By Alexander Grafetsberger, CBO Luware Recording
Most banks are already using AI in some form. The questions now are around governance and implementation: where AI is being trusted, who is accountable for its outputs, and whether the data beneath it is strong enough for regulated work.
Solving the governance and implementation questions is becoming more urgent. Since 2 August 2026, EU AI Act transparency rules have applied. In the UK, the FCA’s Mills Review argues that trusted, safe and responsible AI adoption needs to accelerate.
For compliance teams, the test is simple. If AI flags a risk or produces a summary, someone needs to see what it was based on. AI can speed up review, but it can’t fill in a missing conversation, fix a poor transcript or guess context that should have been captured in the metadata.
That’s why the real problem often sits below the AI layer, in the communications record itself.
The problem sits underneath the model
Compliance data no longer sits neatly in one place. Relevant business communications now run across trader voice, mobile channels, Microsoft Teams, Bloomberg, Symphony, WhatsApp, SMS and other platforms, often with different retention rules, metadata and access controls.
Then there is the off-channel problem. Employees may still use personal messaging apps, SMS or unrecorded mobile channels because they are convenient in the moment. Any business conversation outside the official capture process creates a blind spot, whatever the policy says.
That is a serious weakness for AI. A model can only work with the record it has. It can summarise what has been captured and trace outputs back to the evidence it can see. But it can’t recreate a missing conversation or infer context that was never captured. The output may sound confident even when the evidence underneath is incomplete.
And in compliance, confident answers can create their own risk.
In compliance, polished answers can be dangerous
One risk with AI is that it can make weak evidence sound more coherent than it really is. A summary may read well, or an alert may look convincing. In a regulated environment, that isn’t enough.
Consider a firm using Microsoft Teams to discuss a client transaction. AI might produce a summary suggesting the appropriate disclosure was made. But if part of the interaction is missing, or the recording and metadata can’t establish exactly what was said and when, the summary itself can’t prove compliance.
The pressure is no longer theoretical. In its 2025 multi-firm review into off-channel communications, the FCA found that most firms in its sample continued to identify breaches of internal policies, including among senior staff. It also highlighted issues with direct consequences for AI readiness, including outages, reconciliation problems, missing records and inaccurate transcription.
If firms are still working to prove the right communications have been captured, they aren’t ready to rely on AI-generated summaries, alerts or risk signals as a control layer. The starting point, then, has to be the quality and completeness of the record.
AI-ready compliance starts with the record
When banks talk about AI, the model usually gets most of the attention. In compliance, the better starting point is the record. If AI is being used to flag risk, summarise conversations or support investigations, it needs a complete view of what actually happened.
Communications can’t sit in isolated archives. Voice, chat, collaboration tools and mobile channels need to give compliance teams a connected view of the conversation, with transcripts and metadata strong enough to link the right people, events and decisions.
Traceability doesn’t essentially mean reviewing every conversation manually. It means that when AI produces a summary or alert, the team can get back to the original evidence when needed, and the route from source to output is clear enough to defend.
A model may work well in one team, then struggle across desks, regions or business lines if the underlying records are inconsistent. That creates evidential debt: the growing difficulty of proving what happened and why an AI output should be trusted.
But if banks can fix the record, the opportunity becomes much bigger than compliance efficiency.
Start with the evidence
Banks already have much of the raw material they need. Recorded communications are one of the most valuable datasets in financial services.
When that data is complete, searchable and structured, AI can extend its value beyond recordkeeping. Compliance teams can move from manual sampling to targeted review, risk teams can identify behavioural patterns earlier, and front-office teams can benefit from better client records and performance insight.
Banks that want AI to transform compliance cannot treat recording, transcription and metadata as back-office details. The strongest advantage will sit with firms that have the cleanest, most complete and most auditable data beneath the model.

