AI should accelerate the evidence-to-decision pipeline, not collapse it.
Use AI for evidence processing, mapping, gap analysis and candidate conclusions. Keep the final assurance decision with an explicitly authorised role and preserve the evidence trail.
Control decisions
Evidence must precede every material conclusion. A fluent model answer without traceable support remains a candidate hypothesis.
Assessment ownerBefore productionSeparate AI analysis from independent challenge and final assurance authority.
CISO / DPO / assurance ownerBefore relying on outputsVersion prompts, evidence sets, model/runtime and reviewer decisions for repeatable assessments.
GRC ownerFirst control cycleA large part of GRC work is information processing. Policies, standards, interviews, tickets, technical evidence, risk registers, cloud configurations and previous findings must be connected to requirements and converted into a defensible assessment. Modern AI systems are increasingly capable of doing a useful share of that work.
NIST SP 1353 is a useful signal. It explores practical use of generative AI for cybersecurity framework analysis and reporting, including CSF 2.0 Current State and Target State Profiles. The important point is not that AI can generate another report. It is that we can start treating assessment as an evidence-processing architecture.
From chatbot to evidence pipeline
The weak pattern is simple: documents → LLM → compliance score.
A stronger pattern separates responsibilities:
Requirements + evidence → provenance-controlled intake → structured assessment procedure → AI analysis and candidate mappings → independent challenge → draft assessment → authorised assurance decision → evidence packet and audit trail.
The evidence layer establishes what we know. The AI layer proposes what the evidence may mean. The review layer challenges that interpretation. The assurance layer decides what the organisation is prepared to claim.
Rule 1: evidence precedes conclusion
A fluent answer is not evidence. If an AI system says that an organisation has an effective access-control process, the next question is: based on what?
A governed assessment should resolve a material statement through a chain such as requirement → claim → evidence → source → reviewer decision. If that chain breaks, the statement is not an assurance conclusion. It is a candidate hypothesis.
This also changes the role of retrieval and memory. Provenance is not merely a citation feature. In assurance workflows, provenance becomes part of the control environment.
Rule 2: “I don’t know” is a valid result
Real assessments are rarely binary. An AI-assisted process should distinguish supported, partially supported, unsupported, insufficient evidence, not applicable, conflict detected and review required.
Forcing uncertainty into a compliant/non-compliant classification creates false assurance. Sometimes the safest output is simply: there is not enough evidence to make this determination.
Rule 3: current state and target state are different reasoning tasks
A Current State assessment asks what the available evidence demonstrates today. A Target State asks what the organisation should become. The latter can use business objectives, threat landscape, regulation, contractual requirements, risk appetite and implementation constraints. The former must remain evidence-constrained.
If target-state expectations leak into current-state reasoning, the system can start describing the organisation it expects to exist rather than the organisation supported by evidence.
Rule 4: prompts become governed procedures
Once AI is used repeatedly for assessments, the prompt stops being just a prompt. It becomes part of the assessment procedure. Repeatability therefore requires versioning of the framework, evidence set, prompt or procedure, model/runtime, retrieval configuration, generated findings, assumptions, reviewer changes and final decision.
The goal is not deterministic reproduction of identical wording. The goal is replayability of the decision context.
Rule 5: draft is not assurance
An AI system may produce a better first-pass assessment than a junior analyst. That does not give it authority to make an assurance decision.
These are different questions: can the system perform the analysis? and who is accountable for accepting the conclusion?
This is also a security and privacy problem
Assessment evidence may contain vulnerabilities, architecture weaknesses, privileged-access information, incident details, personal data, internal audit findings and supplier weaknesses. Before evidence enters an AI pipeline, organisations need to apply provider approval, data classification, least privilege, retention, residency, logging, confidentiality and untrusted-content controls.
Public-model convenience should not override the controls protecting the evidence being assessed.
The broader architectural pattern
The same separation appears in many governed AI systems: evidence → reasoning → challenge → decision → action. The dangerous shortcut is input → AI → action.
This is why I increasingly see the AI harness, rather than the model alone, as the practical governance boundary. The harness determines what evidence the model can see, which sources are trusted, which tools it can use, how uncertainty is represented, who can authorise decisions and what evidence of the process is retained.
The model provides cognition. The surrounding architecture provides control.
What this means for GRC teams
I do not think the future of GRC is humans manually reading thousands of pages while AI waits on the side as a chatbot. Nor is it autonomous compliance software issuing unquestioned green checkmarks.
The more useful direction sits between these extremes. AI can perform a growing amount of evidence collection, mapping, comparison and analytical work. Humans can move upward toward exception handling, challenge, risk acceptance and accountability.
The objective is not simply to automate compliance. It is to build a system where every important conclusion can be traced to evidence, every uncertainty can remain uncertainty, and every consequential decision has an identifiable authority.