Written by a human

New technologies, new risks – The evolution of communications compliance

The evolution of communications technology has changed the way firms do business. But every step change has presented compliance teams with new challenges. We explore how the communications landscape has changed, from voice communications to AI chats, and how compliance teams are already armed with the tools they need to tackle emerging risk.

Jay Hampshire Senior Content Writer
8 mins read 11 September 2026

In brief:

  • A perennial challenge for compliance teams is staying ahead of emerging technologies and the risks they may present
  • Compliance functions must balance known legacy risk areas with fast-evolving channels like generative AI and “smart” wearable technologies
  • While technology and its evolution are presenting the challenge, communications capture and monitoring are also providing a compliant solution

From the introduction of smartphones in the 2000s to the normalization of digital communications channels within workplaces in the 2010s (and the subsequent regulatory crackdown on off-channel communications), compliance officers have needed to be both reactive to changing communications behaviors and proactive in anticipating and preparing for the next wave of technology that would bring yet more change.

The introduction of artificial intelligence (AI) has increased the pace of this change exponentially. It’s estimated that around 80% of firms are now leveraging AI in some capacity, and both generative AI (Gen AI) and agentic AI are beginning to pose communications compliance and recordkeeping challenges.

Compliance teams are now sandwiched between established, “familiar” risk areas like voice channels and digital communications, and evolving risks including AI and wearable “smart” technologies. While technology is presenting the challenge, it is also providing solutions that empower compliance teams to tackle evolving technology risk.

Heard it all before — Voice channel risk

For years, voice channels were the backbone of financial services. From desk phones to cell phones, decisions were made via voice calls. But even with most calls lasting mere seconds because of the frenetic pace of trading, compliance teams faced multiple challenges.

  • Scale: Calls may have only lasted for seconds, but times that by dozens of daily calls placed by hundreds of individual traders across multiple offices, and the scale quickly becomes unmanageable.
  • Localization: Global firms faced the challenge of surveilling communications taking place in multiple languages, meaning either having native-language surveillance teams operating from every office or employing translators.
  • Jargon: From spoofing to smurfs, constantly evolving trading slang and jargon meant that bad actors could obfuscate misconduct behind a wall of words.

Its immediacy and its history of previously being unable to be intensively surveilled has made voice a channel favored by those attempting to hide misconduct. But recent advances in AI-enabled voice surveillance such as highly accurate transcription and translation, have given firms the ability to move beyond random manual sampling and comprehensively surveil their voice communications for potential signs of both financial and non-financial misconduct — leaving bad actors with nowhere to hide. 

The “war on WhatsApp” — Digital communications channels

The advent of digital messaging platforms like WhatsApp in the early 2010s gave individuals greater flexibility, able to send text-based messages instantly and internationally over Wi-Fi. They also posed a challenge for firms that had previously only had to capture and monitor communications across approved “legacy” channels like email or SMS.

The wave of regulatory enforcement activity for off-channel communications spanning from the early 2020s underscored the scale of that challenge. Firms that weren’t capturing communications data from digital channels risked keeping incomplete records and being unable to monitor for potential signs of misconduct. Regulators, particularly the Securities and Exchange Commission (SEC), reinforced this message with multiple enforcement actions and penalties.

The industry diverged on how to tackle this challenge, with many organizations choosing to ban channels, while others invested in compliant capture and monitoring solutions. Subsequently, the pace of enforcement activities has slowed through 2026, and the number of firms banning channels has risen to 66% — the highest in four years.

However, with a Financial Conduct Authority (FCA) multi-firm review identifying 178 communications policy breaches at eight firms in just 12 months (with senior staff responsible for over 41% of those breaches), and regulatory expectations that firms can exhibit data completeness and good recordkeeping remaining high, the need to continue capturing and surveilling digital channels is no less pressing.

Now you see it — Ephemeral messaging risk

A feature of many digital messaging channels, including Telegram and WhatsApp, whether known as ephemeral, disappearing, or self-destructing messages, the outcome is the same — messages disappear from chats completely after a set time or after being read.

This type of message can not only be used by bad actors to hide misconduct, but can also lead to firms falling foul of recordkeeping regulations as they cannot provide a complete record of communications data. Changes to the Department of Justice’s Evaluation of Corporate Compliance Programs (ECCP) specifically called out ephemeral messages as one type of type of communications data firms must ensure they capture.

It’s not just firms that can find themselves falling foul of regulation. The Financial Industry Regulatory Authority (FINRA) has placed sanctions on individuals for deleting messages “in order to impede … investigation” into potential misconduct. Those using ephemeral messages run the risk of being seen to be trying to hide something, even if unintentionally.

Data connectors that capture communications from the source can help firms overcome the challenge of disappearing messages. By capturing the original message data when it is sent, before it can be deleted, firms ensure they have a full, tamper-proof record of all communications data.

Model behavior — GenAI chat risk

GenAI platforms like ChatGPT and Microsoft Copilot are increasingly used across financial services organizations for a range of tasks. From producing internal communications to assisting with research, AI is changing the way people work. But it is also presenting a potential recordkeeping risk many might overlook.

AI prompt logs might feel benign but should be treated in the same way as other business communications – captured and monitored. Employees may input sensitive business data into these chats, or ask GenAI models to assist them in misconduct, thinking prompt logs are not being surveilled.

Some platforms allow teams to collaborate within AI threads, meaning that employees could have unmonitored conversations under the guise of collaboration if firms are not capturing these channels. Many firms have also banned some (or all) GenAI platforms. But, as with channels like WhatsApp, this risks individuals using personal accounts to circumvent the bans, meaning their conduct and communications go unseen and unmonitored.

With the number of firms capturing ChatGPT communications data surging 3,000% in 2025, it’s clear that many are anticipating this risk area and preparing accordingly.

Making a spectacle — Wearable tech risk

Projections suggest that 13 million pairs of smart glasses are likely to be sold in 2026 — almost double the number sold the previous year. While compliance and legal discussion has largely been around individual privacy, hypothetical situations of these technologies being used for misconduct do not feel outside the realm of possibility:

  • An individual could use a smart watch or pair of smart glasses to record a meeting or conversation or take an image of a slide deck and then trade on material non-public information they contain.
  • Smart glasses could be used to take pictures or videos of colleagues or clients without their knowledge or consent, potentially as part of a wider pattern of non-financial misconduct behaviors.
  • Livestream video from the glasses or text conversations taking place on smart watches might constitute off-channel communications if the channels they use are not captured and monitored.
  • Devices could be hacked by external bad actors, enabling them to remotely conduct any of the above activity and potentially allowing access to systems or networks that the devices are connected to.

Governmental bodies and regulators are beginning to set out rules governing the use of these technologies, although many businesses are enacting outright bans. The Norwegian government is assembling an expert group to advise on regulating new technologies, and the U.S. state of California is working on legislation that would prohibit wearable devices in workplaces without explicit consent to capture sound or video. FINRA recently issued a disciplinary action to an individual who used smart glasses to help answer exam questions, putting these technologies firmly on the regulatory radar.

The pace of technological evolution is not slowing, and compliance teams will always be under pressure to keep up. However, while the assumption might be that novel challenges will require novel solutions, the communications and monitoring tools that firms are already equipped with lay a firm foundation for continued compliance.

Whichever channels your business uses, communications compliance starts with data. Learn how Global Relay’s range of data Connectors enable you to capture data from the source and connect it to a secure, compliant archive.

Jay Hampshire Senior Content Writer
8 mins read 11 September 2026