AI IN PROCUREMENT
“ It also means human judgment remains central, especially in regulated environments,” says Eric. Compliance is not the gate that slows AI down; it should instead be seen as the architecture that allows AI to scale safely. When governance is embedded from the start, organisations do not have to choose between speed and assurance. Both can be achieved while earning the trust of clients, regulators and the board.
Andrew echoes this:“ AI compliance isn’ t a brake on innovation; it’ s a governance discipline. The answer, we think, is co-development, so the guardrails are built into the product from the ground up, directed by the client. We build the governance with you.”
The shadow AI problem While organisations try to restrict unauthorised tools to manage security risks, what happens when employees adopt useful technology faster than policy can keep up? The organisations that accept this truth and build their strategy for it are creating a far more resilient culture than those trying to outrun it. Shadow AI has changed the conversation from restriction to responsibility.“ The reality is that employees will always adopt useful technology faster than policy can keep up. That is not a failure of people. It reflects the pace at which innovation now moves,” explains Eric.“ The problem begins when organisations respond with blanket bans, because bans rarely stop usage; they simply drive it into places where there is no oversight.” Eric suggests a shift in mindset:“ Instead of saying,
“ The reality is that employees will always adopt useful technology faster than policy can keep up. That is not a failure of people. It reflects the pace at which innovation now moves”
Eric Winston Executive Vice President, General Counsel, and Chief Risk, Ethics & Compliance Officer Mphasis
‘ do not use AI’, we focus on‘ use AI responsibly within clear guardrails’. That change matters because culture is shaped not only by policy, but by whether people view security and compliance as obstacles or as enablers.”
Employees need to know what is acceptable, what is not and why. When those boundaries are well designed and defined, people can experiment with greater confidence and the organisation gains both innovation and control.“ A strong compliance culture today depends on three things: visibility, clear risk boundaries, and trust,” says Eric.“ The objective is not to suppress adoption. It is to create an environment where AI can be used safely, openly and responsibly.”
80 August 2026