Why ‘confidently wrong’ AI is compliance’s biggest threat

AI compliance

The question sharp compliance leads ask about Karavel is rarely about features. Instead, it cuts deeper: how do they know the AI will not fabricate an answer and deliver it with total conviction? According to the RegTech firm, it is precisely the right thing to worry about.

Karavel’s founder built a career in environments where errors carry real cost, spanning credit reporting at ClearScore and payments and logistics at Deliveroo. That experience instilled a core discipline: never trust an output that cannot explain itself. In compliance, the costly failure is not a system that admits uncertainty, but one that is sure, sounds right, and is wrong.

In most software, a confidently wrong answer generates a support ticket. In compliance, it manufactures the very exposure regulators fine firms for. The asymmetry matters too. Wrongly flagging a compliant ad wastes a reviewer’s minutes, but passing a non-compliant one can trigger a breach. An honest tool, Karavel argues, must treat these as fundamentally different problems.

The firm is blunt about the underlying technology. Language models are trained to produce fluent, plausible text rather than correct answers, and they lack any inbuilt sense of when they do not know. The industry calls this hallucination, with measured rates ranging from low single figures to a quarter of answers or worse on some finance questions.

The warning signs are well documented: a New York lawyer was sanctioned in 2023 after filing a brief built on invented cases, while Stanford research found leading legal-research tools, marketed as hallucination-free, still erred between one in six and one in three of the time.

Regulators are now naming the risk directly. FINRA’s 2026 oversight report lists AI hallucination as a standalone compliance risk, while the EU AI Act places much of financial-services AI in its high-risk tier, demanding meaningful human oversight, demonstrable accuracy and reconstructable logs.

The FCA, meanwhile, has confirmed existing rules such as Consumer Duty apply to AI, with Parliament asking it to clarify senior-manager accountability by the end of 2026. The ASA is scaling enforcement too, now scanning tens of millions of ads a year.

Karavel’s response is architectural. Assets are read in context, broken into individual claims and checked against the relevant rulebook, with the model required to cite the rule behind every finding. Internal brand guidelines and pre-approved claims are checked in the same pass. Crucially, a named human reviewer always makes the final decision, with the system’s verdict serving only as a recommendation.

The audit trail, the firm insists, is the actual product. When a regulator or board asks on what basis an ad was approved, “the AI said so” is not a defensible answer. What holds is the full chain of claims, rules, sign-offs and revisions. Karavel’s conclusion is deliberately unflashy: the correct product is fast where speed is safe, rigorous where rigour is required, and always able to answer “says who”.

Read the full Karavel post here.

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.