Recently, one of Symbiant’s FTSE 100 clients paid Symbiant’s embedded AI one of the strongest compliments a compliance team can pay a piece of software: they trusted it.
Its recommendations had proved so consistently reliable that the team rarely found reason to amend them. Human review was beginning to feel like a formality, prompting an understandable question: could the AI’s outputs simply be accepted automatically?
Technically, we could have enabled that.
We advised against it.
Not because the system was performing badly, but because it was performing exceptionally well. The greater risk was that repeated accuracy could gradually turn human approval from a meaningful control into a ceremonial click, and eventually make that control appear unnecessary altogether.
That conversation reveals something important about the future of AI in compliance. The most consequential risk may not arise when AI produces an obvious error. It may arise when an organisation becomes so accustomed to accepting good recommendations that it stops independently judging them.
An AI recommendation can be factually accurate, logically coherent and entirely consistent with the information available to the system, and still require human judgement.
Compliance is not simply an optimisation exercise. A recommendation that appears correct against one control, policy or objective may have implications elsewhere in the organisation. It may affect another regulatory obligation, conflict with an accepted risk position, overlook commercially sensitive context or create consequences that sit beyond the task the AI was originally asked to perform.
The AI does not need to malfunction for this to happen. It may simply pursue its assigned objective successfully without being positioned to judge the wider organisational consequences.
That is why accuracy and accountability cannot be treated as the same thing.
AI can analyse evidence, identify gaps, map obligations and recommend a course of action. But the decision to accept that recommendation changes the organisation’s compliance position. That decision must remain with someone who understands its wider implications, has the authority to make it and can be held answerable for the outcome.
The technology industry, meanwhile, is moving rapidly towards Agentic AI: systems that can be given an objective and allowed to determine and execute the steps required to achieve it, with progressively less human intervention.
For many business processes, that model may deliver enormous value. Compliance, however, presents a harder question:
At what point does removing friction also remove meaningful human control?
Regulators and auditors are unlikely to accept “the AI decided” as an explanation. The organisation will still be expected to identify who approved the decision, what evidence was considered, how its wider consequences were assessed and who was accountable for the outcome.
Automation does not eliminate that responsibility. It can only make its ownership less visible.
At Symbiant, our position is not that AI should be held back. AI is extraordinarily valuable when it helps compliance professionals interpret information, surface connections and reach better-informed decisions. But assistance and authority are not the same thing.
The future of AI in compliance should therefore not be defined by how completely people can be removed from the process. It should be defined by how effectively AI can strengthen human judgement while preserving a clear and defensible chain of accountability.
Even an accurate AI recommendation is not automatically a responsible compliance decision.
That distinction is the starting point for a more mature discussion about AI in compliance. The central question is not simply whether an AI system can reach the right answer. It is whether an organisation should allow that system to convert its answer into an organisational decision without an accountable person judging the wider consequences.
The real risk does not always begin with an error
Much of the debate about AI governance begins with familiar concerns: hallucinations, inaccurate outputs, bias or poor-quality data. Those risks are real, but they are not the whole problem.
An AI system can produce an output that is factually accurate, logically coherent and consistent with the information available to it, and the recommendation can still be inappropriate for the organisation.
Why? Because compliance decisions are rarely questions of factual accuracy alone. They require judgements about materiality, proportionality, regulatory intent, acceptable risk, competing obligations and the practical consequences of acting. Those considerations may sit outside the task the AI was given or outside the information it was permitted to see.
A system might correctly identify that an action meets its documented closure criteria, while a compliance professional knows that closing it before an upcoming regulatory review would create an incomplete or misleading picture. It might accurately map evidence to a control, while a human recognises that the evidence is outdated, locally inapplicable or inconsistent with how the control operates in practice. It might recommend the most efficient remediation without appreciating that the change would create a different legal, operational or customer risk elsewhere.
None of these scenarios requires the AI to malfunction. The system may simply succeed within the boundaries of its assigned objective while the organisation suffers consequences beyond those boundaries.
Compliance is not an optimisation problem
Agentic AI is commonly described as AI that can orchestrate and execute a sequence of tasks towards a goal with some degree of autonomy. The appeal is obvious: instead of asking for individual pieces of work, an organisation defines an outcome and allows the system to determine how to achieve it.
But compliance metrics are representations of organisational reality; they are not the reality itself. Treating them as pure optimisation targets can produce an apparently improved dashboard without producing a better-controlled organisation.
Consider a seemingly sensible instruction:
Reduce all overdue compliance actions.
A compliance professional is unlikely to treat every overdue action in the same way. They may ask:
- Why is this particular action overdue?
- Is the owner waiting for evidence from a regulator, supplier or third party?
- Has the deadline been formally extended or challenged?
- Would closure conceal an unresolved control weakness?
- Should the action be escalated rather than completed?
- Would changing its status distort management or board reporting?
An autonomous system may be instructed to consider some of these factors. It may also have access to extensive organisational data. But its ability to optimise for the target does not guarantee that it will preserve the purpose behind the target.
The system could reduce the number of overdue actions by closing, reclassifying, consolidating or rescheduling them. Each step might be procedurally permitted. Yet the combined effect could weaken the control environment the metric was intended to reveal.
This is the compliance version of a familiar governance problem: once a measure becomes the objective, pressure builds to improve the measure rather than the underlying condition. In compliance, a cleaner dashboard is not automatically a safer, fairer or more defensible organisation.
Accuracy is evidence of capability – not a transfer of authority
The FTSE 100 client’s request was reasonable precisely because the AI had earned confidence. But confidence in an output and authority to act are different categories.
Authority in compliance comes from an organisational mandate. A compliance officer, control owner or responsible executive is expected to understand the decision, exercise judgement, work within defined responsibilities and answer for the result. Software can support each of those activities, but it does not acquire that mandate merely by being correct repeatedly.
This is why removing an approval step does not remove accountability. It creates a mismatch: the system exercises practical authority, while responsibility remains with people who may no longer be meaningfully involved in the individual decision.
What regulators, standards bodies and auditors are signalling
The emerging governance direction is strikingly consistent. Different frameworks use different language, but they repeatedly return to identifiable responsibility, documented oversight, traceability and meaningful human involvement.
The ICO: no loss of accountability
The Information Commissioner’s Office says there should be no loss of accountability when a decision is made with the help of, or by, an AI system. Its AI audit framework expects organisations to designate responsibility for AI oversight, assign technical and operational roles, secure senior-management sign-off on AI risks and maintain a documented governance framework.[1][2]
Crucially, the ICO does not treat the mere presence of a person as sufficient. Its human-review guidance says reviewers should have the knowledge, experience, authority and independence to challenge AI decisions.[3] That moves the standard beyond ‘human in the loop’ as a workflow label. The human must be capable of changing the outcome.
ISO/IEC 42001: innovation within a management system
ISO/IEC 42001, the international standard for AI management systems, frames responsible AI as an organisational management discipline. It emphasises structured governance, risk treatment, traceability, transparency and continual improvement.[4] The implication for compliance teams is important: trustworthy AI is not achieved by relying on the apparent quality of individual outputs. It depends on the policies, responsibilities, controls and review mechanisms around the system.
The FRC and auditors: the professional remains accountable
The Financial Reporting Council’s 2026 guidance on generative and agentic AI in audit is especially direct. It states that regulatory accountability for deploying AI tools and for the quality of audit outputs remains unchanged: the human auditor is always accountable, and professional judgement remains at the core of regulation.[5]
The FRC also identifies a subtle risk that maps closely to compliance: a plausible-looking AI output may be misunderstood, misinterpreted or relied upon for a purpose for which it was not designed. An output therefore does not need to be obviously false to create an inappropriate conclusion.[6]
The Institute of Internal Auditors’ Global Internal Audit Standards similarly place integrity, objectivity, competence, due professional care and judgement at the centre of assurance work.[7] AI can expand the evidence available to professionals; it does not remove the professional obligations attached to interpreting that evidence.
The FCA: AI does not dissolve individual responsibility
For regulated financial services firms, the FCA says its rules emphasising senior-manager accountability remain relevant to the safe use of AI.[8] The broader logic of the Senior Managers and Certification Regime is that firms should be able to show who is responsible for what. AI may change how work is performed, but it does not make that chain of responsibility optional.
Human review can exist on paper and disappear in practice
There is, however, an uncomfortable truth: retaining an approval button does not automatically preserve human judgement.
When a system produces reliable recommendations repeatedly, reviewers learn that challenging it rarely changes the result. Attention declines. Acceptance becomes habitual. The approval remains visible in the audit trail, but the underlying judgement has become progressively thinner.
This is often described as automation bias: people place disproportionate confidence in automated outputs or fail to notice information that contradicts them. In a compliance workflow, that creates a dangerous illusion. The organisation can point to human approval, yet the human may no longer be exercising meaningful review.
That was the deeper significance of our client’s request. Automatic acceptance would have formalised a behavioural shift that had already begun: review felt unnecessary because the AI was usually right.
Good governance therefore requires more than keeping a person nominally ‘in the loop’. Review must be designed so that the person remains intellectually engaged and operationally capable of intervening.
Meaningful human review should ensure that:
- A named and authorised person owns the decision.
- The recommendation, relevant evidence and stated reasoning are visible.
- The reviewer can amend, reject or escalate the proposed outcome.
- The reviewer has enough time, competence and organisational context to challenge it.
- The final decision and any departure from the AI recommendation are recorded.
- Higher-impact decisions receive stronger scrutiny than low-risk, reversible actions.
The objective is not to make every AI-assisted action slow. It is to make oversight proportionate and real.
The better boundary: broad assistance, controlled execution
The choice is not between manual compliance and unrestricted autonomy. A better model distinguishes between analytical freedom and decision authority.
AI can be given considerable latitude to collect, compare, connect and draft. Stronger controls can remain around actions that materially change the organisation’s compliance position.
Stage | AI can assist by | The responsible human should |
Research | Search policies, controls, obligations, previous findings and evidence. | Set scope, confirm source relevance and identify missing context. |
Analysis | Detect gaps, inconsistencies, duplicate records and relationships across compliance data. | Assess materiality, proportionality and implications beyond the assigned task. |
Recommendation | Draft actions, map evidence, suggest controls and explain likely consequences. | Challenge assumptions and decide whether the recommendation fits the organisation’s obligations and risk position. |
Execution | Prepare the proposed record change or workflow action. | Authorise, amend, reject or escalate any material change and remain accountable for it. |
Assurance | Maintain structured evidence and surface patterns in accepted, amended or rejected outputs. | Monitor performance, test controls and determine whether the level of autonomy remains appropriate. |
A governed model expands AI’s analytical contribution while preserving human authority at the point of material decision.
This boundary need not be identical for every workflow. Low-impact, deterministic and easily reversible tasks may be automated more extensively. A reminder email, a duplicate warning or a request for missing evidence does not carry the same significance as closing a compliance action, accepting an exception, changing a control status or representing that an obligation has been met.
The level of human control should therefore follow the potential consequence of the action, not the novelty of the technology.
What this means for Symbiant’s approach
At Symbiant, we believe AI should make compliance professionals better informed, more consistent and more effective, not less accountable.
Symbiant’s embedded AI works within connected governance, risk, compliance and audit data. It can help identify gaps, analyse relationships, map evidence, surface potential root causes, recommend actions and show how issues may connect across the organisation.[9] This context allows AI to do far more than summarise isolated documents.
But context-rich analysis and organisational authority remain different things. The purpose of the AI is to strengthen the professional’s judgement by reducing administrative effort and revealing information that deserves attention. The responsible human still determines whether the recommendation is appropriate, proportionate and defensible.
That is not a limitation of the technology. It is a deliberate governance control.
The human is not retained because we assume the AI will be poor. The human is retained because compliance decisions belong to accountable people.
The future is not less AI. It is better-governed AI.
AI will become more capable, more connected and more autonomous. Compliance teams should benefit from that progress. Refusing useful automation is not a serious governance strategy.
But neither is surrendering judgement simply because a system has earned our operational trust.
The most mature AI implementation will not necessarily be the one with the fewest human touchpoints. It will be the one that knows which touchpoints add no value, which can be streamlined safely and which preserve the organisation’s chain of accountability.
Our FTSE 100 client was right to trust the quality of the AI’s work. We were right to protect the distinction between trusting a recommendation and granting the authority to act on it.
Where this leaves compliance teams
AI is going to reshape compliance, that part isn’t really in question anymore. The real question isn’t whether to adopt agentic AI, but how much genuine autonomy a compliance function is willing to grant it, and at which stage of the decision.
In environments defined by trust, regulatory scrutiny and personal accountability, full autonomy isn’t the sophisticated choice. It’s the fragile one. The more durable version of “powerful AI” isn’t the system that acts independently, it’s the system that makes the people responsible for the compliance outcome measurably faster and better at their jobs, while leaving them unambiguously in charge of the decision.
That’s the line we’ve chosen to hold at Symbiant:
The AI provides the recommendation. The human provides the judgement – and remains accountable for the decision.

Experience AI-Assisted Compliance Without Surrendering Control
Symbiant’s embedded AI helps compliance teams analyse connected data, identify gaps, map evidence and develop better-informed recommendations—while authorised people retain control over what is accepted, changed or acted upon.
Discover how Symbiant can strengthen your compliance processes without weakening the chain of accountability.
Sources and further reading
[1] Information Commissioner’s Office, Governance and accountability in AI
[3] Information Commissioner’s Office, Artificial intelligence audit framework: Human review
[4] International Organization for Standardization, ISO/IEC 42001:2023 – AI management systems
[6] Financial Reporting Council, Generative and Agentic AI Guidance factsheet, 2026
[7] The Institute of Internal Auditors, Global Internal Audit Standards, 2024
[8] Financial Conduct Authority, AI and the FCA: our approach
[9] Symbiant, AI-Embedded GRC Software for Risk, Resilience & Compliance

