AI & TechnologyAutomation

AI CAN AUTOMATE COMPLIANCE – BUT IT CAN’T TAKE THE BLAME

By Vivek Dodd, CEO of Skillcast

Using AI for everyday tasks has become a common practice across the corporate landscape. Our recent research has shown that in modern offices, 75% of UK professionals are using AI at least weekly, with half relying on the technology multiple times a day. From summarising lengthy email threads and condensing reports to writing code and debugging, LLMs (large language models) can complete manual tasks in seconds. Their efficiency is undeniable.

Driven by market pressure, organisations and individuals are now adopting LLMs at breakneck speed. However, this swift integration carries a number of significant operational and legal risks – especially within corporate compliance.

One major risk is DIY compliance with AI. As workloads grow and budgets tighten, senior leaders and stretched managers are increasingly relying on LLMs to undertake complex regulatory, legal, language and technical tasks, including generating makeshift policy documents and answering regulatory queries from their teams.

Alongside DIY compliance, we’re also seeing growing risks linked to shadow AI. This rise is fuelled by several factors, from ambiguous corporate policies on the correct deployment of AI to clunky and challenging legacy software. We’ve seen it first-hand: unvetted tools can present a dangerous environment and a false sense of security. If left uninterrogated for accuracy and correctness, hallucinations or legal errors inevitably slip through the cracks. Against this backdrop of technical innovation, regulatory frameworks are intensifying, as seen with the FCA’s evolving governance frameworks. Additionally, in the aftermath of the EU AI Act, accountability has become more important than ever. While we can leverage automation to execute tasks rapidly,  AI should never shoulder legal liability. When a regulatory breach occurs – resulting in massive fines or mandatory AI model ban – leadership cannot delegate responsibility to an algorithm.

Unvetted LLM blindspots

It’s easy to understand the appeal of instant, readily available compliance tools in a high-pressure corporate environment. However, generic LLMs cannot uphold the rigorous standards and intricate scrutiny required for effective corporate governance. These tools predict outcomes rather than providing definitive answers. They offer little transparency regarding how decisions are reached and can even alter responses when asked recurring questions. LLMs must be treated as efficiency tools, instead of as a cheat code or shortcut mechanism for resolving complex, multifaceted regulatory issues.

Transparency is another critical gap. Currently, standard LLMs will simply fail to acknowledge when a query falls outside their training data. Instead, they generate the next most probable answer, resulting in a hallucination.When evaluated under scrutiny, it becomes impossible to establish an audit trail or prove how the answer was derived.

One such example is if an employee uses a free AI tool to verify if an internal process complies with regional data privacy laws. The AI could hallucinate old data or outdated regulation information to approve the workflow. This sort of error could go completely unnoticed by an organisation until it is flagged in an official regulatory audit , deemed as a severe breach, and exposes the organisation to massive financial penalties.

Accountability remains human

When an algorithmic failure triggers a breach, liability always rests with human decision-makers. Beyond   severe reputational damage, these errors can lead to significant regulatory penalties. For instance, a major bank was recently fined £21 million by the FCA for systemic failures in its AI-driven customer risk assessment system, which incorrectly reclassified thousands of high-risk profiles as low-risk.

In the aftermath of these situations, we must hold leadership accountable and ask questions such as why were unvetted platforms able to handle sensitive governance materials, where were the guardrails and who signed off on the final decision.

Overreliance on black box technology directly undermines an organisation’s efforts to foster a culture of compliance grounded in robust and stringent oversight. Establishing a healthy compliance culture requires active administration alongside collaboration and individual responsibility. When business leaders delegate decision-making to automated systems, leadership loses visibility over internal operations, creating blind spots that conceal regulatory exposure and erode employee trust.

Building secure AI software

Despite the risks, organisations don’t need to completely halt AI adoption altogether. Instead, firms need to deploy business and domain-specific AI architecture. These specialised networks draw directly from a secure repository or verifies internal data, regulatory frameworks and corporate policies.

Implementing domain-specific networks restrict external web searches and decrease the likelihood of private data appearing online. The technology creates answers using private company information and therefore has a traceable, pinpointed origin.

Maintaining a human in the loop framework requires comprehensive workforce training on AI governance, as well as regular audits and detailed sign-off processes.

AI offers a fast, efficient mechanism  for compliance teams, but nothing can replace human judgement and oversight. Governance is not a passive tick-box exercise. To navigate the future safely, organisations must deploy secure and domain-specific AI architectures while remembering a fundamental truth, that technology can automate the process, but we as humans retain ultimate responsibility for keeping our business and people safe.

Related Articles

Back to top button