Monochrome illustration of AI data flowing through governance and compliance controls for a regulated firm.
Monochrome illustration of AI data flowing through governance and compliance controls for a regulated firm.

AI in Regulated Firms: What Compliance Leaders Should Be Asking Now

Artificial intelligence is moving quickly from experimentation into day-to-day business operations. For regulated firms, that raises new questions around accountability, data, supervision and control effectiveness. CIRO has already signalled that it will ask dealers about their use of AI and review the operational controls in place to ensure those tools are working as intended.

Kanchan Mehta

Founder & Principal Consultant

AI in Regulated Firms: What Compliance Leaders Should Be Asking Now

Artificial intelligence is moving quickly from experimentation into day-to-day business operations. For regulated firms, that raises new questions around accountability, data, supervision and control effectiveness. CIRO has already signalled that it will ask dealers about their use of AI and review the operational controls in place to ensure those tools are working as intended.

Kanchan Mehta

Founder & Principal Consultant

The compliance question is no longer simply whether a firm uses AI. It is whether the firm knows where AI is being used, what decisions it influences, what data enters the system, who reviews the output, and how the organization can demonstrate that appropriate controls are operating.

AI Is Becoming a Compliance Issue

AI is already being used across financial services and other regulated sectors for tasks such as:

  • Drafting and summarizing documents

  • Reviewing client or transaction information

  • Supporting compliance monitoring

  • Analyzing large data sets

  • Assisting with customer service

  • Producing internal reports

  • Automating operational processes

Used well, these tools can reduce a significant amount of manual work. The compliance issue arises when AI begins to influence a regulated process, a client outcome, or a control the firm is expected to supervise.

In its 2026 Compliance Report, CIRO said it will ask dealers about their use of AI during examinations and review the operational controls implemented to ensure AI is working as designed. CIRO also reminded dealers to consider whether AI or automation of regulatory functions could amount to a material business change.

For Compliance, the implication is fairly direct: AI use can no longer be treated solely as a technology implementation. Once it touches a regulatory function, Compliance needs visibility into how it is being used and controlled.

Start by Knowing Where AI Is Being Used

The starting point is visibility. Before a firm can assess AI risk, it needs a reliable picture of where the technology is already being used.

That may include formal AI projects, but also everyday employee use of generative AI tools for:

  • Summarizing regulatory material

  • Drafting policies

  • Reviewing contracts

  • Analyzing spreadsheets

  • Preparing client communications

  • Conducting research

Other AI capabilities may already be embedded within third-party systems used for CRM, compliance, cybersecurity, or operations.

A practical AI inventory should identify:

  • The tool or system

  • The business purpose

  • The team using it

  • Whether client or confidential information is involved

  • Whether the output affects a regulated activity

  • Who owns the use case

  • What controls apply

Without that visibility, firms cannot assess risk consistently.

Not Every AI Use Case Carries the Same Risk

Using AI to improve the wording of an internal email is very different from using AI to:

  • Assess client suitability

  • Review AML alerts

  • Approve marketing

  • Monitor employee conduct

  • Support client onboarding

  • Influence investment or supervisory decisions

The closer AI comes to a regulated decision, client outcome, or supervisory process, the stronger the governance framework should be.

A simple risk-based approach may be enough for lower-risk uses, such as administrative support. Moderate-risk uses may involve internal analysis or compliance research. Higher-risk uses may affect client outcomes, regulatory obligations, compliance monitoring, or financial controls.

The framework does not need to be elaborate. What matters is that higher-impact use cases receive more scrutiny than routine administrative uses.

Human Oversight Needs to Be Meaningful

“Human in the loop” is often treated as a sufficient control.

It is not.

A reviewer should be able to:

  • Understand what the AI is being used for

  • Identify an incorrect or incomplete output

  • Challenge or override the result

  • Escalate exceptions where necessary

  • Evidence the review where appropriate

Human oversight should reduce reliance risk.

It should not become a rubber stamp.

This matters particularly where AI supports compliance or supervisory functions.

Data Exposure Needs to Be Understood

Before employees or systems provide information to an AI tool, firms should understand what happens to that information.

Questions should include:

  • Is client information being entered?

  • Is personal or confidential information involved?

  • Where is the data stored?

  • Is it retained by the provider?

  • Can it be used to train the provider’s model?

  • Is it transferred outside Canada?

  • Who can access it?

A convenient AI tool can create significant risk if sensitive information is being entered into an environment the firm has never assessed.

Simple internal rules around approved tools and prohibited data can therefore be valuable even while the broader governance framework is still developing.

AI Outputs Need to Be Tested

AI can produce convincing answers that are incomplete or wrong.

That creates particular risk in compliance work, where precision matters.

An AI-generated response may:

  • Cite an outdated rule

  • Confuse jurisdictions

  • Omit an exception

  • Misstate a filing deadline

  • Produce an inaccurate summary

  • Reach a conclusion unsupported by the underlying data

The quality of the language can make an output appear more reliable than it is.

Validation should therefore be proportionate to the use.

That may involve:

  • Human review

  • Sample testing

  • Comparing outputs against known results

  • Monitoring errors

  • Restricting uses that cannot be reliably validated

Where AI supports a control, the firm should be able to explain how it knows that control is working.

Five Questions Compliance Leaders Should Be Asking

For firms still developing their AI governance approach, these five questions are a useful starting point:

Where are we using AI?
Do we have a clear inventory of tools and use cases?

What regulatory or client decisions does it affect?
Not all AI use carries the same level of risk.

What data is entering the tool?
Client, personal, and confidential information require particular attention.

Who is accountable?
The business, Compliance, Technology, Risk and Privacy may all be involved, but ownership still needs to be clear.

How do we know the controls are working?
Approval, testing, exception reporting, and human review should be evidenced where necessary.

These questions are straightforward.

The answers often are not.

What CIRO’s 2026 Focus Means for Dealers

CIRO’s 2026 Compliance Report makes the direction clear.

The regulator is not simply observing AI adoption from a distance. It has said it will ask dealers about AI use and review the operational controls around those tools.

For Dealer Members, an examination conversation could begin with a very basic question:

Where are you using AI?

The quality of the answer will depend on whether the firm already has visibility, ownership, and evidence around those use cases.

Firms that wait until a regulatory request arrives to establish that inventory will be starting too late.

Building AI Governance That Fits the Business

No single AI governance framework will work for every regulated firm.

The controls should reflect:

  • The firm’s size

  • Its business model

  • The sensitivity of its data

  • The significance of the AI use case

  • The potential impact on clients

  • The degree of automation involved

Good governance should allow firms to distinguish between low-risk uses that need light controls and applications that warrant formal approval, testing, and ongoing oversight.

How GoldSleeve Supports AI Governance

GoldSleeve works with regulated and risk-sensitive organizations to build practical governance and compliance frameworks around emerging technology.

Support can include:

  • AI use-case inventories and risk assessments

  • AI governance frameworks

  • Policies and acceptable-use standards

  • Regulatory impact assessments

  • Compliance and control mapping

  • Third-party risk reviews

  • Governance and accountability design

The goal is to help firms use technology with a clear understanding of the regulatory, operational, and governance risks surrounding it.

The Question Is No Longer Whether AI Is Being Used

For many firms, AI use is already developing faster than the governance around it.

A firm should be able to explain:

where AI is being used, why it is being used, who is accountable, what controls apply, and how management knows those controls are working.

That is a much stronger position than discovering the answers when a regulator asks.

This article is part of GoldSleeve’s AI Governance for Regulated Firms series. The next article will look more closely at AI risk ownership and how regulated firms can establish clear accountability across the business, Compliance, Risk, and Technology.

This article is for general informational purposes only and does not constitute legal or regulatory advice.