No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Risk

‘Blame the Bot’ Won’t Cut It in Front of Regulators

Responsible automation requires human judgment, independence and evidence

by Jonny Frank, Nathan Gibson, Michael Costa and Kashif Sheikh
May 11, 2026
in Risk
robot fallen over

Regulators won’t simply look at your AI outputs when scrutinizing your organization’s compliance, Jonny Frank, Nathan Gibson, Michael Costa and Kashif Sheikh of StoneTurn write. Your decision-making is being evaluated, and relying on the defense that AI told you to make a certain decision is a recipe for disaster.  

AI is changing the speed and scale of compliance work, identifying anomalies in real time and surfacing risks that would have taken weeks to find manually.

But speed without structure creates different risks. Regulators are not evaluating your algorithms. They are evaluating your decisions — how you reached them, whether they are supported, and whether they hold up under scrutiny. Using AI isn’t the risk. In fact, neglecting the use case for AI can create a different risk entirely. Where organizations can find themselves in the hot seat is treating AI output as the defense behind every conclusion it helps produce.

The defensibility gap

Recent allegations involving a provider of AI-automated auditing and compliance reviews underscore a growing problem: the defensibility gap. Whistleblowers allege the firm bypassed authentic reviews and used “certification mills” to rubber-stamp compliance reports.

Whether those specific allegations are proved, the lesson is clear: If you cannot explain and defend the result, the process does not matter. In today’s environment, where AI missteps are scrutinized and amplified, a weak or opaque process risks not only regulatory exposure but immediate reputational damage.

The allegations also highlight a broader structural issue: Independence required for credible assurance breaks down when a single platform implements compliance measures and evaluates their effectiveness. For companies facing DOJ or SEC scrutiny, “check-the-box” automation is a liability.

What regulators expect is straightforward: a clear, auditable trail; evidence of independent judgment; and conclusions that can be explained and defended

Where AI helps and where it doesn’t

AI is powerful where scale and pattern recognition matter. This can include identifying anomalies across large datasets, canning contracts or transactions for outliers and surfacing potential misconduct signals. These capabilities are not theoretical. Many compliance teams use AI to accelerate reviews that previously took weeks. The technology works.

But uncovering the genesis of a compliance failure is rarely rooted in data alone. That requires an understanding of why people acted, whether controls were bypassed and whether leadership reinforced — or undermined — the program

AI cannot interview a whistleblower effectively. It cannot assess tone at the top. It cannot distinguish a technical failure from a cultural one. These require human judgment. That is where experienced professionals add irreplaceable value — not as a check on AI but as the judgment layer that makes AI outputs meaningful.

magritte son of man deepfake
Risk

Deepfakes Are Now a Board-Level Risk & Regulators Are Watching

by Matt Flegg
May 1, 2026

Recent UK regulatory developments are making deepfake risk a board-level disclosure and accountability issue, not just an IT problem

Read moreDetails

The shift in skillset

As AI becomes embedded in compliance, the job is changing. Less time gathering data. More time interpreting it and acting on it. Four capabilities matter most:

  • Model validation: Understanding what the AI is doing, where it is most effective and how to spot when its outputs need a closer look.
  • Data integrity: Ensuring inputs are reliable, knowing that bad data can produce confident but wrong answers.
  • Contextual judgment: Recognizing when controls exist on paper but fail in practice.
  • Defensible conclusions: Translating outputs into a clear, supportable narrative that explains why a conclusion was reached.

Questions to ask before deploying AI

AI compliance-testing products are sure to proliferate. Ask these questions from your vendor to assess whether the output will stand up to scrutiny:

  • Who is accountable if the tool flags or clears an issue?
  • What evidence supports the conclusion?
  • Does the same system design, implement and test controls?
  • Does the tool produce auditable documentation or just outputs?
  • What are the limits of the model?
  • What data is excluded?
  • How are false positives and false negatives handled?
  • Would you rely on this output in front of the DOJ or SEC?

AI will continue to transform how compliance work gets done, but it will not lower the bar. Prosecutors and regulators evaluate whether a program is adequately resourced, empowered and effective. Technology is but one piece of the puzzle.

In other words: Do not expect credit for automation alone. Every automated insight still needs a human who can stand behind it. In the end, compliance is not about what your system can detect. It is about what your organization can defend.

AI has permanently raised the bar for what defines ”defensible” compliance. The leaders of this new era will not be those who avoid AI, nor those who automate blindly. They will be the firms that pair powerful technology with the professional judgment required to explain, defend and stand behind every conclusion.

Tags: Artificial Intelligence (AI)
Previous Post

Your Next AI Risk Is Inside the Systems You Trust the Most

Next Post

Need for Speed: What DOJ’s New Approach to the CEP Means for Internal Investigations

Jonny Frank, Nathan Gibson, Michael Costa and Kashif Sheikh

Jonny Frank, Nathan Gibson, Michael Costa and Kashif Sheikh

Jonny Frank, a partner with StoneTurn in New York, brings more than 40 years of public, private and education sector experience in forensic investigations, compliance and risk management.
Nathan Gibson, a manager at StoneTurn in Washington, D.C., has more than six years of experience in forensic accounting and compliance monitoring. Specifically, he focuses on FCPA monitorships, anti-money laundering (AML) investigations and export control compliance.
Michael Costa, a partner with StoneTurn in Chicago, has deep experience in data analytics and data science, financial crime, investigations, complex litigation and compliance matters. He has worked with clients in the financial services, technology, education, life sciences and hospitality industries, as well as with public sector entities
Kashif Sheikh, a manager at StoneTurn in Chicago, is a full stack data scientist and AI engineer with over 15 years of experience assisting clients in the financial, technology, government, and legal sectors on data-oriented solutions impacting e-discovery, compliance and regulatory issues.

Related Posts

double helix of lego

Illinois Genetic Information Protection Act Comes of Age

by Michael C. McCutcheon and Ruby Borja
August 17, 2026

Illinois’ experience with biometric privacy offers a cautionary tale for companies that keep genetic information in the AI era

news roundup bundled papers

26% of Execs Say Audit Has Caught Public-Facing AI Mistake

by Staff and Wire Reports
August 14, 2026

Few orgs say AI governance is fully mature; data center boom running into risk hurdles

data abstract pixelated

Cyber Leaders Wary of Giving Agentic AI Too Much Authority

by Staff and Wire Reports
August 6, 2026

Plus: Most finance leaders need to see AI ROI; large majority of companies see rising supply chain risk

rubiks cube

Put the General Counsel in Charge of AI Strategy

by Eric Dodson Greenberg
August 5, 2026

The conventional play for enterprise AI strategies is IT leads, committees advise, everyone weighs in. That produces strategies that live...

Next Post
speeding train in motion

Need for Speed: What DOJ’s New Approach to the CEP Means for Internal Investigations

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights