The audit of the cited regulation: compliance's cardinal sin
In compliance, a legal article or policy clause cited wrong doesn't cost rework: it costs a false report to the committee or the regulator. This is the RESPOND moat lesson applied to compliance: AI proposes, the analyst verifies, and whoever signs the report is a person, always.
A compliance analyst asked AI for the legal grounding to clear a new customer data flow and got back, in seconds, "in accordance with article 7, item IX, of the General Data Protection Law (LGPD), the processing is grounded in legitimate interest, waiving the need for consent." The wording was impeccable, the article number looked right. He almost attached it straight to the opinion going to the risk committee. A colleague, out of habit, opened the text of the law before filing it: item IX covers credit protection, a completely different case from what the flow required. The entire report was resting on a wrong reading of the article, and only checking the source, before reporting, kept the committee from approving a flow with no real legal basis.
An analyst asked AI for the accounting standard grounding a provision classification and received the citation of a CPC item "in effect," with convincing wording. The real CPC item, when checked, covered a different accounting case, and the classification AI proposed didn't hold up. Checking the official source, done before attaching it to the audit report, prevented the wrong classification from going out.
An in-house lawyer asked AI for case law to support the company's defense in a regulatory inspection and received four rulings with panel, division, and judge listed. Auditing before filing, he found two were invented from scratch and a third was real, but said exactly the opposite of what AI claimed it said. There was one hour left before the deadline to respond to the regulator.
A team asked AI for the regulatory grounding of a campaign claim ("approved by ANVISA") and received the citation of a registration with number and date. The piece was almost aired. In the audit, the cited registration didn't match the campaign's actual product, and the unsupported claim exposed the company to a false-advertising lawsuit. Checking the registration at the source before approving the piece was what kept the claim from airing.
An HR analyst asked AI for the labor-law article backing a corporate email monitoring policy and received the citation of an "in effect" provision, convincing. She was about to attach it to the policy that would be communicated to the whole company. On verification, the cited article covered a different type of monitoring, and the proposed policy overreached what the law actually authorizes. Checking the official text before communicating the policy prevented exposing the company to a practice with no real legal backing.
A PM asked AI whether a geolocation feature needed a specific privacy notice and received the citation of a General Data Protection Law (LGPD) article "that waives notice for this type of data." He was about to paste it into the PRD to justify the absence of the notice. Before that, he went after the official text: the cited article didn't cover any waiver, and the feature did need a clear notice. The entire prioritization was resting on a fabricated reading, and checking the source before launch prevented shipping a feature without the legal basis it needed.
A sales manager asked AI for the legal limit on gifts to a public official before closing a negotiation with a state agency and received the citation of an anti-corruption regulation "in effect," with a specific amount. He almost followed that amount in the negotiation. He went to check the company's real policy and the cited law: the real amount was much lower, and AI had mixed the limits of two different regulations. Checking before negotiating prevented an offer that would have constituted improper advantage to a public official.
An operations coordinator asked AI for the approval threshold defined in the internal purchasing approval regulation and received a specific value, cited with confidence. He was about to distribute it to the team as the official rule. In the audit, he opened the real regulation: the value AI cited didn't match the text in effect, which defined a different threshold. The document looked operational and was based on a wrong reading, and only opening the real regulation before distributing it prevented spreading the wrong rule.
An analyst asked AI for the article of the General Data Protection Law (LGPD) backing an internal data retention control and received the citation of an "in effect" provision, with a convincing number and wording. She was about to attach it to the risk opinion closing out the quarter. Before signing, she checked the official text: the cited article had been misread by AI, which mixed the text of one article with the interpretation of another. A control resting on a poorly cited regulatory basis is exactly the kind of failure the next external audit finds, and checking the official text before signing was what prevented that.
A security analyst asked AI for the access-policy item backing the grant of a privileged credential and received the citation of an item "in effect," with a convincing number and text. He almost granted the access based on that. He went to check the real policy: the cited item covered a different type of access, and the proposed grant had no real backing in the internal regulation. Checking the policy before granting access prevented an improper grant.
A designer asked AI whether a consent-screen pattern aligned with the General Data Protection Law (LGPD), citing the article backing the analysis, and received "in accordance with article 9, the format is adequate," confident, ready to approve the flow. On verification, article 9 covered a different requirement, and the proposed format didn't meet the law's real transparency requirement. Checking the article before approving the flow prevented shipping a screen out of compliance.
A strategy analyst asked AI for the regulatory requirement to enter a new international market and received the citation of a licensing regulation "in effect in that country," with number and regulator. It was already going into the board memo as a resolved item. Before presenting, he went after the country's official source: the cited regulation didn't exist under that number, and the real requirement was different, more restrictive. The entry decision was resting on a fabricated reading, and only checking the primary source, before taking it to the board, prevented presenting a requirement that didn't exist.
Look, I'll be honest with you. The most dangerous part of AI in compliance isn't when it gets it wrong in an obvious way. It's when it nails the format and gets the regulation wrong. It hands you an article with a number, wording, and the tone of someone who knows the subject, and your guard drops because it looks like the work of an experienced colleague. That relaxation is the hole. In compliance, a wrongly cited regulation doesn't cost a bad comment: it costs a false report to the risk committee or the regulator, and it can cost the entire area's credibility.
The core idea of this lesson. AI doesn't "consult" the regulation: it predicts the most likely next piece of text. That's why it invents articles, internal policy clauses, and technical standard items with absolute confidence, and its confidence is exactly what fools you. The rule is simple and non-negotiable: never trust an AI regulation citation without checking. You audit it. And whoever signs the compliance report is a person, always, because "the AI that cited it" doesn't exist before the committee or the regulator.
01Why AI lies with the straightest face in the world
Let's clear up a misunderstanding that costs dearly. AI doesn't have a database of regulations in its head that it "opens" to answer you. It works by predicting the most likely next word, given everything that came before. When you ask for the article backing a decision, it doesn't search: it composes something that has the shape of a correct citation. Number, text, the tone of someone who knows the subject, all in the perfect format, because it has seen thousands of real citations and learned the mold. The mold is correct. The content can be wrong, or might not even exist.
The problem isn't that it gets things wrong; it's that it gets things wrong with the same confidence it gets things right. There's no warning, no "maybe," no hesitation. Out comes secure, polished text, the way an experienced specialist would write it. And there are real cases of institutions sanctioned for reporting a nonexistent or poorly grounded control to a regulator, long before any generative AI existed. Now, with AI generating that kind of text in seconds, the risk of repeating that error at scale increases, it doesn't decrease.
Notice the cruel inversion. In the analog world, the signal that something is trustworthy is that it looks well made. With AI, looking well made says nothing about being true, because producing something well made is exactly what it does best. Form stopped being proof. Only the fact is proof. And a fact, in compliance, gets checked at the official source.
02The speed paradox: you feel faster while getting it wrong
There's a study that needs to sink into your head before you trust your own sense of things. In 2025, METR measured experienced professionals working with and without AI assistance. The result went against everyone's expectations: with AI, they got slower, about nineteen percent slower. But the detail that matters for compliance is another one: they thought they were faster. The sense of acceleration was real; the gain wasn't.
Why does this happen? Because AI gives you an instant draft, and your brain registers that fast delivery as progress. Except the real work, checking, correcting, undoing what came out wrong, stays hidden and disappears from your perception. In compliance, this paradox costs more than hours. It costs a report wrongly submitted to the committee, a non-compliance that went unnoticed, a fine. That's why the regulation audit can't depend on how you feel about the report. You need an external, cold process, one that doesn't ask if you're confident. It asks whether the regulation exists and says what the report claims.
03The compliance audit checklist: five questions before reporting
Here's the heart of the lesson. Auditing an AI-assisted report isn't intuition, it's a routine. Five questions, always the same, always at the source. If any one fails, the report doesn't go out. It's not about how much you trust it: it's about passing through all five gates.
- Does every cited regulation exist and say what AI claimed? Open the official text (law, technical standard, internal policy). Check the article, item, section number. And read the actual text, because a real article can say the opposite of what AI guaranteed it says.
- Is the regulation in effect? A cited regulation might be repealed, amended, or updated since the model's training. AI doesn't automatically track repeals. Confirm currency in the updated official text.
- Does the regulation apply to this process? Existing and being in effect isn't enough. The regulation needs to cover the case, the type of data, or the type of operation compatible with your real matter. A regulation out of context is ammunition that blows up in your hand at the next audit.
- Is any fact about the operation made up? AI fills gaps with what sounds plausible: data volume, a control's date, a responsible person's name. Cross-check every fact stated in the report against what the process actually shows and against the real evidence. A made-up fact about your own operation is the error that destroys the entire report's credibility.
- Can whoever signs actually stand behind it? If the risk committee or the regulator asks where that argument came from, on the spot, with no AI around, can you back it up? If the answer is no, the report still isn't yours. It's a draft you don't understand.
04The RESPOND principle: whoever signs the report is a person, always
Back in the map The 3 Moves, RESPOND is the moat: the part of AI-assisted work you don't outsource, because that's where accountability lives. In compliance, RESPOND has an exact and unforgiving translation: the report goes out with a human name under it, and that name answers for every regulation cited in it.
Think about what happens during a regulatory inspection. If there's a problem in the compliance report, the regulator doesn't call AI. There's no "the AI that cited it" before the risk committee, before the regulator, before the board. There's the analyst or manager who signed it. The machine executes, the machine proposes, the machine sweeps fast. But the signature is the boundary where responsibility stops being able to get pushed further along. It hits a person and stays there.
And here's the frame that changes your relationship with the audit. Checking every cited regulation isn't distrusting the tool, isn't old-fashioned, isn't a waste of time. Auditing protects three things at once: the company, which reports to the regulator based on what you sign; the real process, which gets committed to a single poorly cited article; and your professional credibility, which is your most expensive asset in the field. AI gave you speed in the draft. The audit is what turns that speed into something you can sign without losing sleep. Whoever skips the audit isn't being faster. They're outsourcing their own risk and pretending not to see it.
Do it now
Take a real compliance report (your real task works well) where you'd use AI to ground a conclusion with a cited regulation. Before thinking about filing or reporting anything, build YOUR OWN five-item compliance audit checklist, adapted to your area of practice:
- REGULATION EXISTS AND CHECKS OUT: write the exact question and which official source you'll check every article, internal policy clause, or technical standard item against (which law, which document, which page).
- CURRENCY: how do you confirm every cited regulation is currently in effect, and not repealed or amended since the last update AI knows about?
- APPLICABILITY: what criterion do you use to decide whether the regulation really serves THIS process (type of data, type of operation, context)?
- OPERATION FACTS: how do you cross-check every fact stated in the report against the process's real evidence, to catch anything AI made up?
- STANDING BEHIND IT: the question you ask yourself to know whether you could defend each citation before the committee or the regulator, with no AI around.
Write the five out on one page and stick it next to your screen. If you report without going through all five, it wasn't AI that signed: it was you.
Practice
1. Why should a regulation cited by AI never enter a compliance report without checking the official source, even when it comes with a full article number and wording?
2. The 2025 METR study showed experienced professionals were slower with AI, but thought they were faster. What is the direct lesson for the compliance audit?
3. Applied to compliance, what does the RESPOND principle (AI proposes, the analyst verifies, the person signs) determine about responsibility for the report?
For the board
On the cardinal sinthe danger is not it being obviously wrong. It is getting the format right and the rule wrong.
On the feelingyou feel faster exactly when you should be more suspicious. The checklist does not ask if you trust it, it asks if the rule exists.
On the signatureit is the border where risk stops being passed along. Whoever signs the report is a person, always.
Thanks for the feedback. It helps sharpen the next lesson.