M

“The AI Did It” Is Not a Defense

August 31, 2026

An assessor stops at a control marked as met and asks what evidence supports that call. 

Two years ago you'd answer from memory. You'd name the system and walk the assessor through the evidence behind it. These days there's a reasonable chance a model wrote that justification, and the person defending it isn't the person who wrote it. 

That's the awkward part of AI in compliance. It isn't that the tools don't work. They work well enough that people have quietly stopped checking. 

The governance gap 

Organizations are adopting AI considerably faster than they're governing it. ISACA's 2026 AI Pulse Poll, which surveyed more than 3,400 digital trust professionals, found that only 38% of organizations have a formal, comprehensive AI policy. That's up from 28% the year before, which is progress, but it still leaves most organizations without one. 

Put that in a compliance context and the irony gets uncomfortable. Every other system near your assessment is governed. Your SIEM has an owner, your scanner has access controls, your evidence repository is logged. But the AI tool generating your implementation statements and evidence citations often has none of that. It's a browser tab nobody inventoried. You end up using your least-governed tool to prove you run a governed program. 

How AI may get compliance wrong 

Language models are very good at producing answers that read well. That's the whole problem, because reading well and being right are different things, and the first one is much easier to fake. 

A implementation statement can look completely convincing while the reasoning underneath it is wrong. It might cite the wrong provision, or map evidence to a requirement it doesn't actually satisfy, or skip past contradictory evidence that a human reviewer would have caught in thirty seconds. 

Other professions have already been through this. Lawyers have been sanctioned for filing briefs containing AI-generated citations to cases that never existed. Bloomberg Law covered one where the sanction was $6,000, which is cheap compared to the reputational cost. 

Compliance has the same exposure, and the failure mode here looks like inaccurate findings, incorrect attestations, remediation work nobody needed to do, and an assessment package that falls apart the moment someone asks a hard question about it. 

None of this means you should stop using AI. It means checking the draft before it becomes a finding. 

Draft, Challenge, Record 

This is where a lot of organizations misread agentic compliance. They see it as a faster typewriter: same assessments, same narratives, same packages, half the time. 

Speed is real and it's welcome, though it's a byproduct of the thing that matters more. 

In a working agentic model, the agent handles the grinding work. It collects and correlates technical evidence, maps it against control objectives, flags gaps and conflicting signals, and drafts findings tied back to specific supporting evidence. 

Then a human challenges it. The compliance officer or ISSO or control owner reads what the agent proposed, checks the evidence underneath it, pushes back on conclusions that seem thin, fixes what's wrong, and makes the call. 

All of it gets logged, so when someone asks why a control was assessed as met, you can reconstruct the path: what evidence the agent pulled, which requirement it mapped against, what it concluded, who reviewed it, what they changed, and who signed off. That record is what separates AI-generated compliance work from compliance work you can defend. 

What still needs a human 

Not every AI action needs a human sitting next to it. Agents can collect evidence continuously, detect configuration drift, correlate telemetry, classify artifacts, flag missing evidence, and open tickets without anyone approving each step. Asking a compliance officer to approve each one would consume the time the automation saves. 

The useful distinction isn't AI versus human. It's automating work versus delegating accountability. You can automate an enormous amount of the first without giving away any of the second, and organizations that blur the two are the ones that end up unable to answer the assessor's question. 

Your AI is in scope too 

AI governance is moving out of the policy discussion and into operational risk management. NIST's preliminary IR 8596, a Cybersecurity Framework Profile for Artificial Intelligence, applies CSF 2.0 to AI-related cybersecurity risk across three areas: securing AI systems, using AI for cyber defense, and countering AI-enabled attacks. 

That first area is the one compliance teams will feel soonest. An AI agent that can reach enterprise data, call APIs, or shape a compliance determination is a system that touches regulated information, which means an inventory entry, an owner, access controls, documented data flows, and monitoring, the same as anything else in that category. None of that stays internal for long. If you use AI to prove your controls work, expect to be asked how you govern the AI. The specific requirements will keep changing, but the direction has been clear for a while. 

From authoring to verifying 

Compliance professionals have spent decades writing narratives, mapping controls, collecting evidence, and assembling packages. AI can absorb a large share of that work. What's left is the part that was always harder anyway: deciding whether the evidence is sufficient, whether the interpretation holds up, and whether you'd be comfortable defending the conclusion to someone whose job is to find the weak spot. That takes judgment rather than throughput, and judgment is the part the tooling doesn't replace. 

The assessor's question 

"Because the AI said so" doesn't survive an assessment. The record has to carry the reasoning, and a person has to be willing to stand behind it. 

So ask your own team: if an assessor asked today, could you explain how the AI reached its conclusion without pointing at the AI? 

Want to see Agentic Compliance in action, with AI agents that correlate evidence, draft assessment artifacts, and support a workflow designed for human investigation, review, and sign-off? 

Contact us at earlyaccess@qmulos.com.

Related Blogs

Where to Find Federal Funding for Compliance Modernization

April 21, 2023

What is the SEC’s rule on cybersecurity risk management, strategy, governance, and incident disclosure?

July 10, 2024

What is NY DFS Part 500 compliance?

June 20, 2024