The function that
both uses AI and
must police it.
Legal, Risk, and Compliance face a tension no other corporate function carries: they are simultaneously adopting AI across their own work and serving as the enterprise's control authority over everyone else's AI. The winners treat this dual mandate as the design principle — redesigning workflows, the operating model, and the three lines of defense — not as a compliance afterthought.
already use AI (BoE/FCA, 2024)
fully autonomous (BoE/FCA)
of the AI they use (BoE/FCA)
content (Charlotin, Jun 2026)
Three positions this report defends.
LRC functions treating AI as a productivity overlay capture some efficiency but no durable control advantage. The functions pulling ahead recognize that the same discipline that makes them effective adopters — governance, evidence, defensibility — is exactly what the enterprise needs from them as AI's control authority.
The dual mandate is the design principle, not a conflict to manage.
LRC both adopts AI and governs the enterprise's use of it. Treating these as one capability — built on inventory, validation, audit trails, and human-in-the-loop thresholds — is what separates leaders from firms that bolt governance on after the fact.
The model-risk ground shifted in April 2026.
The interagency Revised Guidance (OCC 2026-13; Fed SR 26-2; FDIC FIL-15-2026) superseded SR 11-7 and SR 21-8 — and expressly placed generative and agentic AI outside its scope. The tools LRC worries about most now sit in a governance gap LRC must close with its own frameworks.
The professional-responsibility and disclosure floor is rising fast.
ABA Opinion 512, a court record of 1,547 hallucination decisions, and SEC AI-washing enforcement scoped to registrants and RIAs have redrawn the red lines. Verification, privilege preservation, and disclosure-committee review are now non-negotiable.
75% are using AI. 34% understand it. 2% run it autonomously.
The most important numbers in the Bank of England/FCA survey aren't the adoption rates — they're the gaps. Most financial-services firms have deployed AI faster than they can explain it, and control-function adoption deliberately lags the business side because the same function setting the guardrails is cautious about deploying the riskiest tools on itself.
of organizations use AI in at least one function (McKinsey State of AI 2025, n=1,993) — but only 7% report AI fully scaled across the enterprise (Exhibit 1). LRC adoption is real but early, and control functions trail the business.
court decisions worldwide now address AI-hallucinated content (Charlotin database, Jun 6 2026) — up from 712 when Bloomberg Law reported it in December 2025. The trajectory, not the count, is the board-relevant point: it more than doubled in six months.
Four levels of AI in legal, risk & compliance work.
The four are not interchangeable. Most enterprises stall at level two — adding AI to existing review workflows — and never restructure the work itself, the decision rights, or the lines of defense around it. The most valuable and riskiest shift is reinvention: moving from “review everything” to risk-sampled, near-comprehensive AI triage.
Task automation
A discrete step gets faster. AI extracts contract clauses or summarizes a regulation; the workflow is unchanged.
Workflow augmentation
Human + AI in the same process. Reviewers triage alerts, draft memos, and redline contracts with AI assistance.
Workflow reinvention
The process logic changes: sampling becomes near-comprehensive coverage; downstream review becomes upstream guardrail. Sequence, handoffs, and decision rights all shift.
Autonomous LRC
Agents perform defined activities — first-level alert disposition, triage — within control boundaries, with exception handling, audit trails, and approval thresholds. New roles (AI control owner, audit-of-AI specialist) appear that did not exist before.
Four reference points — what scaled deployment actually looks like.
Outcome metrics below are company-, vendor-, or court-reported and not independently audited. Treat them as directional evidence rather than benchmarks for your own business case. Two are adoption stories; two are cautionary tales about the governor's side of the mandate.
“Dynamic Risk Assessment” AML AI built with Google Cloud · monitors >1bn transactions/month · Celent Model Risk Manager of the Year 2023
COiN (Contract Intelligence), live since June 2016 · automates review of commercial credit agreements · LLM Suite rolled out to 200,000+ staff
SEC's first AI-washing enforcement actions (Mar 18, 2024) · settled charges for false/misleading statements about AI use · charged under Advisers Act §§206(2)/206(4), Marketing Rule, Compliance Rule
Victim of a deepfake-CFO video-conference fraud, Hong Kong, January 2024 · an employee was induced to make 15 wire transfers after a call populated with AI-cloned executives
Where most LRC functions actually sit.
Most large financial-services enterprises sit between Level 2 and Level 3 for both LRC adoption and their governance of enterprise AI — pilots running, an AI inventory emerging, the operating model and three-lines design largely untouched. The BoE/FCA finding that only 2% of FS AI use cases are fully autonomous confirms Level 5 is still aspirational.
Four tiers of LRC AI permission.
A defensible enterprise LRC AI policy distinguishes between routine, enhanced, approval-gated, and prohibited use. The prohibited tier is where the function's professional accountability is non-delegable — and where 2023-era policies are most often silent.
Allowed with standard QA
- Summarizing public documents
- Internal research first-drafts
- First-pass alert triage with human disposition
Allowed with heightened scrutiny
- Contract drafting & redlining
- Regulatory-change mapping
- Reg-reporting QA
Only with GC / CRO / CCO / privacy / audit sign-off
- Anything touching privileged / MNPI / customer data
- Training on internal data
- Customer-impacting models
No use, no exception
- Final legal advice without attorney sign-off
- Filing AI citations unverified
- Autonomous AML/sanctions alert closure
- Autonomous customer-impacting decisions (closure, denial, de-risking)
- SAR/STR filings without human accountability
- Voice cloning/deepfakes for approvals
- Same model performing & testing a control
The 2024–2026 record that redrew the floor.
The governing frameworks moved faster than most LRC policies. The single most consequential change for financial-services risk teams arrived in April 2026 — and it leaves the enterprise's most novel AI without a default prudential model-risk regime.
From pilots to governed transformation.
A practical sequence for a large financial-services LRC function moving from AI pilots to AI-enabled workflow, operating-model, control, and enterprise decision transformation — covering both its own adoption and its stewardship of enterprise-wide AI governance. The discipline is govern, inventory, assess, design, implement, monitor.
The full evidence, on demand.
Every analytical table from the underlying research is below as a click-to-expand data view. The Roles & skills table is open by default — it's the most relevant evidence for individual contributors on how AI augments specific legal, risk, and compliance roles. The other eleven are closed to keep the briefing scannable; open one, several, or all at once.
What the GC, CRO & CCO should do differently now.
Stop measuring AI maturity by how many tools the function has adopted. Start measuring it by the question that defines the dual mandate: can you produce, on demand, a complete inventory of the enterprise's AI — including the generative and agentic systems your regulator just placed outside the model-risk perimeter — and the evidence that each is governed?
By 2027, the difference between LRC functions that strengthened the enterprise through the AI transition and those that exposed it will not be access to models — every function will have the same frontier tools. The difference will be defensibility.
That difference rests on three things: (1) whether workflows, decision rights, and the three lines of defense were genuinely redesigned rather than merely augmented; (2) whether the function closed the governance gap the April 2026 model-risk guidance opened, instead of assuming the old rules still cover the new AI; and (3) whether LRC treated its role as the enterprise's AI control authority as a source of advantage rather than a burden to minimize.
The GCs, CROs, and CCOs who will lead are the ones who recognize that the discipline making them credible adopters — inventory, validation, audit trails, human-in-the-loop, and the refusal to delegate professional judgment — is exactly the discipline the enterprise needs from them as AI's governor. Using AI well and policing it well are not two jobs. They are one.