
Artificial intelligence is moving rapidly from experimentation into day-to-day compliance operations at financial institutions, changing not only how firms monitor communications and investigate potential breaches, but also the governance, data and skills they need to support those processes.
That shift was evident during a private executive roundtable hosted by compliance recording specialist Luware at A-Team Group’s recent RegTech Summit in London. Participants from major global banks, investment managers and other financial institutions discussed an environment in which AI is already reducing surveillance workloads, triaging alerts and analysing communications at a scale that would be difficult for human teams to replicate.
The conversation has consequently moved on. Firms are increasingly concerned with what happens when AI becomes part of the compliance operating model: how models are governed and audited, what data they can access, which models should perform which tasks, and how organisations retain the human expertise needed to challenge their output.More Channels, More Complexity
Communications surveillance provides a particularly clear illustration of the problem AI is being asked to address.
Financial institutions are dealing with a steadily expanding range of channels, while different firms continue to take markedly different approaches to their use. Some prohibit external channels such as WhatsApp and WeChat entirely. Others allow them where there is an approved business case and appropriate controls.
Business demand continues to test those boundaries. Zoom became an important channel during the pandemic because clients wanted to use it, creating questions around recording, confidentiality and transcription. Wealth management teams increasingly want access to LinkedIn and other social media channels for client acquisition. AI meeting assistants are now routinely appearing in meetings, forcing banks to determine whether they can be used and what happens to the information they capture.
Even established channels present challenges. One participant described having around 4,000 employees under voice surveillance, with language switching and transcription accuracy continuing to complicate monitoring.
The result is a surveillance environment in which simply adding more people to review more communications becomes increasingly difficult to sustain.
Reducing the Surveillance Burden
This is where AI is beginning to have a measurable impact.
One institution represented at the roundtable is targeting a 90% reduction in Level 1 surveillance false positives. It has already reached 64% and expects to achieve its target in the first quarter of next year. Another use case involves AI generating short disposition summaries to support Level 2 triage, with participants reporting surprisingly high levels of accuracy.More sophisticated models are also becoming better at understanding context across large and complex datasets. In one potential data-exfiltration case discussed at the roundtable, AI identified hidden changes within a large spreadsheet that would have been extremely difficult to uncover manually.
The significance goes beyond reducing false positives. AI potentially changes what surveillance teams can look for by identifying patterns and relationships across volumes of information that would overwhelm conventional review processes.
Captured communications are also starting to have value outside compliance. Participants described the growth of “convenience recording”, where transcripts originally captured for regulatory or supervisory purposes can help identify customer-service bottlenecks, improve staff training or contribute to a broader picture of the firm’s relationship with a client.
That creates opportunities, but also expands the governance problem. Personal use of tools such as ChatGPT for work was identified as a critical concern, particularly where employees may inadvertently submit confidential or proprietary information to services outside the firm’s controlled environment.
Auditability Versus Explainability
As AI becomes embedded in regulated workflows, firms are also having to determine what they need to demonstrate about its behaviour.
An important distinction during the discussion was made between explainability and auditability. Firms can potentially maintain detailed records of the data supplied to a model, the processes followed and the output generated, creating an auditable trail. Explaining precisely why increasingly complex models reached a particular conclusion may be considerably harder and can still require human interpretation.
Regulatory approaches remain uneven. Participants characterised UK regulators as relatively open to firms developing AI within appropriate controls, while approaches in other jurisdictions can be more prescriptive or enforcement-led.
For global institutions, that creates another layer of complexity: the same AI-enabled process may need to satisfy different expectations around governance, reporting accuracy and model oversight across multiple jurisdictions.
One participant described developing AI internally and presenting the underlying architecture to regulators before moving into production, alongside approval through the firm’s Model Risk Management process. Experience gained through those early deployments is now feeding into scrutiny of AI elsewhere within the organisation.
Internal audit is evolving too. Audit teams are beginning to use AI to test the outputs generated by compliance AI, raising the prospect that firms will increasingly find their automated controls being challenged by other automated systems.
Regulators may eventually acquire similar capabilities.
The Model Is Only Part of the System
Another feature of the discussion was the absence of a single preferred AI model.
Participants reported using different models for different workloads, with Claude, ChatGPT and Microsoft Copilot each regarded as stronger in particular areas. Rather than attempting to select one universal model, firms are increasingly considering architectures capable of using multiple models according to the task.
That shifts attention towards what surrounds the model.
The “harness” (encompassing architecture, data access, routing, permissions, monitoring and controls) can become as important as the underlying foundation model. A highly capable model has limited value if it cannot securely access the appropriate information or if the firm cannot govern how its output is used.
Cost is becoming part of that equation too. Some organisations are monitoring token consumption at individual-user level and restricting access where usage becomes excessive or projects are not considered sufficiently important.
AI is therefore beginning to look less like an experimental technology budget and more like another finite enterprise computing resource that has to be allocated and controlled.
The Data Problem Hasn’t Gone Away
Underneath those questions sits a more familiar challenge: data quality.
Participants highlighted inconsistent internal policies and procedures as a significant obstacle to reliable AI output. Feeding contradictory or poorly structured documentation into a model can produce equally inconsistent answers.
Preparing for AI can therefore require considerable work before a model is deployed. Policies have to be rewritten and standardised, information classified and regulatory obligations mapped against internal controls.
Regulatory mapping is one area where firms see significant potential. Tools capable of maintaining repositories of global obligations and mapping regulatory changes against internal standards could eventually automate parts of the documentation process that currently require substantial manual effort and external legal support.
Work towards machine-readable regulation could take that further, allowing regulatory changes to feed more directly into firms’ internal compliance frameworks.
Protecting the Human Expertise
Perhaps the more difficult long-term issue raised around the table was what increased automation means for the compliance workforce.
Most participants described AI primarily in terms of efficiency rather than headcount reduction, although experiences vary between institutions. The deeper concern is what happens to domain expertise when AI begins performing work traditionally undertaken by junior staff.
Level 1 surveillance review, investigation and other repetitive tasks may be obvious candidates for automation. But those activities have also historically helped employees develop the knowledge and judgement required for more senior compliance roles.
If future employees primarily consume AI-generated conclusions without understanding the underlying processes, institutions risk weakening the expertise required to recognise when those conclusions are wrong.
That is driving greater emphasis on training. One firm represented at the roundtable mandates two hours of AI training per employee every quarter and monitors how approved tools are being used. The prevailing view was that organisations should invest in people who already understand the business and compliance environment, giving them the skills to work effectively with AI, rather than assuming that AI expertise can substitute for domain knowledge.
The speed at which these questions are emerging is itself notable. Luware observed that a similar roundtable only a year earlier had also been dominated by AI, but the depth of deployment discussed this time was markedly different.
Model capability will continue to advance, but it is no longer the only constraint on adoption. As AI moves further into regulated workflows, progress will increasingly depend on the architecture, data, governance and expertise surrounding those models.
The firms that make the most effective use of AI in compliance may therefore be those that can do more than generate accurate answers. They will need to control what their models can see and do, demonstrate how they have been used, and retain enough human expertise to recognise when those answers should not be trusted.
Subscribe to our newsletter


