With AI, Compliance Professionals Must Be Technologists Now
By Jonathan Roberts, FTI Technology
At the midpoint of 2025, the state of artificial intelligence appears to be defined by two major themes: a rapid acceleration of corporations adopting AI tools or integrating AI into existing systems of work; and a shift toward AI governance rather than AI compliance, amid deregulatory signals in the U.S. The imperative for the modern compliance professional in this environment is to fill the gaps between regulation and best practice, and acting proactively where regulators are not.
While Congress considered a moratorium on AI regulations through the 2026 budget reconciliation process, according to a recent article from CIO Dive, more than 80% of tech leaders indicated in a survey that employee AI tool adoption has outpaced their IT teams’ capacity to evaluate those tools for safety. In the same report, one-third of employees indicated they had entered confidential client data into non-approved external AI applications and nearly two in five had entered confidential company data into such tools.
Considered in another light: the likelihood of AI misuse or system penetration is increasing with greater adoption. In parallel, the regulatory pullback reduces the likelihood for these risks to be identified and mitigated across industry sectors.
Accordingly, as proposed AI solutions and use cases arise within an organization, compliance professionals must be tech-conversant (if not tech-fluent) in order to first interrogate those purposes and uses; and second, to properly weight the accompanying risks.
These actions are complicated by the unique risks posed by AI solutions generally and generative AI in particular. Along with the ever-present risk of deliberate misuse, compliance professionals must consider the risks of under-educated use that imparts to the technology a capability or factual authority that it does not have. Further, the probabilistic nature of AI-generated content — wherein the machine presents the user with, essentially, the answer it calculates that the user expects to see — heightens the risk of reinforcing cognitive biases or amplifying discriminatory patterns. Compliance professionals must also consider the potential for the pace of AI innovation to surpass the ability of any proposed testing or controls regime to fully govern it.
Where AI tools are being used for compliance purposes, these risks are magnified. By definition, the compliance AI tool lacks true understanding and institutional context. Both compliance domain expertise and technological fluency are needed, particularly in maturing organizations: the former, to establish whether the AI tool’s output is useful for compliance purposes; and the latter, to articulate how the tool works and make full use of its capabilities.
For these reasons, tech up-skilling within the compliance function is a risk mitigation strategy unto itself. The essence of this strategy is to adopt a technology maturity approach: understanding the lifecycle and usage of data within the organization’s AI tooling; the outputs created by those tools, how they are used and whether they are useful; and crucially, the potential pathways of future development. Organizations should support these objectives by embedding compliance and legal professionals in the AI development process from its earliest stages. Organizations can also partner with a trusted advisor to conduct a technology maturity assessment and develop targeted recommendations for AI governance, risk and compliance.
For compliance controls and testing regimes to be effective, compliance professionals need to know what actions, outcomes or types of conduct need to be prevented. Future regulatory regimes may require organizations to understand the platforms used, data handoffs implicated and the business processes that are served by AI-generated products, but will not always clearly define what level of knowledge will be considered sufficient.
Therefore, where AI tools are concerned, compliance professionals must become, to some degree, technologists. Cultivating technical knowledge and capabilities within the compliance function will be increasingly important, to ensure teams can recognize the risks posed by AI tools and AI use and execute the necessary mitigations. Compliance professionals can and should act now to develop these skills, which will pay dividends irrespective of future regulation, as AI innovation and adoption accelerate.