Global Software AI
4 мин чтения

Why AI-assisted compliance review still needs a human signature

AI can read a marketing document against MiFID II requirements faster than any human. It still shouldn't be the one who approves it. That's a design principle, not a limitation.

Автор: Tim Crouch

Больше из серии Building CompylotAI

There's a tempting pitch in compliance technology right now: point an AI at your documents, let it flag the problems, and watch the review queue disappear. We're building CompylotAI, an AI-assisted compliance platform for EU financial institutions, so you might expect us to make that pitch. We won't. It is wrong, and in a regulated environment it is the sort of wrong that eventually gets its own meeting with Legal.

Here's the principle we build on instead: AI accelerates the review; a human signs the decision. Every time.

What AI is genuinely good at here

Let's give the technology its due. Modern language models are remarkably capable at the mechanical parts of compliance review: checking a fund factsheet against disclosure requirements, screening marketing copy for prohibited claims, and verifying that risk warnings are present and prominent.

  • Reading a fifty-page document and mapping every claim to the regulatory requirements it touches
  • Catching the omission a tired reviewer misses on a Friday afternoon: the absent risk disclosure, the performance figure without its mandatory context
  • Applying a rule set consistently across thousands of documents, without the drift that creeps into human review over time
  • Producing a structured trail of what was checked and why it was flagged

This is real value. A compliance officer who spends four hours locating potential issues in a document set can instead spend forty minutes reviewing findings that have already been located and explained. Speed matters. Marketing teams wait on these reviews, and slow compliance has a nasty habit of becoming bypassed compliance.

Why the signature stays human

So why not let the model approve the clean documents and be done with it? Three reasons, and none of them are "the AI isn't smart enough yet."

Accountability is not transferable. Under MiFID II, the obligation to keep client communications fair, clear, and not misleading belongs to the firm. Supervisory regimes such as BaFin's also expect identifiable people behind compliance functions. When a regulator asks, "Who approved this document, and on what basis?" the answer "a model scored it 0.97" will not improve anyone's afternoon. An accountable person must be able to say: I reviewed this, I understood the findings, and I made the call. Software can make that person dramatically better informed. It cannot become that person.

Judgment lives in context the document doesn't contain. Is this performance projection misleading? That depends on the target audience, the distribution channel, the client relationship, and what the regulator emphasised in its last industry letter. A model sees the document. The compliance officer sees the situation. The genuinely hard calls are rarely just about what the text says. They are about what it will do.

Errors compound silently when nobody is looking. Any automated classifier will be confidently wrong sometimes. In a human-approval workflow, a bad AI finding costs a few minutes. The reviewer sees it, overrides it, moves on, and the override becomes useful feedback for improving the system. In an auto-approval workflow, the same error ships to clients and resurfaces during an audit, traditionally the least amusing time to discover a design flaw. The cost difference is enormous, and it only takes one.

Designing for the human, not around them

The practical consequence is that "human in the loop" has to be an architecture, not a checkbox. If the human's role is to click "approve" on a hundred AI verdicts an hour, you have built rubber-stamping with extra steps. What we aim for instead:

  • Findings, not verdicts. The system presents the claim, the relevant rule, and the reason it was flagged. The reviewer reaches the conclusion.
  • Overrides as first-class data. When the human disagrees, that's recorded, auditable, and used to make the checks better.
  • An audit trail built for regulators, showing both the machine's analysis and the human's decision, separately and traceably.

The honest trade-off

Yes, this is slower than full automation. That is the point. The value proposition is not "remove your compliance team." It is "let your compliance team cover ten times the ground at the same depth, with a better paper trail than manual review ever produced."

Regulated financial services run on accountable human judgment. The right ambition for AI is not to replace that judgment, but to support it with better information, delivered faster and more consistently than a manual process can manage. That is the product we're building. When it gets something wrong, we would much rather a human catches it before a regulator does.

CompylotAI is in early access with EU financial institutions. If document compliance review is part of your team's week, we'd like to compare notes.