AI and Compliance: How to Embrace AI Without Creating New Risk

October 9, 2026

Artificial intelligence is already changing how businesses work.

Teams are using AI to write documents, analyse information, automate tasks, support customers and improve decision-making. However, as adoption increases, so does the need to understand the risks that come with it.

For businesses in regulated sectors, particularly financial services, this creates an important question:

How do you take advantage of AI without creating new compliance, security or governance risks?

This was the focus of our recent Compliance in the Age of AI webinar, where Target Integration CEO Rohit Thakral was joined by Hugh, a governance and compliance specialist, to discuss the practical challenges businesses need to consider.

The discussion covered AI governance, risk management, DORA, operational resilience, employee training, third-party providers and what businesses can realistically do to prepare.

AI Is Already Being Used in Your Business

One of the biggest points from the discussion was simple:

Businesses should not treat AI as something that might arrive in the future. It is already here.

Even if an organisation has not officially introduced an AI strategy, employees may already be using AI tools for everyday tasks.

That could include:

  • Writing or reviewing emails
  • Creating documents
  • Summarising information
  • Research
  • Data analysis
  • Generating reports
  • Customer communications
  • Improving productivity

Simply banning AI does not necessarily remove the risk.

In fact, it can make the situation harder to manage because employees may continue using AI without the organisation knowing what tools they use, what information they enter or how those tools handle the data. Pasted text

The better approach is to understand how AI is being used and create a framework around it.


Four Things Every Business Should Consider

During the webinar, the discussion highlighted four key areas businesses should address when developing their approach to AI:

1. Create an AI Policy

Employees need clear guidance on what they can and cannot do with AI.

An effective policy should consider the organisation’s industry, data, customers, systems and regulatory environment.

It should answer practical questions such as:

  • Which AI tools can employees use?
  • What information can they enter?
  • What information must never be shared?
  • When should AI-generated content be reviewed?
  • When should employees disclose the use of AI?
  • Who is responsible for approving new AI tools?

A policy should not simply say “don’t use AI.”

Instead, it should help employees understand how to use AI responsibly.


2. Establish Accountability

Someone within the organisation needs to own AI governance.

That does not necessarily mean creating a completely new department.

The important thing is to establish clear accountability and bring together the different perspectives across the business.

For example, IT may focus on technology and security, while operations may consider cost and business value. HR may focus on training and policy, while compliance considers regulatory requirements.

All of these perspectives matter.

Therefore, someone needs to bring them together and make sure AI becomes part of the wider business governance structure rather than another isolated technology project. Pasted text


3. Add AI to Your Risk Framework

AI should not sit separately from your existing risk management processes.

Businesses should consider questions such as:

  • What could go wrong?
  • What information is being used?
  • Who has access to it?
  • Which AI systems are being used?
  • What happens if the system produces an incorrect result?
  • Could AI affect customers or financial decisions?
  • What controls are in place?
  • Who owns each risk?

The webinar highlighted that organisations need to consider AI within their existing risk appetite, risk register and control environment.

For regulated businesses, this becomes particularly important because requirements can differ depending on the jurisdiction, organisation and use case. Pasted text


4. Train Your People

Technology alone will not solve the problem.

Employees need to understand not only how to use AI, but also when they should and should not use it.

Training should cover areas such as:

  • Company AI policies
  • Data protection
  • Security risks
  • Appropriate AI use cases
  • AI-generated errors
  • Verification of AI outputs
  • Transparency
  • Different types of AI tools
  • Practical examples relevant to the employee’s role

This is particularly important because AI adoption often happens faster than formal training programmes.

The webinar highlighted that training needs to go beyond teaching people how to write better prompts. Employees also need to understand the wider risks, responsibilities and opportunities surrounding AI. Pasted text


Compliance Is Not One-Size-Fits-All

Another important takeaway was that there is no universal compliance checklist that works for every organisation.

A small financial services business will have different requirements from a large bank.

Similarly, businesses operating in Ireland and the EU may face different requirements from organisations operating in the UK.

The webinar explored areas including DORA, the EU AI Act and the UK’s operational resilience regime, while also highlighting the importance of existing frameworks such as ISO and GDPR.

The key point is that businesses need to understand which requirements actually apply to them and what evidence they need to demonstrate compliance. Pasted text


Don’t Just Write the Policy. Test It.

One of the strongest practical points from the webinar was the importance of testing.

Businesses often have policies and business continuity plans in place, but that does not necessarily mean those plans will work when something goes wrong.

During the discussion, Hugh shared an example of a business that tested its business continuity plan and discovered that its crisis procedures were stored in the very document repository it had supposedly lost access to during the simulated cyber incident.

It highlighted an important lesson:

You do not really know whether a process works until you test it. Pasted text

For businesses adopting AI and other connected technologies, testing should form part of the wider resilience strategy.


Your Third Parties Matter Too

Modern businesses rarely operate entirely on their own.

They depend on cloud platforms, software providers, technology partners and other ICT service providers.

That means your own security and compliance controls are only part of the picture.

Businesses should understand:

  • Who their critical technology providers are
  • What services those providers deliver
  • What contracts are in place
  • What security and compliance commitments exist
  • What happens if a provider becomes unavailable
  • Whether appropriate exit or contingency plans exist

The webinar recommended auditing ICT service providers as an important practical starting point, particularly for businesses working towards DORA requirements. Pasted text


Start Small Rather Than Trying to Fix Everything at Once

Compliance can feel overwhelming.

There are regulations to understand, systems to review, suppliers to assess, policies to create and employees to train.

However, the answer is not to try to solve everything at once.

A more practical approach is to break the work into manageable steps:

1. Assess where you are now

Understand your current systems, processes, risks and compliance position.

2. Identify the gaps

Determine where your policies, controls, evidence, systems or training need improvement.

3. Build a roadmap

Prioritise the actions, assign ownership and establish realistic timelines and budgets.

4. Implement the changes

Turn the recommendations into practical improvements rather than allowing the assessment to become another report sitting on a shelf.

This three-stage approach formed a key part of Target Integration’s compliance methodology discussed during the webinar: gap assessment, roadmap and implementation. Pasted text


AI Should Be Part of Your Business Strategy

Perhaps the biggest takeaway is that AI should not become another silo within the organisation.

It should connect with your existing approach to:

  • Governance
  • Risk management
  • Cyber security
  • Data protection
  • Compliance
  • Employee training
  • Business continuity

The goal is not to stop businesses from using AI.

Instead, the goal is to create an environment where employees can use AI safely, responsibly and productively.

As AI becomes more deeply embedded in business systems and everyday workflows, that approach will become increasingly important.


Where Should Your Business Start?

If you are unsure where your organisation currently stands, start with three simple questions:

Who is responsible for AI governance in our business?

Do we know how our employees are already using AI?

Have we assessed the risks associated with that use?

If the answer to any of these is unclear, that is a good place to begin.

A practical health check can help identify where you currently stand against relevant regulations and best practice, highlight gaps and provide a clearer path forward. The webinar also highlighted the value of combining regulatory and documentation reviews with technical cyber assessments to create a more complete picture of organisational risk. Pasted text


Final Thoughts

AI presents enormous opportunities for businesses.

However, responsible adoption requires more than simply choosing an AI tool and giving employees access to it.

Businesses need policy, accountability, risk management and training.

They also need to understand their regulatory obligations, review their technology providers and test whether their processes actually work when something goes wrong.

Most importantly, businesses do not need to solve everything overnight.

Start with an assessment. Identify the gaps. Build a roadmap. Then take action.

That is how organisations can move towards AI adoption without losing sight of compliance, security and resilience.

🎥 Watch the Full Webinar

We explored these topics in much more detail during our Compliance in the Age of AI webinar with Rohit Thakral and Hugh.

Want to understand where your business currently stands? Target Integration can help you assess your digital, compliance and cyber environment and identify practical next steps.

Get in touch with our team to start the conversation