Why Compliance Must Speak Up About AI
- Raimund Laqua

- Jun 11
- 6 min read

Just because AI may not yet be regulated does not mean compliance should sit on the sidelines.
Compliance has always struggled to know how it creates and preserves value. AI now presents both the opportunity and the necessity to do so.
Here is why.
Organizations everywhere are adopting AI. Many are slowly realizing that adoption is not the objective: AI must create value.
But this prompts a question few are asking. Not what value is AI creating, but what value is it losing?
This is where compliance comes in.
The losses fall squarely within our concern, and we should be the first to see them coming.
What we mean by Value
Most organizations measure value as margin: revenue, cost, productivity, output. That is shareholder value, and it is real. But it is not the whole of what an organization creates, nor the whole of what its stakeholders depend on.
Stakeholder Value is everything an organization delivers to all of its stakeholders: quality, safety, security, sustainability, integrity, reputation, and ultimately trust. This is what we call Total Value. Customers, employees, regulators, and communities extend their trust because the organization makes commitments and keeps them. Stakeholder Value is, in essence, the measure of promises kept.

Organizations create this value through two kinds of work. Productivity work creates margin. Certainty work keeps promises: the programs and functions that manage risk, meet obligations, and protect the opportunity to succeed. Both are essential to mission success.
The difficulty is that only one of these is measured well.
Margin appears on every dashboard. Promises kept appear on almost none.
When an organization can see only half of the value it creates, it can destroy the other half without noticing. I believe AI is now being used in ways that do exactly that.
The doorman fallacy
Rory Sutherland describes what he calls the doorman fallacy.
A hotel defines the doorman's job as opening doors. An automatic door opens doors better and at lower cost, so the doorman is eliminated. Only afterwards does the hotel discover what the doorman actually did. He provided security, hailed taxis, remembered guests, and signaled something about the establishment itself.
None of this was in the job description, so none of it was considered when the job was automated.
The hotel saved a salary and lost a function.
The fallacy is this: define a role by its measurable tasks, automate the tasks, and unintentionally eliminate everything else the role was doing.
We are now committing this fallacy at enterprise scale, and the roles being reduced to task lists are precisely the ones that create the certainty half of Stakeholder Value.
What goes into the job description, and what does not
Before a role can be delegated to AI, it must first be written down. The job description captures what is legible: the tasks, the outputs, the artifacts.
A safety manager's role becomes: conduct risk assessments, track corrective actions, deliver training, file reports.
A compliance officer's role becomes: monitor obligations, map controls, collect evidence, produce attestations.
A manager's role becomes: allocate resources, track indicators, review performance.
Each of these task lists is automatable, and each is being automated now.
What never makes it into the job description is harder to name but no less real.
The walk through the plant where something does not look right. The credibility that leads an operator to admit a near-miss. The authority to stop a job that no one else would stop. The judgment that a transaction is technically clean and still should not proceed. The accountability that cannot be transferred to something that cannot be held to account.
These roles were never task lists. They were regulatory functions, the means by which the organization kept its promises.
The tasks were how the function was performed, not what the function was. When the tasks are automated, the function does not transfer. It should remain, because the organization still needs it, but it does not. It is eliminated.
Losses that book as gains
What makes this more serious than the hotel's mistake is that AI performs the legible portion of these roles better than the people did. More assessments are completed, obligations are tracked faster, and the documentation is impeccable. Every indicator suggests the function is improving at the very time it is being hollowed out.
These are Stakeholder Value losses that book as gains.
The margin gains are real and immediate. The risk & compliance losses are equally real but deferred, and our accounting captures the first while remaining blind to the second, because promises kept were never on a balance sheet. The doorman's salary was a line item. What the doorman did was not.
However, there is a second mechanism that compounds the first.
The capabilities that never made it into the job description were developed by doing the work that did.
The engineer who reviews a thousand routine calculations develops the judgment that catches the one that matters. When the routine work is delegated, the apprenticeship is deleted along with the job. The first generation after delegation still includes people who understand what the role really was. The second generation will not.
We are likely to discover the truth of the doorman fallacy at the point when no one remains who can name what was lost in the first place.
When the promises come due
An organization can perform every task and keep none of its promises. This is the known failure of procedural compliance, conformance to procedures without the capability to be effective, and it is the very problem operational compliance exists to address.
AI does not resolve this failure; it accelerates it, performing the procedures flawlessly while whatever capability stood behind them is eliminated.
That is how AI destroys Stakeholder Value: the gains show up on every dashboard, the losses show up nowhere, and obligations go unmet until a failure no indicator predicted. The Grenfell Tower fire showed us how such losses are discovered — at the event, when it becomes clear that no one was performing the part of the process that was never written down.
The fallacy is avoidable
The doorman fallacy is a fallacy, not a fate. It is, at its root, an error in application: the job description specified the tasks and missed the function. But the failure that allows this error lies in governance and leadership, and that is also where the solution lies.
Much is said today about AI governance. Frameworks are published, committees are formed, policies are written, and its parts are described in detail. Yet describing the parts of governance is not governing.
To govern is to steer — to set the direction of the organization, decide what must be protected while pursuing that direction, and intervene when the organization drifts. Leaders who are steering do not automate away the functions that keep their promises, because they know what those functions are and why they exist.
The fallacy occurs when delegation proceeds from a description of tasks. It is avoided when delegation proceeds from a definition of function, and that definition is a leadership responsibility. Before automating a role, leaders should be able to answer:
What is this role for?
What promises does it keep?
What must remain true after the automation?
Who remains answerable, and with what authority and what information?
The hotel never asked what the doorman was for. It asked what he did.
Leaders who ask the first question will still delegate tasks to AI, but they will deliberately preserve the functions that keep their promises: lodged in accountable people, supported by machines, designed rather than assumed.
Compliance must not sit on the sidelines
This is also a call to the compliance profession. Organizational obligations were never limited to what regulators require; they include every promise the organization has made to its stakeholders. Those promises are at risk now, not when the regulations arrive.
Compliance, safety, and quality professionals are the people who know what these roles actually do.
We know what the doorman was doing. That knowledge carries a responsibility: when AI adoption reduces these roles to task lists, we are the ones who must speak up. Waiting for regulation is itself a form of the fallacy — defining our own role by its prescribed tasks and missing its function.
AI will not be the end of Stakeholder Value. Ungoverned delegation will be, one reduced role at a time, with every indicator favourable until the promises come due. Describing AI governance is necessary, but it is not sufficient.
The work ahead is to practise it: to steer, and to define what the doorman was doing before automating the opening of the door. And this steering needs to include the function of risk & compliance.
If your organization is adopting AI and you want to steer that adoption — so that you continue to meet your obligations and keep your promises — reach out to us at Lean Compliance. This is the work we do.



