
Regulators find themselves in an unusual position. They must regulate or control a technology while simultaneously deciding whether to use it themselves.
This dual mandate (AI as something to oversee vs AI as something to self-use) is reshaping what it means to be a regulatory professional. Whether you work in Nairobi or New Delhi, Bogotá or Dhaka, the question is the same: how do you master both sides of this equation?
AI systems present governance challenges that traditional regulatory frameworks weren’t designed to address.
Consider opacity (also called black box). When a machine learning model makes a decision, whether approving a loan, flagging content, or recommending a sentence, the reasoning often isn’t transparent. Even the engineers who built it may struggle to explain why a specific output emerged. How do you regulate something that can’t fully explain itself?
Consider bias. AI systems learn from historical data. If that data reflects past discrimination, the system may perpetuate it at scale. A hiring algorithm trained on decades of biased decisions will replicate those biases, efficiently and consistently. Identifying and addressing this requires expertise that most regulatory professionals never needed before.
Consider accountability. When an AI system causes harm, where does responsibility sit? The developer? The deployer? The organisation that purchased it? The answers aren’t obvious, and they differ across jurisdictions.
Different markets are taking different approaches to these challenges. The EU has adopted a risk-based classification system. The UK emphasises sectoral regulators and principles over prescriptive rules. The US relies more heavily on existing agency mandates and executive action. ASEAN nations and others are developing their own frameworks, often drawing on multiple models.
For regulatory professionals, understanding this matters. Not to copy any single approach, but to make informed decisions about what fits your own market context.
Here’s where the story gets more interesting. The same technology that creates governance challenges can transform how regulators themselves work.
Generative AI excels at tasks that consume enormous regulatory resources: analysing lengthy consultation responses, summarising complex documents, drafting initial policy text, identifying patterns in compliance data, responding to routine stakeholder queries.
These aren’t theoretical applications; regulatory bodies are already experimenting with them.
Imagine processing a public consultation that generated 500 responses. Traditionally, that means weeks of staff time reading, categorising, and synthesising. An AI tool can produce a structured summary of key themes, points of agreement and disagreement, and notable outliers; it can do this in hours rather than weeks. Staff still review and validate but the process is streamlined.
Or consider compliance monitoring. AI tools can scan operator reports, flag anomalies, and identify patterns that might indicate issues worth investigating. They don’t replace human judgment. They direct it toward where it’s needed most.
For regulators operating with constrained resources (which describes many regulators, frankly), these efficiency gains could be transformative.
Efficiency gains come with risks. And the biggest risk is over-reliance.
Generative AI systems produce confident-sounding outputs. They’re “fluent”, structured, and persuasive. However, they’re also sometimes wrong. “Hallucination” (generating plausible sounding but fabricated information) remains a fundamental limitation of large language models.
This matters enormously in regulatory contexts. A policy document with fabricated legal references. A compliance summary that misrepresents what a report actually said. A stakeholder response that sounds authoritative but contains invented statistics.
The principle is straightforward: AI assists, humans decide. Every AI-generated output in a regulatory context needs human review before it influences decisions. The question isn’t whether to have humans in the loop; it’s how to structure that oversight effectively.
This requires regulatory professionals who understand AI well enough to use it critically. Who know what these tools can and cannot do. Who can spot when an output looks questionable and verify it independently.
Which brings us back to the dual competency challenge.
Effective regulatory professionals in the AI era need two distinct skill sets.
The first is governance literacy. Understanding how AI systems work at a conceptual level. Knowing the policy frameworks emerging across jurisdictions. Recognising the risks (bias, opacity, accountability gaps, etc.) and the mechanisms being developed to address them. Being able to evaluate proposals and contribute meaningfully to policy development.
The second is operational competency. Knowing how to use generative AI tools effectively. Understanding prompt engineering, specifically how to structure queries to get useful outputs. Identifying workflows where AI can add value. Establishing appropriate governance and guardrails for AI deployment within your own organisation.
These aren’t the same skill set. But they reinforce each other. The professional who understands AI well enough to regulate it will also likely understand it well enough to deploy it responsibly. And vice versa.
No single market has figured this out completely. The EU is still implementing its AI Act. The UK is testing its principles-based approach. Developing economies are watching, learning, and crafting their own paths.
This creates value in global peer networks. Regulatory professionals who connect with counterparts across jurisdictions gain perspectives they couldn’t develop in isolation. They see how different markets balance innovation and protection. They learn what’s working and what isn’t. They avoid reinventing wheels that others have already built.
The most valuable learning often comes from markets facing similar constraints: resource limitations, capacity challenges, the need to leapfrog rather than incrementally evolve. A regulator in one developing economy may have more relevant insights for another than any amount of material from well-resourced Western agencies.
Regulatory bodies that emerge stronger from this transition will share certain characteristics. They’ll have professionals who understand AI from both perspectives: what it means for governance and what it means for operations. They’ll use AI tools to amplify their impact while maintaining the human judgment that legitimacy requires. They’ll contribute to shaping AI governance frameworks rather than simply implementing rules written elsewhere.
Cenerva’s AI for Policy & Regulation TRMC helps regulatory professionals build both governance literacy and self-use competency in AI. Through hands-on workshops, global case studies, and expert-led sessions, participants gain practical skills they can apply immediately. Explore the programme.