Every year-ahead piece in this industry predicts the same future: more AI, more automation, continuous evidence collection, and finally, fewer spreadsheets. Fine. That’s not the interesting part.
The interesting part is what happens when organisations get exceptionally good at producing evidence of compliance without getting materially better at managing risk.
AI can draft a policy in seconds. A GRC platform can map a single control across half a dozen frameworks and turn every tile on the dashboard green. Evidence can be collected automatically, timestamped, and filed without a human ever touching it. On paper, governance has never looked more mature.
Meanwhile, critical vulnerabilities sit unpatched for months. Incident response plans exist but have never been rehearsed. Nobody in the building can say with confidence which AI tools are already connected to company data. Welcome to the age of synthetic compliance: the evidence is real, the dashboard is green, and the confidence it creates may be almost entirely undeserved.
Synthetic compliance, defined
Synthetic compliance describes an organisation that looks beautifully governed on paper, but whose controls have rarely been tested against anything real. It isn’t usually dishonesty. It’s what happens naturally when a GRC function rewards the existence of evidence more than the effectiveness of the control that evidence is supposed to represent. Nobody sets out to build this. It accumulates, one green tile at a time, because green tiles are what get reported upward.
We’ve automated the paperwork. We haven’t automated the truth.
Why this is the moment it matters
The pressure to produce proof of compliance is rising at exactly the moment technology is making that proof easier to manufacture, and the numbers make the gap hard to ignore.
Compliance is now the leading driver of cyber investment for 70% of European organisations surveyed in ENISA’s most recent NIS Investments report. Yet within that same survey population, roughly 30% hadn’t carried out a cyber assessment in the previous year, and around 28% took longer than three months to patch a critical vulnerability. Compliance spend is going up. The controls it’s supposed to fund aren’t reliably being tested.
Closer to home, 43% of UK businesses identified a cyber breach or attack in the past year, according to the government’s 2025/2026 Cyber Security Breaches Survey, and the resilience gap between large organisations and small ones hasn’t closed. Meanwhile, the UK Corporate Governance Code’s Provision 29 now requires listed company boards to declare, in explicit terms, whether their material internal controls were effective, not simply whether they exist. It’s a small change in wording and a large change in what boards will need to be able to prove.
A different question
Most of what currently passes for assurance answers the wrong question. “MFA is enabled” is not the same as knowing whether it’s enforced across every account, including privileged, legacy, and emergency access. “We have an incident response plan” is not the same as knowing whether it’s ever been rehearsed out of hours, under realistic pressure. “Backups complete successfully” tells you nothing about when a full restoration was last tested, or whether it worked. “The supplier is certified” doesn’t tell you what access that supplier actually has, or what happens to your organisation if it fails. A penetration test tells you what was found on the day it ran, not whether the findings were fixed and independently retested afterwards.
A green dashboard shows you what the system has been configured to measure. It cannot, on its own, prove resilience.
Where AI complicates this further
AI is currently both the tool GRC teams are using to manage this problem and a significant part of the problem itself. It’s genuinely useful for drafting policy and assessing risk faster than a team could manage manually. At the same time, most organisations still can’t give a confident answer to where AI is already operating inside the business, what data it can see, or whether it’s been tested for the risks it introduces. A control framework built to govern last year’s technology stack isn’t automatically governing this year’s.
What boards can no longer avoid
Regulatory direction across the UK and EU is moving in one direction: away from evidence of existence, and towards evidence of effectiveness and outcome. Provision 29 makes that explicit for listed boards. The UK’s Cyber Security and Resilience Bill is extending scope and strengthening enforcement for a wider range of organisations, including managed service providers. The paperwork that used to be sufficient is quietly becoming necessary but not sufficient.
That leaves boards and GRC leaders with a genuine choice about what “good” looks like from here. The direction that actually holds up under scrutiny is continuous validation rather than continuous compliance. That means GRC connected to real monitoring, real penetration testing, real recovery exercises, real incident data, and real operational behaviour, rather than to a dashboard that only reflects what it was configured to show.
The reckoning
Stop asking whether the control exists. Start asking when it was last tested, how it could fail, and whether anyone would actually notice if it did.
The next major GRC failure won’t be caused by a lack of evidence. Most organisations now have more evidence than ever. It will be caused by mistaking that evidence for proof, and continuing to say the word “compliant” long after it stopped meaning the risk was actually under control.

