AI Agents · Compliance

Compliance: AI Agents

Continuous control monitoring, evidence collection and regulatory mapping, and why a compliance agent must never mark its own control as passing.

Markdown. No sign-up, no email.

Compliance work is mostly evidence: proving that a control which is supposed to operate actually operated, on a date, with a record. That is exactly the work machines do well and people do resentfully at 2am before an audit.

What must not be automated is the assertion that we are compliant. That is a claim made to a regulator, a customer or an auditor, and someone has to be answerable for it.

Continuous control monitoring#

The change is from testing controls once a year to knowing continuously whether each one is operating.

Control typeContinuously checkableExample
AccessYesNobody has production access without approval on file
ChangeYesEvery production change has a review and an approver
DataYesRetention periods are enforced rather than documented
BackupYesThe backup ran, and the restore was tested
VendorPartlyTerms are on file; whether the vendor honours them is not observable from here
TrainingPartlyCompletion is checkable; whether behaviour changed is not

A control is either operating or it is not, and the honest answer changes daily. The annual audit model measures one day a year and infers the other 364, which is why so many audits pass in organisations that later turn out to have had a gap for eight months.

Evidence collection#

Evidence gathered as work happens rather than reconstructed afterwards.

Reconstructed evidence is the source of most audit pain and some audit failures: the control did operate, nobody kept the proof, and six months later a reconstruction is indistinguishable from a fabrication even when it is honest.

Regulatory mapping#

Which obligations apply, which control satisfies each, and where the gaps are.

The gap list is the deliverable. An obligation with no control against it is not a compliance risk in the future; it is an uncontrolled obligation now.

The hard limit#

A compliance agent must never mark its own control as passing. Monitoring and attestation are separate roles, and collapsing them removes the only independent thing in the system.

Concretely:

  • The agent reports evidence, not verdicts. "Access review completed on 14 July, 62 accounts reviewed, 9 removed" is evidence. "Access control: compliant" is a verdict.
  • A person reads the evidence and attests.
  • Any control the agent cannot evidence is reported as unevidenced, never as passing. Absence of a failure signal is not a pass, and treating it as one is how a control quietly stops operating.

What stays with a person#

  • Any statement of compliance, to anyone.
  • Accepting a control gap, with a date.
  • Deciding an obligation applies, jointly with Legal.
  • Anything said to an auditor or a regulator.
  • Declaring a control effective. The agent shows it ran; a person judges whether that was enough.

Where this sits#

Checked 9 August 2026. Most enterprises now run three frameworks together: OECD principles as the values statement, NIST AI RMF as the internal risk operating model, and ISO/IEC 42001 as the certifiable management system procurement actually asks about. None of the three was written for autonomous agents, which means the agentic parts of our own operation need controls that no framework will hand us ready-made.

That gap is worth stating plainly rather than pretending a certificate covers it.

Back to Compliance

Get new material when it is published

Everything here is free and stays free. There is no form in front of any document. If you want to know when new guides and templates go up, leave an email.

Roughly monthly. Unsubscribe in one click. We do not share your address, and we will not call you.