Disclosure: we are Fortitude Media and Compliance Guardrails is our add-on, so we have a side. This page is not legal or regulatory advice; it describes controls, and your compliance officer remains the judge of what your firm can run.

Last checked: 20 July 2026.

The short answer

Yes, regulated firms run AI departments, and the sensible ones do it with three controls in place: locked approval modes (chosen action types can never run without a human), rule checks before any action queues (your sector's dos and don'ts applied to every draft), and an audit trail built for a compliance review rather than for a demo. That is what our Compliance Guardrails add-on does on top of any department, for firms in financial services, insurance, legal, healthcare-adjacent and other supervised sectors. The honest boundary: an AI department drafts, routes, logs and handles the routine; it does not give regulated advice, and anything that constitutes advice stays with your qualified people, permanently.

The worry, stated properly

A compliance officer's objection to AI is rarely about technology. It is about three specific failures: an unapproved statement reaching a customer (a promotion that was not signed off, a claim the firm cannot stand behind), an advice boundary being crossed by software that does not know where the boundary is, and an audit that cannot be passed because nobody can show who said what, when, or why. Any AI vendor who answers these with "our model is very good" has not understood the question. The answer has to be structural: make the failure impossible by design, not unlikely by quality.

What Compliance Guardrails locks down

Approval, structurally. In every department, AI Assisted mode queues actions for human approval. Guardrails goes further: your firm chooses action types that are locked to Assisted permanently. Not "we recommend you keep approvals on", but a setting your compliance officer controls and we cannot override. Customer-facing statements about products, anything touching money, anything near the advice line: locked, forever, if that is your rule.

Checks before the queue. Every draft passes your sector rules before a human even sees it: banned phrases, required wording, disclosure lines, sign-off routing by topic. A draft that fails a check does not reach the approval queue with a warning attached; it gets rewritten or escalated. The rules come from your compliance manual during onboarding, not from our guesses about your sector.

The audit trail. Every action, in every mode, logs the inbound trigger, the draft, the checks applied and their results, the human approver where there was one, and the timestamp. Exportable, searchable, and formatted so that the person reading it is assumed to be your compliance officer or your regulator, not our support desk.

The advice boundary. Departments are configured with an explicit list of what must never be answered, only routed. "Should I move my pension?" gets a warm, immediate, compliant handover to a qualified human, logged. The AI's job at the boundary is to be excellent at knowing where it is.

What this looks like per department

Department Routine it handles What stays human, always
Inbound Answering, qualifying, booking, message-taking Anything constituting advice; complaints routing per your process
Customer Care Status queries, documents, appointments, the routine two thirds Complaints, vulnerable customers, advice-adjacent questions
Outbound Calling Quote chases, renewal reminders, callbacks on your script Any call your rules define as a regulated conversation
New Business Research, drafting, sequencing to your approved messaging Claims sign-off; financial promotions approval stays in your process
Online Marketing Drafting, scheduling, reporting Financial promotions approval; every public claim through your sign-off
Web Team Publishing, upkeep, technical hygiene Regulated content sign-off before anything goes live
AI Analyst Reading the numbers, drafting the Monday page Interpretation that would constitute advice to clients

Where we say no

Candour, because it is the whole point of this page. If your firm wants AI to give regulated advice, we decline; that is not a product we sell, and anyone selling it to you deserves harder questions than ours. If your compliance manual cannot be expressed as rules and sign-offs (rare, but it happens mid-restructure), fix the manual first; Guardrails automates a process, it cannot invent one. And if your volumes are tiny, a well-trained human team with a good checklist may be the right answer, and the £1,500 Department Discovery will say so in writing before you spend anything real; it is credited in full if you go ahead.

The quiet advantage

Here is what surprises regulated clients: the guardrailed department is often more compliant than the humans it relieves, not less. It never improvises on a script. It never sends the Friday-afternoon email without the disclosure line. It never forgets to log a call. One hundred per cent of its actions carry a complete record, which no human team has ever achieved. The risk conversation usually starts with "can we trust the AI?" and ends with "why does our human process not log like this?"

Frequently asked questions

Can FCA-regulated and other supervised firms use AI departments?

Yes, with structural controls: Compliance Guardrails locks chosen action types to human approval permanently, applies your sector's rules to every draft before it queues, and logs every action with a full audit trail. The AI handles the routine around regulated work; anything constituting advice stays with your qualified people. This page is not regulatory advice; your compliance officer decides what your firm runs.

What exactly is Compliance Guardrails?

An add-on for any Fortitude AI department, built for regulated sectors: sector-specific approval steps, prompt guards with banned and required wording, sign-off routing by topic, permanently locked Assisted mode for chosen action types, and an exportable audit trail recording input, draft, checks, approver and timestamp for every action.

No, structurally. Departments carry an explicit routing list of what must never be answered, only handed to a qualified human, warmly and immediately, with the handover logged. The AI's role at the advice boundary is recognising it reliably.

Is our customer data used to train AI models?

No. Your customer content is not used to train shared models, and we never sell or share your configuration or your data. Access, retention and processing terms are set out in our data processing agreement, and the audit trail keeps every action inspectable by your compliance team.

How does an audit work with an AI department?

Better than you are used to. Every action in every mode carries a complete record: the trigger, the draft, the compliance checks applied and their outcomes, who approved it (human or promoted action type), and when. Exports are formatted for compliance review. In practice the department's log is usually more complete than the human process it replaced.