For years, communications compliance has meant one thing: monitoring what people say. Emails, chats, calls, and meetings were captured, supervised, and retained because a human being produced them. That definition is already out of date. Copilots are drafting responses, meeting assistants are generating summaries and action items, and recommendation engines are shaping decisions before a person even weighs in. None of it fits neatly into the old model of communication surveillance, and compliance teams are having to work out, often in real time, whether it needs to. Few people are watching that shift from closer range than Soniya Bopache, SVP and GM of Arctera and Enterprise Vault. Speaking to UC Today, she makes the case that AI governance has stopped being a future consideration and become a live enterprise compliance issue.
AI Is Already Embedded in Enterprise Collaboration Platforms
The starting point is that AI-generated content is no longer an edge case in regulated workflows. It is part of how work gets done. Employees are using AI to draft emails, summarise meetings, generate reports, and, in some cases, respond directly to customers across communication platforms. According to Arctera’s State of AI Governance 2026 report, 85% of organisations are using AI tools in some capacity within their day-to-day workflows that involve regulated communications or decision-making. That does not diminish the compliance obligation. It raises it. Bopache says:
“AI isn't replacing governance, it's raising the standard for it. As AI becomes another participant in business communications, those AI-assisted interactions need to be governed with the same rigour as any other business records.”
The stakes are highest in regulated industries like financial services, healthcare, and the public sector, where organisations still need to retain communications, demonstrate oversight, and respond to regulators with confidence. With Arctera’s State of AI Governance 2026 finding that 60% of organizations are placing the responsibility of AI risk squarly on compliance, the organisations that succeed will be those that combine AI innovation with trusted governance.
Why AI-Generated Outputs Are Becoming Regulated Business Records
One of the most significant changes in thinking concerns what actually counts as a record. Historically, the answer was simple: communications produced by people. But when an AI-generated email, report, or recommendation influences a business decision, it enters the corporate record whether a human wrote it or not, and organisations need to be able to retain it, explain how it was created, and demonstrate compliance if regulators or courts ask questions later. Bopache says:
“The moment AI-generated content influences a business decision, it stops being just an AI output. It becomes a business record that needs to be governed.”
This is a meaningful expansion of scope for compliance leaders. AI prompts, responses, and recommendations are increasingly viewed as business records in their own right, and the volume of that content is growing with every new copilot and meeting assistant that enters the workplace.




