In 2024 and 2025 most of us tried using AI for research, Word documents or presentations and were underwhelmed. The shift in 2026 is using it differently: as a development function and a knowledge repository for the compliance team, rather than a writing assistant.
James chaired the HFM Legal AI panel in October 2025. Since then he has built his own compliance tooling this way, including the AI Compliance Workbench and the FCA Regulatory Review.
A compliance instrument, not a writing tool
AI needs the firm’s own knowledge and experience to be effective. Once it has that context, it takes away the admin, the repetition and the fatigue. It keeps the links between risks, controls, policies, rules and owners up to date, responds to regulatory change and new business initiatives, and reduces key-person risk.
Realistic quick wins
- Compliance tracker for routine and ad hoc work, with items in flight tracked to completion.
- Bespoke training built around the firm’s profile, people and regulatory perimeter.
- Regulatory horizon monitoring that turns rule changes and final notices into firm-specific impact assessments.
- Policy and procedure library — harmonised, easier to query, and updated in one pass when rules change.
- Monitoring and testing plans generated from the risk profile, with outcomes captured and reported.
- Regulatory operations — surveillance, best execution and reporting workflows: ingestion, reporting and record keeping.
- Risk and control assessment that keeps each risk tied to its control, policy, rule, activity and owner.
- Routine outputs — reports, dashboards, presentations and correspondence.
How it works in practice
The work happens inside the firm’s own AI environment, under its enterprise licence and data governance. The first step is feeding it the firm’s permissions, activities, policies and procedures. From there, tools are built and tested with the team in days.
The long-term goal is a habit: the team works with the AI the way it works with Slack, capturing and updating its work through it. Once that habit exists, agentic workflows can automate procedures and materially reduce the cost of compliance operations.
What this is not
There is no product, seat licence or annual renewal. Compliance software is built for the average firm, so the gap between what it does and what you need becomes manual work. A tool built from your own permissions, activities and policies fits from the start, and keeps working if the engagement ends.
The limits
AI should not make compliance judgements unsupervised. Outputs need review by someone with regulatory expertise, and firms should settle their data governance position before client or trade data goes in. Handled that way, the efficiency gain is material.
Where firms are starting
- Scaling surveillance, best execution, periodic reporting, horizon scanning, policy and training with new tools and AI
- Expediting due diligence — AML/KYC, operational, vendor and counterparty
- SMCR non-financial misconduct rules, in force since 1 September 2026
- Building, capturing and reporting compliance testing
- MiFIDPRU ICARA reviews and wind-down planning
- Cryptoasset authorisation — the FCA application window runs from 30 September 2026 to 28 February 2027