AI Can Do Your Compliance Work, but It Can't Sign Off for You
A while back, a friend of mine in fintech invited me to dinner. At the table he vented: half of what his marketing department ships these days is written by AI.
A while back, a friend of mine in fintech invited me to dinner. At the table he vented: half of what his marketing department ships these days is written by AI. Landing pages, WeChat official-account posts, ad creatives, sales scripts — AI produces the first draft, a human gives it a quick touch-up, and out it goes.
I asked one question: what about compliance? Who is reviewing it?
He froze.
His compliance department is all of three people, and they're expected to clear several hundred assets a month. It used to be that humans couldn't keep up. Now AI has cranked up the pace of output — and they still can't keep up.
I couldn't stop thinking about that dinner. So today, let me lay it out properly: in heavily regulated industries like finance, how exactly should AI be used in marketing compliance?
Let me put my conclusion up front: AI can do the work of compliance for you, but it can't carry the responsibility for you.

What Is AI Marketing Compliance?
So what is AI marketing compliance?
Put simply, it means using AI to review, watch, and log every piece of content before it reaches a customer.
Review for what? Whether marketing claims are exaggerated, whether disclosures are complete, whether cited data has a source, whether personal data is being used lawfully, whether brand guidelines are upheld. And what gets reviewed is just as messy: emails, landing pages, ads, social posts, sales decks, app copy — plus the drafts AI itself generates.
This used to be work a compliance officer did line by line. Now the volume has simply outgrown them.
People who can't keep up naturally reach for machines. That's only natural.
But can you give the machine free rein? The regulator has come right out and said it.
This year, FINRA (the Financial Industry Regulatory Authority) devoted a section of its annual regulatory report to generative AI: for companies using GenAI, not a single existing rule is waived. Supervisory obligations, communications standards, recordkeeping, fair treatment of customers — all unchanged.
In plain English: AI as first-pass reviewer, yes. AI as the approving officer, no.
The report also specifically called out a new role: the AI agent. Unlike a chatbot, it acts on its own and gets work done across systems. The more power it has and the more moves it makes, the more likely that when something goes wrong, you won't even know what it did at the time.
Don't worry — we'll get into that later. First, let's run the numbers.
What Compliance Actually Costs
Here's a set of numbers — let them sink in.
On average, companies spend about 25% of their revenue on compliance. Of every $4 earned, $1 goes toward "staying out of trouble."
Harsher still: nearly one in five companies estimates on its own that more than half of its revenue is consumed by compliance-related costs. And 35% of risk executives believe compliance and regulatory risk is the biggest threat on the company's road to growth.
Staggering — 25%.
Little wonder, then, that KPMG's survey found 68% of financial services institutions rank "using AI in risk and compliance" as a top priority; or that in Thomson Reuters' survey, 48% of compliance professionals believe AI can raise internal efficiency, and 35% believe AI can help them keep up with regulatory change.
The results really are visible. Among risk and compliance teams already using AI, 90% say AI has brought a positive impact: automatically flagging violations in marketing assets, scanning data usage for privacy red lines. Fewer errors, shorter cycles.
AI's Role Has Changed
But the point I want to press today isn't that "AI can write copy."
It's that AI's role has changed.
The real change is: AI is no longer just a content generator — it is becoming a workflow layer. What does that mean? Teams use it to summarize long documents, extract risk points, classify assets, route approvals, suggest edits, watch pages after they go live, and save review records.
FINRA itself has observed that the most common GenAI use case among member firms is summarization and information extraction.
Makes sense. This kind of repetitive grind is exactly what compliance teams hate most.
But once AI enters the workflow, new problems arrive. The company must be able to answer: what did the AI see? What did it change? What did it recommend? Who accepted the recommendations? Which version finally went live?
If you can't answer a single one, an audit turns into a disaster.
And to answer them, you first have to get a handle on the thing that acts on its own.
Agents: Ten Times the Capability, Ten Times the Risk
What is an agent?
It's AI that doesn't just talk — it also acts. Given a task, it can break it into several steps and run them across several systems on its own.
In a marketing context, an agent can read the campaign brief, write the first draft, check itself against policy, propose revisions, submit to compliance review, update tasks, and archive the final version.
No human touches any of it.
Efficiency maxed out. But this is also what regulators have watched most closely this year. In the GenAI section of its annual report, FINRA named a string of risks: autonomy, scope of permissions, auditability, sensitive data, domain knowledge, misaligned incentives.
In plain terms: it has too much freedom, and you know too little.
So what do you do? Five control lines, every one of them actionable:
- Draw clear permissions. AI may draft, flag, classify, and suggest. It may not publish, may not approve exceptions, may not change policy, may not bypass mandatory disclosures.
- Lock down access. Which repositories, which CRM fields, which ad accounts, which customer data it can touch — list them one by one in a whitelist.
- Keep an audit trail end to end. Prompts, outputs, model versions, timestamps, reviewers, final decisions — record all of it.
- High-risk content must be signed by a human. Performance claims, client testimonials, rate comparisons, privacy statements, loan terms, deposit-insurance statements — none of these pass until a human signs.
- Keep watching after launch. AI drifts, policies change, marketing moves old copy into new scenarios. Monitoring must be continuous; checking once is not enough.
A useful agent has a clearly defined job description. A dangerous agent has a vague mission and unrestricted permissions.
Who You're Really Up Against
Do marketing compliance, and you're not facing one regulator — you're facing a map. Let me walk you through the heaviest ones.
GDPR, the EU's privacy law, the strictest in the world. The fine? Up to €20 million, or 4% of global annual revenue — whichever is higher.
That's not a scare tactic. As of March 2025, cumulative fines have already exceeded €5.6 billion, averaging about €2.4 million per case. In 2023, Ireland's Data Protection Commission fined Meta €390 million over "forced consent" — agree to personalized ads or don't use the service; the same year it fined TikTok €345 million because children's data was improperly handled in targeted advertising.
For marketing teams, GDPR means: email marketing must be able to prove users opted in, dropping tracking cookies requires explicit consent, and cross-border data transfers need a lawful safeguard. One more twist of the knife: "lack of a lawful basis for processing" is the number-one GDPR violation of all time — 612 fines, averaging €2.7 million each.
CCPA/CPRA, California's privacy law. In 2025, the California Privacy Protection Agency hit Honda with a $632,500 fine, with the violations centered on consumer rights and opt-out processes. Do your cookie banner, preference center, and unsubscribe links actually execute users' choices? That's exactly what enforcers are watching.
The SEC Marketing Rule governs investment advisers. How performance advertising is done, whether client testimonials can be used, how third-party ratings are displayed, what Form ADV must disclose, how books and records are kept. The moment a performance figure leaves your mouth, you must be able to produce the evidence.
FINRA Rule 2210 governs broker-dealer communications. In the 2026 exam findings, everything named is a new scenario: how influencer partnerships are supervised, manipulative push notifications in apps, misleading promotions, inadequate sampling, non-English communications left unreviewed.
The FTC: advertising must be truthful, substantiated, and non-deceptive. For subscriptions and auto-renewals, disclosure and consent design — even though revisions to that rule have been through litigation, this line has never loosened.
Then there are UDAAP (unfair, deceptive, or abusive acts or practices) and the banking marketing rules. Banks, lenders, and fintech companies must not engage in unfair, deceptive, or abusive practices. Marketing for loans, deposits, and cross-border remittances each carries its own disclosure requirements — for example, Reg Z and the FDIC's advertising rules.
The map looks intimidating. But it proves exactly one thing: humans alone can't review this anymore.
The Cost of Not Using AI
Some will say: then I won't use AI — can't I just hire two more people?
First, look at how the no-AI crowd is doing. A 2023 survey showed: 60% of fintech companies paid at least $250,000 in compliance fines in the prior year, and one-third paid more than $500,000.
Now run the numbers on privacy requests. The number of personal data requests (DSRs — think users asking you to export or delete their data) grew 246% from 2021 to 2023, from 248 per million people to 859. Processing these requests by hand — that is, exporting and deleting data for users — cost about $880,000 per million identities in 2023, up another 36% from the year before.
Relying on manual labor, you can't catch up.
But the number that stings more is this one. A survey asked fintech companies: what is the biggest driver of your compliance work?
You'd think everyone would say "fear of fines."
No. 34% of companies chose maintaining customer trust — more than chose avoiding fines. Another 25% fear reputational damage most.
Sit with that logic for a second: fines lose you money; losing trust loses you the business.
Customers can hand you their data — and take it back whenever they like. So compliance is, in essence, the infrastructure of trust.
The Four Pitfalls Marketers Hit Most Often
Let me show you a few real failures, all pulled from enforcement records of the past few years.
The first pitfall: installing a consent banner and thinking you're safe.
In 2025, an apparel retailer was fined $345,000. It had installed a cookie consent banner, but the configuration was wrong, and users' opt-out requests went unprocessed for a full 40 days. The regulator's wording stung, but it was right: using a consent management platform is not the same as being off the hook. You bought a tool — the responsibility is still yours.
By the way: tonight, go click through your own unsubscribe links and opt-out buttons. Plenty of companies have never clicked them once themselves.
The second pitfall: using the data you happen to have, with no lawful basis.
Dropping everyone who has bought something straight into the marketing list for another product. Having bought from you is not consent to be marketed to. This is the textbook source of those €2.7-million-average fines.
The third pitfall: the user said no, and you keep chasing.
One analysis found that 75% of organizations still have more than three ad trackers on their sites after a user explicitly declines tracking. The user clicked decline; your systems didn't sync. Most of the time this isn't intentional. But the law doesn't care whether you intended it.
The fourth pitfall: AI-written content with no paper trail.
Assets that are AI-generated or AI-assisted need to leave behind the same evidence chain as human-written content: the original draft, the AI's suggestions, the human's decisions, the final version, the policy basis. If you can't produce it, the workflow won't survive an audit.
And the old warning still stands: don't hand an agent unlimited permissions. An agent that can publish, change policy, and pull customers' sensitive data is not a helper — it's a ticking time bomb.
How AI Pays You Back
Enough about risk; let's talk about returns. Compliance investment can be earned back — the math is there to prove it.
Cisco has researched this: for every $1 spent on privacy compliance, organizations get back about $1.8 in benefits on average.
Why? Because trust itself has a conversion rate. Only about 30% of consumers are willing to hand their email to a company with nothing in return. But offer a fair value exchange — a relevant deal, or a candid word on "how we'll use your data" — and the share willing to give climbs to 90%.
One brand made its site's consent forms more transparent and friendlier, and its opt-in rate rose 20%. Not a cent more spent on media — it simply gave the choice back to users.
AI's role here is to make compliant personalization scalable: recommendations built inside first-party data and privacy red lines, with targeting adjusting the instant a user withdraws consent. By 2024, 72% of companies had adopted AI in some form, with marketing and sales showing clear revenue growth.
Compliance is not the brakes on growth. A well-tuned compliance function is the suspension. The car still goes fast — it just doesn't flip.
Making It Real: Four Decisions and One Pipeline
Ready to get started? First, take the industry's temperature. In NAVEX's 2024 survey, 56% of companies planned to put generative AI into risk and compliance within the following 12 months; in 2023, 65% of companies said they were willing to budget for compliance technology.
When you're ready to implement, think four things through.
First, goals. Don't do AI for AI's sake. Pick high-value scenarios, such as first-pass ad review, tracing the flow of personal data, identifying suspicious marketing campaigns. Stand up a cross-functional group with compliance, IT, and marketing all at the table; pilot first, verify accuracy, then roll out. Here's a signal worth reading: in one survey, 35% of practitioners expected AI to bring the biggest change to compliance processes, whereas a year earlier that number was only 9%. One year — nearly a fourfold jump.
Second, money. Before launch, run three calculations: how many review hours AI can save, how many potential fines it can avoid, how much it can shorten approval cycles. After launch, set metrics and review: has review time dropped, have compliance incidents decreased?
Third, governance. The black box is the compliance team's biggest concern. When choosing a tool, ask one pointed question: can it explain why it flagged this piece of content? Does it have audit logs? An AI that cannot explain itself is a negative asset in front of an auditor. Then train the team on how to read the AI's alerts and how to correct its suggestions.
Fourth, pacing. Roll out in stages. Stage one does only one thing: scan for banned words and missing disclosures. Once that's stable, add personal data tracking and high-risk prediction. At every stage, ask: is what the AI catches a real problem? How many times did humans overrule it? Use the answers to tune thresholds and fill in data.
And finally, here's a review pipeline you can copy outright — eight steps:
- Collect. Landing pages, emails, ads, PDFs, social posts, scripts, app copy — everything goes into the pool first.
- Classify. Which channel, which jurisdiction, retail or institutional, consumer lending or deposits, whether personal data is touched.
- Extract. Performance claims, rates, testimonials, endorsements, rankings, guarantees, deposit-insurance statements, personal data references — pull them all out.
- Check. Run it against regulatory rules and internal policies.
- Explain. Point out exactly which sentence is risky, which rule it's based on, how severe, how to fix.
- Route. Low-risk items self-review and self-correct; high-risk ones go to compliance, legal, or the person in charge.
- Archive. Original draft, revision records, comments, approvals, sources, timestamps, final version — all filed.
- Monitor. Rules change, rates change, disclosures change — rescan live content.

AI's place in all of this is clear: help the compliance team achieve full coverage and leave behind a defensible review record. Those two things, no amount of manual labor will ever give you.
One Last Thing
This market is already sprinting. By mid-2025, the global RegTech market had exceeded $22 billion, with a compound annual growth rate of about 23.5%. You have the big players, like IBM Watson Compliance and Microsoft Purview, and you have a wave of startups focused specifically on marketing content compliance and privacy request automation. Choosing between tools comes down to two things: whether the built-in rule library fits your industry, and whether it can plug into your existing marketing technology stack.
Remember that friend from the dinner table? His company eventually distilled the fix into three sentences: AI first-reviews every asset, humans sign off on all high-risk content, and the system records every decision.
AI makes it fast, humans make it right, records make it provable.
Regulators won't wait for you, and they won't go easy on you. But the tools are already here.
Here's hoping you put them to work soon — and then give that freed-up afternoon back to the business that actually matters.