{
  "id": 10665652,
  "title": "The regulatory readiness problem hiding in plain sight",
  "url": "https://urgent.news/2026/09/29/the-regulatory-readiness-problem-hiding-in-plain-sight",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-29T09:52:42.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/the-regulatory-readiness-problem-hiding-in-plain-sight"
  },
  "original_language": "en",
  "account": "The EU AI Act's upcoming transparency demands are pushing businesses to prioritize regulatory preparedness, as fines of up to €35 million or 7% of global turnover underscore the gravity of compliance. To satisfy regulators, firms must not only detect AI-related risks but also exhibit how these risks were identified, reviewed, and escalated. However, many organizations struggle with this challenge, often due to fragmented evidence that is scattered across disparate platforms and workflows. This makes it difficult to present a coherent, defensible narrative when regulators inquire. Surveillance activities, while still relevant, are no longer sufficient. Compliance teams now need to demonstrate that surveillance activity correlates with supervisory outcomes, providing a detailed account of why a risk was identified, how an alert was reviewed, what evidence supported a decision, and whether escalation was justified. The lack of a unified evidence chain is a significant hurdle, particularly as AI-driven communications pose an increasing compliance risk. Despite the majority of organizations having AI policies and training in place, fewer than one in five has the necessary logging, retention, detection, and scoring controls to substantiate what happened. This creates inefficiencies and delays, as investigations become more complex and evidence collection becomes laborious. Regulators are increasingly expecting firms to demonstrate not just the existence of controls but how those controls function during risk scenarios. To address this, organizations are moving from a mere monitoring function to a comprehensive governance approach encompassing communications governance, surveillance, investigations, and retention. The key is operational visibility, which, combined with effective communication surveillance, aids in risk identification, efficient issue resolution, and the creation of a defensible evidence framework. Ultimately, readiness is about being able to prove what happened, not merely locating the information.",
  "summary": "Organizations must connect AI risk, review and evidence to demonstrate effective regulatory oversight.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}