# AI at Scale in a Regulated World

> White paper · 14 pages · 2026-08-04

Compliance is the floor; orchestration is the control layer that keeps pace with AI as it scales. Why regulated businesses must move from policy-led oversight to continuous, orchestration-led AI governance, and how to build it before regulators demand the evidence.

- **13x** More likely to be scaling AI with orchestration-led governance versus compliance-only approaches (IBM, 2024)
- **12%** Of organisations have orchestration platforms in place: the gap between policy and control is the default, not the exception (IBM, 2024)
- **6x** Greater productivity impact from orchestration-led governance versus compliance-only organisations (IBM, 2024)

## Why it matters

- **Compliance is the floor, not the ceiling** A fully compliant AI policy can still leave live models operating outside it. The policy is a document; the models are systems. In compliance-heavy environments, that gap is a direct exposure to regulatory, legal, and reputational risk.
- **The cost of late governance is measurable** IBM's research is unambiguous: organisations relying on compliance-only approaches are 6 times less likely to see meaningful productivity impact from AI, and they carry substantially higher costs when irregularities occur. Late-stage governance is the most expensive kind.
- **Regulators now expect runtime evidence, not policy documents** EU AI Act fines reach 35 million euros or 7% of global turnover. The FCA, PRA and ICO increasingly expect firms to explain and evidence AI decisions in practice. Firms that wait for formal guidance will build their documentation infrastructure under scrutiny rather than ahead of it.
- **You can build the control layer on your terms, or under scrutiny** There is a structural advantage in building orchestration-led governance before enforcement reaches full maturity. AiRE embeds a working governance prototype inside your existing infrastructure in two weeks, running against real workflows and real data. Act now, while it is a choice.

## Executive summary: the case in 60 seconds

**Artificial intelligence is no longer a side project for regulated businesses.** It is becoming part of core operations, customer service, decision support, compliance workflows, and third-party ecosystems, which means the governance model must evolve as quickly as the technology itself.

IBM's research shows that organisations with orchestration-led governance are 13 times more likely to be scaling AI, and they report 6 times greater productivity impact than organisations relying on compliance-only approaches.

**For compliance-led organisations, the immediate priority is how to govern AI continuously.** That requires moving from policy-led oversight to an operational control layer that connects inventory, identity, risk management, auditability, and enforcement inside the AI estate.

The distinction that matters is between organisations that can govern AI continuously, across the full lifecycle, all systems, and every third-party integration, and those that cannot. The first group is scaling with confidence. The second is accumulating exposure without knowing it.

**Technology is no longer the limiting factor.** The IBM research is unambiguous about the cost: organisations relying on compliance-only approaches are 6 times less likely to see meaningful productivity impact from AI, and they carry substantially higher costs when irregularities occur.

The audience is every General Counsel, Chief Risk Officer, Chief Compliance Officer, and Chief Operating Officer in a regulated business who has signed off on an AI policy without yet asking whether that policy is enforceable in production.

> The first group is scaling with confidence. The second is accumulating exposure without knowing it.

## I. The signal: AI is scaling faster than governance

**The signal is clear.** AI is scaling faster than governance structures designed for slower, more static technologies. The visibility gap this creates is a direct exposure to regulatory, legal, and reputational risk.

**AI is rarely deployed as a single system.** It arrives as a collection of assistants, workflows, models, and vendor tools, often adopted by different teams for different purposes, and often without a common control layer.

The underlying mechanism explains why the gap does not close on its own. Most governance frameworks for technology were designed for static deployments: a system is assessed, approved, and then monitored periodically. AI does not behave that way. Models drift, integrations multiply, and new use cases are added without formal review. Teams build workarounds when sanctioned tools feel slow. The governance surface expands continuously, and point-in-time controls lose their grip almost as soon as they are applied.

Traditional governance runs on a fixed cycle: annual policy review, a spreadsheet-based AI inventory, a quarterly or annual audit, and retrospective remediation that fixes problems after they are found. AI-native governance replaces that cycle with a continuous loop: a living policy framework that updates with regulation, automated discovery through a real-time AI registry, continuous monitoring for drift and compliance, and proactive remediation that fixes exposure before it occurs.

> Point-in-time controls lose their grip almost as soon as they are applied.

- **69%** Executives who lack full AI visibility (IBM, 2024, across 1,000+ senior leaders)

![Traditional point-in-time governance against a continuous, AI-native control loop.](https://baytqnxeuvjwpvnwqpvj.supabase.co/storage/v1/object/public/website-assets/white-papers/ai-at-scale-in-a-regulated-world/page-4-governance-loop.png)

## II. What this means: compliance alone is no longer enough

**Compliance is necessary but no longer sufficient.** It was never designed to be the whole answer. Compliance frameworks define acceptable behaviour. They do not, on their own, enforce it in runtime. An organisation can have a fully compliant AI policy and still have models operating outside the parameters that policy describes, because the policy is a document and the models are live systems. IBM's research draws a precise distinction: organisations with orchestration-led governance do not abandon compliance, they build on top of it. Compliance sets the standard; orchestration ensures the standard is met in practice, at the point of execution, continuously and evidentially.

**Late-stage governance creates the failures it tries to prevent.** A compliance team can be active, well-resourced, genuinely rigorous, and still structurally unable to prevent the problems it is reviewing, because it enters the process after the decisions that matter have already been made. Architecture choices, data pipeline design, third-party integrations: by the time these reach a governance review gate, the practical options for correction are limited and the cost of exercising them is high. The organisations IBM identifies as governance leaders embed controls at the point of design, making compliance an architectural property of the system rather than an assessment applied to it afterwards.

**Visibility is an operational imperative.** When 69% of executives cannot account for the AI their organisations are running, visibility is more than a nice-to-have. It is the prerequisite for everything else. You cannot manage what you cannot see, you cannot audit what you cannot inventory, and you cannot defend a regulatory position you cannot evidence. IBM found that organisations with orchestration-led governance were more than twice as likely to have full visibility into their AI assets. That differential is explained by whether governance was treated as an architecture decision or as a documentation exercise. The same gap extends beyond the organisational boundary: AI arrives through vendor tools, SaaS integrations, partner systems, and outsourced processes, often without a common control layer and subject to different oversight regimes. Orchestration extends the control layer to cover this perimeter, setting enforceable standards for what third-party AI can and cannot do with data that touches the firm's regulatory exposure.

**The accountability gap compounds over time.** AI creates accountability challenges that are structurally different from those created by human decision-making. When a human makes a poor decision, there is a record: a meeting, an email, a sign-off. When an AI system produces an outcome that later attracts regulatory scrutiny, the ability to reconstruct the reasoning, the data inputs, the model version, and the override history depends on whether those things were logged at the time. IBM found that orchestration-led organisations are 169% more likely to maintain transparent documentation of AI processes. The organisations that cannot demonstrate explainability in retrospect are carrying a liability that has not yet been called in.

> The policy is a document and the models are live systems.

## III. The research evidence base: what IBM found

The IBM data tracks outcomes at the organisational level. The regulatory and academic evidence explains the mechanism, and makes clear that the gap between governance intent and governance capability is not a niche concern. It is the central challenge of regulated AI deployment.

**The sample is substantial.** IBM surveyed 1,006 senior executives across 20 geographies and 23 industries, and found a strong and consistent relationship between orchestration maturity and business performance.

Organisations using orchestration-led governance were 13 times more likely to be scaling AI. Those with a full orchestration approach saw more than 6 times the productivity impact of organisations focused on compliance alone. They also experienced 29% lower cost from AI irregularities and 20% higher return on AI investments.

Visibility and documentation were not soft benefits, they were the operational differentiators. Organisations with orchestration-led governance were more than twice as likely to have full visibility into their AI assets, 169% more likely to maintain transparent documentation, and 132% more likely to protect data through anonymisation, impact assessments, and strict access controls.

> Visibility and documentation are not soft benefits, they are the operational differentiators.

- **1,006** Senior executives surveyed across 20 geographies and 23 industries (IBM, 2024)

- **13x** More likely to be scaling AI with orchestration-led governance (IBM, 2024)

- **20%** Higher return on AI investments for orchestration-led organisations (IBM, 2024)

![The IBM evidence: orchestration-led governance against compliance-only approaches.](https://baytqnxeuvjwpvnwqpvj.supabase.co/storage/v1/object/public/website-assets/white-papers/ai-at-scale-in-a-regulated-world/page-6-ibm-evidence.png)

## The supervisory signal: FCA, Bank of England, PRA and Gartner

**The FCA and Bank of England: explainability is a supervisory expectation.** In April 2024, the FCA and the Bank of England jointly published updates on their strategic approach to AI. The practical implication is unambiguous: where AI is being used, firms should expect to need to explain that use to their regulators, covering how risks have been identified, assessed, and managed. This is a current supervisory expectation, applied through existing frameworks including the Consumer Duty, the SM&CR, and the SYSC sourcebook requirements for governance arrangements and systems and controls. The FCA has since launched its AI Lab and AI Live Testing initiative, with the first cohort of firms entering live testing in late 2025. Formal guidance specifically on audit trails and explainability is expected by the end of 2026. Firms that wait for that guidance before building their documentation infrastructure will be building it under scrutiny rather than ahead of it.

**The PRA: model risk governance now covers AI explicitly.** The PRA's Supervisory Statement SS1/23, effective from May 2024, established that model risk management applies across all model types, including AI and machine learning systems. It requires firms to maintain comprehensive model inventories, conduct independent validation, and implement continuous performance monitoring. The PRA has been explicit that existing frameworks need to be extended, not merely reinterpreted, to cover the specific characteristics of AI: iterative development cycles, opaque decision logic, and continuous drift. In October 2025, the PRA held dedicated CRO roundtables with 21 regulated firms specifically on AI and machine learning in the context of SS1/23, a clear signal that supervisory attention is intensifying, not plateauing.

**Gartner: the monitoring gap is structural.** A Gartner survey of 360 organisations in Q2 2025 found that organisations deploying AI governance platforms are 3.4 times more likely to achieve high effectiveness in AI governance than those that do not. Yet Gartner also projects that only 40% of organisations deploying AI will have dedicated observability tools in place by 2028, meaning the majority are currently operating AI systems without the continuous monitoring capability that effective governance requires. Gartner has identified this as a compounding risk: without standardised model telemetry and runtime monitoring, incident resolution for AI applications requires complex manual effort to trace and debug the behaviour of opaque models.

> Firms that wait for guidance to arrive will be building their documentation infrastructure under scrutiny rather than ahead of it.

- **3.4x** More likely to achieve high effectiveness in AI governance with a governance platform (Gartner, Q2 2025)

- **40%** Of organisations projected to have dedicated AI observability tools by 2028 (Gartner)

## IV. The eight questions boards must now ask

Strategic leadership in a regulated AI environment is about asking questions that reveal whether governance is real or performative. These are the eight questions that boards and executive committees in regulated businesses should be pressing today.

**1. Can we produce a complete inventory of every AI system active in our business, including third-party integrations, right now?** If the answer requires more than 48 hours to compile, the inventory does not exist in any operationally meaningful sense. You cannot govern what you cannot see, and you cannot defend regulatory exposure you have not mapped.

**2. Do our AI controls operate in real time, or at the point of review?** Policy-based governance is periodic. Orchestration-led governance is continuous. The question is whether your controls shape AI behaviour as it happens, or whether they describe the behaviour you would have preferred after the fact.

**3. Who owns accountability when an AI system produces an outcome that attracts regulatory scrutiny?** In many organisations, AI accountability sits between functions: nominally owned by technology, operationally driven by business lines, and reviewed by legal and compliance only when something goes wrong. That disconnect is a governance failure waiting to be triggered.

**4. Can we reconstruct the reasoning behind any AI-assisted decision made in the last twelve months?** Explainability is not just a technical property of a model. It is a documentation discipline. Regulators in the UK and EU are increasingly treating the ability to explain AI decisions as a minimum standard. Can you meet it today?

**5. What proportion of AI in our business was procured through formal channels, with documented risk assessment?** Shadow AI is already present in most regulated businesses. IBM's research suggests that in many organisations, significant AI usage is unsanctioned. Every unsanctioned AI system that touches client data, financial models, or regulated processes is an unmanaged exposure.

**6. How does our governance framework extend to the AI used by our key suppliers and outsourcing partners?** Your regulatory obligations do not stop at your firewall. If a supplier's AI system processes your clients' data or supports a regulated activity, the accountability sits with you. Do your third-party governance frameworks reflect that?

**7. Are our legal, risk, compliance, technology, and business functions aligned on what AI can and cannot do, and is that alignment documented?** Governance by consensus is not governance. Alignment means defined decision rights, clear escalation paths, and documented approval criteria. A shared sense that we are roughly on the same page is not sufficient.

**8. Is AI governance embedded in our delivery process, or does it arrive at the end as a review gate?** Late-stage governance is the most expensive kind. It catches problems after architecture decisions have been made, after data pipelines have been designed, and after commercial commitments have been entered into. The organisations that govern AI well build the controls from the start.

> You cannot govern what you cannot see, and you cannot defend regulatory exposure you have not mapped.

![The eight questions that reveal whether governance is real or performative.](https://baytqnxeuvjwpvnwqpvj.supabase.co/storage/v1/object/public/website-assets/white-papers/ai-at-scale-in-a-regulated-world/page-8-board-questions.png)

## V. The regulatory imperative

**The regulatory framework has hardened.** For years, AI governance in regulated industries operated in a soft-law environment: guidance, principles, expectations. The EU AI Act, the most comprehensive AI regulatory framework in the world, is now in phased enforcement. The prohibitions on unacceptable-risk AI applications came into force in February 2025. Obligations for high-risk AI systems, including those used in credit, insurance, employment, and critical infrastructure, are active and expanding. For organisations operating in or serving European markets, the stakes are explicit: fines for non-compliance can reach 35 million euros or 7% of global annual turnover, whichever is higher. That is a boardroom-level commercial risk.

**The UK approach is principles-based but not permissive.** The UK has chosen a different regulatory architecture: sector-led, principles-based, and coordinated through the AI Safety Institute and existing regulators rather than through a single AI-specific statute. Principles-based does not mean low-accountability. It means the accountability is on the organisation to demonstrate how its AI systems deliver the outcomes regulators require. The FCA has been explicit that AI used in regulated activities must meet the same standards of fairness, transparency, and explainability as human decisions. The PRA has identified model risk as a primary supervisory concern for AI in financial services. The ICO has issued detailed guidance on lawful AI and personal data, and is actively examining compliance. For UK regulated businesses, whether the organisation can evidence compliance in the way each regulator's framework demands is the non-negotiable, and that increasingly means runtime evidence, not policy documentation.

**There is a window for proactive governance.** A structural advantage is available to organisations that build orchestration-led governance now, before regulatory enforcement reaches full maturity. Those organisations will arrive at supervisory review with audit trails, documented decision rights, and demonstrable controls already in place. Those that wait will be building governance infrastructure under scrutiny, at higher cost, and with less room for the iterations that operational governance always requires. The firms that define what good looks like will shape the standards the rest of the sector is measured against. It is the documented pattern of every regulatory maturation cycle in financial services: the early movers write the playbook, and the late movers follow it. Or fail to.

> The early movers write the playbook, and the late movers follow it. Or fail to.

- **35m euros / 7%** Maximum EU AI Act fine: 35 million euros or 7% of global annual turnover, whichever is higher

- **29%** Lower cost from AI irregularities for orchestration-led organisations (IBM, 2024)

## VI. The execution gap and the AiRE response

The execution gap is where most organisations struggle. Many businesses have written policies, review boards, and approval gates, but those measures do not automatically create control at scale. IBM's research suggests that only 12% of organisations currently have orchestration platforms in place, which helps explain why AI governance remains disconnected from actual system behaviour.

In compliance-led businesses, the most common failure is late-stage governance that tries to correct design decisions after systems have already been built and deployed.

**Generic AI platforms do not solve this.** Microsoft Copilot and equivalent tools were not built for the domain specificity, regulatory context, and adoption inertia that define knowledge-intensive regulated businesses. The value in a law firm, a private equity fund, or a financial services firm sits in the firm's own criteria, formats, and decision logic. The compliance teams in these organisations are sceptical, time-poor, and will not adopt tools that create new governance problems while claiming to solve old ones. The gap between 'we have AI tools' and 'our AI is governable' is exactly the divide AiRE was built to close.

**AiRE, the AI Rollout Engine, embeds alongside compliance, technology, and operations teams** to design, prototype, and deploy orchestration-led AI governance inside the organisation's existing infrastructure, with domain expertise, regulatory context, and adoption as the primary success metric. The use cases are drawn from the compliance and regulated-services environment specifically:

- **AI asset inventory and classification.** Current state: no single source of truth, inventory compiled manually and quarterly from departmental self-reporting, with significant shadow AI undetected. AiRE outcome: automated discovery and classification across the estate, continuously updated, with full visibility into systems, data flows, and control status in real time.
- **Regulatory obligation mapping.** Current state: legal and compliance teams manually track regulatory updates across multiple frameworks, and cross-referencing obligations takes weeks per cycle. AiRE outcome: obligation mapping automated against the AI asset inventory, with gaps between requirements and current controls surfaced automatically and prioritised remediation paths.
- **Audit trail and explainability logging.** Current state: AI-assisted decisions logged inconsistently or not at all, and reconstructing decision rationale requires manual forensic work across multiple systems. AiRE outcome: a structured audit trail generated at the point of execution for every AI-assisted decision, with explainability documentation produced automatically and stored in a retrievable, regulator-ready format.
- **Third-party AI risk monitoring.** Current state: supplier AI governance reviewed only at contract renewal or incident trigger, with no continuous visibility into third-party AI touching the firm's regulated perimeter. AiRE outcome: continuous monitoring of third-party AI activity against defined governance parameters, with anomalies and policy breaches flagged in real time and escalation paths pre-configured.

Critically, each capability is delivered with change management and adoption built in, because the most technically sound governance architecture fails if the people responsible for operating it do not understand or trust it. QuantSpark embeds a working prototype inside your existing infrastructure in two weeks. Not a proof of concept. Not a pilot in a sandbox. A functioning governance capability running against real workflows, with real data, inside your own environment, generating the evidence trail your regulators will eventually ask to see.

> A functioning governance capability running against real workflows, with real data, inside your own environment.

- **12%** Of organisations currently have orchestration platforms in place (IBM, 2024)

- **2 weeks** To embed a working AiRE governance prototype in existing infrastructure

## VII. A framework for action

**Phase 01: Map the estate before you govern it.** You cannot govern AI you cannot see. The first step is a complete inventory: every system in use, every data flow it touches, every third party with access, and every use case, whether formally approved or not. Most organisations discover significantly more AI in active use than their governance frameworks account for. That discovery is uncomfortable. It is also the only honest starting point.

**Phase 02: Redesign governance into the architecture, not onto it.** The most expensive governance failure is late-stage governance: controls added after systems have been built, pipelines have been committed, and commercial obligations have been entered into. Governance designed into the architecture from the start is both more effective and substantially cheaper. The question to ask at every design review is not 'does this comply?' but 'how does compliance get enforced at runtime?'

**Phase 03: Build the orchestration layer.** Orchestration is the operational translation of governance policy into system behaviour. It connects model access, data permissions, approval workflows, override logging, and audit trails into one managed environment. Deployed inside the organisation's own infrastructure, not as an external SaaS layer, orchestration gives compliance teams continuous visibility and control without creating new data sovereignty risks.

**Phase 04: Extend governance to the ecosystem.** Internal AI is the part you control. Third-party AI is the part most likely to produce a regulatory event you did not anticipate. Phase four extends the orchestration layer to the supplier and partner ecosystem, defining what third-party AI can and cannot do with data that touches the firm's regulated perimeter, and building the monitoring infrastructure to enforce it.

**Phase 05: Train for governance fluency, not just tool adoption.** Governance architecture is only as effective as the people operating it. Legal, risk, compliance, technology, and business teams need shared fluency in what the controls do, how to use them, and when to escalate. The difference between governance on paper and governance in practice is almost always a training gap, not a technology gap.

**Phase 06: Monitor continuously and improve systematically.** Governance is not a project with a completion date. Models drift, integrations change, regulatory obligations evolve, and new use cases are added continuously. Phase six establishes the feedback loop: regular monitoring against defined governance metrics, systematic identification of drift and exceptions, and a structured process for updating controls as the AI estate changes.

> The question to ask at every design review is not 'does this comply?' but 'how does compliance get enforced at runtime?'

![The six-phase framework for building orchestration-led AI governance.](https://baytqnxeuvjwpvnwqpvj.supabase.co/storage/v1/object/public/website-assets/white-papers/ai-at-scale-in-a-regulated-world/page-11-framework.png)

## Conclusion: govern AI as an operating model, not a capability

**The organisations that govern AI well do not treat governance as a capability.** That reframe matters because it changes what gets built and when. Compliance as a checklist produces controls that sit outside the system. Orchestration as an operating model produces controls that are the system: embedded in the architecture, running continuously, and generating the evidence trail that allows the organisation to move faster, not slower, because its AI is demonstrably trustworthy.

The regulatory environment will continue to harden. The EU AI Act's obligations are expanding, UK regulators are sharpening their supervisory expectations, and the organisations already operating with orchestration-led governance are pulling further ahead. Not just in their ability to demonstrate compliance, but in their ability to deploy AI at scale in the first place.

The question for every compliance, risk, and technology leader is whether to act now, while the control architecture can be built on your terms, or later, when it must be built under scrutiny. Not acting is out of the question.

In a regulated world, the businesses that win will prove their AI is both effective and governable.

> The businesses that win will prove their AI is both effective and governable.

---

Canonical page: https://quantspark.ai/resources/white-papers/ai-at-scale-in-a-regulated-world
More about QuantSpark: https://quantspark.ai/llms.txt
