As AI embeds itself into every layer of enterprise UC, the firms that will stay ahead of regulators are not the ones slowing down adoption. They are the ones building governance fast enough to keep pace with it.
Meeting summaries, real-time transcription, coaching assistants, automated note-taking: for most organisations running modern UC platforms, these are no longer features you opt into. They are simply on. The compliance question is not whether AI is active in your communications environment. It is whether anyone is watching what it does.
Theta Lake’s latest survey of 500 financial services firms found that 99% are expanding their use of AI capabilities within UC platforms. At the same time, 88% reported governance challenges. That gap is not a coincidence. It is where the real risk lives.
The Problem Is Visibility, Not Intent
The instinct in most governance conversations is to focus on deliberate misuse: the rogue employee, the policy breach, the bad actor. Esteban Lopez, Senior Manager of Product and Technical Marketing at Theta Lake, says that framing misses the point:
“Most organisations that we talk with, especially heavily regulated ones, security and compliance is just built into their DNA. They are not purposefully deploying AI recklessly. They just don’t know what they don’t know.”
Organizations have put guardrails in place. They monitor prompts and responses at the point of interaction. What that approach cannot see is what only becomes visible over time: the patterns of behaviour that no single interaction would reveal. Lopez explains:
“It is the nuance of the question over time. Understanding the behaviour of users and the AI, getting that holistic view of what is actually happening: organisations come to us and say they do not have a tool that allows them to do that.”
Why Legacy Tools Are Not Built For This
Legacy compliance systems were designed for a different world: keyword matching, known policy violations, PII detection. That logic holds up reasonably well for structured, human-generated communications. It breaks down in a world where the risk does not exist in any single message.
Stacey English, Director of Regulatory Intelligence at Theta Lake, explains how that plays out in practice. An advisor using Copilot to look up information on high net worth customers raises no flags. A follow-up prompt narrowing that analysis might still look legitimate. But a thread that ends with prompts identifying single women in a specific geographic area is a different matter entirely. English says:
“The real risk often emerges across a sequence of prompts rather than in a single request. Legacy compliance tools simply were not built to understand that progression of intent or the context surrounding AI interactions.” Read the full article.










