AI can be a valuable tool for compliance. But it creates new risks too. A human needs to be more than just ‘in the loop’ when it comes to compliance.

AI can be a hugely valuable tool for compliance. It can provide information at just the moment someone needs it, such as sending an employee a warning about potentially misleading claims, alerting them to sensitive information in a document, or taking them straight to the relevant procedure in a lengthy manual. Brilliant.

This is progress. Many compliance failures happen because guidance is difficult to find, employees fail to recognise a risky situation or the correct action requires more time and effort than the apparently obvious one. Well-designed AI can help mitigate those risks.

But it creates new risks, too. The same technology is making us lazy. Everyone talks about keeping the human ‘in the loop’ regarding processes led by AI. But that can often just mean being involved in the final approval of a decision. More direct engagement than this is vital, especially for issues around compliance. For genuine improvement and a sense of ownership over the decisions made, active engagement is key.

Presence is not the same as participation

A recent study of psychological ownership in AI-assisted work found that people retained a sense of ownership when they led the process, iterated with the AI, rejected its suggestions or rewrote its output. They felt less ownership when they merely approved what the AI had produced. One participant put it starkly: “I reviewed, I looked, I was in the loop, but I wasn’t in charge.”

The study, Ownership in AI-Assisted Everyday Tasks, was small and qualitative, so its findings should be treated as suggestive rather than conclusive. Nevertheless, it identifies the fact that human approval doesn’t necessarily represent human judgement.

person clicking approve

This matters in compliance. Imagine an AI system that reviews an expense claim, assesses a customer interaction, classifies a cyber alert or recommends whether a workplace incident requires escalation. A person may still be required to click “approve,” but that tells us little about the quality of the review, or the context or complexities of the decision made.

Did the reviewer understand the recommendation? Did they inspect the relevant evidence? Could they identify what the system might have missed? Did they have the expertise and authority to disagree? Or did the presence of a confident recommendation make approval feel like the default?

 

If the human’s role is simply to confirm an answer generated elsewhere, the organisation has only preserved the appearance of oversight, rather than having someone responsibly decide on the right course of action.

The risks across compliance

Conduct and ethics: An AI assistant might help an employee identify an issue in conduct and ethics, helping to spot a potential conflict of interest, inappropriate communication or vulnerable customer. But ethical decisions are often contextual. This is where human knowledge becomes so valuable. A system can check whether an action fits a rule. It cannot spot if someone was pressured into it, unusual personal circumstances or whether smaller decisions have added up to something that isn’t ok. AI might miss the core of the problem.

Cybersecurity: AI can help classify suspicious emails, detect unusual activity and recommend responses. This can make good cybersecurity behaviour much easier. Yet it can also encourage employees to assume that anything not flagged is safe - or lead analysts to approve recommended actions without investigating the underlying signals.

hands pointing at eachother: noone's taking accountability

Health and safety: AI can retrieve procedures, interpret incident reports and identify hazards. But conditions on the ground may differ from those represented in the system’s data. A worker who treats an AI-generated procedure as definitive may overlook damaged equipment, changing weather, fatigue or another local factor that an experienced person would recognise.

Across all three areas, the danger is not only that the AI will produce a wrong answer. It is that no one feels they were the one to make the decision. When responsibility is blurred, people engage less. If no one feels they need to take charge of a decision, because the process removed the moment when they would need to make a meaningful decision, they won’t feel the urge to choose carefully and ethically – they can just let the decision roll along without getting in the way.

AI Adoption is moving faster than engagement

Recent workforce surveys suggest that this is not a marginal concern. Deloitte’s 2026 survey of 25,000 UK workers found that 63% had used generative AI, but half of users had received no training and one in three were using it without their employer’s knowledge. Only 35% believed their leaders spoke about the technology with a good understanding of it.

A 2025 University of Melbourne and KPMG study of more than 48,000 people across 47 countries found that 66% of people reported using AI output without evaluating its accuracy. More than half said they had made mistakes in their work because of AI, while 57% concealed their use and presented AI-generated work as their own.

unengaged human in the loop

These surveys do not prove that AI inevitably weakens judgment. They do, however, reveal the conditions in which passive oversight can flourish: widespread adoption, limited training, hidden use and pressure to work faster.

Traditional compliance programmes often assume that the main challenge is getting people to follow the process. AI introduces a different challenge: ensuring that people remain cognitively and ethically engaged while following it.

Designing for an engaged human in the loop

Organisations should not respond by requiring a human click at the end of every automated process. That creates delay without necessarily improving decisions. Instead, compliance workflows, skills programmes and communications should be designed around meaningful human agency.

  1. Clarity around decision-making
    Be explicit about what the AI is doing. Is it retrieving policy, identifying a possible risk, recommending an action or making a decision? The further down that list you go, the more a person needs to understand the decision, be able to challenge it, and answer for it.
  2. Design review around questions
    For higher-risk cases, ask reviewers to identify the relevant evidence, uncertainty or reason for their decision. Prompts such as “What could the system have missed?” or “What local circumstances affect this recommendation?” encourage active evaluation. A frictionless “approve” button does not.
  3. Acknowledge uncertainty
    Systems should show the evidence and policy behind a recommendation, highlight missing information and indicate when a case falls outside normal patterns. A confident-looking answer is not the same as a correct one. If it isn’t sure, that needs to be clear.
  4. Encourage people to challenge
    People need safe routes to override, question and escalate AI-generated recommendations. Organisations should monitor patterns of overrides and disagreements as sources of learning, rather than treating them automatically as failures to comply with the system.
  5. Train for judgment
    AI learning should extend beyond prompting and productivity. Employees need practice in testing outputs, recognising automation bias, protecting sensitive information and deciding when not to use AI. Scenario-based exercises should include ambiguous conduct, cyber and safety situations in which the AI’s first recommendation is incomplete or wrong.
  6. Accountability can’t be delegated
    Compliance communications should avoid implying that an approved tool is an infallible source of truth. Employees should understand which judgements remain theirs, what they are expected to verify and when they must seek specialist advice. Leaders should also model transparent discussion of AI use, limitations and mistakes.
  7. Measure engagement
    A completed review or approval is weak evidence of effective oversight. Far better to be able to demonstrate that reviewers inspected supporting evidence, identified exceptions, challenged recommendations and escalated appropriately. A baseline of engagement should be that someone can explain decisions after making them.

The balance of the human and the AI

AI shouldn’t be looked to as an authority in place of human judgement. It may be smoother at making decisions than humans, but some friction in decision-making is valuable. Pausing to investigate an anomaly, challenge a recommendation or consider an exception can significantly mitigate risk. If AI removes every pause, it also removes the moments when professional judgement, ethical reflection and personal responsibility prevent serious harm.

A well-designed AI-enabled compliance programme should make routine checks easier while making consequential judgements more visible. With the increasing embedding of AI, it’s more important than ever that the human ‘in the loop’ has the understanding, authority, skills and attention required to lead.