Illustration of a humanoid robot working alongside a human operator in an operational setting, highlighting compliance needs for policy rules, permissions, human oversight, and audit trails.

When AI Joins the First Line, Compliance Must Adapt

Earlier, I wrote about what happens when AI begins to move beyond digital environments and act in the physical world.

That raises another question for Compliance:

What happens to the Three Lines Model when the First Line is no longer entirely human?

The Three Lines Model — which distinguishes management, risk and compliance support, and independent assurance — remains a useful governance framework.

But one of its operating assumptions may begin to change.

Traditionally, many First Line activities have been performed by people: executing procedures, applying controls, identifying exceptions and escalating issues.

As Agentic AI becomes more capable, and humanoid systems increasingly enter operational environments, some of those activities may instead be executed by machines.

This does not mean that AI becomes “accountable” for the First Line.

Management must still retain responsibility for managing risks and achieving organizational objectives. But the way the First Line operates may change significantly and that creates an important challenge for Compliance.

Many compliance programs still rely heavily on human-centered mechanisms: policies, training, supervision, approvals, segregation of duties and monitoring.

But what happens when an AI agent executes part of the process?

The compliance questions may need to evolve.

Not only:

Did the employee follow the policy?

But also:

Was the AI system configured to operate within the policy?

What authority and constraints were built into its operation?

Can the organization reconstruct what happened and intervene when necessary?

This could also reshape the Second and Third Lines.

Compliance may increasingly need to understand how policies are translated into system permissions, machine behaviour, monitoring and escalation.

Internal Audit may need to evaluate whether AI-enabled processes and machine-executed controls operate as intended — and whether management oversight remains effective.

The Three Lines Model may not need to be replaced.

But organizations may need to rethink how each line operates when more business activities are performed through AI agents, autonomous systems and humanoids.

For Boards, Compliance, Risk and Internal Audit, the practical question may therefore be worth asking now:

Which First Line activities in our organization could become machine-executed — and are our controls, escalation mechanisms and accountability structures ready for that change?

The future compliance challenge may not simply be governing how people use AI. It may be governing business processes in which people and machines jointly form the operational First Line.

For a deeper discussion, please watch the full 13-minute episode on YouTube: https://youtu.be/HRWyma1oD9w