{"id":7470,"date":"2026-08-02T07:53:00","date_gmt":"2026-08-02T11:53:00","guid":{"rendered":"https:\/\/workai.tv\/news\/2026\/08\/ai-security\/the-60-25-15-rule-reshaping-ai-compliance-pilots\/"},"modified":"2026-08-02T07:53:00","modified_gmt":"2026-08-02T11:53:00","slug":"the-60-25-15-rule-reshaping-ai-compliance-pilots","status":"publish","type":"post","link":"https:\/\/workai.tv\/news\/2026\/08\/ai-security\/the-60-25-15-rule-reshaping-ai-compliance-pilots\/","title":{"rendered":"The 60-25-15 rule reshaping AI compliance pilots"},"content":{"rendered":"<h2>Share with your CISO<\/h2>\n<p>Financial services compliance teams are getting the AI investment sequence badly wrong, and a <a href=\"https:\/\/fintech.global\/2026\/07\/30\/the-60-25-15-rule-reshaping-ai-compliance-pilots\/\" target=\"_blank\" rel=\"noopener nofollow\">Vixio webinar on AI compliance pilots<\/a> put a number on it. Nilesh Khatri, head of technology at regulated FinTech and financial services, proposes the 60-25-15 rule: 60% of any AI compliance budget on data hygiene in a narrow domain, 25% on governance and controls, 15% on the AI tooling itself. Most failed pilots invert this entirely. Andrew Dawson, CRCO at Yeepay UK, demonstrated the upside when the ratio holds, collapsing a five-hour SAR filing process to near-instant.<\/p>\n<h2>What this means for your business<\/h2>\n<p>The firms most exposed here aren&#8217;t the ones that haven&#8217;t started AI compliance pilots. They&#8217;re the ones that already have, because the failed-pilot pattern is almost always the same: a vendor demo gets funded, the data preparation work gets squeezed into whatever&#8217;s left, and governance gets treated as a post-launch audit concern rather than a build requirement. If your pilot produced a proof of concept that never scaled, the 60-25-15 ratio is probably a diagnosis, not a prescription.<\/p>\n<p>The SAR filing example from Yeepay deserves more attention than it gets as a model. Dawson&#8217;s team didn&#8217;t deploy a general-purpose LLM and hope for accuracy. They ran it in a proprietary environment, anonymized customer data, and deliberately suppressed the model&#8217;s &#8220;temperature,&#8221; the setting that controls how creative or exploratory the AI&#8217;s outputs are. High temperature produces fluent, varied text; in a legal filing it produces hallucinations that a regulator will treat as fabrications. The architecture choice to strip creativity out entirely is the design decision most compliance teams skip because vendors don&#8217;t sell it as a feature.<\/p>\n<p>Personal liability regimes change the calculus in a way that budget conversations often miss. Under the UK&#8217;s Senior Managers and Certification Regime, accountability for a compliance failure doesn&#8217;t transfer to the vendor when the AI makes a bad recommendation, it stays with the named individual who signed off on the system. That means the CISO or CRCO defending an AI-assisted compliance workflow needs runtime audit trails, explainable outputs, and documented human sign-off at every interpretive step, not because the regulator asked for a demo, but because the alternative is a personal enforcement action. The firms that treat explainability as a nice-to-have are building liability, not reducing it.<\/p>\n<h2>Concept deep-dive: LLM temperature<\/h2>\n<p>Temperature is the dial that controls how predictable or creative a large language model&#8217;s outputs are, think of it as the difference between a calculator and a brainstorming partner. At low temperature the model consistently picks the most statistically likely next word; at high temperature it ranges further, producing more varied and sometimes surprising text. For consumer chatbots, higher temperature feels more natural. For regulatory filings where a fabricated detail is a legal liability, it&#8217;s a defect, not a feature, which is why Dawson&#8217;s team set it to the minimum.<\/p>\n<p><em>Based on reporting from <a href=\"https:\/\/fintech.global\/2026\/07\/30\/the-60-25-15-rule-reshaping-ai-compliance-pilots\/\" target=\"_blank\" rel=\"noopener nofollow\">The 60-25-15 rule reshaping AI compliance pilots<\/a>, originally published 2026-07-30 07:58:00.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Share with your CISO Financial services compliance teams are getting the AI investment sequence badly wrong, and a Vixio webinar on AI compliance pilots put a number on it. Nilesh Khatri, head of technology at regulated FinTech and financial services, proposes the 60-25-15 rule: 60% of any AI compliance budget on data hygiene in a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":7471,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[143],"tags":[238],"tmauthors":[],"class_list":["post-7470","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai-security","tag-ciso"],"_links":{"self":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/posts\/7470","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/comments?post=7470"}],"version-history":[{"count":0,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/posts\/7470\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/media\/7471"}],"wp:attachment":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/media?parent=7470"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/categories?post=7470"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/tags?post=7470"},{"taxonomy":"tmauthors","embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/tmauthors?post=7470"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}