Why AI Programmes Stall the Moment Someone Mentions Compliance

Referring historical data to legal looks like diligence. More often it is a way of avoiding a decision nobody owns.

Ask an organisation that is investing seriously in AI what the plan is for its historical data, and watch what happens next.

Someone says they will need to check with compliance. Compliance says it needs to go to legal. Legal is looking at it. Weeks pass. The question does not come back, and the AI programme carries on regardless, building on whatever information happens to be convenient.

I have spent nearly thirty years working with organisations and their information, and this particular sequence has become familiar. What makes it interesting is that nobody in the chain does anything wrong. Nothing is refused. No one is obstructive. And yet nothing is decided either.

The referral is not a decision

To be fair to everyone involved, the caution is not irrational. Historical information carries genuine complexity. Different categories of records attract different retention requirements, privacy considerations, access controls and commercial sensitivities. Getting that wrong has consequences, and legal teams are paid to notice as much.

But look at what has happened structurally. A strategic question about what the organisation wants its AI to know has quietly been reclassified as a legal risk question. Those two framings produce very different default answers. A strategy question defaults to “what is the opportunity and what would it take?” A risk question defaults to “not yet.”

The referral feels like progress because it produces activity. It is not progress. It is the point at which the subject leaves the AI programme and does not return.

Historical data is the only part of the programme with no owner

Every other component of an AI investment has someone whose job it is. The platform belongs to the CIO or CTO. The models and pipelines belong to the head of data or AI. The use cases belong to the business functions demanding them. Budget belongs to whoever signed it off.

The historical information estate sits across legal, compliance, technology, information governance and operations at once. It is everybody’s concern and therefore nobody’s responsibility.

I asked a CIO recently what the plan was for their historical data, shortly after a substantial AI budget had been approved. There was no plan. That was not negligence. It was simply not anyone’s job, and it had not occurred to anyone that it should be.

When a question has no owner, it drifts towards whichever function is least able to refuse it. That tends to be compliance – which is unfortunate, because compliance is structurally designed to answer a different question altogether.

Retention answers a question nobody is asking any more

Retention policy exists to establish what must be kept, why, and for how long. It was built to manage obligation, risk and storage cost, and it does that job perfectly well.

AI asks something else entirely: How can appropriate historical information safely generate value?

Nothing in a retention schedule addresses that. A schedule can tell you a category of records must be held for seven years. It cannot tell you whether those records are searchable, whether the context that made them meaningful was ever captured, whether provenance can be established, or whether it is appropriate for a model to retrieve them when answering a question for a member of staff.

So compliance answers the question it was asked, answers it correctly, and the answer turns out to be beside the point. The organisation is compliant. The information is still unusable.

Compliant is not the same as AI-ready

This is the distinction that gets lost, and it is worth stating plainly. An organisation can comply fully with every retention obligation it has and still hold an estate that AI cannot meaningfully use.

Readiness asks a different set of questions. Can we find the right information? Do we understand what it represents and how it relates to other records? Has the context survived, or was it only ever in the heads of the people involved? Can we establish where something came from? Can we control what may access it, and trust what comes back?

Format, classification, metadata, context, provenance and governance all determine the answers. None of them are compliance questions. They are strategic data questions wearing compliance clothing, which is precisely why routing them to legal closes a conversation that ought to be opening.

Ask a question that can actually be answered

There is a further reason these referrals stall, and it is the one I would encourage any CIO or data leader to sit with.

The question usually gets asked in a form nobody can answer. “Can we use our historical data for AI?” is unanswerable. The scope is unbounded, the purpose is unstated and the risk is unquantifiable. Faced with that, the only responsible legal answer is to keep looking at it. The deferral is not obstruction; it is the correct response to a badly framed question.

Narrow it and the whole dynamic changes. Choose one AI use case that genuinely matters to the business. Identify the specific categories of historical information that use case would need. Establish what condition those records are in, who they concern and what they were originally created for. Then ask whether they may be used for this defined purpose, under these controls, for this audience.

That is a bounded question with a stated purpose, and it is the sort of question legal and compliance teams answer competently every week of the year.

It also changes who is in the room. Alongside the lawyers, you need the people who know what the records actually are, what state they are in, and what context has already been lost. Those people are rarely invited to AI strategy discussions, and they usually know more about the organisation’s institutional memory than anyone else in the building.

The organisations that get this right will not be the ones with the most permissive legal departments. They will be the ones that stop treating decades of accumulated information as a risk to be cleared and start treating it as a decision to be made, deliberately, one use case at a time, with governance designed in rather than requested afterwards.

Someone has to own that decision. In most organisations, at the moment, nobody does.

Which brings me back to the question I keep asking. Can you really have an AI strategy without a historical data strategy?