At the Risk-!n Conference 2026 in Zurich, experts discussed why artificial intelligence in compliance and risk management is only as good as the people who control it. And why the biggest weak point in the system is often the supplier.
It was one of the most succinct statements of the two-day conference: “The algorithm decided it” is not a justification that will stand up to a regulatory authority. Michael Rasmussen, GRC analyst (GRC Report) and conference moderator, put it in a nutshell with an image: anyone who sees AI as “data” from “Star Trek” – loyal, error-free, reliable – is mistaken. In truth, AI is more like Jack Sparrow from “Pirates of the Caribbean”: brilliant, creative, but without governance, ready to sail off on its own.
When prejudices migrate into algorithms
Pierre Lauquin, Risk and Business Continuity Manager and expert in cognitive biases, and Rafael Tiedra from the AI team of the cantonal government of Geneva showed how human biases are systematically built into AI systems long before the first model is trained. Confirmation errors and simplification biases creep in as early as the design phase, when decision-makers determine which data is relevant in the first place. Selection bias follows during data collection: a dermatological AI system trained exclusively on patient data from an affluent, fair-skinned urban population will simply fail with other skin types.









And at the end of the chain is the user with their own cognitive biases. The so-called “fluency bias” is particularly insidious: because language models respond fluently, quickly and in a structured manner, people tend to attribute human reliability to them. Added to this is the “authority bias”: the answer seems competent, so it is believed. The conclusion of the two: An AI system is not a neutral tool, but a medium that transfers bias from human to machine and back again. “An AI system is not biased by chance, but is the product of thousands of human, cultural and political decisions.”
From experiment to defensible practice
This raises an urgent question for compliance teams: How do you use AI in such a way that it can also be explained to a supervisory authority? Cecilia Garcia Podoley, lawyer and consultant for ethics and compliance (Ethics & Compliance Switzerland), named three prerequisites: Firstly, there always needs to be a human who views, understands and approves the AI output. Secondly, the AI must provide explainable answers, as a black box is not legally compliant under the EU AI Act. Thirdly, continuous monitoring is essential, as a model that is unbiased today can be systematically wrong tomorrow.
Demir Arifovski from NAVEX added from a sales perspective: “Many companies confuse AI with automation. Anyone who wants to replace manual processes with AI without first cleaning them up and digitizing them will only accelerate existing errors. “First understand, then automate, then digitize and only then AI.” For the introduction of AI in compliance workflows, he also called for clear documentation not only of the result, but also of the thought process: Why was this decision made? What alternatives were rejected? Nowadays, when employees change employers every three to four years, institutional knowledge is otherwise irretrievably lost.
The invisible back door in the supply chain
At the same time, Christian Koxholt, CCO of Quantum Fort, warned of an underestimated attack surface: the supply chain. According to recent studies, the logistics and transportation sector is the most attacked industry, not because it is poorly protected, but because it has to be structurally open. Every company that ever sends a parcel has EDI interfaces, tracking systems and supplier portals. These are the gateways.
The scenario he drew was sober: an attacker does not infiltrate the company itself, but a supplier who sends Excel files as a material replenishment plan. The MRP manager opens the file and the production line stops. For a car manufacturer, every hour of production downtime means seven-figure losses. A ransom note does not require a Hollywood hack, but only a weakly protected supplier.
The principle he shared is simple: “If my value is digital, my risk is digital.” Business continuity plans for a flat tire on a delivery truck exist in every regulated business. A plan for a digital supply chain breakdown? Rarely.
What to do now
The conference did not provide any easy answers, but it did provide clear pointers for action: Create an AI inventory (including shadow AI), clean up basic processes before AI is introduced, institutionalize human oversight, prioritize suppliers according to digital vulnerability and not just sales, and follow the strictest standards in terms of regulation, i.e. the EU AI Act, even if Switzerland is still waiting for its own law.
And above all: know your own biases. As Lauquin asked at the end of the conference: “Does expertise protect against bias?” Most hands stayed down.
Binci Heeb
Read also: Cyber resilience is becoming a question of survival