The conversation about AI in compliance has been running for long enough that the question is no longer whether compliance teams will use it, but what they are actually doing with it right now and whether it is working. Based on operational experience and conversations across regulated firms, the picture is more granular than most of the commentary suggests.
Most AI deployments in compliance functions are not the transformational implementations described in conference presentations. They are quiet, incremental applications to specific tasks that were previously time-consuming but not technically difficult. That is not a criticism. It is an accurate description of where genuine value is being generated, and it matters because it sets realistic expectations for compliance functions that have not yet started.
Where value is being generated
The most consistently successful applications share a common characteristic: they involve tasks that require structuring and drafting rather than original professional judgement. Producing a first draft of a suspicious activity report (SAR) narrative from a set of established facts, summarising a regulatory publication in plain English for a board briefing, generating a template customer risk assessment structure for a specific business type or customer profile, and drafting the narrative section of an enhanced due diligence (EDD) file are all tasks where a well-constructed prompt, supplied by someone who understands the subject matter, reliably produces output that is faster and often cleaner than starting from scratch.
These are not trivial time savings. For a compliance team processing high volumes, the ability to move from facts to structured first draft in minutes rather than hours, and then apply professional judgement to review and refine, changes what is achievable within a given resource base.
A second category of genuine usefulness is policy and procedure gap analysis. When a regulatory change is published and a compliance team needs to assess its current documentation against the new requirements, AI tools are capable of working systematically through a document against a reference framework and identifying gaps or inconsistencies at a speed that no manual process can match. The output still requires expert review, and the AI cannot exercise the contextual judgement that an experienced MLRO brings, but as a first-pass tool it is materially useful.
A third area, less commonly discussed but increasingly relevant, is training content generation. Producing realistic scenario-based training materials that reflect current typologies, regulatory expectations and firm-specific risk profiles is time-consuming. AI tools can generate plausible scenarios, suggest red flag indicators and draft discussion questions at a pace that makes regular refresh of training content practically achievable rather than aspirationally intended.
Where it is falling short
The failure modes are as instructive as the successes. The most common problem is not hallucination or factual inaccuracy, although those risks are real and require management. The more prevalent problem is over-reliance on AI-generated output without the level of expert review that the task demands.
SAR narratives drafted with AI assistance and submitted with minimal review are a regulatory risk. The MLRO bears legal responsibility for every SAR submitted, and that responsibility cannot be delegated to a language model. Where firms have started treating AI-drafted SARs as finished product rather than first draft, they are creating exposure that will not be visible until it is tested by a regulator or law enforcement query. The same principle applies to EDD files, risk assessments and board reports.
A second failure mode is the quality of prompts. The output of an AI tool is directly determined by the quality of the input. Compliance teams that are producing poor outputs are generally producing poor prompts, and poor prompts are generally being produced by people who do not understand what the tool needs to understand the task. Prompt construction is a skill that takes time to develop, and it is not the same skill as being a competent compliance professional, although subject matter expertise is the foundation that makes good prompts possible.
What the FCA's position means in practice
The FCA has been carefully watching AI adoption across regulated firms and has made clear through publications, speeches and supervisory communications that it expects firms to govern AI use appropriately. Three practical implications follow from this. First, if your firm is using AI tools in compliance workflows, you need a documented AI use policy that addresses accountability, review processes and the limits of permitted use. Second, the compliance professional responsible for a decision remains accountable for that decision regardless of what tools contributed to it. Third, firms should expect AI governance to become a standard area of supervisory scrutiny, and those without documented policies and oversight frameworks will be at a material disadvantage when that scrutiny arrives.
What good looks like
The compliance functions that are making genuine progress with AI adoption share several characteristics. They are using AI as a force-multiplier for experienced compliance professionals rather than as a replacement for them. They have clear internal policies governing what AI can and cannot be used for, who is responsible for reviewing AI-generated output, and how AI use is documented. They are applying human expert review to every piece of AI-assisted output before it is used, filed or submitted. And they are iterating based on what works, refining their prompt libraries and workflows based on operational experience rather than vendor presentations.
None of this requires a significant technology budget or a dedicated AI team. The tools that compliance functions are finding useful are generally the same large-language-model interfaces that are already widely accessible. What it does require is the time and organisational discipline to develop operational protocols, and the seniority and expertise to ensure that those protocols are taken seriously across the compliance function.
The firms that will derive sustained value from AI in compliance are not the ones that adopted it earliest, but the ones that adopted it most thoughtfully.