A Compliance Officer's AI Action Plan: From Debate to Deployment
Host Nick Gallo, Chief Servant & Co-CEO of Ethico, sat down with Hayley Tozeski, Senior Counsel, Ethics & Compliance at Cisco, to move the AI conversation from debate to deployment. This recap covers every major theme: why the hype is finally reality, treating AI as a sparring partner rather than a replacement, building quality-check guardrails into every prompt, running new tools in parallel before flipping the switch, cutting through vendor marketing, use-case-level governance and documentation, accountability and the 'work slop is your slop' rule, and what a defensible AI-enabled program looks like to a regulator.
Download Ethico's 2026 Benchmark Report
Latest data on case closure, substantiation rates, issue types, and more...
Joah Park
Lead Producer for The Ethicsverse

For the past few years, most ethics and compliance teams have been standing at the edge of the pool, debating whether the water is safe. The genie is out of the bottle, and the real question is no longer whether to use AI but how to leverage it responsibly. In this Ethicsverse session, host Nick Gallo, Chief Servant and Co-CEO of Ethico, framed the hour as a move from debate to deployment: a compliance officer's practical action plan.
His guest was Hayley Tozeski, Senior Counsel, Ethics and Compliance at Cisco, who has stood up compliance programs across five continents. Rather than stay at the altitude of theory, the conversation went deliberately tactical, walking through where AI is genuinely earning its place, the guardrails that keep it honest, how to evaluate vendors, and how to govern and defend AI use cases when regulators come knocking. What follows are the key takeaways.
Key Takeaways
The Hype Has Finally Become Reality
Hayley's assessment: the hype is here, now, and actually coming into fruition. Efforts from three years ago to integrate AI for monitoring and analytics were often frustrating, producing false positives that created more noise than insight. That has changed. She has seen a massive reduction in noise and a massive improvement in the quality of insights, delivered at a scale humans simply cannot match.
The improvement has not been linear but closer to parabolic. Many practitioners are still stuck in the first inning, anchored to early horror stories like the lawyer who filed a brief full of fabricated cases. Nick and Hayley encouraged the audience to recognize that the game has moved on.
The reframe that matters: AI is not going to put people out of a job, but the job is going to change. Insisting on doing the work the old way is like insisting on staying paper-based when email and the internet arrived. It is a new skill to build, not a replacement to fear. Getting a hammer is not an existential risk to the carpenter.
Treat AI as a Sparring Partner, Not a Replacement
Hayley's signature frame: AI is a sparring partner. She is not comfortable using agentic AI to replace a human in the loop, so she keeps a human at every step. But as a partner for digesting information intake across compliance processes such as conflicts of interest, gifts and entertainment disclosures, sponsorship approvals, and third-party due diligence, she now considers it indispensable.
We all become managers and leaders on day one of our AI counterparty, and we remain responsible for every piece of output it produces. Think of it like an intern: the control is you.
What if your sparring partner is wrong? So are the friends and colleagues you rely on. Sometimes it is a genuine error and sometimes it is a difference of opinion. The answer is to keep training it, keep giving feedback, feed your corrections back in, and review every output with a skeptical eye, exactly as you would when overseeing anyone else's work.
Where to Start: Busy Work and Employee Engagement
The easiest place to begin is the busy work that crowds out higher-value effort. On the Eisenhower matrix, AI creates leverage to spend more time in the important-but-not-urgent quadrant where real effectiveness lives.
The impact is not headcount reduction, it is greater effectiveness, doing more with the same team and finally reaching the strategic work that always got crowded out.
Employee engagement is a standout early use case. AI can tailor communications and training at scale to different audiences, cultures, geographies, and learning styles, meeting factory-floor colleagues differently from those behind desks.
Start with one narrow, real pain point. Once you get a foot in the door and grow comfortable, your mind opens to possibilities you had not previously considered.
Build Quality-Check Guardrails Into Every Prompt
Hayley includes a standard set of quality checks in every prompt and requires them in every output:
Tell me every assumption you made that may not be accurate, and the basis for it, so I can validate it.
Give me sources and citations, and point me to every resource used to derive the output.
Tell me if a reasonable person might disagree with you and why, so the output gets stress-tested and she becomes the third person in the room rather than falling into groupthink.
These parameters cut off hallucinations and misunderstandings from the start and give a fast way to sense-check results.
Practically, keep a living AI prompt library. Some platforms retain history, but at a minimum keep one place where reusable prompt chunks live so you never reinvent the wheel. Talking to the model out loud can be the fastest way to build, and you can ask the model to turn a brain dump into a clean, reusable prompt.
Make AI a Team Sport and Systematize the Learning
Crowdsource internally. When everyone experiments in their own sandbox without sharing, teams waste effort and approach the same problems inconsistently. Centralize prompt libraries and make them available to everyone who should have them.
Systematize knowledge transfer or it falls by the wayside. Hayley runs a 15-minute monthly one-on-one with each team member focused purely on their AI learning and use case, plus a monthly full-team round robin where everyone demonstrates what they built.
Beyond the efficiency gains, this feeds a strategic need: people stay engaged when they are learning and growing, and AI injects novelty into work that had started to feel like a hamster wheel.
AI also removes external dependencies. Work that once waited on an IT timeline or scarce data-engineering resources such as cleaning data or building analytics can increasingly be unlocked by the compliance team itself.
Cut Through the Marketing With an Experimental Mindset
Vendors and frontier-model marketing teams are incentivized to hype capabilities and downplay risks. Bring a critical lens to claims like "AI catches what humans miss."
Make it a team sport across the industry. Talk to trusted colleagues and vendors in your network to learn how they actually use AI, rather than relying on net-new players you have no reason to trust yet.
Adopt an experimental mindset and run in parallel. Do not decommission your existing solution and flip the switch. Run the AI approach alongside your current monitoring of AP data, procurement-to-pay, high-risk deals, and discounts, then compare the outcomes and the costs. AI is not cheap; some use cases are clearly worth it and others are not. Interrogate the results before moving away from what you have.
The Two Questions to Ask Any Vendor
Why? Understand why the tool catches more, because the claim rests on assumptions about data quality, system access, or integrations that you need to see.
What investment will I need to make to get those benefits? This is where expectations and reality most often diverge. There is a monumental upfront investment in human time to validate outputs and teach the model, and the frustration people feel usually traces back to underinvesting in exactly that.
Understanding how the sausage is made helps you judge whether a marketing or sales claim will hold up in your own organization.
Govern at the Use-Case Level and Document Relentlessly
In the current regulatory gray zone, treat AI like any other risk: apply a risk-based approach anchored on downstream human impact, taking a steer from the limited legislation and voluntary standards that courts and insurers already look to. Where impacts on people could be dispositive, governance needs to look different.
Engineers love to build, but no one loves to maintain or document. If a regulator comes knocking, the first document Hayley would want is not the global corporate AI policy but the AI policy for the specific use case that went wrong, covering what was built, why, the guardrails, how it is governed, who is responsible, and how it is operationalized.
Rather than spinning up use cases like whack-a-mole, get one solid use case fully documented end to end, then move on as part of a deliberate roadmap. Governance should nest like concentric circles: individual use, team use, department use, and enterprise use.
To make micro-governance a consistent best practice, start with your most adjacent organization such as legal ops, and learn from what already exists so you do not diverge from how the company approaches these tools. If it is blank space, ask your AI sparring partner to help build the initial checklist and template, then validate it with industry peers.
Accountability: Work Slop Is Your Slop
Accountability is not complicated. If you let AI be dispositive, you are accountable. If you were the human in the loop and still got it wrong, you are accountable. AI is a tool, not an outcome, and this is no different from any other employee decision.
As Nick put it, "work slop is your slop." If a team of interns built the slide deck that went up to leadership, it is still your slide deck. Hayley's analogy is plagiarism: you would not cut and paste someone else's work and pass it off, and AI output is no different.
To keep a human reviewer from becoming the scapegoat for a system they could not realistically catch, build a sufficiently robust monitoring and validation process so you can be confident in the AI the same way you validated non-AI controls, and be transparent that AI is not perfect. Secure buy-in at the right levels that this is the risk the organization is willing to accept, with a cost-benefit analysis in the remediation plan, because you can control your way out of almost any risk but also control the business out of operating.
Design for monitoring from day one. Just as a good program designs policy, process, and validation together, the holistic approach is even more important with AI. You must know at the outset how you will validate, monitor, and test, and have the resources to do it before you launch. As Nick said, you have to put the plumbing in while you build the house, not after.
What a Defensible AI-Enabled Program Looks Like
AI is a democratizer of information and data. The old argument that certain parts of the company could reasonably lack visibility into risk is going by the wayside. If you have significant third-party channel risk and your compliance team still cannot see it while you blame data quality or an in-progress M&A integration, that is where regulators will be most frustrated.
Failing to operate standard parts of a program because of resource constraints, while not using AI to make the best of the resources you do have, invites fair criticism. "These are the bare basics we had" will not pass the smell test for long.
The standard remains reasonableness and good faith. Regulators understand resource scarcity across every industry, and governments are among the most resource-constrained organizations there are. Defensibility comes from demonstrating a genuine, good-faith effort to curtail foreseeable risks given your constraints, and from solving for that defensibility up front.
A scalable extra control: create a saved prompt or chat that acts as an adversarial agent, taking a fresh look at your output and picking it apart before it leaves the room.
The One Thing to Resolve Before Deploying
Asked for the single thing to resolve before deploying AI in a compliance function, Hayley was unequivocal: make sure you know exactly who needs to sign off on new use cases within ethics and compliance.
Closing Thoughts
The throughline of the session was liberating in its simplicity. AI is not a different discipline; it is a new tool that the same skill set which got compliance professionals this far can govern. Treat it as a sparring partner, build guardrails into every prompt, run it in parallel before you trust it, document governance at the use-case level, and own the output the way you own everything else with your name on it. The separation in the years ahead, Nick argued, will not be between the haves and have-nots but between those willing to exercise agency with this new technology and those holding on to the old way. You do not have to jump into the deep end, but it is time to at least put your feet in the water.
Enjoyed this article?
Subscribe to our newsletter for more insights on ethics and compliance.
View All Articles