← News

ZeroDrift Anchor 3.0 official release graphic — The compliance enforcement model

23 Sep 2026

ZeroDrift

ZeroDrift launches Anchor 3.0 enforcement models for AI agent communications

ZeroDrift made Anchor 3.0 generally available, a family of small language models built to enforce regulatory and company rules on AI-generated communications before they are sent, and published a FINRA communications benchmark built with Surge AI.

SOFTWARE desk — as companies let agents email customers and write marketing copy, somebody has to stop the model from promising returns it can’t keep; ZeroDrift is betting a tiny specialist beats a giant generalist at that single job.

What the company says the test showed. The same release says ZeroDrift published the first benchmark of how well AI models enforce FINRA rules on business communications. FINRA is the Financial Industry Regulatory Authority, the US self-regulator for brokerages. The data, the release says, is human-written and attorney-labeled, and was independently produced by Surge AI, which the release calls the data labeling company trusted by the world’s leading AI labs. That trusted-by line is the release’s description of Surge. This desk did not audit Surge’s client list. The headline result, in the release’s words: Anchor 3.0 caught 95.5 percent of violations, more than any frontier model tested. It also outperformed GPT-5.6 Sol, which the release calls the strongest frontier model on the test, on recall, precision, and F1, while running up to 34 times faster and up to 12 times cheaper. Recall is the share of real violations the model caught. Precision is the share of its flags that were real violations. F1, the release says, is a measure that balances recall and precision. Up to 34 times and up to 12 times are the best cases the release states. They are not clocks or bills this desk timed. 95.5 percent is the company’s figure. This desk did not rescore the set.

Why the release says the check has to happen before send. It cites Cambridge research that 81 percent of surveyed financial services firms are adopting AI at some level, and that traditional financial institutions report 45 percent agentic AI adoption. Agentic, here, means software that takes a series of steps, not only one answer. It cites FINRA’s 2026 oversight report for a note that generative AI can implicate supervision, communications, record-keeping, and fair dealing. Generative AI is software that writes something new from a prompt. The release says regulators have levied billions of dollars in fines for communications failures. Billions is the release’s word. It does not print a dollar total. Do not invent one. It says frontier models can catch many violations, but at 12 to 51 seconds per message for the strongest of them, so they can only review after the fact. Anchor 3.0, the release says, runs the check on every message before it leaves, in about 1.5 seconds on ZeroDrift’s API and under 100 milliseconds when a company hosts it. An API is a door other software can call. A millisecond is a thousandth of a second. Under 100 milliseconds is a tenth of a second. Those times are the release’s. The Cambridge line and the FINRA report line are citations on the wire. This desk did not re-read those papers.

The founder’s sentence, as a quote, not as a market this desk measured. Kumesh Aroomoogan, founder and chief executive, said frontier models made it easy to build capable agents, and that the hard part is running them inside a regulated business, where every message has to follow the rules and the check has to happen every time, before anything goes out. He said a frontier model is too slow and too expensive to do that on every message, that Anchor is built for this job, and that developers keep building with the models they choose while Anchor makes sure what their agents say is compliant. Compliant, here, means the message follows the rule. That is his sentence on the wire. It is not a count of messages this desk watched.

Three sizes, in the release’s order. Anchor 3.0 Mini has 9 billion parameters, with 4 billion active, and was post-trained from Gemma E4B. A parameter is one number inside the model. Active, on this line, is the share the release says runs. Post-trained means the company took an existing model and trained it further for this job. Gemma E4B is the Google model the release names as that starting point. Mini, the release says, is the fastest and lowest-cost size, built for the highest-volume traffic. It runs ZeroDrift’s pre-built rule packs and flags violations. Anchor 3.0, the flagship, has the same 9 billion parameters and 4 billion active, also post-trained from Gemma E4B. The release calls it the model behind the headline results. It runs a library of more than 200 pre-built rules across FINRA, the SEC, and other regulations. The SEC is the US Securities and Exchange Commission. It flags the exact lines that break a rule and rewrites them so the message goes out compliant. Custom company policies are trained in through a LoRA adapter. LoRA is a small add-on trained on top of the model, here on the company’s own rules, rather than a new model from scratch. Anchor 3.0 Max has 27 billion parameters and was post-trained from Qwen3.8-27B, the Alibaba model the release names. The release calls it the most capable size, built to enforce a company’s own policies with no fine-tuning, and says it handles long documents and attachments, with the largest context window in the family. A context window is how much text the model can read at once. Fine-tuning is extra training. No fine-tuning, on Max, is the release’s claim. These sizes are the release’s. This desk did not open the weights.

One customer sentence, and how a developer starts. Cristian Felix, chief AI architect at Wand AI, said ZeroDrift extends Wand’s governance layer so agents’ communications can be checked and corrected before they are sent, and that strong governance is what lets a financial institution move from experimentation into production. Governance, here, means the rules the company refuses to break. That quote is on the wire. A name on a release is not a contract this desk read. The release says developers can sign up at https://zerodrift.com/ and start through the ZeroDrift Enforcement API, and that the full model-by-model results and methodology are available now. The copy of the wire this desk read did not leave a second public results URL past that sentence. The summary numbers below are the product page’s.

What the product page adds, and only that page. The page at zerodrift.com/model/anchor does not print the 9:00 a.m. Eastern stamp. The clock is the wire’s. The page says Anchor reads every message an AI writes, catches what breaks a regulation or a company policy, and fixes it before the message goes out. It says the design is a small model trained on the regulations, post-trained from Gemma E4B, with a deterministic rules engine beside it. Deterministic, here, means the written rules run the same way every time, not as a fresh guess. It says each response returns a verdict, the rule it applied, the exact passage, and a verified rewrite, and that Anchor re-checks its own rewrite against the same rules before the message ships, so a fix cannot add a new violation. The page’s example is a line that calls a fund a safe way to increase returns. The verdict is rewrite, the rule cited is FINRA Rule 2210, and the rewrite says past performance does not guarantee future results. That block is the page’s illustration. It is not a customer message this desk saw. The page says the check works on agents, email, chat, voice, marketing, documents, and APIs, on text, in ZeroDrift’s cloud or in the customer’s own private cloud. It says the two smaller sizes run as a classifier or a line editor, and it names the chip each size uses. Those chip names are parked in the source note.

The page’s scorecard, prices, and whose they are. The page labels 95.5 percent as recall on a human-labeled FINRA set, scored against human compliance reviewers, and says the best frontier model on that set caught 92.9 percent. It says the set was scored against Claude, GPT, and Gemini models, with the same rulebook for every model. It says Anchor is up to 34 times faster than the four frontier models closest to it, and up to 12 times cheaper than those same four. The wire’s “up to 34 times” and “up to 12 times” do not print the word four. Do not merge the page’s four into the wire’s sentence. The page also says 37 percent fewer misses than the closest frontier model, and glosses that as: for every 100 violations that model let through, Anchor caught 37. That gloss is the page’s. This desk did not recompute it. The footer of that scorecard says FINRA Communications Benchmark, 150 human-labeled tasks, Surge AI, September 2026, and that the results are self-reported and an independent run is in progress. Self-reported means the company published its own scores. The wire says the labels were produced independently by Surge. The scores are still the company’s until that independent run exists. The page’s prices: Mini is $0.002 per enforcement, the flagship is $0.01, and Max is $0.05. One enforcement, the page says, is one message up to 2,000 tokens, with rewrite and verification included, and output tokens are never billed. A token is a small chunk of text. The glance line says $0.01 per message, flat, which matches the flagship price, not Mini and not Max. New accounts start with $10 in free credits. Mini, on this page, classifies the whole message, does not rewrite, and does not take custom policies. The flagship works per line, rewrites and verifies, and learns custom policies as a trained adapter. Max works per line with reasoning, rewrites and verifies, and enforces uploaded policy documents with nothing to train. The page says thirteen regulation areas are already learned. The wire names FINRA and the SEC. The longer list is the page’s, and it is in the source note. These figures are the page’s. This desk did not buy an enforcement.

What an independent report adds the same morning, and where it does not match the wire. SiliconANGLE’s story is by Paul Gillin. The visible line is UPDATED 09:00 EDT / SEPTEMBER 23 2026. The structured published time is 2026-09-23T13:00:48+00:00, which is 9:00 a.m. Eastern plus 48 seconds. The modified time is 2026-09-23T15:35:23+00:00, which is 11:35 a.m. Eastern. The story says ZeroDrift Inc. launched Anchor 3.0, generally available through the Enforcement API. It says the flagship detected more than 95 percent of violations. More than 95 percent is that story’s rounding. It is not the wire’s 95.5 percent, and this filing does not treat them as one printed figure. It says the model matched the overall accuracy of GPT-6 Astra and Claude Fable 5.1 while running more than 34 times faster and at one-twelfth the cost. Matched overall accuracy, and those two model names, are SiliconANGLE’s. The wire’s comparison is that Anchor outperformed GPT-5.6 Sol on recall, precision, and F1. Do not merge GPT-6 Astra, Claude Fable 5.1, and GPT-5.6 Sol into one ranking. The story says the benchmark used attorney-labeled data produced independently by Surge AI, according to ZeroDrift, and that ZeroDrift published the benchmark itself, so the performance figures remain company claims. That last clause is SiliconANGLE’s caution. It matches the product page’s line that an independent run is in progress. On Mini, SiliconANGLE says it is a 9 billion-parameter mixture-of-experts model with 4 billion active parameters. Mixture-of-experts means only part of the model runs on each message. The wire prints 9 billion and 4 billion active and does not use those words. File the label as SiliconANGLE’s. The same story says Mini caught about 5 percent more violations than Claude Fable 5.1 and about 20 percent more than GPT-6 Astra, with fewer than half as many false positives as Claude. Those Mini gaps are SiliconANGLE’s. They are not on the wire, and they are not the flagship’s 95.5 percent. SiliconANGLE also says the broader platform can flag, rewrite, block, or route a message for a person to review, and keep a record for an audit. The wire’s flagship sentence is flag the lines and rewrite them. Do not collapse the four verbs into the wire. The story says the company recently introduced Guard for Agents, a separate API that inserts checks into agent workflows. That product name is SiliconANGLE’s. It is not a second name for Anchor 3.0 on the wire. The story says the production release follows an August preview, when the company described the software as a risk-reduction layer rather than a guarantee that every violation would be caught. August, and that guarantee line, are SiliconANGLE’s. The photo credit on that page is SiliconANGLE/Dreamina. That image is not this filing’s hero.

Who started it, in the release’s about box. ZeroDrift says it pioneered enforcement runtime for AI communications: every major regulation pre-loaded, a company’s own policies trained on top, and a control on what agents say, see, hear, and do before they communicate or act, with a record a regulator can audit. It says it is starting with communications and expanding to every rule a company writes. It was founded in New York by AI and platform leaders from Google DeepMind, Microsoft AI, and Goldman Sachs. The release does not print those leaders’ names. Do not invent them. It is backed by $10 million from a16z speedrun, PitchDrive Ventures, and other leading AI investors. a16z is Andreessen Horowitz. speedrun is that firm’s program, as the release writes it. $10 million is the backing the release states. It is not a valuation, which would be a price on the whole company. The page does not print a valuation. These lines are the release’s. This desk did not see a term sheet.

Plain English for the rest of the card: Anchor 3.0 = the model family. general availability = a developer can use it. FINRA = the US brokerage self-regulator. SEC = the US securities regulator. small language model = a compact model trained for one job. recall = the share of real violations caught. 95.5 percent = the company’s recall figure. 92.9 percent = the product page’s best frontier model on that set. precision = the share of flags that were real violations. F1 = the wire’s balance of those two. GPT-5.6 Sol = the frontier model the wire calls strongest on its test. GPT-6 Astra and Claude Fable 5.1 = the models SiliconANGLE names for a matched-accuracy sentence. Those are not the wire’s sentence. 34 times and 12 times = the company’s best-case speed and price claims. four = the product page’s count of frontier models in that speed and price comparison. The wire does not print four. 1.5 seconds = the API time on the wire and the page. under 100 milliseconds = the self-hosted time. 12 to 51 seconds = the wire’s range for the strongest frontier models. 9 billion and 4 billion active = the wire’s size for Mini and the flagship. 27 billion = Max. Gemma E4B = the Google starting model for the two smaller sizes. Qwen3.8-27B = the Alibaba starting model for Max. LoRA = a small add-on for a company’s own rules. $0.002, $0.01, and $0.05 = Mini, flagship, and Max, on the product page. 2,000 tokens = the page’s cap for one priced enforcement. $10 = the page’s starting credits. 150 = the page’s count of human-labeled tasks. 81 percent and 45 percent = the wire’s Cambridge citation. billions = the wire’s word for communications fines, with no total printed. $10 million = the backing, not a valuation. independent run in progress = the product page’s line, and SiliconANGLE’s caution that the scores are still the company’s. This filing is the 23 Sep launch. It is not a rescore, and it is not a guarantee that every violation is caught.

PRIMARY here: ZeroDrift’s 23 Sep 2026 GlobeNewswire release, published time 2026-09-23T13:00:00Z, datelined New York — Tier A PRIMARY, the company’s own record. The product page at zerodrift.com/model/anchor is the product primary, not a second announcement clock. SiliconANGLE’s same-morning story by Paul Gillin is the independent report, not a substitute primary and not a second set of numbers. The general-availability announcement, the 9:00 a.m. Eastern stamp, the first-family and first-benchmark wording, the human-written attorney-labeled Surge line, 95.5 percent, GPT-5.6 Sol, recall, precision, F1, up to 34 times and up to 12 times, the Cambridge 81 percent and 45 percent lines, the FINRA 2026 report citation, the billions-in-fines sentence, the 12-to-51-second range, the 1.5-second and under-100-millisecond lines, the Aroomoogan quote, the three sizes with 9 billion, 4 billion active, 27 billion, Gemma E4B, Qwen3.8-27B, the 200-rule library, the LoRA line, the Felix quote, the Enforcement API, the New York founding, the unnamed leaders from Google DeepMind, Microsoft AI, and Goldman Sachs, and the $10 million from a16z speedrun and PitchDrive Ventures are the release’s. The 92.9 percent line, the four-model speed and price comparison, the 37 percent misses line, the 150-task line, the self-reported and independent-run sentence, the $0.002, $0.01, and $0.05 prices, the 2,000-token unit, the $10 credits, the verdict-rule-passage-rewrite line, the deterministic engine, the FINRA Rule 2210 illustration, and the thirteen regulation areas are the product page’s. The more-than-95-percent wording, the GPT-6 Astra and Claude Fable 5.1 matched-accuracy sentence, the one-twelfth cost line, the mixture-of-experts label, the Mini 5 percent and 20 percent gaps, the flag-rewrite-block-route list, Guard for Agents, and the August preview’s not-a-guarantee line are SiliconANGLE’s. NOT claimed: a valuation, the founders’ names, that this desk ran the benchmark or opened the product, that 95.5 percent and more than 95 percent are one printed figure, that GPT-5.6 Sol, GPT-6 Astra, and Claude Fable 5.1 are one comparison, that the wire’s speed claim names four models, that Surge’s labels make the scores independent, that the August preview guaranteed coverage, that Guard for Agents is Anchor 3.0, a stock tip, or investment advice. Distinct from the already-filed microsoft-eviltokens, cisco-talos-cairn, and numeral-100m.

RELATED

ONLINE

article thread

guidelines

warming…

warming…

On 23 Sep 2026 ZeroDrift said Anchor 3.0 is generally available. The record is the company’s GlobeNewswire release, “ZeroDrift Launches Anchor 3.0, the First Family of Models Built for Enforcement Runtime of AI Agent Communications.” The page’s published time is 2026-09-23T13:00:00Z, which is 9:00 a.m. Eastern. The header reads September 23, 2026, 09:00 ET, source ZeroDrift. The dateline is NEW YORK, Sept. 23, 2026. General availability means a developer can use it, not only join a private test. The release calls ZeroDrift the Enforcement Runtime for AI, and Anchor 3.0 the first family of small language models built to enforce regulatory and company rules on AI-generated communications before they are sent. A small language model is a compact AI model trained for one job, not a giant model that tries every job. First family, and first benchmark, are the company’s words. These lines are the release’s. This desk did not send a message through the product.

Sources