AI use case

AI regulatory horizon scanning and obligation mapping

An AI system that continuously reads publications from the regulators and standard setters an organization answers to, classifies each item by relevance and urgency, breaks new rules into individual obligations and maps them to the internal policies and controls that meet them, so compliance owners see what changed and where the gaps are.

By Len Debets · Last verified 27 September 2026 · 2 public deployments

USD 108,000 to USD 432,000
Indicative value per year
A bank monitoring regulatory change across 10 jurisdictions. Worked example, see how it is calculated.

What problem does it solve?

A bank operating in a few countries answers to many regulators and standard setters, each publishing consultations, rules, guidance, speeches and enforcement actions. Compliance teams read feeds and newsletters by hand, decide what is relevant, and then work out which internal policies and controls a new rule touches. The work is repetitive, depends on who is reading, and leaves little audit trail of why an item was judged irrelevant.

The cost of missing something is high: a late implementation, a finding in an examination, or a board that cannot show how it stays current on regulatory change. Answering an examiner or auditor who asks how a rule is met takes a traceable line from each obligation to the policy and control that meets it, and that line is hard to keep up to date by hand.

How does it work?

  1. Collect. The system monitors regulator websites, official journals, standard setters and enforcement publications for every jurisdiction in scope.
  2. Classify. Each item is tagged by jurisdiction, topic, document type, business line and urgency, and irrelevant items are filtered with a recorded reason.
  3. Summarise. Relevant items get a short summary, key dates and what is new compared with the previous version or consultation.
  4. Extract obligations. Final rules are broken into individual obligations in a consistent structure (who must do what, by when).
  5. Map to the library. Each obligation is matched to existing policies and controls through retrieval over the internal obligation and control library, and unmatched or partly matched obligations are flagged as gaps.
  6. Route and record. Items go to the owner of the affected area, who confirms materiality and accepts, changes or rejects each mapping; the decision and reasoning are kept.
Audience
Employee facing
Autonomy
Assist
Adoption
Early adopters
Channels
Internal tools, Email, Microsoft Teams

What is it worth?

Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.

No public deployment has disclosed a measurable outcome yet.

Value drivers: Compliance quality, Employee productivity, Risk and loss reduction.

Indicative value

A bank monitoring regulatory change across 10 jurisdictions

USD 108,000 to USD 432,000

Compliance monitoring effort released per year

How this is calculated

Formula: monitoringFte * efficiency * costPerFte. The low scenario uses every low input, the high scenario every high input.

InputLowHighBasis
Full time staff spent on monitoring and first assessment of regulatory change monitoringFte, full time equivalents612Editorial assumption. Replace with your own team size.
Share of that effort saved efficiency, fraction of effort0.150.2The high end is derived from the only published efficiency figure on this page, a 25% efficiency gain reported by a vendor, in the benefits section of a case study, for the compliance monitoring and compliance risk insight teams of an anonymous European tier 1 bank. A 25% efficiency (output per unit of effort) increase corresponds to about 20% of effort released, so it does not match the source figure directly. Treat it as a ceiling, not a typical result. The low end is an editorial assumption for teams that keep more manual review.
Fully loaded cost per compliance analyst costPerFte, USD per year120,000180,000Editorial assumption.

What it leaves out: Counts analyst effort only. It leaves out licence and content costs, the cost of building and maintaining the obligation library, and the harder to price value of fewer missed changes and a cleaner audit trail for supervisors.

Who already uses it?

2 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.

Administration for Children and Families

United States · Government and public sector · 2025

ProductionGrade B

In March 2025 the Administration for Children and Families, part of the US Department of Health and Human Services, deployed AI to review its existing grants, new grant applications and position descriptions for alignment with HHS Secretarial Directives related to recent executive orders. The AI produces an initial list of documents that may need revision (for grants, with an initial assessment and example passages); program office staff then review, justify and recommend. For position descriptions the agency states that AI was not used to make any final determinations. It is the gap detection half of policy change work: finding which existing documents a new requirement touches.

No outcome disclosed.

Financial Conduct Authority

United Kingdom · Government and public sector · 2017

ProductionGrade C

The UK Financial Conduct Authority worked with Corlytics to turn its Handbook into a searchable, machine readable rulebook. A pilot that started in September 2016 added taxonomy tagging with a four eyes approval workflow. Corlytics then developed with the FCA a machine learning framework for auto tagging and classifying content, which the vendor describes as using a rules based approach, with users able to review, approve or reject tags under a full audit trail. After the pilot, Corlytics delivered taxonomy tagging for the remaining Handbook provisions; it describes the Handbook as over 18,000 provisions. The system went live on 10 May 2017, and according to the vendor it made regulatory obligations much easier to identify. It shows the regulator side of obligation mapping. No outcome figure was published.

No outcome disclosed.

How do you implement it?

A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.

Data you need

  • A list of regulators, jurisdictions and topics in scope
  • A policy and control library with owners, ideally already linked to obligations
  • A taxonomy of business lines, products and risk types
  • Historical regulatory change decisions to test classification against

Systems to integrate

  • Regulatory content feeds or website monitoring
  • Governance, risk and compliance (GRC) platform
  • Policy management system
  • Collaboration tools for routing and sign off

Complexity: Medium

Monitoring and classification are mature, and commercial regulatory content feeds exist. The hard part is a clean internal library of policies and controls to map against, and owners who review the mappings.

  1. 1

    Define scope and relevance

    List jurisdictions, regulators and topics, and write down what makes an item relevant for each business line. That definition is what the classifier is tested against.

  2. 2

    Clean the obligation and control library

    Mapping only works against a library that is current, owned and consistently written. Fix the library before automating the mapping.

  3. 3

    Run in parallel with the manual process

    For a quarter, let the system classify and map alongside the team and compare: what it missed, what it flagged that people missed, and where mappings differ.

  4. 4

    Route to owners with the evidence

    Send each relevant item to the accountable owner with the summary, the proposed mappings and the source, and require a recorded decision.

  5. 5

    Report to management and the board

    Use the recorded decisions to show open changes, gaps and implementation status per regulator and business line.

Guardrails

  • A named owner confirms materiality and accepts or overrides every mapping
  • Every filtered out item keeps its reason, so exclusions can be audited
  • Summaries always link to the official source text
  • Obligations are extracted from final texts, not from secondary commentary

KPIs to instrument

  • Share of relevant items found within a set number of days of publication
  • Items missed by the system but found by people, and the reverse
  • Owner agreement rate with proposed mappings
  • Analyst hours per week on monitoring and first assessment
  • Open gaps and their age

Human in the loop

Compliance owners confirm relevance and materiality, approve obligation mappings and decide on gaps. Legal interprets ambiguous rules. The system proposes; people decide, and their reasoning is retained for supervisors.

Common failure modes

Silent misses
A source changes its website or feed and nothing arrives. Monitor each source's volume and alert when it drops to zero.
Confident but wrong mappings
The system maps an obligation to a control that sounds similar but does not meet it. Require owner sign off and sample accepted mappings.
Summaries treated as the rule
Staff act on a summary that missed a qualification. Always link to and quote the source text.

What are the risks and rules?

EU AI Act

Limited risk (transparency)

An internal tool that monitors and classifies regulatory publications for staff makes no decisions about natural persons, so it is not listed in Annex III and is not a prohibited practice under Article 5. Staff know they are using an AI tool and its summaries are not published to the public, so the Article 50 duties to inform users and to disclose published generated text add little for the deploying organization. Article 50(2) still requires the provider of a system that generates text to mark its output, in a machine readable format, as AI generated: usually the vendor, but an organization that builds its own summariser can itself be that provider, which is what puts this use case at the limited tier rather than minimal. Beyond this and AI literacy (Article 4), no specific obligations apply. General model risk and third party rules still apply.

Guidance

  • MAS Guidelines for Artificial Intelligence Risk Management (Monetary Authority of Singapore, Asia Pacific). Proposed in a consultation paper of 13 November 2025 that closed on 31 January 2026; no final Guidelines were listed on the consultation page when checked on 27 September 2026. The proposed Guidelines will apply to all financial institutions, cover different AI applications and technologies, including generative AI and AI agents, and expect controls proportionate to the assessed risk materiality of each AI use.
  • AI Risk Management Framework (NIST, North America). Voluntary framework to govern, map, measure and manage the risks of AI systems, including generative AI.

Controls to put in place

  • Documented source list with monitoring of each source's availability
  • Decision log of relevance, materiality and mapping decisions with owners and dates
  • Periodic sample review of excluded items and accepted mappings
  • Inventory entry for the tool with its intended use and limitations

Frequently asked questions

Can AI replace a regulatory change team?
No. It removes the reading and first sorting, and proposes obligation mappings, but relevance, materiality and interpretation stay with compliance owners and legal. The value is coverage, speed and an audit trail.
What results have organizations reported?
Published figures are scarce and come from vendors. Corlytics reports a 25% efficiency gain for the compliance monitoring and compliance risk insight teams of an anonymous European tier 1 bank, stated in the benefits section of its case study rather than as a measured outcome. Other deployments on this page, such as the UK FCA Intelligent Handbook, where a machine learning framework developed with Corlytics auto tags Handbook content with review and a full audit trail, and the US Administration for Children and Families review of documents against new directives, describe their benefits in words only.
Is regulatory horizon scanning high risk under the EU AI Act?
No, it is not a high risk Annex III use. It is limited risk: an organization that builds its own summariser can be the provider of a text generating system under Article 50(2), which requires marking its output as AI generated. Treat it as a model with an owner, documented limits and human sign off on every mapping.

How to cite this page

Blits.ai AI Use Case Library, "AI regulatory horizon scanning and obligation mapping", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/regulatory-horizon-scanning. Licensed under CC BY 4.0. Method: how we verify use cases.

Changelog
  • 27 September 2026: First published

Related use cases

Cross industryBanking

AI for policy drafting and policy gap analysis

An assistant that takes a new or changed obligation, finds every internal policy, standard and procedure it touches, flags clauses that now conflict or are silent, and drafts the updated wording in house style as a redline for the policy owner to approve.

Deployments
3 public, best grade B
Autonomy
Copilot
Cross industryBanking

AI for continuous controls testing and control self assessment

AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.

Deployments
3 public, best grade B
Autonomy
Supervised agent
BankingInsurance

AI for regulatory report assembly

AI that assembles periodic and data driven regulatory filings and returns, such as prudential and statistical returns, threshold and transaction reports and disclosure packs, by pulling data into the regulator's schema, validating it, reconciling figures to source, explaining movements against prior periods and drafting commentary, before a named officer reviews and submits. Narratives for individual suspicious activity cases are a separate use case.

Deployments
2 public, best grade B
Autonomy
Copilot
BankingInsurance

AI for supervisory exam and information request responses

An assistant for the bank's regulatory affairs team that reads a supervisory information request or exam question, retrieves the relevant evidence, policies and prior correspondence, drafts a response for legal and compliance to approve, and tracks every commitment and remediation action through to closure.

Deployments
3 public, best grade B
Autonomy
Copilot
Cross industryBanking

AI copilot for marketing content with compliance pre review

A copilot that drafts campaign copy, product explainers and social posts on brand and in the customer's language from approved product facts, then runs a first pass compliance check against advertising rules and required disclosures, flagging unsupported claims and missing warnings before a human in marketing compliance approves publication.

Deployments
3 public, best grade B
Reported productivity gain
34%
Ally Financial, organization claim
Cross industryBanking

AI system and model inventory with shadow AI discovery

A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.

Deployments
4 public, best grade B
Autonomy
Copilot