2026 Outlook Enterprise Legal · Risk · Compliance AI Transformation

The function that
both uses AI and
must police it.

Legal, Risk, and Compliance face a tension no other corporate function carries: they are simultaneously adopting AI across their own work and serving as the enterprise's control authority over everyone else's AI. The winners treat this dual mandate as the design principle — redesigning workflows, the operating model, and the three lines of defense — not as a compliance afterthought.

75%
of UK financial-services firms
already use AI (BoE/FCA, 2024)
2%
of FS AI use cases are
fully autonomous (BoE/FCA)
34%
claim “complete understanding”
of the AI they use (BoE/FCA)
1,547
court decisions on AI-hallucinated
content (Charlotin, Jun 2026)
12 reference tables · expandable below
Every analytical table from the underlying research report — value chain, workflows, financial crime, risk intelligence, operating model, roles, model risk, legal, red lines, cases, governance, and governing enterprise AI — is available below as a click-to-expand data view. Closed by default to keep the briefing scannable.
01 The Thesis

Three positions this report defends.

LRC functions treating AI as a productivity overlay capture some efficiency but no durable control advantage. The functions pulling ahead recognize that the same discipline that makes them effective adopters — governance, evidence, defensibility — is exactly what the enterprise needs from them as AI's control authority.

i.

The dual mandate is the design principle, not a conflict to manage.

LRC both adopts AI and governs the enterprise's use of it. Treating these as one capability — built on inventory, validation, audit trails, and human-in-the-loop thresholds — is what separates leaders from firms that bolt governance on after the fact.

ii.

The model-risk ground shifted in April 2026.

The interagency Revised Guidance (OCC 2026-13; Fed SR 26-2; FDIC FIL-15-2026) superseded SR 11-7 and SR 21-8 — and expressly placed generative and agentic AI outside its scope. The tools LRC worries about most now sit in a governance gap LRC must close with its own frameworks.

iii.

The professional-responsibility and disclosure floor is rising fast.

ABA Opinion 512, a court record of 1,547 hallucination decisions, and SEC AI-washing enforcement scoped to registrants and RIAs have redrawn the red lines. Verification, privilege preservation, and disclosure-committee review are now non-negotiable.

02 Adoption vs. Understanding

75% are using AI. 34% understand it. 2% run it autonomously.

The most important numbers in the Bank of England/FCA survey aren't the adoption rates — they're the gaps. Most financial-services firms have deployed AI faster than they can explain it, and control-function adoption deliberately lags the business side because the same function setting the guardrails is cautious about deploying the riskiest tools on itself.

The FS AI understanding gap
BoE/FCA · n=118 firms · Nov 2024
Using AI in some formup from 58% in 2022
75%
Use cases with some automated decision-makingbut a human remains in or over the loop
55%
Firms with “complete understanding” of their AIa further 46% report only “partial” understanding
34%
Use cases that are fully autonomousthe frontier remains overwhelmingly human-supervised
2%
Adopter signal
88%

of organizations use AI in at least one function (McKinsey State of AI 2025, n=1,993) — but only 7% report AI fully scaled across the enterprise (Exhibit 1). LRC adoption is real but early, and control functions trail the business.

Governor signal
1,547

court decisions worldwide now address AI-hallucinated content (Charlotin database, Jun 6 2026) — up from 712 when Bloomberg Law reported it in December 2025. The trajectory, not the count, is the board-relevant point: it more than doubled in six months.

03 Workflow Redesign

Four levels of AI in legal, risk & compliance work.

The four are not interchangeable. Most enterprises stall at level two — adding AI to existing review workflows — and never restructure the work itself, the decision rights, or the lines of defense around it. The most valuable and riskiest shift is reinvention: moving from “review everything” to risk-sampled, near-comprehensive AI triage.

I

Task automation

A discrete step gets faster. AI extracts contract clauses or summarizes a regulation; the workflow is unchanged.

II

Workflow augmentation

Human + AI in the same process. Reviewers triage alerts, draft memos, and redline contracts with AI assistance.

III

Workflow reinvention

The process logic changes: sampling becomes near-comprehensive coverage; downstream review becomes upstream guardrail. Sequence, handoffs, and decision rights all shift.

IV

Autonomous LRC

Agents perform defined activities — first-level alert disposition, triage — within control boundaries, with exception handling, audit trails, and approval thresholds. New roles (AI control owner, audit-of-AI specialist) appear that did not exist before.

04 Enterprise Cases

Four reference points — what scaled deployment actually looks like.

Outcome metrics below are company-, vendor-, or court-reported and not independently audited. Treat them as directional evidence rather than benchmarks for your own business case. Two are adoption stories; two are cautionary tales about the governor's side of the mandate.

HSBC
Banking

“Dynamic Risk Assessment” AML AI built with Google Cloud · monitors >1bn transactions/month · Celent Model Risk Manager of the Year 2023

2–4×
more suspicious activity identified vs. prior rules-based system
60%+
reduction in alert volumes — less time chasing false leads
~4×
more financial crime found in retail banking; ~2× in commercial
Company-reported (HSBC/Google), not independently audited · alert-volume reduction is only beneficial if false negatives do not rise · explainability and human disposition thresholds remain essential
JPMorgan Chase
Banking

COiN (Contract Intelligence), live since June 2016 · automates review of commercial credit agreements · LLM Suite rolled out to 200,000+ staff

12,000
commercial credit agreements reviewed per year
360,000
lawyer/loan-officer hours/yr the manual process previously consumed
200k+
staff with access to the firmwide LLM Suite assistant
12,000/360,000 figures from Bloomberg (Hugh Son, Feb 27 2017), company-reported & unaudited · the widely repeated “~150 attributes/contract” detail traces to secondary write-ups (HBS case study), not the Bloomberg primary source
Delphia & Global Predictions
Asset/Wealth · RIAs

SEC's first AI-washing enforcement actions (Mar 18, 2024) · settled charges for false/misleading statements about AI use · charged under Advisers Act §§206(2)/206(4), Marketing Rule, Compliance Rule

$225k
civil penalty — Delphia (USA) Inc.
$175k
civil penalty — Global Predictions, Inc.
$400k
total — “say what you do, do what you say”
Primary source (SEC PR 2024-36) · scoped to registered investment advisers, not universal coverage · the LRC lesson: disclosure-committee review of any external AI claim
Arup
Engineering

Victim of a deepfake-CFO video-conference fraud, Hong Kong, January 2024 · an employee was induced to make 15 wire transfers after a call populated with AI-cloned executives

~$25.6M
(HK$200M) lost across 15 transfers to five accounts
15
fraudulent transfers triggered by one deepfake call
Media-reported (CNN/Fortune/WEF, 2024) · cross-industry warning · the threat LRC must govern: voice cloning and deepfakes for payment approvals and executive instructions are now an explicit red line
05 Maturity Model

Where most LRC functions actually sit.

Most large financial-services enterprises sit between Level 2 and Level 3 for both LRC adoption and their governance of enterprise AI — pilots running, an AI inventory emerging, the operating model and three-lines design largely untouched. The BoE/FCA finding that only 2% of FS AI use cases are fully autonomous confirms Level 5 is still aspirational.

Level 01
01
Ad-hoc experimentation
Individuals use public AI tools. No enterprise AI policy. High shadow-AI risk.
Level 02
02
Functional pilots
Teams pilot contract review, legal research, monitoring, reg-change tracking. First-draft AI policy. Training nascent.
Level 03 · Most enterprises
03
Scaled use cases with control
AI embedded in repeatable workflows. Approved tools, model governance, audit trails, measurable gains. Enterprise AI inventory and risk-tiering exist.
Level 04
04
Workflow & operating-model redesign
AI reshapes monitoring, contracting, investigations, decision rights, controls, and the three-lines model. LRC actively governs enterprise-wide AI.
Level 05
05
Autonomous & decision-intelligent LRC
Agents, controls, data products, and professionals work together for continuous monitoring, near-real-time risk sensing, and defensible automated dispositions within bounds — with regulator-ready evidence.
Self-diagnostic: if your organization cannot point to a workflow that has been structurally rebuilt around AI — not just augmented — and to a complete AI inventory that captures the generative and agentic tools now outside the scope of the revised model-risk guidance, you are at Level 2–3 regardless of tool count. The governor's side of the mandate matures more slowly than the adopter's, and that gap is itself a supervisory finding waiting to happen.
06 AI Red Lines

Four tiers of LRC AI permission.

A defensible enterprise LRC AI policy distinguishes between routine, enhanced, approval-gated, and prohibited use. The prohibited tier is where the function's professional accountability is non-delegable — and where 2023-era policies are most often silent.

01Normal review

Allowed with standard QA

  • Summarizing public documents
  • Internal research first-drafts
  • First-pass alert triage with human disposition
02Enhanced review

Allowed with heightened scrutiny

  • Contract drafting & redlining
  • Regulatory-change mapping
  • Reg-reporting QA
04Prohibited

No use, no exception

  • Final legal advice without attorney sign-off
  • Filing AI citations unverified
  • Autonomous AML/sanctions alert closure
  • Autonomous customer-impacting decisions (closure, denial, de-risking)
  • SAR/STR filings without human accountability
  • Voice cloning/deepfakes for approvals
  • Same model performing & testing a control
07 Regulatory Floor

The 2024–2026 record that redrew the floor.

The governing frameworks moved faster than most LRC policies. The single most consequential change for financial-services risk teams arrived in April 2026 — and it leaves the enterprise's most novel AI without a default prudential model-risk regime.

Feb 2025EU
EU AI Act
Prohibited practices & AI-literacy obligation enter application
Article 5 (banned uses) and Article 4 (staff AI literacy) became applicable on 2 February 2025. GPAI model obligations followed on 2 August 2025.
Jul 2024US
ABA
Formal Opinion 512 on generative AI
Maps existing Model Rules to GenAI: competence, confidentiality, candor to tribunals, supervision (including over third-party AI), and reasonable fees. Lawyers may not abdicate professional judgment to AI.
Mar 2024US
SEC
First AI-washing enforcement
Settled charges against two registered investment advisers (Delphia, Global Predictions) for misleading AI claims; $400k in total penalties. Scoped to registrants/RIAs under the Advisers Act.
Apr 17 2026US
OCC · Fed · FDIC
Revised Guidance on Model Risk Management supersedes SR 11-7 & SR 21-8
OCC Bulletin 2026-13 / Fed SR 26-2 / FDIC FIL-15-2026. Principles-based, most relevant above $30B assets, non-compliance not itself a supervisory criticism. Critically, it expressly excludes generative and agentic AI from scope — those tools must be governed under existing frameworks pending a forthcoming interagency RFI.
May 7 2026EU
EU Digital Omnibus
Provisional agreement to defer high-risk obligations
A provisional political agreement would move Annex III high-risk obligations to 2 Dec 2027 and Annex I to 2 Aug 2028. Not yet formally adopted — until Official Journal publication, 2 August 2026 remains the binding date. Plan two parallel tracks.
08 12–24 Month Plan

From pilots to governed transformation.

A practical sequence for a large financial-services LRC function moving from AI pilots to AI-enabled workflow, operating-model, control, and enterprise decision transformation — covering both its own adoption and its stewardship of enterprise-wide AI governance. The discipline is govern, inventory, assess, design, implement, monitor.

Months 0–6
Govern & Inventory
01
Charter an enterprise AI governance committee. Clear GC / CRO / CCO / CPO / CISO / CDO ownership. Publish an AI acceptable-use policy and approved-tools allowlist. Mandate AI-literacy training (EU AI Act Art. 4 baseline).
02
Build a complete AI/model inventory. Include LLMs, agentic tools, and the generative/agentic systems now outside the scope of the revised interagency model-risk guidance. Close the gap examiners are finding on un-inventoried LLMs.
03
Issue the red-lines policy and a citation-verification mandate. Brief the board risk and audit committees on the dual mandate and the model-risk scope change.
Months 6–12
Assess & Design
04
Risk-tier every use case. Against EU AI Act Annex III, the revised model-risk materiality logic, and NIST AI RMF. Prioritize high-risk: credit/insurance models, AML, customer-impacting decisions. Explicitly extend model-risk frameworks to GenAI/agentic tools the guidance leaves out of scope.
05
Design the controls. Human-approval thresholds, segregation-of-duties rules preventing the same model from performing and testing a control, audit logging, exception management.
06
Pilot 2–3 well-bounded use cases. Contract extraction, reg-change mapping, AML alert triage — each with defined metrics and human-in-the-loop.
Months 12–18
Implement & Monitor
07
Scale validated pilots into production. With model monitoring (drift/bias/accuracy), evidence retention, and regulator-ready documentation.
08
Stand up model-risk-for-AI and audit-of-AI capabilities. Ensure third-line independence: where internal audit uses AI, independent assurance of that use comes from elsewhere.
09
Implement disclosure-committee review of external AI claims. The AI-washing defense — say what you do, do what you say.
Months 18–24
Optimize & Operating Model
10
Redesign the operating model where evidence supports it. Surveillance hubs, legal/compliance product teams, human-AI exception management. Address junior-talent development explicitly.
11
Establish continuous-control and assurance automation. Measure OUTCOMES and DEFENSIBILITY, not just usage and throughput.
12
Watch the triggers. If false-negative rates rise, tighten thresholds and pause expansion. If the Digital Omnibus is adopted, lock in the deferred dates. If the agencies issue the AI/GenAI RFI, re-open the model-risk section.
12 Reference Tables · Expandable

The full evidence, on demand.

Every analytical table from the underlying research is below as a click-to-expand data view. The Roles & skills table is open by default — it's the most relevant evidence for individual contributors on how AI augments specific legal, risk, and compliance roles. The other eleven are closed to keep the briefing scannable; open one, several, or all at once.

09 · So What

What the GC, CRO & CCO should do differently now.

Stop measuring AI maturity by how many tools the function has adopted. Start measuring it by the question that defines the dual mandate: can you produce, on demand, a complete inventory of the enterprise's AI — including the generative and agentic systems your regulator just placed outside the model-risk perimeter — and the evidence that each is governed?

By 2027, the difference between LRC functions that strengthened the enterprise through the AI transition and those that exposed it will not be access to models — every function will have the same frontier tools. The difference will be defensibility.

That difference rests on three things: (1) whether workflows, decision rights, and the three lines of defense were genuinely redesigned rather than merely augmented; (2) whether the function closed the governance gap the April 2026 model-risk guidance opened, instead of assuming the old rules still cover the new AI; and (3) whether LRC treated its role as the enterprise's AI control authority as a source of advantage rather than a burden to minimize.

The GCs, CROs, and CCOs who will lead are the ones who recognize that the discipline making them credible adopters — inventory, validation, audit trails, human-in-the-loop, and the refusal to delegate professional judgment — is exactly the discipline the enterprise needs from them as AI's governor. Using AI well and policing it well are not two jobs. They are one.

End of briefing · The Dual Mandate · v2 (corrected)
Your future is our focus.™