65% of Compliance Leaders Distrust Generic AI in Regulatory Decisions
According to Vixio's report published in August 2026, most compliance officers find generic artificial intelligence tools unreliable for regulatory decision-making in highly regulated sectors such as gambling, banking, and payments.

Key Takeaways
- 65% of compliance officers distrust generic AI for regulatory decisions.
- Only 53% of teams use AI, mainly for monitoring and basic regulatory change management.
- 59% identify audit risk from erroneous AI interpretations.
- 56% mandate human review before implementing any AI recommendation.
- Vixio defines four pillars for trust in AI systems applied to regulatory compliance.
The report 'The State of AI Trust in Regulatory Compliance 2026', conducted by Vixio and published in London on August 27, 2026, concludes that 65% of compliance leaders do not trust generic artificial intelligence tools for regulatory decisions. The research includes qualitative interviews with compliance, legal, and risk executives from payment providers, retail banks, and gambling operators. The main finding is the mismatch between organizational pressure to adopt AI and the actual trust level of compliance teams, especially in the face of regulatory audits.
Current Use of AI Tools in Regulatory Compliance
The study indicates that 53% of compliance teams are already employing AI tools for basic tasks, such as initial regulatory change management: monitoring, impact assessment, and implementing relevant updates for their operations. However, the interviewees draw a clear line between the use of AI for early research and its application in regulatory interpretation with legal weight.
Frequent Frictions: Hallucinations and Misplaced Confidence
Among the main points of conflict mentioned are the "hallucinations" generated by AI models and the apparent confidence with which incorrect responses are conveyed. 59% of respondents expressed specific concern regarding the audit risk when an AI, based on insufficient or misinterpreted data, provides erroneous yet convincing regulatory responses. The challenge is to prevent errors in the interpretation phase from allowing AI to become a source of final decisions.
Limits and Safeguards: AI as an Assistant, Not an Arbiter
Of the total interviewees, 56% maintain strict protocols requiring human review and approval before relying on any AI output. This stance emphasizes the role of AI as an assistant in the compliance process, rejecting its autonomous use where there is legal or sanctioning risk. Typical tasks delegated to AI include data gathering and the detection of regulatory novelties, but interpretive responsibility remains under the direct supervision of an expert human team.
“This report makes one thing clear: in regulated industries, speed without trust is a risk no company can afford. Compliance leaders should not face a dilemma between AI efficiency and defensible accuracy.” — Christian Erlandson, Executive Chairman and CEO at Vixio
The 4 Foundations of AI Trust According to Vixio
Vixio proposes four minimum requirements for considering any AI system a valid tool in compliance processes:
- Verified Data: All AI inputs must come from reliable and auditable sources.
- Direct Citations to the Source: It is imperative that each regulatory interpretation is accompanied by a specific reference to the original document or regulation.
- Mandatory Human Review: No report or recommendation produced by AI is implemented without clear verification by human experts.
- Transparent Activity Logging: Systems must maintain clear logs that allow for reconstruction of what information and criteria were used in each relevant case.
This methodology seeks to strengthen the traceability and "defensibility" of any process involving artificial intelligence, favoring its acceptance in regulatory audits.
Challenges for the Gambling, Payments, and Banking Sector in Adopting Trustworthy AI
Although there is a growing expectation for AI to help betting operators, retail banks, and payment processors meet new regulatory demands, the reality is that compliance teams set clear limits on its use. The main concern is to avoid automated decisions without oversight in contexts where exact interpretation of regulations can have significant legal and financial consequences. The report suggests companies prioritize investment in AI platforms that meet the four foundations suggested by Vixio and maintain human control at critical stages of the regulatory process.
For more information on regulatory advancements and challenges in integrating technology in the sector, consult the regulation section.
Frequently Asked Questions
Why do compliance leaders distrust generic AI in regulatory processes?
65% fear that generic AI may provide inaccurate regulatory interpretations, exposing companies to penalties in an audit, especially since models can issue erroneous opinions with excessive confidence.
What tasks is AI currently used for in regulatory compliance?
53% of teams use it for monitoring, impact assessment, and basic change management, but rarely as a final authority on regulatory interpretation.
What is the main risk identified in the use of AI for compliance?
59% point to the audit risk associated with AI 'hallucinations', where the system presents incorrect responses as if they were true legal interpretations.
What safeguards do compliance teams apply before adopting AI?
56% require a review and validation by humans of all results generated by AI before real implementation within the company.
What are the four foundations for trustworthy AI proposed by Vixio?
Vixio proposes verified data, direct citations to the source, mandatory human review, and transparent activity logging as minimum requirements for AI platforms applied to compliance.
Tags
About the author

Miguel Sandoval
Regulatory Affairs Correspondent
Miguel Sandoval tracks gambling legislation, licensing, and regulator enforcement — from Spain's DGOJ and the Latin American authorities to the UKGC, the MGA, and the state-by-state map in North America. The reports answer three questions precisely — what changed, where, and who it affects — with jurisdictions, dates, and penalties cited exactly as published. Operators and compliance officers read Miguel Sandoval to know which rulebook moved before their next meeting.
More from Miguel Sandoval








