Compliance Automated Itself First. It Still Answers to No One.
By Jean-Hugues Migeon
More than a third of financial firms have put AI to work inside their own compliance function: drafting investigation memos, triaging alerts, summarizing regulatory change, testing controls. Most of them plan to expand that use over the next year. Read on its own, it sounds like a success story, the function built to catch risk is also the function moving fastest to modernize itself.
Now look at who can actually stop one of those tools if it starts making bad calls. Fewer than one in five of those same organizations has an enterprise-wide council with the standing authority to approve, restrict, or kill an AI use case anywhere in the business, including inside compliance itself. The function with the clearest mandate to govern AI risk is, on the numbers, no better structured to govern its own AI than any other department. In a lot of firms it is worse, because nobody thinks to check the checker.
The two numbers were never supposed to move this far apart
A Nasdaq survey of financial firms puts AI use inside compliance functions at roughly 36 percent. Separate industry research on responsible AI governance structures finds that only about 18 percent of organizations have a council with enterprise-wide, binding authority over AI decisions. Adoption and authority are not two readings of the same trend. They are two different curves, and the gap between them is where the actual risk sits, not in the AI tools themselves but in the absence of anyone who can say no to one.
That gap does not stay static either. Every quarter compliance teams adopt more AI to keep pace with their own workload, and the 18 percent figure does not move nearly as fast, because standing up a body with real authority takes a mandate, a budget line, and a name willing to own the decisions, none of which arrive as a side effect of buying software.
A council is not a policy that got a promotion
Most firms in the 82 percent without a council are not ungoverned in the sense of having nothing written down. They have an AI policy, often a good one. The confusion is treating the policy as if it does the job a council does. A policy states principles. It does not approve a specific use case, it does not decide when a lightweight review is enough versus a full model risk assessment, and it does not own the register of what is actually running where. A council does all three, and it produces something a policy never does on its own: a decision log with a name attached to it.
That distinction is invisible until the day an examiner or an auditor asks for the record of who approved a specific tool, and the honest answer is that nobody with enterprise-wide authority ever weighed in, because nobody with that authority exists.
Who is actually deciding, if not a council
Usually whoever bought the tool. IT procurement signs a contract, a business unit lead approves a pilot, a compliance director greenlights a use case inside their own team, each acting well within their own remit and none of them holding authority beyond it. That is not misconduct. It is what happens by default whenever adoption moves faster than structure: the decision gets made at the point of purchase, because that is the only point where a decision-maker actually exists.
Three reasons this default arrangement does not hold up once anyone looks at it closely.
- The buyer and the approver are the same person. A compliance director who adopts an AI tool to cut her own team's workload has every incentive to see that tool as low risk, and no obligation to have anyone else confirm the assessment.
- Nobody is checking the checker. Compliance exists to provide independent review of the rest of the business. When compliance governs its own AI use with no outside body involved, that independence disappears exactly where it matters most, inside the function whose job is independence.
- There is no name on the decision. A tool adopted through a team's own workflow rarely produces a documented approval that survives past the person who made it. When that person leaves or the examiner asks, the record is a reconstruction, not a file.
Where the gap actually surfaces
Almost never as a finding titled no AI council. It shows up as a mismatch between what an examiner can ask for and what the organization can produce. The European Commission's early September information requests to more than 30 AI providers asked, among other things, for exactly this kind of governance evidence. Fannie Mae's Lender Letter LL-2026-04 gives the agency a no-notice right to demand a lender's AI inventory on the spot. Under DORA, EU financial firms already have to decompose their ICT suppliers layer by layer, including the AI tools compliance teams pick for themselves. None of these three coordinated with each other. They are converging on the same demand independently, which is usually a sign the demand is permanent rather than a passing enforcement trend.
The fix costs less than the gap does
Closing this does not require a large program. A three or four person cross-functional group, drawn from compliance, technology, and legal, with an explicit written mandate to approve or block AI use cases and keep the system inventory current, closes most of the gap before it needs to grow into a full council. It cannot be advisory. An advisory committee that compliance, IT, or the business can each override achieves nothing the current default already achieves. What makes it real is the power to say no, a register that is actually kept current rather than reconstructed on request, and a name attached to every approval, because that name is what an examiner is actually looking for.
The usual objection is staffing. Most firms without a council do not lack the intent, they lack four people with the right mix of AI, legal, and risk expertise who are not already fully booked on something else. That is the actual reason the 18 percent figure moves so slowly: standing up the body is easy to approve in principle and hard to staff in practice. This is the part that does not have to wait for a hiring cycle. Anove's insAIght includes an Expert on Demand capability that puts named AI governance, legal, and technology professionals directly onto a specific AI project's review, on the timeline the project needs rather than the timeline a recruitment plan allows. It does not replace the standing authority a firm eventually needs to own internally, but it removes the excuse that sits behind most of the 82 percent: the council does not have to exist on the org chart before it can start reviewing anything.

The open question
None of this makes AI in compliance a bad idea. Using it to triage alerts and draft investigation memos faster is a genuine gain, and the firms doing it are not wrong to. The question worth sitting with is narrower: if an examiner asked your organization tomorrow who has the standing authority to say no to an AI tool your own compliance team already uses, would there be a name, or would there be a policy document and an awkward pause.
Learn more
- insAIght: a live inventory of the AI systems in use across an organization, including the ones compliance adopts for itself, with Expert on Demand access to outside AI governance professionals who can review a specific project before a permanent council is in place.
- Four of Five 2026 Threats Are Governance Failures. That Is an Org Chart Problem.: the same structural gap, seen from the CISO's side of the org chart rather than compliance's.
Ready to see what a current, defensible record of who approved what actually looks like for your own compliance function, with expert reviewers you can bring in on demand rather than hire from scratch? Book a demo.