The tool call looks perfect. The syntax is clean. Parameters check out. And yet the AI agent is about to authorize a customer refund based on shipping data that's three days old—wrong enough to matter, correct enough to slip through.
This is the nightmare scenario keeping enterprise AI teams up at night, and it's precisely the problem a small Y Combinator-backed startup called Bylaw thinks it can solve. Not by blocking agents from taking actions, but by fact-checking the evidence they use to justify those actions before anything happens.
The pitch sounds almost quaint in its specificity: What if, before your AI agent updates that CRM record or launches that pricing test, something checked whether the underlying facts were actually current, non-conflicting, and authorized? What if agents needed to prove their homework was fresh?
"Every company giving agents write access will need this layer," Bylaw declares on its Y Combinator profile, a confident stance for a three-person team barely out of the gate.
A Gate, Not a Guardrail
Bylaw describes its core product as a pre-execution "evidence gate"—terminology that matters here. According to the company's website, this isn't a traditional guardrail checking permissions or filtering content. It's a deterministic checkpoint that scrutinizes the specific facts an agent is relying on before allowing it to touch production systems.
The workflow is straightforward, almost mechanical. Before an agent can issue a refund, update customer data, or trigger an experiment, Bylaw examines what the company calls an "evidence manifest": the facts used, their sources, timestamps, whether information was directly observed or merely inferred, and any conflicts detected between data sources. Then it issues one of three verdicts: allow, review, or block.
The distinction the startup is drawing feels important, perhaps more than it first appears. Most agent safety tools ask whether a tool should be used. Bylaw is asking whether the information justifying that use is trustworthy. The tool call can be right; the evidence can still be wrong.
Born from Crypto Wallets and Recommendation Algorithms
The founding team's backgrounds hint at why they gravitated toward this particular problem. CEO Gurshabd Singh Varaich interned at BitGo, the cryptocurrency custody platform known for its pre-execution wallet policies and multi-signature approval controls—systems designed to catch mistakes before money moves. Co-founder Farhan Ur Rehman comes from Meta's Instagram Reels team, where recommendation systems live or die on data freshness and source quality. Mazin Al-Ani spent time at quantitative trading firm Optiver and AI investment platform Boosted.ai, both environments where stale data isn't just inconvenient; it's catastrophic.
All three studied at the University of Waterloo and are now splitting time between San Francisco and their Canadian base. The company is projected to have been founded in 2026, emerging from what appears to be a recent Y Combinator batch, though no separate funding round has been announced publicly.
The Workflow: Trace, Simulate, Gate

Bylaw's approach begins offline, not in production. Teams upload traces or logs from past agent runs—pulled from platforms like LangSmith, Langfuse, OpenAI's ecosystem, Braintrust, or homegrown logging systems. The goal is forensic: identify where evidence was weak, missing, outdated, or contradictory in previous actions.
The system simulates what would have happened under Bylaw's policies. Which actions would have sailed through? Which would have triggered review? What would have been blocked outright? Recurring failure patterns get codified into runtime gates.
Then comes deployment. Teams wrap sensitive agent actions with Bylaw's SDK. When an agent attempts a write operation, Bylaw intercepts the call and evaluates that evidence manifest. A deterministic policy engine applies versioned rule packs and returns a decision. Everything—the evidence, the rules applied, any human approver involved in a review—gets recorded as a signed audit trail.
It's governance infrastructure, not sexy, but potentially essential for any company planning to let AI agents loose on systems that matter.
Launching Into a Suddenly Crowded Room

Timing in startups is everything, and Bylaw is entering a space that has gotten remarkably crowded, remarkably fast.
Microsoft added AI agent runtime protection to Defender for Endpoint in preview this past June. Ory launched Agent Security roughly three weeks ago. Noma announced agentic access control in early June. A cluster of startups—ThirdLaw, Containment.ai, Fendray, UseTruth, Runplane, among others—are all staking claims around runtime governance, audit-grade evidence, and execution control for agent actions.
Even the academic community is converging here. Papers published in May and June describe runtime safety layers, "unfireable safety kernels," and frameworks for evidence verification at the point of action. The language mirrors what Bylaw is building almost exactly.
Industry commentary has shifted to match. According to a Forbes Tech Council piece in April, every AI agent will eventually require a "guardrail layer" focused on action control rather than just language filtering. A Built In essay from June asked whether agents need a "kill switch," advocating for deterministic execution control with binary rules and cryptographic audit trails—concepts that could have been lifted directly from Bylaw's product description.
This convergence could validate Bylaw's thesis. Or it could mean the window is already closing.
Still Very Early

Bylaw's website is live, complete with calls-to-action for both self-serve signup and sales-assisted demos. But much remains undisclosed or unavailable. No pricing structure. No public SDK documentation or performance benchmarks. No customer logos or case studies yet, which isn't unusual for a company this nascent but does leave questions about market traction.
What is clear is the positioning: as enterprises wire AI agents into critical systems—CRMs, payment processors, customer service platforms—the question shifts from "can the agent do this?" to "should the agent do this, given what it knows?" A subtle but potentially crucial distinction.
The right tool call, executed on the wrong evidence, doesn't just cause operational headaches. In regulated industries, it can become a compliance event. An audit problem. A liability question.
Whether Bylaw's answer—a deterministic evidence gate that checks facts before execution—becomes standard infrastructure or gets swallowed by larger platform vendors remains to be seen. The three-person team is betting that in the race to deploy AI agents, someone needs to be asking: But are you sure?
Note: Some dates and details in this article reference events described as occurring in 2026, which may reflect forward-looking statements or projections from the company rather than confirmed past events.
