Skip to content.
Three people in an office setting work together around a laptop. One person stands smiling and pointing at the screen, while the others sit, one looking at the laptop and one holding papers.

AI regulation is still evolving, but organizations don’t need to wait

As organizations in the United Kingdom and beyond eye the ongoing development of regulations impacting their use of artificial intelligence, experts from a recent NAVEX panel said existing, comparable rules and some fundamental best practices can already give substantial confidence in a go-forward AI governance strategy.   

Pointing to the European Union’s groundbreaking AI Act, along with some basic tenants of enterprise risk management, experts said risk and compliance professionals have much to go on to inform their own organization’s fundamental principles around AI use. Those principles will provide a foundation for future compliance as new regulatory requirements solidify. 

For those efforts to be successful, however, Compliance will require enough influence to break the AI contemplation away from a conversation occurring purely within Information Technology. 

“Fundamentally, compliance needs to be at the heart of the conversation,” said Paul Hockley, global Head of Ethics and Compliance at the global engineering and design firm Arup. 

Finding the right balance

The vast majority of U.K. compliance teams – 91% – are involved in conversations around AI use at their organizations, according to a recent NAVEX survey report. Yet the nature and timing of that involvement varies, said Erena Langley, director of regulatory solutions at NAVEX. 

“Our benchmark number really hides a spectrum. There is a range from the best-case scenario in which Compliance is very embedded, to, maybe in a worst-case scenario, involvement means being informed after the fact,” she said. 

The webinar audience echoed that concern, with 32% citing a lack of visibility into where AI is being used during a live poll. Nearly half (49%) identified employee behavior or uncontrolled AI use as one of the biggest barriers to responsible adoption. Unclear governance and ownership and the challenge of keeping human oversight meaningful were each selected by 36%. 

These findings reinforce the risk of involving Compliance too late. That worst-case scenario – Compliance being informed after the fact – is a significant risk as organizations only accelerate in their use of AI. In many cases, it is likely organizations aren’t even aware of the scope of AI use within their operations as employees find creative new uses with authorized or even freely available tools. This is leading to an explosion of innovation, but comes with inherent risks, Hockley noted. 

“That opportunity is enormous. It’s changing the way decisions are made in organizations, and the quality of products and services we can provide to our clients and customers,” he said. “The converse of that is that the risk scales up in the same way. The scale and the speed of change in AI is escalating that risk." 

“The challenge for organizations is to find that right balance,” Hockley said.

Following the EU’s example

The EU AI Act is the world’s first comprehensive legal framework for AI. The regulation came into force in 2024, with elements that are continuing to roll out in the coming years. 

While only impacting companies whose business involves the European Union, the wide-ranging act still provides a strong sense for the “direction of travel” for other emerging regulation, Langley said. In absence of guidance from relevant jurisdictions, the act provides a path to start with. 

“Definitely don’t wait,” she said. “I would say, knowing the direction of travel should be a suitable guideline for how you handle the use in your organization. You should assume the use will be holistic, it’s going to be across the board – it’s not just going to be in IT.” 

Practices put in place across the organization aligned with requirements under the AI Act are likely to pay off not only in compliance with future rulemaking across differing jurisdictions, but also in enabling the practices of basic risk management when it comes to AI, speakers noted. 

For example, Hockley highlighted a fundamental tenet of the AI Act involved a simple inventory and risk assessment of AI use across the business. Regulatory requirements aside, this stands as a major area where Risk and Compliance should act regardless of regulatory obligation. Technology is moving fast, he noted, and a lack of awareness in its use could allow risks to emerge unseen.  

“You can’t govern the unknown,” he said. 

Why “human in the loop” is not a complete strategy  

Speakers acknowledged the emerging mantra of having “a human in the loop” to review the use and outputs of AI in business operations. That involvement can provide important oversight and quality control. 

Simply assigning a person to review an AI-supported process, however, is not a substitute for a robust governance framework. Reviewers need the knowledge, authority and information required to challenge the system and act on concerns. 

“You don’t want to have rubber stamps, you don’t want to have an uninformed approver, you don’t want to have a disempowered challenger,” Langley said, noting that the EU AI Act has specific elements describing the need for humans to be involved in AI activities. 

The sophistication of this human-involved approach will need to mature as AI becomes more widespread, with AI serving as the check for other AI functions in some cases.

Two colleagues sit at a desk in a modern office, looking at a tablet together. The man wears glasses and a black shirt; the woman, in a white blouse with black polka dots, listens attentively. A plant is visible in the foreground.

Is Compliance ready?

Hockley expressed surprise that only 45% of U.K. risk and compliance leaders NAVEX recently surveyed expected AI to fundamentally transform compliance. That number seems like it would have been greater, he said. 

“What’s really interesting is how it enables us to be a better server of our business,” he said. “Where that comes in is the ability to get better data quicker – to be more preventative, more strategic, across multiple aspects of what we do.” 

A question lingers over the 55% who did not share that same response, he noted. Is Compliance in the U.K. ready for the wave of transformation AI will represent? 

Next steps

Panelists suggested some next steps for Compliance practitioners in the U.K. and beyond: 

  • Get visibility of use cases: assess how AI is currently being used across the organization 
  • Tier use cases: organize use cases by risk 
  • Start building risk assessment and controls: users across the organization will need guidance for determining the acceptable use of AI, and the organization will need ways to monitor for activities and emerging risks

Learn more

Watch our webinar on demand to learn more about how the emerging foundations of AI use and regulations are providing guidance to organizations in the U.K. and beyond in how they set out on their own AI governance journey. 

Watch on-demand

Learn more

Watch our webinar on demand to learn more about how the emerging foundations of AI use and regulations are providing guidance to organizations in the U.K. and beyond in how they set out on their own AI governance journey.