Regulations Change, Architecture Remains
Which rules will AI systems operate under? The real question is not predicting regulation, it is not having to rebuild the system when the rules change.

Enterprise AI projects are no longer driven by a single agenda. In the first phase, organizations focused on finding the right use case and seeing that the technology actually worked. Rolling systems out at wider scale, producing business value and making them dependable followed. Today another item is being added to that list, and it carries more weight than before: which rules will AI systems operate under, and how ready are organizations for those rules?
The European Union's AI Act and the guidance published in Türkiye by KVKK on the use of generative AI are putting data use, human oversight, transparency and corporate accountability squarely on the agenda of AI projects. The transparency obligations that took effect on 2 August 2026 under the AI Act show that these topics are no longer discussed only at the level of good practice.
What we see in the field at CBOT points the same way. As AI systems settle into operations, answering "how well does this system work?" is no longer enough. Which data it reaches, where that data is processed, which decisions it can take on its own, at which point human control enters and how traceable its actions are have all become part of the design.
Here is the critical point: most of these items are not clauses that can be bolted on after a regulation is published. They are bound up with how the AI solution is built in the first place. So the question in front of organizations is not only "when will comprehensive AI regulation arrive?" The more important question is this: how ready are the AI systems we are building today for rules that may change tomorrow?
In our view, what organizations should be doing today is not trying to predict how regulation will take shape. The real task is to design AI systems with data control, transparency, human oversight and traceability in mind from the start. A well designed AI architecture does not just meet today's need, it also makes tomorrow's rules easier to comply with.
The New Question Is Not Compliance, It Is Resilience
How Do Enterprises Prepare for the AI Act and KVKK?
In large organizations, AI projects already pass through legal, compliance, information security and data teams. In banking, insurance, telecom, airlines and the public sector, anything else would be unthinkable.
So the subject we need to discuss today is not involving legal teams earlier. That is already a natural part of the work.
The real change is somewhere else.
Until now, most organizations assessed a project within the existing rules: can we use this data? Can we store this information here? Can we automate this process?
Now a harder question sits alongside those:
How easily can our system change when the rules change?
This is not a small difference.
Because in AI, regulation covers more than the data being used. How the system introduces itself to the customer, how far it decides on its own, when a human enters, whether the source of the content it produces can be understood, whether its actions can be traced back: all of this is becoming more visible.
It may not be possible to tie every one of these to a clause in today's legislation. But they all point in the same direction: AI has to be designed not merely as a technology that works, but as a corporate actor that has to be governed.
We think this is where the real break of the new period lies.
Being ready for regulation is not knowing every rule in advance. It is not having to rebuild the system when the rules change.
As AI's Role Changes, So Does What Regulation Covers
From Chatbot to Digital Employee: How Does Responsibility Grow?
What is accelerating this discussion is not only new legislation. AI's role inside the organization is changing fast.
Not long ago, what we expected from a virtual assistant was to understand the customer's question and give the right answer. Today we expect digital employees to deliver work, not just answers.
It reaches data. It talks to enterprise systems. It determines the next step. It moves the workflow forward. In some scenarios it takes action.
That shift matters for governance.
Because a system that produces answers and a system that performs transactions cannot be governed the same way.
When a chatbot gives a wrong answer, we usually face a communication problem. When a digital employee takes a wrong action, the operation changes. A record can be opened, a transaction can be triggered, a process that directly affects the customer can start.
That is why, in the agentic era, the critical question is not only how capable AI is, but where its capability begins and where it ends.
In our digital employee projects at CBOT we pay particular attention to this distinction: capability and authority are not the same thing.
The fact that a system is technically able to perform a transaction does not mean the organization should hand that transaction to it.
A new layer emerges here that companies need to design. Which task can run fully autonomously? Which action requires user approval? In which situation should an employee step in? Which decision should remain a human responsibility?
These are not only controls that reduce risk. Built correctly, they are the mechanisms that let AI be used at a wider scale.
When we covered trust last month we arrived at the same point: organizations are not slowing down because they distrust AI. They are slowing down because they cannot define where they can trust it.
The regulation debate is making that need more visible.
Transparency Is Bigger Than Saying "This Is an AI"
What Does the AI Act Transparency Obligation Require?
The transparency obligations that came into application on 2 August 2026 under the European Union's AI Act are a good example of this shift.
In certain situations, users need to know that they are interacting with an AI system. Transparency conditions also apply to some AI generated or AI modified content. The European Commission's approach to AI Act transparency shows that the relationship between the user and AI will become more visible.
But the lesson organizations should take is not simply writing "this service is provided by artificial intelligence" on a chatbot screen.
The real question is this:
Do the user and the organization genuinely know what role AI plays in this process?
Is it providing information? Making a recommendation? Helping someone decide? Or acting on the user's behalf?
Until that distinction is clear, transparency turns into a notice on a screen. Yet as AI's responsibility grows, the system's role needs to be defined openly.
At this point good design and regulation meet in the same place again.
When the user knows what they are dealing with, the experience becomes more predictable. When the organization knows the system's limits, risk becomes more manageable. When the operation knows at which point it takes over, scaling becomes easier.
So transparency does not only deliver compliance. It reduces uncertainty.
The New Data Question: How Much Should AI See?
KVKK's Generative AI Guidance and Data Minimization
We see a similar shift on the data side.
For a long time, data in AI projects was approached with a "more is better" reflex. The thinking was that opening more documents, more customer history and more corporate knowledge to the system would make the model stronger.
As enterprise AI matures, that approach is changing.
The question is no longer "which data can AI access?"
It is "which data does it genuinely need in order to do this job?"
KVKK's guidance on generative AI and the protection of personal data also emphasizes data minimization, an explicit processing purpose and controlled use of personal data.
But here too the subject is bigger than a legislative clause.
Think of the access rights an organization has granted its employees over the years. Not everyone on the finance team can reach all financial data. Not every agent in customer service can see every piece of customer information. There are roles, responsibilities and access boundaries.
The same corporate discipline is needed in AI.
Which digital employee can connect to which system? Which data fields can it see? Which information can it only read, and which can it change? Which data can be sent to a model outside the organization? These questions are directly linked to whether data is processed inside or outside the enterprise boundary.
As AI scales, the answer companies give to "who can access what?" now covers AI systems as much as people.
That is why data governance and AI governance are becoming inseparable.
Human Oversight Needs Redefining Too
What Does "Human in the Loop" Mean in AI?
One of the concepts we hear most often in AI governance is "human in the loop".
But putting a human inside every decision is not good governance on its own.
If a digital employee runs hundreds of transactions automatically yet every one of them needs human approval, the technology may work in theory while the operation does not scale.
At the other extreme, leaving every decision to the system is not realistic for enterprise use either.
The real task is not whether a human is in the system, but designing where they need to be.
Steps that are high confidence and low risk can run automatically. When uncertainty rises, when the system moves outside its defined limits, or when a decision is critical for the customer, a human can step in.
This is why we at CBOT do not treat handover to a person merely as an error handling method. Designed well, it strikes the balance between autonomy and control.
That distinction will matter for future rules too. As the extent of AI's role in decision making is debated, what organizations will need to show is not just "we have human oversight".
They will need to explain why and at which point the human enters.
Traceability Is the New Institutional Memory
Why Is an AI Audit Trail Critical?
Another fundamental topic is traceability.
A system may be working correctly today. But when a customer queries a transaction six months later, or the organization investigates an error, what matters is not only the outcome but how that outcome was reached.
Which data did the AI use? Which model did it call? Which enterprise tools did it talk to? Which step did it take on its own? Where did it get user approval? Where did a human enter?
A system that cannot answer these questions does not only create an audit problem. It also limits the capacity to learn.
Because when something goes wrong, you cannot see where it went wrong.
Did the model err? Was the data wrong? Did the integration fail? Or did the system perform its defined task correctly while the process itself was designed badly?
As AI's role inside operations grows, traceability stops being a technical log. It becomes the memory of the work the organization does with AI.
So traceability, which today looks like an investment made for regulation, may tomorrow be one of the core tools of performance and operations management.
The Real Issue: Building an Architecture Ready for Change
What Does a Regulation-Resilient Enterprise AI Architecture Look Like?
All of these topics bring us to the same place. Data access, authority boundaries, human oversight, transparency and traceability are not independent control areas. Together they form the architecture that determines how an organization governs AI.
We think this is where the real difference will show in the period ahead.
Because models will change. What digital employees can do will widen. New use cases will appear. As the responsibility organizations give AI grows, the control mechanisms that look sufficient today will be reassessed.
Predicting all of that change from where we stand is impossible. It is also unnecessary.
What organizations need is not to write rules from scratch with every new development, but to put in place today the basic principles that can adapt to new conditions. When it is clear which data will be used for which purpose, when authority is defined openly, when human intervention is possible at critical points and when the system's actions are traceable, managing change becomes far easier.
This approach prepares an organization for regulation while also making AI easier to scale. When an organization knows what it controls, it can give the system more responsibility. As uncertainty falls, the field of use widens and more processes become workable with AI.
The paradox here is fairly simple: more control, designed correctly, does not mean less room to move. It creates a safer space to grow.
At CBOT we believe the next stage of maturity in enterprise AI takes shape here. The point is not only using powerful models or automating more processes. It is designing the limits, responsibilities and control mechanisms AI will work within inside the organization.
Because the strength of a good AI architecture shows not only in how well it works today, but in how easily it adapts when conditions change tomorrow.
That is exactly what we mean by preparing rather than waiting for regulation.