6 Lessons From XLoD: Rethinking Surveillance for the AI Era
I left XLoD Global-New York with one overriding impression: The conversation around surveillance has changed. Financial institutions are moving from more monitoring to better intelligence.
They are asking how surveillance programs can keep pace with more data, more channels, more sophisticated risk and, increasingly, AI, without simply adding more people, more processes, and more noise.
That shift was visible across XLoD. The official agenda brought together leaders spanning the first, second, and third lines, with discussions covering evolving risk and control operating models, market abuse surveillance, control automation, data and analytics, AI and technology.
Across those conversations, six themes stood out to me.
1. The Three Lines Model Is Evolving
One of the more interesting debates was around the Three Lines model itself.
The fundamental principles remain important: clear accountability in the business, independent challenge from the second line, and assurance from the third. But there was also a challenge to the idea that organizations should design every aspect of risk management around rigid organizational boundaries.
The question is increasingly: “How do we collectively manage this risk effectively while maintaining clear accountability and independence?”
Financial institutions are under pressure to operate more efficiently, and simply adding people and controls every time the risk landscape expands is not sustainable. The opportunity is to remove unnecessary friction while maintaining and strengthening the controls that matter.
The future model, therefore, looks less like three isolated lines and more like a connected risk ecosystem: distinct accountability, but better information, shared context, and stronger collaboration.
2. Surveillance Is Becoming a Business Risk Capability
Surveillance has historically been viewed primarily as a compliance obligation, but that is changing.
The discussion at XLoD positioned surveillance as part of a broader business risk management capability: one that helps institutions understand behavior, identify emerging risks, and make better decisions.
That changes how we should measure success. The questions need to be: Is our surveillance effective? Can we identify meaningful risk earlier? Can we understand why something happened? Can we connect signals that would otherwise remain isolated? Can we demonstrate that the controls are actually working?
That is a significantly higher bar than simply proving a surveillance process exists.
3. AI Is Changing the Job of the Surveillance Analyst
Naturally, AI was everywhere, but one of the most important conversations was about what AI means for the people operating surveillance programs.
For years, surveillance analysts have spent enormous amounts of time processing queues of alerts, many of which ultimately prove irrelevant. AI creates the opportunity to change that operating model. The surveillance professional of the future looks less like an alert processor and more like an investigator. AI can support detection, prioritization, first-level review, contextualization, and investigation.
At the same time, human expertise moves higher up the value chain. Analysts can spend more time understanding the market and the business, connecting signals, and making the judgments that require human expertise.
This also changes the skills institutions will need. Someone who understands the nuances of a particular asset class, market, communication pattern, or behavior will be able to use AI far more effectively than someone simply processing a queue.
4. Efficiency Is Important, but Effectiveness Is the Real Prize.
There was a lot of discussion around reducing false positives, automating first-level review, and allowing institutions to do more with constrained resources. But focusing exclusively on efficiency risks missing the bigger opportunity.
The most interesting question I heard during the day was essentially: If AI frees surveillance teams from a significant amount of low-value work, what could they start doing that they cannot do today?
Imagine teams spending less time closing irrelevant alerts and more time investigating complex behavior. Imagine bringing communications, trades, historical behavior, participants, and other contextual information together, rather than examining each risk signal independently. Imagine looking across surveillance programs for patterns that no individual rule or model was designed to detect.
The goal should not simply be to process the same surveillance program faster; it should be to make the surveillance program better.
5. Before AI Comes the Foundation
There was also a healthy dose of pragmatism around AI. One comment captured it particularly well: If the foundation of the house is not sound, don’t start building the pool.
The analogy applies perfectly to surveillance, because AI is only as useful as the infrastructure and data beneath it. Incomplete communications capture, fragmented archives, poor data quality, disconnected systems, or weak governance do not disappear when AI is introduced. In many cases, AI makes those weaknesses more consequential.
This makes data integrity a strategic surveillance issue. Institutions need to know what data they have, what they may be missing, who owns it, whether it is complete, and how it moves through their surveillance environment.
And as AI becomes embedded into that environment, another layer of governance becomes essential. It includes explainability, testing, model validation, performance measurement, version management, data protection, independent assurance, and human oversight. AI adoption and AI governance cannot be two separate conversations.
6. MCP Could Become the Bridge Between AI and the Compliance Ecosystem
One topic that surfaced repeatedly at XLoD was Model Context Protocol (MCP). The significance of MCP for surveillance is the possibility of giving AI-governed access to the systems and context that compliance teams already rely on.
Today, much of that context remains fragmented. Communications sit in one place, alerts in another, and archived records somewhere else, with trades, policies, investigations, and other relevant information spread across additional systems. Investigators spend valuable time finding and assembling that context before they can make a judgment.
MCP could help change that by creating a standardized way for AI applications to interact with governed enterprise systems and data sources.
For surveillance, that opens up a much bigger opportunity: moving from AI that analyzes an isolated alert to AI that can help investigators connect the dots across the compliance ecosystem. This brings together communications, historical activity, relevant records, and other risk signals to build a richer understanding of what happened and why.
It also creates a bidirectional governance opportunity. AI can access authorized compliance context to support investigation, while the interactions with AI itself become communications that institutions may need to capture, govern, and supervise.
As AI becomes embedded across financial institutions—and as we move toward more autonomous and potentially agent-to-agent interactions—this connectivity will become increasingly important.
The future is about securely connecting AI to the right context, with the right permissions, governance, and human control. MCP could be an important part of making that possible.
From Reactive Surveillance to Continuous Readiness
Perhaps the biggest takeaway from XLoD New York is that the surveillance conversation is moving beyond detection. Financial institutions are being asked to cover more channels, understand more complex behaviors, manage rapidly evolving technology, and demonstrate effectiveness—all while facing continued pressure on resources.
The answer requires better data, intelligence, integration, governance, and technology that allows human experts to focus their attention where it matters most.
For me, that is what readiness looks like. It is creating a surveillance environment that adapts as communications, behaviors, regulations, and technology change, while keeping people in control.
Ready is the state. Human control is the standard. Agentic intelligence is the multiplier. That was my biggest takeaway from XLoD New York: The future of surveillance is about understanding more and being ready to act.
Related Articles
Lexicons, LLMs and AI Agents in Communications Surveillance: A practical guide to designing, testing, governing and modernizing communications surveillance using lexicons, LLMs and agentic AI
Subscribe to our newsletter
Gain access to exclusive insights, industry influencers, and thought leaders in
Digital Communications Governance and Archiving (DCGA).