Compliance and being at the forefront of technology: not an obvious combination. The field is risk-averse by nature and therefore rarely the first to embrace a new technology. And yet there is little work that fits AI so well: knowledge-intensive, highly analytical and problem-solving, and full of repetitive control, monitoring, recording and reporting tasks. Precisely the kind of work where AI can add the most value. So the question is not whether AI will touch the compliance profession, but how you deploy it without throwing your own principles overboard.
And that is exactly the crux of this epilogue: you need the same compliance knowledge and skills to embed the AI application itself neatly within a framework and governance. Compliance deploys AI to do compliance and then brings that AI back under compliance. Almost an AI compliance inception.
This is the epilogue of our series on sustainable compliance. We laid the foundation (read this blog here), kept the framework alive as an ecosystem through the PDCA cycle (part 1, part 2 & part 3), and chose a base to let everything grow on (the GRC tool blog). In the final part, we already introduced the "robot gardener": AI that helps maintain the ecosystem. Below, we walk through the opportunities and the risks.
An ecosystem needs maintenance: pruning, watering, spotting diseases early. That work is repetitive and never finished, precisely where a tireless gardener adds value. AI is that gardener: it does an enormous amount of work, spots patterns you miss, and works around the clock. But it does not decide which garden you want. That remains up to you. The vision, strategy, risk methodology and governance you set out in the previous parts form the design the gardener works to. Without that design, it prunes at random.
With that caveat: where can AI make the difference? Let us walk through the PDCA cycle.
Where legal texts and contracts are now largely combed through by hand to identify relevant requirements, AI can (partly) automate this. Think of:
The human role shifts from collecting data to validating and deciding. The risk appetite conversation becomes richer, not replaced. And you shift from periodic insight to a real-time picture: no risk register updated once a quarter, but a living view of your threat landscape. Work with a rolling roadmap (agile if you like) that you review every quarter, with prioritisation, capacity planning and built-in trigger events for new legislation or incidents. The future lies in continuous monitoring rather than periodic control execution.
Risk: AI likes to fill gaps with plausible-sounding nonsense. A mismapped requirement or an invented article number slips in all too easily. Treat the output as a junior’s draft, not a final verdict: a human validates.
The challenge in the Do phase is scarcity: you never have enough hands for all the controls. AI helps optimise execution relative to risk:
Risk: automation bias. If “the AI has already done it”, no one looks critically any more. That is green ticks 2.0, produced faster, just as misleading.
Traditional monitoring is sample-based and after the fact. An AI-native approach changes that fundamentally:
Concrete example: a cookie-banner checker that scans all domains daily, tests deviations against your internal policy, and only escalates if the deviation persists for more than 48 hours. The second line gets a dashboard, not an inbox full of alerts.
Risk: a model running on wrong or incomplete data will miss precisely the subtle signals, or raise false alarms. Garbage in, garbage out still applies, and a prediction is not evidence.
The Act phase is especially well suited to AI support:
The human role remains to decide, but the decision is better informed. Controls thus shift from response to detection and even prevention.
Risk: learning prioritisation can entrench historical blind spots; what was not measured in the past, the model does not see either. And a slick, persuasively presented action suggestion invites rubber-stamping without your own judgement.
Let AI work within your frameworks, not alongside them. The same vision, risk methodology and governance that steer your ecosystem also steer the gardener. And keep watch over where your (confidential) risk and audit information goes, that was a deliberate consideration in the previous part for good reason: which model do you use, where does it run, and who has access to the data?
The gardener is standing in the garden too. An AI application is a compliance object in its own right. Think of the AI Act and of ISO 42001 for AI management systems: transparency, logging, human oversight and countering bias are all part of it. Anyone deploying AI to speed up compliance must keep that AI compliant too. That is the inception we opened with and precisely why compliance knowledge remains indispensable.
AI is a powerful gardener for your compliance ecosystem: it speeds up understanding legislation, structures control frameworks, allocates capacity to risk, flags deviations and makes risks visible. But above all it speeds up a well-designed framework, it does not repair a shaky foundation. Judgement, the risk trade-off and accountability remain with people.
Along those lines, the circle is complete: from an isolated project to a living ecosystem, with AI as the tireless caretaker that helps that ecosystem grow, as long as you remain the gardener who decides what the garden looks like.
Curious how AI fits within your risk and compliance ecosystem? We are happy to think along with you.