
AI adoption across compliance teams is accelerating, but trust is still lagging behind. Vixio’s latest research captures that tension clearly: 65% of compliance leaders said they distrust generic AI for regulatory decision-making, 59% cited hallucinations or fabricated confidence as a primary concern, and 56% still require a mandatory human checkpoint before relying on AI-generated outputs.
Those numbers matter, but they also point to a broader issue that the market is only beginning to understand. The problem with compliance AI is not simply that models can hallucinate. It is that most general-purpose AI systems were never designed for regulated decision-making in the first place. They are designed to generate useful answers, whereas compliance teams need systems that can explain where an answer came from, understand the regulatory context around it, recognise when the evidence is incomplete, route uncertainty to the right person and preserve a record of how the final decision was reached.
Why the AI trust gap in compliance is really an architecture problem
That distinction becomes more important as AI moves from being used for basic research into live compliance workflows. It is one thing to ask a model to summarise a rule or surface relevant guidance. It is another to use AI to determine whether a financial promotion is suitable to go live, whether a claim needs to be qualified or whether a piece of content should be escalated for further review.
At that point, the quality of the model is only part of the equation. The architecture around it becomes just as important. Regulated firms need to know which sources the system is relying on, what regulatory context has been applied, how uncertainty is handled and what happens when the answer is not clear-cut.
That is why the next phase of AI in regulatory compliance will be defined less by model capability alone and more by the systems built around it.
Hallucinations are only one part of the problem
It is understandable that hallucinations dominate conversations about AI trust. Vixio found that 59% of compliance leaders raised hallucinations or fabricated confidence as a primary concern, and the risk is particularly acute in regulation because an incorrect interpretation can still sound authoritative enough to influence a decision.
But eliminating obvious hallucinations does not automatically create trustworthy compliance AI. A model can give a factually correct answer and still apply the wrong jurisdiction. It can identify the right rule but fail to recognise an exemption. It can correctly interpret a requirement while missing important context about the customer, product or distribution channel.
The issue therefore extends beyond whether the model knows the answer. It is whether the system knows enough about the situation to apply the answer correctly.
For financial promotions, that context can include the jurisdiction, product, target audience, distribution channel, regulatory permissions and the nature of the claims being made. A correct answer applied in the wrong context can still create a compliance problem, which is why regulatory-grade AI needs to be context-aware by design.
Source provenance will become a baseline requirement
Vixio’s research also points to another important shift: compliance leaders want to understand where AI outputs come from.
Source provenance means being able to trace an AI-generated conclusion back to the regulatory material that supports it. That is becoming fundamental in regulated environments because the usefulness of an answer is closely tied to whether someone can verify it.
If a system flags a financial promotion, the user should be able to understand what triggered the issue, which regulatory requirement applies and why the system reached that conclusion. That chain from output to source turns AI from a black-box recommendation engine into something a compliance professional can interrogate, verify and defend.
We expect this to become table stakes for compliance AI. Systems that cannot show where their answers come from will struggle to earn trust in workflows where those answers influence real regulatory decisions.
Human oversight is a control layer, not a temporary workaround
The fact that more than half of compliance teams still require mandatory human checkpoints should not be interpreted as evidence that AI has failed to automate compliance. In regulated workflows, human review plays a different role.
It provides judgement in situations where materiality, ambiguity, proportionality or interpretation matter. Those decisions do not always reduce neatly to binary rules, and that will remain true even as models become more capable.
The more useful future is therefore not maximum automation, but more intelligent automation. Lower-risk, repeatable activity can move quickly, while complex or higher-risk cases are surfaced for specialist review.
For financial promotions, that creates a more practical operating model. Rather than every communication travelling through the same approval process, technology can help determine which pieces of content can move efficiently and which genuinely require deeper scrutiny.
Risk-based workflows will define the next generation of financial promotions compliance
This is where the implications for financial marketing become particularly important.
Marketing teams are already producing more content across social media, websites, email, paid advertising, video and AI-generated channels. The volume of content can scale much faster than a traditional manual review process.
The compliance workflow therefore needs to evolve with it.
Rather than treating every piece of content in exactly the same way, firms can use AI to understand the characteristics of the communication, assess the level of regulatory risk and determine the appropriate route through the review process. Lower-risk content can move faster, while higher-risk or ambiguous communications receive greater scrutiny.
That is a much more scalable model than applying the same manual approval burden to everything, and it is also more aligned with the direction of increasingly risk-based supervisory frameworks.
Auditability will matter as much as accuracy
In regulated financial services, it is rarely enough to know that the final answer was correct. Firms may also need to demonstrate how that answer was reached.
That means an AI-enabled compliance system should be capable of recording what was reviewed, which rules were considered, what issues were identified, what changes were made, who intervened and why the final decision was made.
Auditability therefore cannot sit outside the AI layer as an afterthought. It needs to be part of the architecture from the beginning.
Every automated compliance action should leave behind a usable evidence trail. As firms adopt more flexible and risk-based approaches to review, the ability to evidence why content followed a particular path becomes even more important.
Compliance AI is becoming infrastructure
The first generation of compliance AI has largely been about productivity. Summarising regulation, searching documents, drafting responses and identifying relevant information have all created meaningful efficiencies.
The next generation will be more consequential because AI will increasingly sit inside the workflows where regulated decisions are actually made.
When that happens, the bar changes. Trustworthy compliance AI will require regulatory grounding, contextual intelligence, source provenance, controlled automation, human escalation and audit-ready evidence.
This is where we believe Adclear is ahead of the curve. Financial promotions compliance is not simply a content-review problem, and it is not solved by placing a general-purpose model in front of a regulator’s handbook. It is a workflow problem that sits at the intersection of regulation, context, risk and evidence.
The firms that solve that architecture problem will define the next era of RegTech. Vixio’s research shows that compliance leaders are already asking for exactly these things: verifiable sources, human checkpoints and clearer evidence around AI outputs. The opportunity now is to build systems that make those controls native to the workflow rather than bolting them on afterwards.
The real trust gap is between generic AI and regulated decision-making
The conversation around compliance AI is moving quickly, but the market still tends to frame trust as a model problem. We think that misses the bigger point.
The real trust gap is between what general-purpose AI is designed to do and what regulated firms actually need from it.
Compliance teams do not simply need more convincing answers. They need systems that understand regulatory context, expose their sources, recognise uncertainty, escalate intelligently and preserve evidence.
That is the standard that will define whether AI remains a useful assistant for compliance teams or becomes infrastructure they can genuinely rely on.


