Categories
AI Today in 5

AI Today in 5: August 24, 2026, The AI Phobia Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. On the evolution of voice-to-text AI. (NYT)
  2. Nvidia to build an alternative to Chinese AI models. (WSJ)
  3. OpenAI slow development in light of the Hugging Face hack. (Reuters)
  4. AI phobia in America. (FT)
  5. Is an AI slowdown finally coming? (Bloomberg)

For more information on using AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Daily Compliance News

Daily Compliance News: August 24, 2026, The Racing into Venezuela Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • AI for email compliance. (NJIT News)
  • TikTok settles for $400MM. (Reuters)
  • New GRC products. (CCI)
  • Racing to get into Venezuela. (WSJ)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
FCPA Compliance Report

FCPA Compliance Report: Charisma Doesn’t Scale, Controls Do: Notebook LM on Compliance Lessons from Ted Lasso

In this episode, I take things in a very different direction. Last week I did a 5-part blog post series on leadership lessons from the hit TV show Ted Lasso. I took those 5 blog posts and fed them into Notebook LM. What came out, in the AI voices of Timothy and Fiona, is what I posted for this podcast.

Timothy and Fiona use Ted Lasso characters as operational profiles to show why empathetic leadership and “good vibes” are insufficient under compliance frameworks like the DOJ ECCP, COSO, and the Caremark Doctrine. Some of the analysis includes:

  • Ted Lasso creates psychological safety but introduces key-person risk by relying on an open-door culture without institutional “listen-up” systems, case logging, escalation, and anti-retaliation protections; his immediate forgiveness of Rebecca’s sabotage illustrates why mercy cannot replace investigation, evidence preservation, root-cause analysis, and remediation.
  • Rebecca Welton exemplifies corrupted tone at the top and conflicts of interest, including her relationship with Sam, before shifting toward accountable governance by rejecting unethical commercial moves and selling 49% to fans.
  • Keeley Jones highlights governance debt from rapid scaling, affinity hiring, and investor conflicts, leading to incident-response and third-party concentration failures.
  • Roy Kent demonstrates “tone in the middle,” accountability, and root-cause diagnosis, but also risks of unchecked informal authority.
  • Nate Shelley shows the danger of promoting technical skill without evaluating leadership ethics, enabling “relocating harm,” data silos, and a major confidentiality leak—reinforcing that auditable controls, oversight, and monitoring must outlast charisma.

I would really like to hear your thoughts on this podcast and the approach I have taken. I would greatly appreciate it if you left a comment or emailed me your reaction to both my use of Notebook LM for this analysis and the AI-generated voices for Timothy and Fiona.

 

Blog Posts on the following Ted Lasso characters:

Ted Lasso

Rebecca Welton

Nate Shelley

Roy Kent

Keeley Jones

Other Takes on Ted Lasso

Tom and Matt Kelly on Ted Lasso in Compliance into the Weeds

Matt Kelly in Radical Compliance

Categories
Blog

From Policy to Proof: Six Compliance Priorities for the Next 90 Days

Editor’s note: I am a columnist for Compliance Week.

Compliance Week recently released its Practitioner’s Briefing, which “is crafted as a high-level recap of Compliance Week’s 2026 National Conference (CW 26), held in Washington, D.C., in May. Whether you were there or wished to be, this briefing will bring you up to speed. The briefing captures the six themes that pervaded three days of panel discussion and the networking conversations between them, with practical actions you can implement in the next ninety days.”

The compliance profession is entering the proof era. Policies still matter, but regulators, boards, and employees are asking a harder question: Can the organization demonstrate that its controls operate in practice? That is the central lesson from the Practitioner’s Briefing. Across six themes, the briefing describes a function under pressure from rapid AI adoption, faster whistleblower timelines, redistributed enforcement, expanding third-party exposure, and sharper board expectations.

Today I want to explore the themes and initiatives from the Practitioner’s Briefing. This is not about six disconnected initiatives covered at CW 26. It is an operating model that connects governance, data, accountability, and escalation around existing risks. You can use the next 90 days to produce evidence that the program knows where its risks sit, who owns the controls, how failures surface, and what happens next.

AI Governance: Accountability Must Follow Adoption

AI makes the policy-to-proof gap visible. The Practitioner’s Briefing reports that 83 percent of compliance functions have AI in production, while only 25 percent of leaders are confident in the governance controls. That is not primarily a policy problem. It is an ownership and control-design problem.

Start with your AI inventory. A defensible AI register should identify the tool, approved use case, business owner, data involved, vendor, model, access rights, validation method, human reviewer, retention rule, incident path, and kill-switch authority. Tool approval by IT cannot substitute for use-case approval by Legal, Compliance, Privacy, Security, and the accountable business leader. One platform may be acceptable for drafting training content and unacceptable for evaluating employees or third parties.

The NIST AI Risk Management Framework and ISO/IEC 42001 can help organize this work, but a framework is not the control. The control is the approval record, test result, exception log, monitoring evidence, and documented decision. Compliance should also assume that prompts, summaries, transcripts, and agent logs are discoverable business records. Retention and legal hold procedures must catch those artifacts before the first dispute or investigation forces the question.

AI in Compliance Operations: Redesign the Work

The Practitioner’s Briefing draws a useful line between AI enablement and AI theater. Strong programs redesign a workflow around AI. Weak programs bolt AI onto a slow process and call it transformation. Due diligence, regulatory tracking, training development, and self-service policy guidance are sensible starting points because the work can be scoped, tested, and measured.

Each deployment needs acceptance criteria. Validate performance against known outcomes, constrain source material where accuracy matters, monitor drift, require human review for high-risk decisions, and define escalation when the system is uncertain. Measure return on investment first in hours returned to higher-value work. Faster output that creates more review, remediation, or false confidence is not efficiency. It is control debt.

Speak-Up and Investigations: Trust Is the Control

The Practitioner’s Briefing reports that eight in ten US employees witnessed misconduct during the prior year, yet fewer than three-quarters reported it. That gap is not solved by adding another intake channel. It is solved by showing employees that reporting is safe, fair, and consequential.

One of the Practitioner’s Briefing’s most practical recommendations is to audit the career outcomes of the last 20 employees who raised concerns. Review performance ratings, promotions, transfers, compensation, leave, and departures. Patterns in those records may reveal retaliation or career stagnation that hotline statistics will never show. Pair that review with defined post-report monitoring and documented check-ins with reporters.

Speed is now part of program effectiveness. The briefing highlights a 120-day DOJ window to investigate qualifying internal reports and decide whether voluntary self-disclosure is appropriate. CCOs should calendar that period, establish rapid triage, identify decision rights, preserve evidence immediately, and maintain a standing disclosure team. The goal is not a rushed conclusion. The goal is to prevent delay, unclear ownership, or inadequate resources from deciding for the company.

Enforcement Has Shifted, Not Disappeared

Lower federal case counts are not a safe harbor. The Practitioner’s Briefing describes enforcement as redistributed across state Attorneys General, self-regulatory organizations, the False Claims Act, and future matters still inside applicable limitation periods. A quieter headline environment can encourage exactly the wrong management response: reduced staffing, deferred remediation, and lower investment in controls.

The business discipline is straightforward. Monitor the full enforcement ecosystem, not one federal docket. Maintain the strictest applicable standard as the practical global baseline. Preserve the ability to investigate, cooperate, remediate, and disclose. Most importantly, do not confuse a change in enforcement cadence with a change in underlying legal or ethical risk. Today’s control gap may simply be tomorrow’s case.

Third-Party Risk: Manage the Entire Lifecycle

Third-party risk management is no longer a narrow anti-bribery process. The Practitioner’s Briefing places sanctions, forced labor, transnational crime, material support exposure, supply-chain integrity, and embedded AI inside the modern TPRM remit. That expansion requires a move from onboarding diligence to lifecycle control.

Monitor material relationships from selection through offboarding, with risk-based refreshes, event-driven alerts, beneficial ownership checks, adverse media review, and clear remediation ownership. For AI-enabled vendors, procurement should require disclosure of material fourth- and fifth-party dependencies. Contract terms should address model provenance, data lineage, audit rights, incident notice, control changes, and the ability to explain consequential decisions.

List screening alone is increasingly thin protection. High-risk supply chains may require route mapping, chokepoint analysis, and source-verified information reviewed in context by humans. AI can compress the initial diligence cycle, but it does not replace judgment on coercion, shell companies, access payments, or other facts that demand legal and operational analysis.

Board Reporting and Culture: Lead With the Problem

Directors want a compliance report that begins with bad news, explains the risk, and shows the response. That is the board-reporting message in the Practitioner’s Briefing. Activity counts belong in the appendix. The main discussion should address control failures, investigation aging, retaliation indicators, overdue high-risk diligence, AI exceptions, remediation status, and emerging exposure compared with peers.

This approach also supports a Caremark-style oversight record. The board needs credible information systems, timely escalation of red flags, and evidence that management and directors responded. A between-meetings protocol with the audit or risk committee chair is therefore a control, not a courtesy.

Culture is equally operational. The briefing reports that direct managers and immediate colleagues exert the strongest influence on 80 percent of employees, while only 58 percent of organizations evaluate how results were achieved. Compliance should train managers to receive concerns, audit incentives as rigorously as financial controls, and make conduct part of performance and promotion decisions. The real code of conduct is what the organization rewards, tolerates, and corrects.

A 90-Day Agenda for CCOs

  1. Build the evidence map. Select the highest-risk obligations in AI, investigations, and third-party management. For each one, identify the owner, control, evidence, escalation path, and board metric.
  2. Test AI governance. Reconcile the official AI inventory with procurement records, browser access, expense data, and employee attestations. Review several approved use cases from request through monitoring.
  3. Stress-test investigations. Tabletop a significant internal report against the 120-day decision window. Confirm preservation, privilege, staffing, disclosure authority, and board communication.
  4. Rebuild TPRM around lifecycle risk. Segment critical third parties, define continuous-monitoring triggers, review AI dependencies, and assign remediation deadlines with accountable owners.
  5. Change the board report. Put the three most significant problems first. Add peer comparison, trend data, remediation aging, and decisions required from the board or management.

The Compliance Lesson

The Practitioner’s Briefing is not fundamentally a technology story or an enforcement story. It is a program-effectiveness story. The effective compliance function can identify risk, assign accountability, test controls, learn from failures, and show its work. Policies establish expectations. Evidence establishes credibility. In the next 90 days, that distinction should drive the agenda of every CCO, executive team, and board committee responsible for corporate integrity.

Categories
Sunday Book Review

Sunday Book Review: August 23, 2026, The New Books On Power Edition

In the Sunday Book Review, Tom Fox considers books that would interest compliance professionals, business executives, or anyone curious about the subject. It could be books about business, compliance, history, leadership, current events, or any other topic that might interest Tom. In this episode, we look at 4 new books on power.

  1. 1873 by Liaquat Ahamed
  2. Money to Burn by William D. Cohan
  3. Streetwise by Lloyd Blankfein
  4. Bonfire of the Murdochs by Gabriel Sherman

Resources:

Our list today comes from the FT and Standard Chartered Business Book of the Year Award 2026 — the longlist

Categories
Hill Country Treasures

Hill Country Treasures: Family Heirlooms and Estate Collections

This podcast from MR Mint Coins & Collectibles in Kerrville, Texas, explores the value, history, and stories behind coins, currency, gold, silver, jewelry, bullion, sports cards, memorabilia, and family collections. Whether you are a lifelong collector, a curious beginner, or someone who just inherited a box of old coins, this show helps you understand what you have, what makes it valuable, and how to make smart, confident decisions. Join host Tom Fox and MR Coin owner Mike Russ for a show that celebrates local expertise, honest conversations, and the treasures hiding in plain sight across the Hill Country.

In this episode, Mike and Tom discuss how families should approach inherited coins, jewelry, silver, currency, and estate items. Russ explains most families don’t know what they have, so he assesses how the original collector organized items (books, flips, rolls, bags) and builds rapport before evaluating, emphasizing empathy, listening, and no-pressure guidance, including telling clients they don’t have to sell that day. He stresses transparency and ethical dealing because trust matters in a small community, noting that rare coins can look like common ones and that value depends on details like mint marks. Russ contrasts collector motivations (sentiment vs. value), warns never to clean coins or silverware because it can reduce value, and advises bringing everything in a box for sorting. He also notes estate-sale percentage costs can be higher than direct precious-metal sales.

Key highlights:

  • Reading The Collection
  • Small Town Trust
  • Collector Mindset
  • Hobbies and Values
  • What To Bring In

Resources:

MR Mint and Coin Collectibles

Categories
AI Today in 5

AI Today in 5: August 21, 2026, The Spirit Airlines and AI Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. AI governance for responsible AI. (Yahoo! Finance)
  2. Google wants to buy Spirit AI for its data. (WSJ)
  3. OpenAI to expand monitoring after hacking. (FT)
  4. Transaction monitoring to grow exponentially. (Precedence Research)
  5. AI selecting who gets healthcare in 6 states. (BBC)

For more information on using AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Daily Compliance News

Daily Compliance News: August 21, 2026, The Doing Business With Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Trump threatens countries that do business with Iran. (NYT)
  • More whistleblowers down under. (Reuters)
  • Zelensky fires top aide. (FT)
  • CK Hutchison files an arbitration claim against Panama. (WSJ)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
AI in Healthcare

AI in Healthcare: Five Healthcare AI Stories You Need to Know This Week – August 21, 2026

Welcome to AI in Healthcare in 5 Stories. This podcast is a weekly briefing on the five most important AI developments shaping healthcare, medicine, and life sciences. Each week, Tom Fox breaks down the latest stories on clinical innovation, regulation, privacy, compliance, patient safety, and operational transformation through a practical, business-focused lens. Designed for healthcare compliance professionals, executives, legal teams, clinicians, and industry leaders, the podcast moves beyond headlines to explain what each development means in the real world.

The top five stories for the week ending August 21, 2026, include:

  1. Maine looking at AI for rural health. (Bangor Daily News)
  2. AI helping patients solve mystery ailments. (WSJ)
  3. Guiding Principles for AI in healthcare. (UVA Health)
  4. From Pilot to Profit: AI in Pharma. (PharmaExec)
  5. Can AI make your hospital a Mayo Clinic? (Health Exec)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Compliance and AI

Compliance and AI: Designing Compliance Into iGaming Products From Day One with Mouhcine Jalili

What is the intersection of AI and compliance? What about machine learning? Are you using ChatGPT? These questions are just three of the many we will explore in this cutting-edge podcast series, Compliance and AI, hosted by Tom Fox, the award-winning Voice of Compliance. Today, Tom visits with Mouhcine Jalili, VP of Growth – iGaming at Software Mind, to reframe iGaming compliance as a design, delivery, and platform challenge rather than an end-stage legal checklist.

Jalili brings 15 years of exclusive iGaming experience, having grown from operational roles into commercial, team growth, and technology-focused leadership, and he currently serves as Vice President for Growth in iGaming at Software Minds. He views operational compliance and governance as a design-and-delivery challenge rather than merely a legal checklist, because many of the biggest risks arise when product changes are rolled out across regulated markets without the right release management and controls. From his perspective, responsible gambling and other market-specific requirements should be engineered into the product from the start through automated controls, strong configuration management, and close collaboration between compliance, product, delivery, and engineering teams. Overall, Jalili believes iGaming governance works best when compliance is embedded directly into the system architecture and operational process, making the whole organization more resilient and easier to scale.

Resources:

Connect with Mouhcine Jalili on LinkedIn

Software Mind

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn