/ 1 min read / Tech Law Talks

AI compliance: What regulators expect in the age of agentic AI

As AI transforms communications monitoring and supervision, businesses face growing pressure to demonstrate that their compliance programs are effective, defensible, and well governed. In this episode of “Tech Law Talks,” Smarsh’s VP of Regulatory and Information Governance, Robert Cruz, joins Reed Smith lawyers Anthony Diana, Therese Craparo, and Michael Rubayo to explore evolving regulatory expectations, the shift from lexicons to AI-powered surveillance, and the ways that organizations can manage risk at a time when autonomous AI agents are becoming part of the compliance landscape.

 Transcript:

Anthony: Hello, this is Anthony Diana from Reed Smith, and welcome to Tech Law Talks. Today we're going to be talking about AI and communication surveillance. What do regulators expect? And this is part of our AI compliance series with SMARSH. So joining us today is Robert Cruz from SMARSH, along with Therese Caparo from Reed Smith and Michael Rubayo from Reed Smith. Thanks all for joining. Michael, why don't you kick it off?

Michael: Thanks, Anthony. So when talking about surveillance, right? We're talking about how as AI is moving away from drafting assistant to autonomous agent, you know, the traditional supervision models are breaking down. So, you know, we're here today to talk about why blanket AI bans have failed, what risk-based monitoring looks like in practice, and how firms are closing that accountability gap for when an AI agent is taking the action. So Robert, we'll start with you and what seems like a basic question, but isn't, but what does reasonable supervision mean when applied today?

Robert: It's a great question. And in the case of supervision, you know, the act of a compliance staff reviewing communications of individuals to look for policy infractions, AI or machine-based approaches aren't new. I mean, we've had large language models and natural language processing. So it's not an entirely new concept. But key thing to note here, reasonable supervision, at least in the case of US regulators, is very simple. It's have a policy and demonstrate you're following it. So it's not prescribing a method. It's not saying that random sampling or lexicons or AI is the preferred approach. You know, the obligation is to have a policy, but more importantly, and to the center part of risk, it's like you want to spot the risks that matter. You don't want to be spending your time sorting through a pile of false positives. You want to get to the risk. I mean, that's the purpose of all of this. So regulators wanna know that this system is actually effective in being able to identify and help the firm remediate the risks that they're facing in communications. So fairly straightforward. It's not about the method, it's about the outcome and the way the technology is being used and being able to explain it.

Anthony: I was gonna say I think this is an area where this does make like this is a great business case for AI, right? Like supervision, you know, we all know that lexicon-based and search terms are not the most effective. It has lots of false positives. There's a lot of work that goes into it to escalate and review, and everyone has these processes and I think the reality is is I would assume if the models were correctly and you're doing it, that this actually may work better, right? Using AI may actually work better than what we have now. And I think I don't think the regulators, I think Robert, as you said, regulators are gonna say, well, this method is wrong. You just have to make sure it's working, right? So again, you have to do lots of all the stuff that you should be doing in terms of monitoring, how it's working, adjusting for new data sources, all the things that if you have a supervisory program you should be doing anyway. It's just using a tool instead of probably a lot of people reading and communications and stuff.

Therese: Yeah, and I'm gonna play the role of Anthony Diana here in talking about predicting dramatic changes in the future. But I will say is things to look out for is that look, the reality is that well, Robert is right, like there's been like analytics and things that have been a part of supervision for a long time. The compliance industry in the matter of technology has been fairly slow to move into new and advanced technologies. Right, still heavy reliance on things like lexicons and the like, which we know are not great. I mean, they're not great. They were the only thing we had for a very long time. But it hasn't been as willing to move into these things. I think with AI, just as a general rule, everybody wants to use AI on all the things now. And we're seeing a more greater willingness to adopt AI. But one of the things that I, you know, from the legal industry that I think is fascinating, and I think we should watch for it in the future in the compliance industry. Right, we talk about the use of AI in the legal industry, and there the ABA has opinions out there about the use of Gen AI. And one of the things I always point out in the ABA opinion that was fascinating to me is one of the things that they were talking about is that look, well, maybe we're not there yet. We are going to get to a point. Their belief is that we're going to get to a point where you, as a lawyer, you have to be using AI because that is the best way to give the best advice to your client, right? And while they're careful to say that's not a requirement right now, the view is looking into the future, you know, get ready now because we are going to get to a point where it's as common as saying, well, you know, if you're going to be doing research, you should be doing electronic research, not book research, because that is the best way to give competent legal advice to your client. I do think in the future, and I don't think we're there yet, I think we may get to a point in the future where the use of AI is so prolific that the regulators may say, why aren't you? It is the best way to find, you know, issues. It is the best way to find market manipulation. It is better than these older methodologies that have been common in the past, and it is accessible to everyone. Part of reasonable is always taking into a size, right, the size of the organization and the means and things like that. The regulators are very mindful of that. But I do think eventually we will be in a position where it is the expectation and the norm. And if you are not using it, you are going to have to explain why your approach is reasonable when you are not using AI. And I think again, we may be years off from that, but I believe it is coming. And if you're a financial institution to be prepared, you should be looking at the use of AI now and how do you incorporate it into your supervision process, right? To make sure that you are prepared for the future.

Robert: And I want to come back to that question of regulatory expectations in a second, but just to your point, Therese, that you know, these were the methods that were available at a particular point in time. But if you look at just the basic unit of work, what am I doing? I'm gonna sit down and review a message. And if I review it based upon keywords, as perhaps parallel, you know, in eDiscovery, there's a certain benefit and limitation in that approach. Whereas if you're looking at the output of AI, it's probabilistic and it's telling you what might come before, it might come after. It gives you a much better picture of behavior. It's a leading indicator of where there may be issues. You don't see that with keywords. So it may just be a natural evolution. It's a better mousetrap, it's a better way to understand where employee misbehaviors might lead to policy infractions.

Anthony: Yeah, it'll be interesting to see if there's like a sea change in terms of even what you're looking for, right? I mean, obviously look at sentiment analysis or whatever, but you know, you can imagine a world where it's less about the messages and more about conduct, business process, groups of people, whatever, right? You could just imagine if you're thinking about what the prompt is gonna look like and how you're looking at it, you could really develop something that's much more nuanced. And frankly, more effective, right? Because it's not gonna be, you know, there's a million emails. Is there any fraud? You could do it much more directed in saying, hey, I'm concerned about this with this group, you know, and always be monitoring that like that. I think is exciting. And again, I think this is a perfect use case for AI and being effective. I mean, it's bad also because it's why the government wants to do surveillance with AI. Like everybody wants to do surveillance with AI. You can imagine. Organizations, corporations could do it. Like it's the big brother. This is big brother, but this is what surveillance is, is big brother, right?

Robert: Yeah. And Therese, to your point of the what are the regulatory expectations, I think that's the SEC and the FCA both have said they're all in. They're embracing the most advanced technologies that are available in the market. And it's almost becoming much clearer the statement that we're doing this and if you're not doing it, you need to explain why. You know, if these are available to you and you've chosen not to, it's no one's out there saying we love our lexicons and that's the reason we're still doing it. You know, variety of other reasons and change management, you're comfortable with a certain approach, et cetera. But, you know, I think increasingly you're gonna see regulators question firms that don't have the best available technology to do a particular task.

Therese: Yeah. Yeah, I think so. But I think as well from a regulatory expectations right now, in terms of, you know, if you're setting the expectations for the use in supervision today, I think one of the important things if you're using AI for supervision is, Robert, as you kind of alluded to earlier, is what are your clear processes for using it? And how are you using it? I think the regulators are all in, but they are still a little skeptical about how financial institutions are using it and whether they are using it correctly. And I think that if you want to be using AI, one of the big fears is look, yes, it can do amazing things. You can't just rely on the AI. The AI can surface things for you, but the AI it can do some of that work for you, but it isn't a replacement yet, at least, for individuals doing that review and evaluating the information that is surfaced, right? There is a fear of just this blind reliance on AI. Frankly, we see it every day, right? And virtually every industry. So I think from the regulatory expectations right this minute for the use in AI and supervision, you really need to be able to show this is how we're using it. This is how we know it works, right? We are not assuming that this AI tool for this surveillance practice works and it's surfacing the things we need to review. We have procedures for checking that it is in fact working the way we expect it to work. It is surfacing the things we expect to see that we know we need to look at more closely. We have QC procedures, we have validation procedures to make sure that it's working. And we of course, as always, have humans in the loop who are looking at the escalations and making sure I think the most important thing if you are talking about reasonable use of AI and supervision, is to clearly show the process that is being applied and how you know that tool is working. Right. If you have a process where the tool is, you know, not surfacing the right things and you're saying, well, but we have a process and we're escalate, you know, we escalate things, but the tool isn't working and you can't show you know it's working. That is not going to be considered reasonable. Right. So I do think that in the present time, making sure that you can explain how the tool works, that you understand how the tool works, and that there are procedures for ensuring that it's doing what you expect it to do, right? In addition to the appropriate escalations and human review and the like is going to be critical because you're not just going to be able to say, I'm using AI and they're going to be like, cool, that works. Right. You have to show competence around the use of it.

Robert: Yes.

Anthony: Yeah. And I would say is the idea of this being a cost savings is probably a misnomer here, right? Because it's just different people doing different things, right? It's as Therese said, you're gonna have to, it's like, we don't have to have all these reviewers. Isn't that great? We're gonna save money. No, because now you need a whole team of people who are monitoring the prompts or the tool and how it's being used and tinkering with it and testing it. And if that like there's gonna be a lot of work that just shifts to different people, probably more expensive people, right? Than just somebody's looking. So again, I think the fear of this is, you know, not a fear, but like this idea that, we're gonna save a lot of money by using AI, should people it may be better, right?

Therese: Yeah. Yeah.

Anthony: And that's great. And maybe there will be, but it's it this is not a money saving issue or a cost saving issue.

Therese: And I will say to you know our the financial institutions out there who are listening to this, really important is while the vendor is critical and partnering with your vendor is critical to make sure that you know you know that you understand how the tool works, this should go without saying, and yet it does not. You cannot pass your responsibility off to the vendor or the technology. And just because the vendor says this is what it does or this is how it works, doesn't make it true for your data, for your situation and the like. I had this conversation this morning about a client who's saying, well, we did it this way because the vendor said. And so did you check that? Well, no, the vendor said. But the vendor is not a substitute for your own judgment and your own regulatory responsibilities. You can't say the vendor said it will not get you out of an enforcement action. It will not get you out of an issue with the regulator. So you just need to keep that in mind is that yes, work with your vendor. They should be experts in their own technology. Make sure you're collaborating with them. But at the end of the day, the responsibility is yours and you must understand the technology and how it works. You cannot point to somebody else.

Michael: So I want to take a step back, Robert, and go back to something that you had brought up earlier about the idea of moving from lexicons to models, right? With this proliferation of AI, are we seeing firms move away from the usage of lexicons?

Robert: Yeah, it's a great question. And I like the way that Therese and Anthony framed it. It's not necessarily a continuum. You absolutely need to move toward the most complex, sophisticated and expensive approach to do things. You know, when you have a hammer, everything becomes a nail. I think what we're gonna end up with is that there's certain cases where, you know, you may not know what the nature of the regulatory inquiry is or who's involved or what the terms that I need to look through. So you need that ability to broaden the aperture and look at across data sets and do that more effectively. But in some cases, you know, you see an employee's grandma on polymarkets, you know, trading on your stock, then yeah, you know where to go. And you can find that with a keyword. So I think you're gonna see the right tool for the right job emerge. And in some cases just the coexistence and not necessarily along the current lines of L1 versus L2. Then that's probably gonna blur. But it's just, you know, putting the right tools in the right hands of a compliance executive, so like as Therese said, they own the responsibility. They need to pull out the right equipment to do the right task. But just that said, I think it does enter discussions as far as, you know, organizations making investment decisions that may have a three to five year time horizon, you know, conservatively. And it's as part of that time horizon, you need to be anticipating like what does this technology enable me to do? Is it resilient? Will it allow me to change policies easily if a new set of requirements emerge in the US or internationally. So you're looking for something that has some element of future proof so that it can incorporate or evolve to be able to take advantage of these things. Because it's you know it will move very fast. And so that's one of the tricks here is like how do you stay on top of that? You gotta look for agility in the platforms that you're invested in.

Michael: And then finally, you know, Therese, you sort of started to touch on this earlier, but you know, as firms switch to models, as firms start to, you know, leverage more agentic AI as part of their supervisory systems, you know, what can they do to defend those actions? Like what do they need to do to take the steps so if they're ever questioned about it, they can defend it and, you know, justify their use of these agentic AI.

Therese: I think again, I'm gonna go back to what we've been saying, having clear, documented processes for what you're doing, for how you are doing it, and being able to show the monitoring that is going on by humans as part of the review process, including of the agentic AI, you know, agents that are being incorporated into these processes. I think at the end of the day, it's all about controls, governance, and being able to point to here is my thoughtful documented process. I know what I was doing. We tested it. We validated it. Here's the evidence of it. Where I'm using agentic AI. Here's how we are monitoring the actions of that agentic AI, the same way you would monitor the actions of your individual reviewers, right? You don't just let a human reviewer go and do their review and be like, I'm sure it's fine. Right, you're still monitoring the actions. So you're monitoring the actions of the AI agents and showing how that is done to make sure you can say, again, here is my clear process, here's how I'm following it, here's how I'm validating it, here's how I'm monitoring the AI agents, the way that I would monitor a human who was doing similar work, so that you can show the end to end process. I would say this all the time. To our clients when we're talking about almost any compliance or regulatory activity, you can defend a process, a thoughtful process that is clearly documented. You can defend that. And even when a mistake is made, you can clearly identify okay, a mistake was made and we caught the mistake as part of our process. What you can't defend is I don't have a process, but I'm sure it's right. We do stuff, and I'm sure it's right. Because we find things, right? It's really hard to defend something that is not clearly documented and delineated where you show the steps in the process post hoc. Right? You can try to go back and say, well, but it was fine because effectively this is what we're doing. Regulators don't like that. So I think the best way to defend the actions of systems that are leveraging agentic AI is to have a clear governance process and controls. But before we end, I'm gonna throw a question out there because this came up just this morning, and we see our clients struggling with this quite a bit. Is how or when or what do you do to supervise the AI that's doing not the AI that's doing your supervisory tasks, but your AI agents that are now performing tasks that humans you supervised used to do when do you have to do supervision of that how are financial institutions addressing that in terms of incorporating supervision of AI into their processes.

Robert: Well, I'll take a shot at that. I think it we talked about this a little bit earlier. It's almost treating agentic AI as another persona that can interact with systems and get access to data and some of which, you know, they're authorized to do and some cases may not be authorized to do. So it's really establishing the control perimeter around what those agents are enabled to act upon and having a mechanism to say, you know, here's what I do, the corrective action that's necessary if an agent is going outside of the sandbox. And as we know, this is not hypothetical. You know, the Hugging Face and the Anthropic question that came up recently, firms are going to have to plan for this quickly. Incidents and response incidents all has to be baked into the process and what agents are doing, those all have to be built into the control fabric.

Anthony: Be interesting to see if they think like AI agent prompts and responses, right? Like or the inputs and outputs and all of that happening, whether that has to be supervised in a similar way, right? Not like an e-comm, but just having that built in as a new process. I can imagine that happening. I think the other thing that'd be interesting I'd like to see is if AI is really effective in doing supervision. Does that suddenly mean that there's going to be a lot more regulatory actions and self-reporting because you're going to find a lot more, right? And I think a question could be raised is if you found all this stuff now using AI, what were you doing two years ago? And you didn't find it then? Like that'll be very interesting. I don't know if it'll really work, but I could see that happening where they're going to be like, wait a minute, this clearly shows that your supervisory processes weren't reasonable two years ago, because now you're finding all this with AI.

Robert: I think to what Therese said earlier, it's you know, show me it's well designed. Show me that you're monitoring its performance and behavior managing for drift and such. You know, Claude is not an attorney, and as far as you know, Claude is not talking to FINRA yet. So somebody has to be able to say, here's the rationale and the reasoning of how it arrived at specific decisions. Good tabletop exercise. Put somebody in an elevator and ask them to recite that, you know, in a paragraph. So, you know, just to maintain that defensibility angle of keeping that in the hands of an individual, that can explain the way that all these automated approaches are working.

Anthony: Absolutely. Well, this was great. Thank you, Robert, for joining us. And thanks everybody for Tech Law Talks. We'll have other episodes coming around AI compliance in this series.

Outro: Tech Law Talks is a Reed Smith production. Our producers are Shannon Ryan, Amanda Saunders, and Mason Kautz. For more information about Reed Smith's Emerging Technologies Practice, please email [email protected]. You can find our podcast on all streaming platforms, reedsmith.com and our social media accounts at Reed Smith LLP.

Disclaimer: This podcast is provided for educational purposes. It does not constitute legal advice and is not intended to establish an attorney-client relationship, nor is it intended to suggest or establish standards of care applicable to particular lawyers in any given situation. Prior results do not guarantee a similar outcome. Any views, opinions, or comments made by any external guest speaker are not to be attributed to Reed Smith LLP or its individual lawyers. 

All rights reserved.

Transcript is auto-generated.

Related Insights