Categories
Red Flags Rising

Red Flags Rising: S01 E20 – China, AI, and Export Controls – Facing a Moment of Truth

Mike and Brent follow-up on Episode 19’s discussion of “stack sweeps” with a discussion of the current “moment of truth” facing trade compliance teams dealing with high-probability, catch-all enforcement risks as explained in their recent WorldECR (Issue No. 141, July/August 2025) and Dow Jones Risk Journal article, “Anticipating the moment of truth: how to prepare for ‘high probability’ catch-all enforcement.” Specifically, they discuss the recent decision by the U.S. to allow (licensed) sales of certain advanced integrated circuits to China (00:42), their WorldECR/DJRJ article and how the Bureau of Industry & Security (BIS) guidance of May 13, 2025, which emphasized the “high probability” standard and catch-all provisions of the U.S. Export Administration Regulations (EAR), inspired the article (or at least inspired Tom Blass of WorldECR to ask us for an article) (07:10), how the underlying catch-all provisions are not “new” as of May 13, 2025 (10:26), how compliance teams can’t “zero-risk” export controls risk and need to adopt risk-based approaches (12:17), the relevance of the “inchoate” offenses under the EAR, i.e., aiding, abetting, conspiracy, evasion, acting with knowledge, and misrepresentations (13:21), the limitations of end-use and end-user certificates under the May 13, 2025 policy and guidance documents (14:47), their thoughts on the reportedly pending “50% rule” for the Entity List (18:32), the impact of the ability of malign actors, political parties, and military-intelligence actors to exercise influence even without shareholdings (19:25), why the most risky counterparties are those not on the Entity List (20:49), and the three key takeaways in their WorldECR/DJRJ article (24:09). They conclude with another installment of Brent Carlson’s “Managing Up” segment (30:28).

Resources:

WorldECR

Brent LinkedIn

Mike LinkedIn

Mike & Brent’s “Fresh Looks” Series

Categories
SBR - Authors' Podcast

SBR-Authors Podcast: Finding True Happiness Through Acts of Kindness: A Conversation with Karen Olson

Welcome to the SBR-Authors Podcast! In this podcast series, host Tom Fox visits with authors in the compliance arena and beyond. In this episode, Tom Fox interviews Karen Olson, the founder and CEO Emeritus of Family Promise and the author of ‘Meant for More.’

Olson shares her journey from aspiring nurse to being an influential advocate for homeless families. She elaborates on the importance of acts of kindness in achieving genuine happiness. She describes how the Family Promise organization supports families experiencing homelessness through various programs, including prevention, sheltering, and volunteer services. Olson discusses changes in the homelessness landscape since the 1980s and shares personal stories of volunteers making a difference. She also talks about the inspiration behind her book and the critical role of community involvement in addressing homelessness.

Key highlights:

  • The Story Behind ‘Meant for More’
  • Karen’s Journey
  • The Birth of Family Promise
  • The Current State of Homelessness
  • Inspiring Volunteer Stories
  • Family Promise Initiatives
  • Acts of Kindness and Inspiration

Resources:

Meant for More: Following Your Heart and Finding Your Purpose on Amazon

Visit Family Promise Website

Karen Olson Website

PR by the Book Website

Follow Karen Olson at

PR by the Book

Facebook

Instagram

LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Blog

The Compliance Guide to Designed Intelligence: Part 1 – Rethinking Governance for the Age of AI

If there is one constant in the world of compliance, it is the reality of change. However, in 2025, change takes on a new vector: artificial intelligence, not just as a tool, but as a force reshaping how organizations think, decide, and act. In their article “What Is a Designed Intelligence Environment?” authors Michael Schrage and David Kiron examined how enterprises must rethink their intelligence and compliance strategies to survive and thrive in the new world of AI-rich operations. I found their insights for compliance professionals both practical and transformative. Today, I begin a short two-part blog post series on Designed Intelligence. Today, in Part 1, we consider what is meant by Designed Intelligence. Tomorrow, we take a deeper dive into what it means for compliance.

From Managing Compliance to Orchestrating Intelligence

Traditional compliance frameworks have always focused on managing risk, enforcing controls, and responding to regulatory shifts. But what happens when decision-making itself is no longer exclusively human? In a designed intelligence environment, humans and machines learn, reason, adapt, and improve together. This is not simply the automation of existing workflows; it’s the emergence of a new kind of enterprise, where “epistemic engineering”—the design of how knowledge is generated, shared, and executed—becomes the bedrock of effective compliance.

The first insight for compliance professionals is that we can no longer assume governance is solely about drawing lines around human behavior. Our job is to architect environments in which both human and machine intelligences operate responsibly and transparently, ensuring that knowledge, decisions, and accountability flow where they are needed most.

Computational Irreducibility: The End of Predictive Planning

Stephen Wolfram’s principle of computational irreducibility may sound academic, but its implications are anything but theoretical for compliance leaders. In a nutshell, this principle holds that in highly complex systems, such as those created when humans and AI interact, the future cannot be predicted without running the system in real-time. In other words, the classic compliance cycle of “predict, plan, execute, and measure” is mathematically impossible in many AI-rich contexts.

For compliance professionals, this means shifting from static policy planning to dynamic, real-time oversight. Consider an example from pharmaceutical R&D. A global company faced paralysis in prioritizing compounds for its oncology pipeline. Instead of relying on fixed rankings or endless meetings, leadership created a computational observatory: multiple agentic models simultaneously analyzed each compound from different perspectives (biological plausibility, market readiness, synthetic feasibility)—cross-model consensus and visualization, rather than managerial heuristics, guided decisions, surfacing previously hidden breakthroughs.

Compliance Lesson: Build for Observability, Not Just Control

In today’s world, compliance cannot rely solely on auditing after the fact. The future lies in building observability into the core of decision environments: real-time monitoring, feedback loops, and experimental frameworks that enable compliance to identify emergent risks as they arise, not just when it’s too late. This is the heart of “runtime intelligence.”

Semantic Formalization: Making Compliance Computable

Most compliance programs are based on documentation, training, and knowledge management. But semantic formalization, another key concept, goes much further. It requires organizations to define core business concepts (like “customer value,” “operational risk,” or “conflict of interest”) so precisely that both humans and AI agents can “compute” with them. This is not a matter of semantics for its own sake; it is about ensuring that rules, policies, and standards are unambiguously actionable by both people and machines.

For example, a multinational retailer’s use of large language models (LLMs) for customer support faced breakdowns because definitions of customer experience (CX) varied by region and role. By creating a semantic kernel, which is an enterprise ontology that maps complaints, resolution pathways, sentiment clusters, and CX metrics, the company trained its models (and its people) to reason with consistent, computable definitions. This enabled root-cause analysis and adaptive, system-wide learning that wasn’t possible in the old script-driven model.

Compliance Lesson: Define, Don’t Just Describe

Compliance teams must become architects of semantic infrastructure. That means working cross-functionally to formally define compliance concepts, risks, and obligations so that every AI, dashboard, and human team member speaks the same language, in the same way, everywhere. This is how you build “reasoning standardization” and reduce the friction, ambiguity, and risk that come with AI-driven scale.

Rulial Space: Translating Between Multiple Realities

Perhaps the most disruptive insight for compliance comes from the concept of rule-based space: the recognition that different “intelligences”—whether human teams, AI systems, or even other departments—operate under distinct rule sets, generating unique realities. Finance assesses risk through Monte Carlo simulations, operations analyze it through failure mode analysis, and AI identifies it through statistical correlations. Traditional efforts to force alignment through training or incentives may be fundamentally flawed. What is needed is translation, not assimilation.

In aerospace manufacturing, for example, friction between design engineers and LLMs led to productivity-killing standoffs. Instead of forcing one side to conform to the other, leadership installed an honest mediator: an explicit layer for mapping, negotiating, and reconciling the assumptions, rules, and heuristics of both human and AI systems. This moved the organization from “compliance by enforcement” to “compliance by comprehension,” a far more powerful and sustainable model for managing both risk and innovation.

Compliance Lesson: Become a Translator, Not Just an Enforcer

The future of compliance is not just about enforcing standards but about building systems and processes that can explicitly map and translate between different rule sets: human, machine, and hybrid. This requires cognitive compilers: protocols and infrastructure for negotiating meaning, resolving conflicts, and arbitrating outputs across diverse intelligences. The result is intelligent orchestration of more innovative, safer, and more adaptive enterprises.

Why Smarter Tools Aren’t Enough: Compliance by Design, Not Just Technology

It’s tempting to think that more innovative tools or more sophisticated AI models will solve all compliance challenges. But as the article warns, deploying intelligence as automation—without rethinking the architecture of decision environments—will leave most enterprises stuck with mediocre results. Intelligence, whether human or machine, must be designed into the very infrastructure of the organization: how decisions are made, how meaning is generated, and how value and risk are understood.

For compliance professionals, this means a dramatic expansion of your remit. You must help design the runtime environment for intelligence where learning, adaptation, and ethical execution are embedded, not bolted on. This requires technical fluency, cross-disciplinary collaboration, and a willingness to challenge the old boundaries of policy, training, and audit.

Conclusion: The Compliance Opportunity in Designed Intelligence

The transition to designed intelligence environments represents both a challenge and a once-in-a-generation opportunity for compliance leaders. Those who lean in, who help architect real-time observability, semantic formalization, and rule-based mediation, will become essential strategic partners in their organizations’ transformation. Those who don’t risk being left behind by systems they can neither see, steer, nor secure.

The era of “predict and control” is coming to an end. The age of “orchestrate and observe” is here. As compliance professionals, our calling is clear: to lead the design, governance, and stewardship of intelligence environments that are fit for the complexity and promise of AI. Only then can we ensure that innovation and integrity go hand in hand in the enterprises of tomorrow.

Join us tomorrow for Part 2, where we delve deeper into the compliance considerations.

Categories
The Ethics Experts

Episode 223 – Anitha Vittal

In this episode of The Ethics Experts, Nick welcomes Anitha Vittal.

Anitha is recognized as a global leader in ethics, risk, compliance, and internal audit, with proven experience and expertise in establishing Centers of Excellence at GCCs across various industry verticals.

A passionate professional, she has over 23 years of service in leading and developing high-performing teams across India, Europe, and the US markets. Her engagements include internal audit, risk management, compliance, business process and financial compliance, data privacy, SOX, GRC program management, and digitization.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Avoiding CCO Liability

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we look at the issue of CCO liability in regulated industries and how to avoid it.

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Daily Compliance News

Daily Compliance News: July 21, 2025, The More Reasons Not to Go to China Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings to you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, including compliance, ethics, risk management, leadership, or general interest, relevant to the compliance professional.

Top stories include:

  • Astronomer CEO resigns. (BBC)
  • Wells Fargo employee under investigation, 2 more can’t leave. (NYT)
  • Meta refuses to agree to EU Code of AI Practice. (WSJ)
  • X to fight French investigation. (Reuters)

You can donate to flood relief for victims of the Kerr County flooding by going to the Hill Country Flood Relief here.

Categories
Corruption, Crime and Compliance

Export and Sanctions Enforcement Update

What happens when companies ignore red flags, bypass legal advice, and underestimate the reach of U.S. export laws? In this episode, Michael Volkov unpacks two major enforcement actions from the Department of Commerce’s Bureau of Industry and Security (BIS) and the Treasury Department’s Office of Foreign Assets Control (OFAC). These cases serve as cautionary tales for companies navigating complex trade and sanctions landscapes, highlighting the steep costs of compliance failures, even when violations aren’t willful.

You’ll hear him discuss:

  • BIS’s $4.25 million penalty against Alpha and Omega Semiconductor (AOS) for 15 violations of the Export Administration Regulations (EAR), including unauthorized shipments to Huawei
  • How AOS disregarded legal advice and internal compliance warnings while continuing to export EAR99 items from the U.S. to an Entity List company
  • The significance of BIS’s finding that even non-willful violations will trigger serious enforcement consequences
  • OFAC’s $608,825 settlement with Key Holding LLC over Cuban sanctions violations linked to its Colombian subsidiary, Key Colombia
  • How a failure to implement sanctions compliance after acquiring a foreign affiliate exposed Key Holding to U.S. jurisdiction – and liability
  • The importance of post-acquisition compliance integration and automated screening in mitigating enforcement risk
  • Why these cases mark a return to traditional administrative enforcement priorities and serve as stark reminders of jurisdictional reach

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

Categories
FCPA Compliance Report

FCPA Compliance Report – The Impact of Secondary Tariffs on Global Trade with Mike Huneke and Brent Carlson

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. In this episode, Tom Fox welcomes back Mike Huneke and Brent Carlson, who help us navigate the implications of secondary tariffs, focusing on recent developments following the President’s announcement.

They explore why secondary tariffs could be considered the ‘nuclear bomb’ of trade sanctions, examining their potential impacts on various countries, particularly those doing business with Russia, such as China and India, as well as the broader geopolitical shifts affecting global trade patterns. The conversation emphasizes the need for multinational companies to reassess their supply chains and compliance strategies to mitigate potential risks associated with these tariffs. The episode underscores the importance of companies adapting to a rapidly evolving geopolitical landscape to ensure compliance and maintain their business operations.

Key highlights include:

  • Understanding Secondary Tariffs
  • Implications of Secondary Tariffs on Global Trade
  • Corporate Response to Secondary Tariffs
  • Geopolitical Realities and Trade Compliance
  • False Claims Act and Enforcement Risks

Resources:

Brent Carlson on LinkedIn

Mike Huneke on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com

Categories
Blog

How Generative AI is Transforming Business and Compliance in 2025

One thing I have learned from the digital age is that to stay ahead, we must stay informed and proactive about how new technologies impact corporate governance, ethics, and operational compliance. In this context, generative AI (Gen AI) is no longer a futuristic concept; it is embedded deeply in our everyday activities. Marc Zao-Sanders’ article in Harvard Business Review (HBR), “How People Are Really Using Gen AI in 2025,” presents an excellent opportunity to reflect on how these developments impact compliance, governance, and risk management.

Zao-Sanders highlights a critical shift in how generative AI is utilized: from purely technical assistance towards significantly more personal and emotive applications. With “Therapy/Companionship,” “Organizing my life,” and “Finding purpose” emerging as the top three use cases, it’s clear that users seek emotional and organizational support, demonstrating Gen AI’s versatility beyond traditional technological roles.

Compliance professionals must recognize that as AI increasingly becomes integral to both professional services and personal well-being, the accompanying risk and compliance implications magnify exponentially. The nature of these interactions, often intimate or deeply personal, demands robust data privacy protections and stringent ethical governance frameworks. Businesses integrating these technologies need precise, transparent policies and effective oversight mechanisms to mitigate new compliance risks.

Implications for Compliance Professionals

Enhanced Data Privacy and Ethical Considerations

Zao-Sanders emphasizes the rising prominence of personal and professional support through Gen AI, especially in areas such as AI-based therapy, emotional companionship, and life organization. As users entrust AI with highly sensitive personal data, compliance professionals face increased responsibilities regarding data privacy, security, and the ethical use of data. This scenario elevates the stakes considerably. He notes, “data safety is not a concern when your health is deteriorating,” highlighting users’ willingness to sacrifice privacy for crucial emotional or medical support. Such conditions can quickly lead to ethical and compliance vulnerabilities if businesses fail to manage and protect sensitive user data rigorously.

Organizations must reinforce their compliance strategies to manage ethical risks inherent in AI-human interactions. As Zao-Sanders indicates, professional services, including medical, legal, and financial advisement, are increasingly relying on generative AI, pushing regulatory boundaries. Notably, EY’s deployment of 150 AI agents specifically for tax-related tasks highlights the profound impact of generative AI on professional services, adding layers of complexity to compliance strategies.

Regulatory Response and Enforcement Trends

The article briefly touches on the growing regulatory scrutiny that Gen AI is attracting globally, noting explicitly that governments are “taking more emphatic and explicit positions” due to heightened stakes surrounding AI technology. For compliance professionals, this should serve as a clarion call: regulatory oversight is intensifying. Preparing for audits, demonstrating compliance, and actively engaging with regulatory developments will be essential. The rapid pace of AI adoption necessitates an agile and proactive approach to compliance management that anticipates, rather than merely reacts to, regulatory shifts.

Balancing AI Dependence with Human Oversight

A striking tension highlighted in the article is the debate over the impact of generative AI on human cognitive abilities, decision-making, and ethical judgment. Users express genuine concern about becoming overly reliant on AI, which could erode their ability to think critically and make independent, ethical decisions.

This reliance poses significant implications for compliance officers charged with safeguarding ethical decision-making. Effective compliance programs must emphasize human oversight, cultivating a culture where AI supports rather than supplants human judgment. Investing in AI literacy among employees can mitigate potential over-reliance, fostering an environment where staff understand both the capabilities and limitations of AI.

Compliance in AI-Driven Professional Services

Zao-Sanders illustrates how AI integration into professional tasks is increasingly sophisticated. For instance, the transformation underway at EY, training employees extensively in generative AI, reflects broader industry trends. Compliance officers must respond to these developments by establishing clear standards and compliance checkpoints. It is crucial to determine whether AI outputs meet professional standards, remain unbiased, and do not inadvertently violate regulatory obligations.

Given AI’s pervasive integration into professional judgments (such as tax preparation, legal advice, and medical diagnosis), the accuracy and regulatory compliance of AI-driven outputs become paramount. Compliance programs must integrate AI auditability, accountability, and transparency deeply into corporate governance frameworks.

Practical Compliance Steps in the Gen AI Era

1. Proactive Policy Development and Training

Develop clear policies that outline the acceptable use of generative AI, including specific guidelines on data handling, ethical considerations, and regulatory obligations. Embed these policies into your organization’s culture through rigorous training and communication strategies.

2. Rigorous Risk Assessment and Ongoing Monitoring

Gen AI compliance must adopt continuous monitoring. Regular risk assessments and periodic audits of AI systems will promptly detect and rectify issues. Compliance officers should remain actively involved in assessing new AI technologies for ethical, privacy, and regulatory considerations before full-scale implementation.

3. Transparent Data Practices

Given the heightened public sensitivity to data privacy concerns, as noted by Zao-Sanders’ mention of users’ concerns around data privacy and their cynicism toward Big Tech, companies must prioritize transparent data practices. Clear communication about data usage, consent, and protection measures will foster trust and reduce compliance risks.

4. Ethical AI Governance Frameworks

Design and deploy ethical AI governance frameworks that address algorithmic fairness, transparency, and accountability, ensuring responsible use of AI. These frameworks ensure generative AI tools are deployed responsibly and ethically, aligning with stakeholder expectations and regulatory standards.

5. Encourage Human-AI Collaboration

Foster a balanced approach between AI-driven solutions and human judgment. Reinforce the importance of human oversight to ensure compliance, accuracy, and ethical decision-making, thus minimizing over-dependence on AI.

Looking Ahead—The Compliance Imperative in the Gen AI Landscape

As we approach a future increasingly defined by AI integration, compliance professionals have a unique opportunity to lead their organizations proactively. Understanding and managing the compliance and ethical dimensions of Gen AI is now critical, not optional. The risks and opportunities outlined in Zao-Sanders’ article underscore the urgent need for a strategic, well-informed approach to integrating generative AI into corporate compliance frameworks.

Compliance professionals should view this moment as an opportunity to demonstrate thought leadership, to guide ethical AI adoption, and to establish robust frameworks that enable businesses to thrive responsibly. By proactively addressing the compliance and moral challenges presented by generative AI, we not only fulfill our professional obligations but also position our organizations as ethical, forward-thinking leaders in the digital age. The compliance journey ahead is demanding, but equally, it offers profound opportunities to influence and shape a responsible, compliant, and ethically robust AI-driven future.

Categories
Sunday Book Review

Sunday Book Review: July 20, 2025, The Best Books on Business Edition

In the Sunday Book Review, Tom Fox considers books that interest compliance professionals, business executives, or anyone curious about the subject. It could be books about business, compliance, history, leadership, current events, or any other topic that might interest Tom. For the month of July, Tom looks at the FT’s recommendations for top books in the summer of 2025. In this episode, Tom reviews the FT’s list of the top books on business for the Summer of 2025.

  1. The Chairman’s Lounge: The Inside Story of How Qantas Sold Us Out by Joe Aston 
  2. Abundance: How We Build a Better Future by Ezra Klein and Derek Thompson
  3. Mood Machine: The Rise of Spotify and the Costs of the Perfect Playlist by Liz Pelly
  4. House of Huawei: Inside the Secret World of China’s Most Powerful Company by Eva Dou

The Sunday Book Review was recently honored as one of the Top 100 Book Podcasts.

Resources:

FT’s Best Books of Summer for 2025: Business by Andrew Hill.