into decision frameworks tailored to each client's interpretation and deployment needs, with examples including analyzing content upstream to flag compliance issues like missing disclosures before business publication.

In the news

This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.