In a new episode of the Beyond Tomorrow podcast, in which Mattias Anderson speaks with innovator David Buresund from Regnora, it becomes clear that the central question is no longer whether AI will change compliance, but rather how quickly this development is progressing and which players will lead it.
This article is for those of you who already know your industry well—who rely on regulations, risk assessments, and established work practices every day—but who also want to look beyond the horizon.
What does AI mean for compliance in a world where risks must not increase but the pace must? How can we embrace this technology without losing our footing in the regulatory landscape? And how can we, as experts, create more strategic value now that repetitive tasks no longer stand in our way?
AI is fundamentally changing the way compliance work is carried out
One of the clearest takeaways from the discussion is how the field has evolved. Just a year ago, AI in compliance was mostly about generating individual documents or tests within limited processes. Today, we have AI agents that can reason, use tools, and integrate into workflows.
As a result, compliance experts no longer need to view AI as a risky experiment, but rather as a concrete approach to their work. As David puts it, “Compliance in five years will be about experts orchestrating armies of AI agents and ensuring the quality of the output.”
This is a significant shift. AI does not replace specialists. AI makes specialists faster, more accurate, and less burdened by the tasks that previously took time away from strategic decision-making.
Complex issues require specialized solutions
A common concern for an AI startup is competition from global tech giants with enormous resources. But according to David, that’s not where the battle lies. The big players build the infrastructure. They create the models that the rest of the world builds upon.
It is the niche players who solve the real problems. Life sciences is a clear example. The industry involves complex processes, large volumes of documentation, and strict regulatory requirements. General solutions are not enough here. What is needed here is domain expertise and specific features.
That is why specialized tools such as AI-driven gap analyses, automatic updates to management systems, and AI-assisted risk analyses will become cornerstones of the industry’s digital development. It is in this niche that innovation arises.
Why Compliance Risks Becoming a Bottleneck
At the same time, there is a fundamental problem that many organizations struggle with. Compliance is perceived as burdensome, administrative, and document-intensive.
Many people are overwhelmed by paperwork instead of working in a risk-based and value-adding way. They are forced to spend hours updating, mapping, and quality-assuring tasks that AI already handles better and faster.
This is where AI makes the biggest immediate difference—not by replacing people, but by freeing up time, allowing experts to focus on tasks that truly require human experience and judgment.
"Man in the Loop" Is Here to Stay
The AI Act, Annex 22, and other upcoming regulations all point in the same direction: AI must not be autonomous in critical processes. A human must be involved and bear ultimate responsibility. This is entirely in line with how new AI tools are designed. The goal is not to replace experts. The goal is to provide them with better conditions.
Success does not lie in automation itself, but in how its quality is ensured. This requires a clear intended use, structured validation, testable scenarios, and transparency regarding how AI arrived at its results.
David describes AI as “a skilled but sometimes a little dim-witted colleague” who needs guidelines to function. It’s a spot-on description. AI excels when the work is difficult to perform but easy to monitor.
Building trust is crucial
Perhaps the biggest challenge for new AI solutions in the life sciences is trust—not just that the tools work technically, but that they comply with regulatory requirements.
Validation has therefore become one of the most critical issues. Companies must demonstrate that AI behaves predictably in its intended use, even if the models are non-deterministic.
Validation of AI in compliance largely follows the same principles as for other computerized systems. It involves a clearly defined intended use, structured risk assessments, traceability, and robust documentation, which account for the vast majority of the work.
The AI component itself is relatively small, since the models are generally pre-trained and provided by external parties such as OpenAI, Google, or Anthropic. Instead, the focus is on creating controlled workflows around the model and ensuring that it performs in a way that experts can evaluate and trust. Through test data, defined scenarios, and clear acceptance criteria, the AI’s responses under various conditions are evaluated so that the results can be used safely and consistently in regulatory work.
How to Really Get Started
Despite all the challenges, the enthusiasm is palpable. There’s no doubt that the industry is at a critical juncture. As David puts it: “There’s no set formula, but that’s also what makes it so much fun.”
For organizations facing the decision to start using AI in compliance, the advice is simple: take a structured approach and proceed in small steps.
Start by defining a clear use case and a specific problem to solve. Then, begin on a small scale by automating a limited part of the process. It is also important to ensure access to relevant data, assess the level of risk, and determine whether the solution needs to be validated.
Perhaps most important of all is to make the application user-friendly and ensure that it fits into existing workflows. Finally, a pragmatic mindset is required—one that involves trying things out, testing them, and learning through practical use.
What should we bring?
There are three key takeaways that summarize the podcast's message:
1. AI in compliance is primarily about freeing up time, not replacing people.
2. Specialized solutions will be the drivers of real progress in the industry.
3. Human expertise and quality assurance are crucial even when AI performs the majority of the work.
AI is not a risk to be avoided, but a tool that is already transforming the work lives of compliance experts. The question is not whether we should use it, but how wisely and how soon.
Want to learn more? You can listen to the entire episode here.
How can we help you?
Do you need advice or support in this or a related area? Book a free one-hour consultation with one of our experts, and we’ll help you get started.