Soniya Bopache at Arctera argues that as employees use AI platforms to draft, summarise and act on information, compliance teams need to understand where those interactions sit within existing surveillance, retention and investigation frameworks

AI is becoming a significant part of the way organisations work. It’s being used across drafting, research, investigations, communications, search, and everyday productivity workflows. But with 63% of professionals admitting to using AI tools at work without formal approval, it’s also increasingly clear that compliance teams are facing a new surveillance challenge: how to govern the communications, decisions, and records being shaped by AI-assisted tools.
For many firms, the question is no longer whether AI belongs in the business. It is how that use can be supervised consistently. Our research found more than three-quarters (78%) of global organisations using AI tools expect risk to increase over the next 12 to 24 months – with fewer than one in five (19%) having an evidence layer in place to confidently demonstrate what AI produced, who reviewed it, where it went and whether the record was kept.
As AI adoption accelerates, compliance and surveillance teams are not only being asked to govern AI models or assess individual tools. They are being asked to govern the work those tools help create. Doing so means organisations can apply AI with the context, oversight and defensibility needed to innovate responsibly, reduce risk and support critical decisions.
So, let’s explore where the new surveillance problem is emerging exactly.
When people talk about AI governance, they’re often referring to multiple different issues. For some organisations, the focus is on model governance: maintaining inventories, validating systems, testing for bias, and monitoring for model drift.
Whatever’s being focused on, model governance remains essential. AI systems change over time, behaviour can evolve, and outputs may shift in ways that are not immediately visible. For compliance and surveillance teams, however, the operational challenge sits one layer above the model. Day-to-day risk often appears in the work that follows - from emails drafted to reports being summarised using AI.
Supervision therefore has to cover the communications, decisions, investigations, and records that AI helps create, with enough context to explain what happened and why.
As AI becomes part of everyday business processes, firms are increasingly supervising AI-assisted activity across employees, communications, and records.
That raises practical questions for organisations needing to abide by compliance requirements. How should AI-generated communications be supervised? How should AI-assisted business records be retained? How can firms investigate decisions that were influenced by AI? How can they reconstruct what happened months later if AI played a role in the process?
These issues are already appearing in regulated environments. Compliance teams are being asked to maintain evidence, apply policies, and reconstruct decisions months after they were made, even when AI contributed somewhere in the process.
Many organisations still rely on fragmented governance processes designed before AI became part of everyday work.
In many firms, communications sit in one platform, surveillance workflows in another, and investigation records somewhere else. AI interactions may sit outside those traditional governance processes altogether.
Fragmentation creates visibility gaps, operational friction, and avoidable regulatory risk. When information sits across disconnected platforms, teams struggle to reconstruct decisions, connect signals across workflows, or explain how an outcome was reached. Straightforward questions become harder to answer:
What happened? Who reviewed it? What role did AI play? What controls were applied? Could we reproduce the outcome if asked to do so six months from now?
This kind of evidence is essential in showing how AI has influenced work without leaving an obvious footprint in traditional surveillance systems.
Employees may use ChatGPT, Microsoft Copilot, Claude, Gemini, or the next generation of agent-based tools. New platforms will continue to emerge, and the way employees interact with AI will continue to evolve.
Firms need a governance model capable of operating consistently across different platforms, workflows, and business functions. Rebuilding controls for every new tool would leave compliance teams permanently catching up.
The more sustainable approach is to connect communications, retention, surveillance, investigations, and compliance workflows into a unified operational framework. That gives firms a clearer view of work that AI helps to create.
For regulated organisations, AI creates a new layer of context that must be understood. It’s not enough to know that a communication was sent, a decision was made, or an investigation was completed. Firms now need to understand whether AI was involved, how it influenced the process, and what evidence supports the final outcome.
That doesn’t mean every AI interaction should be treated as a risk event. It does, however, mean firms need the visibility to distinguish between routine AI-assisted work and activity that may require review, escalation, or retention.
Surveillance therefore needs to move closer to the way work is actually being done. It must be able to capture the right signals, connect them to the wider governance process, and support investigations when questions arise.
As AI becomes more deeply embedded into business processes, this distinction will become increasingly important. Compliance teams need to know not just what tools are being used, but how AI-assisted work is created, reviewed, retained, and defended.
The surveillance problem AI creates is therefore purely operational, and solving it will be central to the next phase of regulatory readiness.
Soniya Bopache is SVP and GM of Arctera and Enterprise Vault
Main image courtesy of iStockPhoto.com and Sandwish
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543