Technology

Compliance in the Age of AI: What Actually Changes, and What Doesn't

Every few months, someone asks me if AI is going to replace compliance teams. I understand why they ask. It's a fair question when a technology this capable shows up in a field this manual.

My answer hasn't changed: AI changes how compliance work gets done. It doesn't change who should be doing it.

Here's what I mean by that.

The problem hasn't gotten simpler

Five years ago, online safety regulation meant a handful of laws. Today it's closer to 40 worldwide: the DSA, the OSA, Brazil's ECA, California's AADC, Malaysia's Online Safety Act 2025, India's IT Rules, and more arriving every year.

Each one comes with its own definitions, its own thresholds, its own enforcement style. And none of them stay still. Amendments get published. Commission guidelines get updated. Courts issue rulings that reinterpret what a law actually requires in practice.

Keeping up with that pace, manually, across every jurisdiction you operate in, is not a staffing problem you can solve by hiring one more person. It's a structural one.

Where the real difficulty lives

Ask any Trust & Safety or legal team where compliance actually breaks down, and it's rarely the reading of the law itself. It's what comes after.

Breaking a regulation into obligations. A single article can contain several distinct, separately enforceable duties. Turning 100+ pages of legal text into a clean list of "here is what we are actually required to do" takes real regulatory judgment, not just careful reading.

Translating obligations into product requirements. This is the step I've spent the most years of my career on. "Provide a user-friendly reporting mechanism" is not a specification an engineer can build from. Someone has to turn it into: where does the report button live, what fields does the form need, what happens after submission, how is receipt confirmed. That translation usually means legal and product sitting in a room together, often for longer than either side expected.

Monitoring progress once you've started. Compliance isn't a document you file once. It's an ongoing state. What's actually been implemented versus what's still open. Where the gaps are. Whether a fix from six months ago is still holding. Most teams I've spoken with are tracking this across spreadsheets, which works until it doesn't.

Fragmented regulation, hard translation, unclear progress. Those are the three places compliance work actually gets stuck.

Where AI genuinely helps

I want to be specific here, because "AI helps with compliance" is a claim I'd want to interrogate too if I were reading it.

Monitoring the regulatory landscape. AI is well suited to watching for new regulations, amendments, litigation, and court decisions as they land, and flagging when one of them changes how an existing obligation should be interpreted. This is pattern recognition and continuous tracking at a scale that doesn't fatigue. It's the closest thing to a genuine unlock in this list.

Breaking a regulation into obligations, article by article. AI can do a first, fast pass at decomposing legal text into structured, individual obligations. This is where a human has to stay in the loop. The output needs a person who understands regulatory intent to review and correct it, not just approve it.

Building scenarios that let a machine test compliance. Once an obligation is defined, you can construct a scenario: a defined action, a defined expected system behaviour, and a way to check whether the product actually does it. This is where AI's contribution depends entirely on the human writing the scenario. You need someone who knows how the product actually behaves, not just what the law says it should do. That's Trust & Safety expertise, not legal expertise or engineering expertise on its own. It's the seam between the two.

Running that verification continuously. Once you have scenarios in place, there's no reason to only check them once. AI can re-run them on a schedule (daily, weekly, monthly) or trigger them off a real event: a new feature ships, a meaningful commit lands. Instead of finding out at the next audit that something drifted out of compliance three months ago, you get a live posture. This is the piece that actually answers the "monitoring progress" problem from earlier. Compliance stops being a snapshot you take once a quarter and becomes something you can check on any given day.

Why this is, honestly, the best version of compliance we could ask for

I don't think AI replaces judgment here. I think it's the first time judgment has had proper tools to work with.

We spent years managing compliance manually: gathering people in a room, mapping workflows by hand, translating regulatory text into product logic one article at a time. That work required understanding both the law and the product deeply. AI doesn't remove the need for that understanding. It removes the parts of the work that never needed a human in the first place: the monitoring, the first-pass structuring, the repetitive scenario-building.

What's left is the part that actually requires expertise. And that's exactly where Trust & Safety and compliance people should be spending their time.

This is why we built Codeliance the way we did. Not as a system that tells platforms what to do without them, but as one built by people who managed this exact problem themselves, with the product knowledge and the regulatory background to know where AI should assist and where a human still has to make the call.

If you're navigating this same translation problem on your own team, I'd genuinely like to hear how you're approaching it.

Ready to Simplify Compliance?

See how Codeliance translates regulation into action for your platform.

Book a Demo