top of page

No events at the moment

The Future of Compliance in the Age of Intelligence


Most conversations about AI and compliance go one of two ways. Either they are about technology, which tools to buy and what to monitor with them. Or they are about regulations, which rules now apply and how to map controls to them.


Both are worth having. Neither is the one I think we are missing.


Buying the right tools and knowing the right rules will not be enough, because underneath both is a culture and capability problem that AI is exposing rather than creating.


AI adoption is already overwhelming traditional compliance practices, and it is doing so from two directions at once. New obligations and new risk are arriving faster than most compliance programs can absorb. And AI is entering the compliance function itself.


This is landing on top of shifts already in motion: from static, structural compliance toward dynamic, operational compliance. From assurance by inspection toward assurance by design. From asserted trust toward demonstrated trust.


The methods most organizations rely on were already under strain before AI arrived. AI is what pushes them past what they can carry.


The future of compliance now depends on its capability, competency, and capacity to continually adapt. That is a hard sentence for compliance to hear, because adapting is not what compliance was built to do.


Why compliance struggles to adapt


Most compliance programs run on a bounded-set culture. The question is simple: are we in or out of compliance? You build fences, monitor for gaps, and close them when you find them. Once you are inside the line, there is nothing further to pursue, nothing to improve, nothing to get better at.


This is not wrong. For rules-based obligations, it works. That is why it has lasted this long.


But someone else drew those lines. A regulator, a standards body, a court. Which means compliance becomes a destination you arrive at rather than a direction you travel. You cannot raise a standard that was never yours to set.


That is the trap. A program that only corrects never practices getting better. So when the line moves, and AI is moving it right now, you suddenly need a capability you never had any reason to build.


What AI actually asks of you


AI does not just add obligations to your list. It brings a kind of obligation no fence can hold.

Promises kept by non-human agents. You cannot audit an agent into keeping a promise. Agents must be regulated in real time.


System controls, not internal controls. Closed-loop, not open-loop control systems.


Continuous assurance across the operational lifecycle. Not a point in time. Not once a year.

Requisite capability for real-time oversight. If the system moves faster than you can respond, you are not regulating it. That is just Ashby's Law showing up in your compliance program.


Accountability that cannot be delegated, no matter how far the value chain extends or how autonomous the system becomes.


Every one of these needs a purpose, a goal, a centre to align to. None of them can be met by staying inside a line, because for AI there is no line. Nobody has drawn one yet, and by the time somebody does, the system will already have changed.


The predictable response, and why it will not work


Faced with this, most organizations do the obvious thing. They build a bigger moat. More audits. More attestations. More controls. More documentation. More governance oversight. More monitoring. More reporting.


This is where the two default conversations lead. Better tools make the moat wider. Better regulatory mapping makes it deeper. Neither changes what the moat is for.


Same behaviour, same practices, just more of them. That is not adaptation. That is doubling down on the thing that already got you here.


From boundary to alignment


There is another way for compliance to move forward.


Stop minding the boundary. Start minding your direction.

A centred-set culture asks a different question: is our work aligned toward our mission, our promises, our values, or away from them? The work is not building a bigger fence. It is aligning what the organization actually does with the outcomes it exists to produce.


And because the centre is yours, so is the standard. Your values, your mission outcomes, your commitments become the bar you raise to get better. Nobody has to hand it to you, and nobody has to approve it. Wherever a program stands today, that work can begin.


Raising that bar is also how you get ahead of risk. When you set it above where you are performing today, things that used to pass now register as excursions. Weak signals surface while they are still small, still cheap, and still far from causing harm. Wait at the boundary instead and you only learn when something crosses it, which is the moment risk stops being a prediction and becomes an event.


From there the rest follows. You measure capability as a whole, not the holes in it. Governance guides and adapts instead of just watching.


This is the culture that can respond to AI. The bounded-set culture cannot.


How you build the capacity to adapt


The real work is building the capability, competency, and capacity to adapt. This is often called continuous improvement, and you will find some version of it in every serious transformation program.


Here is what most people miss about it. It is not the specific change that matters most. It is the practice of changing. The discipline of making changes continuously is what builds the capacity to adapt.


But that is only half of it. The other half is guidance: improvement toward a bar that keeps rising. Safety researcher David Woods has written on this, calling it Guided Adaptability, a way of resolving what he frames as the command-adapt paradox in complex systems. You will recognize the same pattern if you have worked in Lean, Toyota Kata, Lean Six Sigma, Theory of Constraints, or systemic safety. Different tools, same pattern. Raise the standard. Adapt to meet it. Raise it again.


Problems, issues, and gaps are not failures in this model. They are what make you stronger and more capable of confronting your challenges.

Deciding to run a marathon is easy. Being able to run one is not. You train, over longer and longer distances, until you become the kind of runner who can run marathons.


Your compliance future works the same way. It is about who you are becoming, more than who you are right now.


Where this leaves compliance


The path forward has already been walked by others. Lean walked it. Theory of Constraints walked it. Compliance, for the most part, has not.


Do not wait for the next obligation, or the next AI system, to breach the fence before you start. The fence was never going to hold on its own. Build the capability now: closed-loop controls instead of open-loop ones, programs that steer instead of just watch, capacity to handle risk and uncertainty before they show up at the edge. That is not something you assemble after the breach, and not something a higher fence gives you.


Start now, on the road of continuous improvement and Guided Adaptability.


That is the future of compliance in the age of intelligence.


This is a summary of "The Future of Compliance in the Age of Intelligence," presented at the Elevate Compliance Huddle, session 99. If this resonates with what you are seeing in your own program, I would like to hear about it in the comments.



About the author


Raimund Laqua, P.Eng., PMP, is the Founder and Principal Engineer at Lean Compliance. He works with organizations across safety, security, sustainability, quality, and regulatory compliance, applying engineering discipline and systems thinking to a practice that has long relied on audit and inspection. His focus is helping companies stay between the lines, ahead of risk, and on mission.


He hosts the Elevate Compliance Huddle, a series that takes on a critical aspect of modern compliance each session. Huddles run weekly for members and open to everyone about once a month. Registration details are on the Lean Compliance website.

bottom of page