Go Back
On-demand

Beyond the Buzz: The Rise of LLMs and AI in Communications Surveillance

Missed our insightful webinar featuring a former FINRA regulator, Shield’s Head of Data Science, and the Head of Americas Supervision at Citadel?
Dive into the impact of generative AI and the rise of Large Language Models (LLMs) on compliance. Watch the recording now to explore AI’s transformative role in enhancing surveillance procedures and shaping the future of financial compliance.

Speakers

Cameron Funkhouser

Former FINRA Senior Executive

Stan Yakoff

Head of Supervision, Americas, Citadel

Dr. Shlomit Labin

VP Data Science, Shield

  • Transcript

    Beyond the Buzz: The Rise of LLMs and AI in Communications Surveillance

    Shield Insiders In-Focus
    Speakers

    • David Aaronson, Product Marketing, Shield (Moderator)
    • Cameron Funkhouser, Former FINRA Senior Executive
    • Stan Yakoff, Head of Supervision, Americas, Citadel
    • Dr. Shlomit Labin, VP, Data Science, Shield

     

    Introduction

    David:Hello, everyone, and welcome to our webinar, Beyond the Buzz: The Rise of LLMs and AI in Communications Surveillance. I’m David Aaronson, Product Marketing at Shield, and I’ll be your moderator for this intriguing and timely conversation. Before we dive in, I have to share something interesting I discovered about some of our panelists in one of our recent conversations together. Turns out we have not one but two accomplished tennis players here today — Stan and Cameron — so you can expect them to serve up some important insights. And just like that, hundreds of people around the world just dropped their faces straight into their hands.
    Now for a little housekeeping: we have fifteen minutes at the end of the webinar for Q&A. If you have any questions throughout the presentation, please feel free to add them in the chat — someone from our team will be monitoring and compiling the questions for our speakers. If we run short on time to answer your question, we’ll be sure to compile answers from the panelists after the event and reach out to you.
    Allow me to introduce our experts who’ll be leading today’s discussion. Cameron Funkhouser is a former FINRA senior executive and an expert in financial services regulations and compliance. Cameron’s experience and unique perspective on protecting the markets are invaluable. Stan Yakoff, our next panelist, is Head of Supervision in the Americas at Citadel, an expert in financial services e-comms compliance who teaches law students on the subject as well. We look forward to Stan’s insights into the practical aspects of AI and e-comms compliance. Last but not least, Dr. Shlomit Labin is Vice President of Data Science at Shield, holding two PhDs, and now has a very shiny Best Cloud Innovator of the Year award from the Cloud Awards — congratulations on that, Shlomi. An expert in AI, data science, and the financial compliance market, she brings a wealth of knowledge and innovative thinking to our conversation.
    As we dive into the discussion, we hope to leave you with a new perspective and tools to understand and leverage the exciting developments in AI and compliance. So sit back, relax, maybe grab a tennis racket, and let’s jump right in.

    Why LLMs and ChatGPT Matter for Compliance

    David:So let’s start with a softball. What makes large language models, and ChatGPT, so interesting to us from a compliance perspective?
    Shlomit:Okay. So in general, when we’re talking about large language models and the new generative AI, we’re talking about real breakthroughs in the domain of text analysis, or free-language analysis. This is the main challenge in compliance — being able to monitor human conversations. It’s been a challenge for many years, and now we have innovative tools to actually deal with it.
    David:Thanks for that, Shlomit. Stan, what have you got?
    Stan:Thanks, David. Before I begin, let me give my quick legal disclaimer that the views expressed herein are solely my own, not any current or prior employer necessarily. With that being said, what’s interesting here, I think, is that for one of the very rare times, we see convenience and compliance possibly hand in hand. When you historically think about how technology has been developed, particularly in the compliance tech, fintech — name whatever acronym you want — space, oftentimes you’re going to need two PhDs like Shlomit, in two different domains, one in psychology and one in computer science, in order to even interact with the tooling. Here, all you have to do is go on the website, sign up, confirm via your email, and then you have access to very powerful technology. The reason I say it’s rare is that oftentimes the tech gets built and then you have to figure out how in the world you’re going to interact with it. Here you actually have a very easy way of interacting with very powerful technology. So that’s caused a lot of us, and our much older family members, to all of a sudden start interacting with robots more than we ever thought we would.
    David:Yeah, that’s true. Grandmothers and grandfathers everywhere actually like going online and getting answers to all their questions — except “why won’t my WiFi work?” That one still won’t help you. Cameron, what do you think? What makes LLMs so interesting?
    Cameron:Yeah, I’ve been around a pretty long time. In the early nineties, I was helping develop some what was considered revolutionary technology using artificial intelligence that, looking back on it, is laughable now, because we were doing structured word analysis and connecting the dots. The potential from there to here — you can imagine in your own minds what the difference is between AM radio and Netflix. There are lots and lots of opportunities, probably more than we could talk about today or even think about. But the opportunities to be more effective, more cautious, and reduce your regulatory risk are enormous.

    Where Firms Are on the AI Journey

    David:Thanks. Before we continue, I want to pose a quick anonymous poll to the crowd. From one to five, five being most advanced — like, “we knew about ChatGPT before it was cool” — how far along is your firm in implementing AI in your compliance strategy? We hear a lot of questions and ideas get kicked around, and I think the audience would like to hear from each other about where everyone else is. We’ll continue on while people answer. Stan, let me pose this to you: how far along is your team in your AI journey, on a one to five?
    Stan:Yeah, I generally don’t put a number on this, but I’ll talk about experience — specifically my own. The way I look at it: I’ve employed certain algorithmic techniques, as I call them, that function to essentially cluster trading activity, which gives an idea for what typical or normal trading activity looks like, and then analyze activity that falls outside those normal distributions over longer periods like thirty, sixty, ninety days. Generally, the longer horizons tend to help reduce noise from an atypical market day — isolated news events like interest rate bumps and such. This technique helps illustrate where people may be behaving anomalously — for example, trading more than usual — and incorporate other important dimensions like P&L, as well as whether the trading activity may have triggered controls that caused rejects.
    Once that occurs, from a detection point of view, the curiosity now goes to the investigation side, and you start to ask what may be the driver for the heightened activity, once you isolate out expected factors like news, contract expiries, and rollovers. What’s pretty cool is you start to identify unusual market data movements that may resemble possible market abuse — and you see this externally in the market, which means the challenge is that you’re a victim in what’s going on. It’s much more challenging to control, because it’s happening in the market. So you use a creative feedback loop between something surveillance found and being preventative from a front-office, trading perspective — how can we identify gaming ourselves and try not to interact with this type of activity once we see the pattern forming?
    This has been pretty interesting, but I still consider it experimental, and really a supplement to non-AI-based algorithms, as opposed to an outright substitution or replacement — and I’m going to talk about being very careful with the word “substitution” or “replacement” quite a lot here.
    Now, if we turn to communication surveillance, I think this lens of “supplement” and “experimental” is a really important one. From a communications perspective, where I personally see technology like GPT having the most value in the near term is where you help provide additional information rather than draw conclusions. A good example, technique-wise, is topic discovery, or summary statements to assess quick themes from otherwise very lengthy, and I’m sure legally, cleverly worded text. Visually, think of it like a word cloud, where certain words are emphasized in size and font — the words jump out at you based on their importance. Topic discovery has its own dimensions, such as who the conversation is with — a client is different than a counterparty or someone internally — and what the tone of the conversation is; a complaint is very different from angst, or a passionate debate over the most optimal lunch choice.
    When I look at how regulators have thought about this, there’s actually a speech from January 2017 from the SEC’s DERA office, the Division of Economic and Risk Analysis, where they give an example of applying another technique called LDA — latent Dirichlet allocation — to SEC registrant disclosures and filings, looking for possible emerging trends. The example was: now that you have hindsight bias, could you have predicted the rise of credit default swaps and the effect they had in 2008? What they saw was that in 1998, if I recall right, there were about three references by banks in their 10-K filings; six years later, over one hundred references; and between 2007 and 2008, a tenfold increase. So from a topic-discovery point of view, you’re finding emerging themes, words, phrases, or products you’ve never seen before that carry their own risks. That’s a natural segue into the tone of the conversation, and applying AI and NLP to provide assessments of emotional context rather than just substantive context.
    Lastly, I’ll say a couple of quick words on the importance of proper governance. I’ve introduced several experimental applications, and I want to caveat with a really strong importance on control and governance. All throughout, I’ve said this is applied on a supplemental basis, not a replacement or conclusive, consequential basis. Having the technology and techniques be aids, rather than conclusive without any oversight or supervision, makes all the difference. I know we’re going to talk later about the nuanced risks, but I wanted to throw that careful balance in earlier on. I’ll hand the mic back.
    David:Fascinating. Thanks, Stan. It’s fascinating that we’re still at the experimental, discovery stage of LLMs and what we can do with this technology today. Reflecting on the poll results — it looks like there are nine people at four and five, thirteen at three, and a lot of people still at one. So people are still figuring it out, which makes sense given the experimental stage. Cameron, now you’ve heard what Stan is doing. As a former FINRA regulator, what do you think — are there any coverage issues there?
    Cameron:Well, from a regulatory standpoint, there’s a baseline set of rules and regulations you have to comply with. I don’t think regulators are too interested in who’s experimenting with what technology, as long as they get coverage. That’s the baseline. When FINRA or the SEC or another regulator comes to call, they’re going to say, “Here’s the rule set; how are you complying with the rules?” Unfortunately, in my experience — and I should caveat that I don’t speak for FINRA; I’m FINRA adjacent, being recently retired — the regulators in the US generally don’t give great guidance on what to do. They don’t say, “Here’s a best practice, Stan’s doing this at Citadel, you might want to give him a call.” They say, “Here’s the rule set, you figure out how to comply. We’re going to come in and kick the tires, and you can explain to us what you’re doing and how it’s compliant.” It’s sort of like they wait for the plane to crash and then say, “Okay, you’re pretty screwed up.” That’s the way the regulatory world tends to work.
    A lot of these — and I come from a dark place, because I ran most of my career doing fraud investigations — you’ve got to have your coverage, but you’ve also got to have some system or techniques to identify holes in your coverage. So in your lexicon, using AI or other technology: what word was just introduced into a conversation in your investment banking department? If somebody throws out a word like “potato chips” or “being canned,” that could be an interesting one-off. It’s complicated for registrants to follow the rules, because they’re at the ten-thousand-foot level. And I’ll say this: the regulators are not expecting perfection. Absolutely not. So reasonable systems and techniques for the type of business you’re in are what they’re looking for. And you should be able to explain that in common, fifth-grade language, if I was giving advice — because overwhelming the regulators with technology and tech talk is going to go over their heads. That’s not to say FINRA and others aren’t tech-savvy; they are. But the people actually enforcing the regulations need it explained to them in compliance-oriented language.
    David:That makes sense. People are people, and I’ve heard you loud and clear that regulators just want assurance that you’re working on risk — perfection is not necessary. So from your perspective, what opportunities do you see for AI in e-comms to ultimately reduce market risk?
    Cameron:Obviously, the more data you have and the better techniques, the better results. If you had to hire someone to watch the market all day — which I did early in my career, watching the market with a very rudimentary computer — it’s impossible. So the more technology you can throw at it, and the better data you have, with governance, it’s unquestionably going to add value. It’s just a question of how you tune that engine to produce meaningful results, and Stan spoke to that. A lot of surveillance systems are very sensitive and produce a lot of noise, so you end up eating up a lot of resources telling yourself “that’s not important.” And from an audit standpoint, regulators are going to want to come in and see the results and what you’re doing with your anomalies — what are you producing, how did you resolve it, what’s your audit trail? The better results you have, the less time you spend resolving things that aren’t meaningful, documenting them, and explaining them to regulators.

    Is It More Than a Buzzword?

    David:Thanks, Cameron. Shlomit, you might be the smartest person in the room — a lot of PhDs lying around. You have a lot to say about what’s being said out there about LLMs and their uses. So in your perspective, is AI, ChatGPT, large language models — are these just buzzwords, or how is AI truly reshaping e-comms compliance?
    Shlomit:Definitely not just buzzwords. I think the main effect that’s occurred in the world since ChatGPT was revealed is that now every person can feel for themselves the capabilities of AI. Large language models have evolved over the past few years and have existed for three to four years in the market. But now, since the emergence of ChatGPT with the general public, everybody knows and feels how good an AI solution can be — and it was shocking, I think, all around the world. You all hear the news and the predictions about the effects of ChatGPT on the world. I think the effect is true and meaningful; the technology is legit.
    Having said that, and referring to the poll you just made, we can see that it’s not easy for organizations to adapt to this technology. It’s existed for a while, and still most organizations are somewhere in the middle in adopting new and advanced AI. Some of that relates to what Cameron was explaining about the heavily regulated industry and the way systems are evaluated and need to be explained to regulators. But on the other hand — and I truly believe this — since people are getting used to this technology, it will be a must-have in any future solution. If you can do it in your own home, if your grandmother can ask ChatGPT something and get an answer, if a kindergarten child can ask something on a cell phone and get answers — why can’t you do it on your communication data?
    I can also refer to everything Stan mentioned about the challenges of this industry. First, the volume of electronic communication is just growing with the growth of technology, and the ability to solve it with older methodologies is not available anymore. But there’s a different challenge too: with the ability of new technologies, we want to solve more challenging problems. Why do we have to satisfy ourselves with detection of compliance issues? We want to be able to predict them. This is a more sophisticated and subtle issue to solve, and you need more robust tools to do that. So for solving such challenges, you’ll definitely need to adopt more sophisticated technologies.

    Explainability and Regulators

    David:Thanks, Shlomit. Reminding everyone: if you have any questions for Stan, Cameron, Shlomit, or just in general, hit the Q&A button below and shoot that question over. Cameron, if it’s more than just a buzzword, I’m going to assume we’ll hear more about regulators responding to emerging industry uses of AI in monitoring. One thing we hear a lot about is explainability in the models — we want to make sure we can talk to regulators about what we’re doing. What are your thoughts?
    Cameron:I think explainability is an important aspect of communicating with regulators. You’re going to need to explain what you’re doing, why you’re doing it, what data governance you have, and what data sources you have. I think you’ll find that regulators will be skeptical — you’re a born skeptic when you’re a regulator. So when they come in and start asking questions, they’re going to want to actually see results. And let me mention something about predictability of compliance issues: that would be amazing if you showed examples of it, because what regulators tend to do is respond to a crisis. If you can get ahead of a crisis and report that to a regulator, amazing. A problem that exists with a product — particularly one that may impact retail investors — is a problem that exists across the industry. So if you can get ahead of it, protect other firms and investors, and give the regulator the heads up, that’s absolutely amazing, and I’d encourage you to use your techniques to identify things quickly. Eventually, these problems always emerge, because it’s the financial industry — money’s going to be lost and somebody’s going to be harmed. So getting ahead of it would be fantastic. Let me raise a point, though: if the technology gets to the point where you have some predictability, remember you don’t know what you don’t know. That’s why I say expectations from regulators are not perfection — but if you improve from not being perfect to better, fantastic.
    David:I like what you said about that shift from playing defense to playing offense — if we can take a new approach that lets people know what’s going on in their own organization versus finding out from someone external, that’s a major shift. Shlomit, implementation concerns are certainly something we hear from our customers. Can you speak to why implementation is so difficult with these models?

    Implementation Challenges: Security, Explainability, and Hallucinations

    Shlomit:Yes. One of the first challenges — with several of the newest solutions, ChatGPT included, but also the Google models — is a security issue: can we send our data over to open APIs? This is a major concern for some of the financial industry. But I think these issues will be solved; new models that don’t require such APIs will emerge eventually, and some are already out there being experimented with. The second main concern, which Cameron referred to, is explainability. And it’s important not only for the regulators — the phrase “you don’t know what you don’t know” is very much to the point. For example, I ask ChatGPT and get an excellent answer. Is it correct? Isn’t it? What do I know, and what don’t I know? Models include a lot of unknowns, and some of the new ones are able to actually invent information, so this is something we should be very careful about.
    A small story: I have a son working toward his final exams in high school. He was asked to produce a final history paper, and his teacher told him he could use ChatGPT if he wanted, but to beware — if he gets any biography references, he should double-check them in Google, because they might be fake. So we’re in a world of having a great technology, with real abilities to do things we couldn’t do before, but we really need all the checks and balances in place to make sure we know what we have, we know what we miss, and we know that what we’re producing is actually correct and valid.
    David:Sounds like ChatGPT also picked up on that human trait, “fake it till you make it.” That’s a very interesting example. With any new technology, the human part of its use matters — it’s a tool, a supplementary tool. At some point, what is it doing for you, and how can you prove and defend that value? Thanks for that story. Stan, we’ve all agreed there are opportunities for AI in surveillance, and Cameron mentioned the skepticism necessary as we move forward at breakneck speed. What controls do you see as key for this forward motion?

    Controls, Governance, and Change Management

    Stan:Yes, David. Since you kicked off with a tennis analogy, I’ve been thinking how to circle back to it. I have a colleague who likes to change his racket every single week — he’s been doing that for about a decade, and his game has not gotten any better. At some point you’ve got to face the reality that the problem isn’t the racket or the tooling, it’s probably more the player. A lot of the pain points you’re hearing are problems manifesting in the firm itself, as opposed to a vendor technology. The vendor can’t magically fix the problems internal to your firm — oftentimes it doesn’t even see them until the initial engagement or later, toward integration, and then teams realize, “How do we fix this?” when their firms have been around fifty-plus years.
    So the control aspect really gets to the heart of change management, which I know isn’t pleasant to hear, because it arises in essentially every facet of organizational operation. We saw a case probably in the last couple of weeks where lawyers are now facing sanctions for using GPT to write a motion in court, and the citations cited — similar to Shlomit’s warning from the professor — were all made up. Some people refer to this as AI hallucination. But I want to be careful with buzzwords, because there’s a lot of hype here. What this really is, is a design problem. When you think about control, you should be thinking about design and transparency into that design.
    In layman’s terms, the algorithm probably has some decision path for “what do I do when I’m not sure?” And that assumption — that it needs to have an answer — is already pretty dangerous, and important to ask about. One answer is to defer to the human — that’s where you get reinforcement learning or semi-supervised machine learning, where an exception is thrown that says “I’m not sure,” or “here’s my confidence interval on this response,” which lets a human dig in. Right now, none of that really exists; the machine just continues to operate, because it doesn’t want to fail over. It ends up giving you an answer, and if you take it for granted, you can see the types of issues that arise.
    From a communication surveillance perspective, none of this is actually new — it’s just that now you’re coming to terms with these hidden risks. Some very classic things: what happens if you get someone with a hyphen in their name, when the algorithm thinks names are just “John space Smith”? What happens when you get two people with the same name — does the algorithm think, “Wait, I’ve already processed this before, this must be an update, let me overwrite it”? Consequently, that second person, or possibly the first, is no longer supervised, and you have a much bigger problem. So you have to study the black box and focus on it from a change-management perspective: what’s the initial design, what are the changes to that design, and look at the testing conducted — unit testing, integration testing. A lot of people don’t like to hear that ninety-five percent of the work is going to be writing tests, and the other five percent is the fun optimization, but that’s the reality when you’re in a regulated business.
    One other thing: let’s unpack the word “regulator,” because it’s no longer just FINRA or the SEC. The FTC is looking at it, the Department of Labor, pretty much every state regulator from a data-privacy perspective. If your product has any retail-facing arm and utilizes AI — especially from an insurance, credit, or banking perspective — that’s going to be in scope. So now you have to study the views of approximately a hundred-plus different agencies, all focused on this. And if one agency is more progressive in this regard, even if they’re not your regulator, I guarantee your regulator is looking at them too, and you’re going to get the same questions. So it’s paramount to focus on this day by day, because that’s the pace of evolution.

    Conflicts of Interest and Insider Threats

    David:That’s a really good point, Stan. Thank you. I want to shift the conversation to different, practical approaches. Cameron, how should firms approach potential conflicts of interest when implementing AI in their surveillance systems?
    Cameron:Before I answer, I have to tell one quick story that Stan made me think of. This is the danger of building these systems. A long time ago, there were message boards out there talking about stocks, and we were trying to figure out the lexicon, so we said, “Let’s put every symbol into the system and see what pops out,” because we were concerned about these message boards. We ended up with about ten million “yard sales,” because one stock was YARD. So your lexicon has to be careful, because your machines could produce results so overwhelming that they’re useless — the hyphen problem, and with lots of similar names, you get every John Smith in the world. It’s an expensive lesson to learn.
    In terms of conflict of interest, there are a lot of opportunities, especially in communications surveillance. Your data has to be set up depending on the type of firm you have. If you’re a full-service retail and investment banking firm, you’re going to have buckets of people playing different parts of the game, some regulated differently — information barriers, and the sharing of information across those barriers. Investment banking communications clearly have a lot of material non-public information floating around. I’ve done probably forty thousand insider trading investigations in my life, and I can assure you that continues to be a very target-rich area for regulators. On the retail side, I’ve been reading about AI doing suitability analysis and targeting messaging to clients on products that might be suitable for them. Sounds good — until they’re unsuitable, and you find that out through an arbitration or lawsuit. So the data being fed and the actual customer have to be analyzed and scoped properly.
    The other thing I’d mention, as a warning — and again, I come from a dark place — is that one hundred percent, no matter what you’re doing, there are people out there, possibly within your own domain, trying to defeat it. That’s why I say perfection isn’t expected, but be aware that the insider threat is real. People always talk about external hacking, but you have to make sure you have governance around your policies, procedures, and access to prevent insider threats. If I had advance knowledge of whatever Citadel’s trading big today, I’d probably not be sitting here — I’d be trading. So there are lots of conflicts, obvious ones people recognize once you say them. Don’t overthink conflicts; dumb it down and ask, literally, what would the common person want to steal from us?

    Integration Gotchas: Data Provenance and Sub-Vendors

    David:Good answer. Thank you, Cameron. Stan, how have you dealt with AI integration? Are there any potential gotchas or challenges firms should be aware of when they start to integrate AI into their operations?
    Stan:I don’t think it’s a gotcha — a lot of this is pretty anticipatory from the beginning. As I said, don’t blame the racket, blame the player; focus on yourself to improve your own game. Let’s go back to the SEC DERA speech from January 2017, before GPT. You’d think the answer to this would be, “It’s very hard to code these clever algorithms.” The answer is actually much simpler and more surprising: registration filings are still on paper. The answer is we should get them electronic, and then have a uniform schema for how people provide the filing information. Really simple. It’s like when people look at pyramids and go, “Wow, what a beautiful structure, how did you create that?” Ninety-five percent of it is laying brick by brick in a very careful, deliberate manner — pretty mundane work, but very important for consistency.
    The analogy applies a lot to firms internally. In my opinion, the preparation and safekeeping of data in a consistent manner is ninety-five percent of the work, and the remaining five percent — what I call optimization — is the AI answer people typically expect. A lot of firms overlook this and rush to vendors looking for explanations of their own data problems, and vendors don’t have control over that. Here’s a simple example: go to HR after this and ask how many different titles they have for people in the firm. If you have a company with fifty people and you’re getting an answer of a hundred, that’s problematic. Even if the answer seems okay for your size, tell them you want to analyze communications by role — say, find all the people who are traders — and see what they come back with. If they come back with, “We have twenty-three different titles for the same function,” that’s a problem. And an interesting question is: who actually owns that data? Is it HR maintaining employee records? The business hiring these people? The person writing the contract? At minimum, you want transparency, because if you’re going to use that data now or down the line — and very likely you are — you have to know whether it’s in the format you need. If it’s not, it’s not going to be usable, and the vendor is not going to solve that for you.
    One other thing, more of a story from the wider world: it’s really important to map out dependencies, or sub-vendors. We’ve been using the word “vendor” for granted. When a communication surveillance vendor comes in, they’re going to be surveilling messages like Bloomberg — that’s a whole separate vendor, or sub-vendor — and similarly for iPhone messages and WhatsApp, each carrying their own data policies and attributes. This creates multiple points of failure: one, the organization; two, the surveillance vendor ingesting all this; and thirdly, the underlying sub-vendor. So if I leave you with two words from this entire question, it’s data provenance — understanding where this information is coming from, how it travels, who touches it, where it changed, and if it changed to a way that’s now incorrect, how and when are you alerted? I kind of hate to give fifteen questions in response to a question, but this is the reality, and welcome to having to build a pyramid.

    Where AI Is Headed Next

    David:That’s a great answer, Stan. Cameron said you don’t know what you don’t know, but you definitely don’t know what you don’t have and can’t make sense of — that’s a nonstarter. With all we’ve covered so far, I know this is enough to keep us all busy, but I’m curious — any thoughts on AI in terms of where it’s going to help us do next?
    Shlomit:Okay, so maybe we can start with even keeping us at the same level we were a year or two ago — we’ll need to use more advanced technology. As mentioned, the volumes of electronic communications are constantly growing, so we have to have more accurate systems in place. We cannot constantly increase the number of people reviewing false alerts. Second — and Cameron mentioned this — we’re dealing with people trying to manipulate the system, the ones we’re trying to catch. Say you have a lexicon solution and you put in phrases like “don’t text me” or “don’t WhatsApp me.” It will take one or two months, and the surveilled employees will be familiar with those phrases; they’ll vanish from communications. Will the behavior stop? No — but they’ll make sure you can’t monitor it the same way you used to. That’s why our solutions need to be growing solutions, sensitive to nuances in language, able to detect different phrasings of the same idea, and not allow humans to quickly cheat the system. This is the great advantage of large language models. So as a first ground rule, even just to stay where we are today and detect the same risks, we’ll need more advanced technologies.
    In terms of the future of AI, I think what’s happening in the world today is really a revolution. The main thing that’s happened is that people are getting more and more used to being able to use free language to question complicated systems. If I’m a compliance officer, I don’t want to collect sets of rules or lexicons, or connect to different databases and set queries just to get information. I want to present the question in a human manner and — we call it — chat with my own data, in free-text language. I think the technology is going to enable that in the very near future, if not today. The second thing for the next generation is models evolving to do more than just answer questions — to connect different tools and systems. So instead of putting in place a sophisticated system to handle the vendor, the data source type, HR data, and everything manually, different models doing different tasks will be able to talk to one another. I’ll be able to chat in free text and also get something to create a sophisticated query or rule for me and collect the data the way I need it. So to sum up, we’re facing really exciting times, and from my point of view, great times to be in.

    Audience Q&A

    David:Very cool. You’re in the front-row seat to all this. I have a question for Shlomit: how do you deal with people using emojis or pictures — something that’s not language? Is there a way to surveil for that, and is it meaningful?
    Shlomit:Oh, definitely. Emojis are part of our language. Old-fashioned solutions treat words as a trigger — that’s just one way of looking at the data. The more advanced models look at emojis, and we do it ourselves as well, of course, along with all kinds of data sources — if we have pictures, if we have voice, all kinds of hints and layers and types of information added to a communication. They should be analyzed with a model that knows those input types. This is becoming more important, because the younger generation isn’t talking in words anymore — they’re talking in pictures, emojis, and other symbols that are different from what we used to use. It definitely needs to be incorporated into any kind of solution.
    David:Very cool. Cameron, we’ve got a question from the audience: how can firms ensure AI and LLMs are used ethically in compliance and surveillance?
    Cameron:Oh, that’s a really great question. The answer is, I don’t know exactly how it could be formulated, but you have to think about it from the standpoint that it would be an important aspect of your employee agreement — that you act ethically and only in the business interest. Let’s use Stan’s example: the SEC did some lexicon search, or saw a trend in filings where credit default swaps were mentioned. Say in your own world of communications you had access to a trend in a product, a target, or an investment, and one of your employees leaked that information to somebody. That would clearly be unethical. But I don’t think people really think about it that way, because ethics is “you know it when you see it.” So you’d want to think about your business, what the vulnerabilities are in terms of opportunities for employees to extrapolate information and use it improperly — and train them. You cannot over-train people, and there are enough real-world examples of misfires, cases brought by the SEC and FINRA — use those to train people. Regulators are impressed when you have a training cycle, documented and relevant, not just a stale guest speaker talking about stuff that happened three or five years ago. This stuff is rapidly changing. The other thing that always comes to mind is people who are leaving your firm — what are their ethical obligations? You have this concept of bad leavers: people who are leaving, for whatever reason, and are going to cause chaos. Not everybody who’s leaving is happy with you, so be careful of bad leavers, and put things in place to monitor people who are leaving.
    David:Some really good examples and ideas. Thank you. Stan, I’ve got a question here: what strategies can employers use to upskill current employees to work with AI?
    Stan:There are a lot of free resources — edX, Coursera. Quite frankly, literally Google it and look for introductory courses, to understand how it’s being utilized and where it came from. This stuff isn’t all groundbreaking in the sense that you’re in an entirely isolated place; understanding the history will help you get grounding, and then understanding the context all this technology works in will be key. This isn’t one of those “immediately go set up Python courses and be coding tomorrow” situations — that’s not what you should be rushing to. Take it carefully, but there are a lot of free resources for understanding how this comes to fruition, how it’s architected, and the risks associated with the activity. It’s really important not to have your head in the sand — you essentially have constructive notice right now that a lot of firms are experimenting with this, and pretty much everyone and their family members have been talking to a chatbot. The more you come to grips with evolving and emerging tech and interact with it yourself, the more you’ll start to see the faults, weaknesses, and advantages, which gives you really good context when you speak to the business. But I strongly encourage taking some introductory classes, which again are free, and using that to reform your firm training. People find that a more interesting approach than off-the-shelf material developed by some other vendor. I give this analogy: if you’re in the financial industry and your training presentation has a character with a construction hat on, that training is probably not well suited to the activity you’re engaged in.
    David:Thank you, Stan. Good to make sure whatever we’re learning actually seems directed at us and makes sense for what we’re trying to do. Last question, as we’re getting toward time — Shlomit, what advice do you have for firms that are skeptical of integrating AI?
    Shlomit:This is a good question, and there are a lot of firms that are skeptical. I tend to say the proof is in the pudding — results are the measurement you need to make sure are good for you. A second suggestion is to request and ask for all formats of explanatory models, model governance, and bias evaluation, to make you more confident in your ability to use it. But I think it’s already common knowledge that AI can do better; for those who are hesitant, just ask to test it and see if the results are really better for you. I’m sure that if the solution is implemented correctly, you’ll find that it is.
    David:That’s a good answer. It’s certainly being used in so many use cases. You’ve actually mentioned to me a number of times, Shlomit — every time you go through passport control in a country, there’s an AI scanning your face, and depending on the country and setup, you’re relying on it almost fully.
    Shlomit:Every skeptical person is looking at their phone and expecting it to recognize their face. So think about that the next time you say no to AI.
    David:That’s a good point. Thank you.
    Stan:David, if I could also add to Shlomit’s answer — going back to the previous question, the mention of the word “framework” is really important. The Federal Reserve just published updated commentary on Model Risk Management, and there are a lot of frameworks available that look at AI, change management, and technology governance in general, that are really effective training material for any firm. They’re written in a way that anyone should be able to pick up and understand. I highly encourage looking at it from that perspective. I’m pretty sure FINRA has also published on this.

    Closing

    David:Yeah, thank you, Stan. I just want to wrap up with a short anecdote I was thinking about earlier in the week. Imagine you’re running to get to a train and just barely miss it, so you’re frustrated, sweating, losing your breath. You wait for the next one, and finally it arrives — except it’s not a train. It’s a hypersonic vehicle that takes you home in half the time. That sounds nuts, but that’s basically what’s happening right now with AI and compliance, and really any industry. What you can do changes every time you look at the news again. If you’re paying close attention, every day there are new companies popping up with whole new use cases, and a lot of them are really good. So the question isn’t just about the best model or tool to use now, but how we can position ourselves to adapt and leverage the next wave of technological advances. That level of opportunity is a fundamental part of why our guests today, and many others, are focusing on AI, and particularly ChatGPT and LLMs.
    Thank you to our panelists, Stan, Cameron, and Shlomit. Your insights provide us with a real, nuanced understanding of how AI — and especially ChatGPT and large language models — is reshaping the world of financial e-comms compliance, and how you can effectively leverage it to control risk. Thank you to everyone who joined us today. We hope this discussion has challenged your thinking and sparked curiosity. As the conversation around AI and compliance continues to evolve, we invite you to stay engaged, ask questions, and continue learning.
    Now, just a quick word about Shield: the Shield platform is built with modern architecture designed to deliver actionable insights about risk to stakeholders throughout your organization. It’s engineered to adapt to the fast pace of technology, ensuring you’re always ahead of the curve. We invite you to learn more by visiting our website and reaching out to our team of experts. In closing, the rise of AI in financial services e-comms compliance is an exciting journey, and one we’re thrilled to be a part of with all of you. We hope to see you at our next webinar. Thank you all, and have a great day.

Q&A

Is AI in compliance just hype, or is it real?

It’s real. Large language models delivered a genuine breakthrough in analyzing free-text human conversation — the core challenge in communications compliance. They’ve existed for three to four years, but ChatGPT made the capability tangible to everyone. The panel’s view was clear: this isn’t a buzzword but a fast-emerging must-have, because once people can query AI at home, they expect the same power applied to their communications data.

Should AI replace our current surveillance system?

No — treat it as a supplement, not a substitution. The panel was emphatic that AI works best providing additional information, like topic discovery and tone analysis, rather than drawing conclusions on its own. Keep it experimental and under human oversight, with governance around every output. Techniques should be aids, not consequential decisions made without supervision — that distinction, they stressed, makes all the difference.

What do regulators actually expect if we use AI?

Coverage, results, and explainability — not perfection. US regulators rarely prescribe best practices; they hand you the rule set and expect you to explain, in plain language, what you’re doing and why, plus your data sources and audit trail. And “regulator” now reaches beyond FINRA and the SEC to the FTC, the Department of Labor, and 100-plus state privacy agencies watching how AI is used.

How do we deal with AI “hallucinations” and wrong answers?

Treat it as a design problem, not magic. Models can invent information — one panelist’s son was warned by a teacher to Google-check any ChatGPT citations, and real lawyers were sanctioned for filing fake AI-generated case references. Build in transparency, confidence scoring, and a path for the system to flag “I’m not sure” to a human, rather than always forcing an answer it can’t support.

Why do AI compliance projects stall at implementation?

Usually it’s your own data, not the vendor. The panel estimated that 95% of the work is preparing consistent, well-governed data and only 5% is the AI itself. A revealing test: ask HR how many job titles exist — if a 50-person firm has 100, or 23 titles for one function, that mess will break your surveillance. Vendors can’t fix internal data problems for you.

Can AI catch people who dodge keyword monitoring?

Yes, and that’s a key reason to move beyond lexicons. Once employees learn the trigger phrases — “don’t text me,” “don’t WhatsApp me” — those words vanish within a month or two, but the behavior doesn’t. Large language models detect different phrasings of the same intent, and can analyze emojis, images, and voice, not just words — increasingly important as younger users communicate in symbols.

How do we evaluate an AI vendor and prove it works?

Test it — the proof is in the pudding. Run a proof of concept and judge it on results, then request model governance, explainability, and bias-evaluation documentation. Remember the panel’s tennis analogy: don’t blame the racket, blame the player. Fix your internal data first, and map data provenance across every sub-vendor (Bloomberg, WhatsApp, iPhone), because each one is a potential point of failure.

How do we get our team ready to work with AI?

Start with the basics, not a coding sprint. The panel recommended free introductory courses on edX and Coursera to understand AI’s history, context, and risks, then building your own training around them rather than using generic off-the-shelf material. Lean on published frameworks — the Federal Reserve’s Model Risk Management guidance and FINRA materials — which are written for non-specialists to pick up and apply.