The Review Bottleneck: Machine Speed, Human Sign-Off
AI generates compliance work faster than people can review it. Banking and medical-device regulators met that problem first, by pre-agreeing the envelope.
The Constraint Nobody Budgets For
Automation programmes in compliance are costed on the assumption that the expensive resource is preparation. It is not. Preparation is what automation makes cheap; review is what it makes scarce — and review is where accountability actually lives, because the signature is what a regulator examines.
The arithmetic is unforgiving and rarely modelled. A system that raises document throughput several times over does not raise the number of hours a qualified reviewer can spend reading carefully. Those hours are fixed by human cognition and by headcount, and neither scales with the model. What changes is the ratio: the same person now sits in front of many more determinations, each arriving more polished and more plausible than the last. Polish is the aggravating factor, not the mitigating one — output that reads confidently is harder to interrogate than output that reads roughly.
The failure this produces is not visible in the file. A reviewer who is genuinely examining and a reviewer who has become a click-through produce the same artefact: an approved determination with a name on it. The signature does not record how long the eyes stayed on the page. Which means an organisation can lose its oversight function entirely while every metric on the dashboard improves.
Regulators Have Named This Problem Precisely
Trade is not the first domain to hit this wall, and the sectors that hit it earlier described it in language worth borrowing. Banking supervision has required, since the 2011 model-risk guidance and continuing under its successor, a standard called effective challenge — defined as "critical analysis by objective, informed parties who can identify model limitations and assumptions and produce appropriate changes."
The definition repays close reading, because every element of it is a constraint on volume. Critical analysis is not confirmation. Objective excludes the person who built or depends on the model. Informed requires the reviewer to understand the model well enough to find its limits. Produce appropriate changes means the challenge has to actually alter outcomes sometimes, or it was not challenge. A review function that approves everything fails this standard by definition, regardless of whether the approvals were correct.
Currency matters here for anyone citing the framework: the Federal Reserve, OCC and FDIC issued revised interagency model-risk guidance as SR 26-2 in April 2026, replacing the 2011 guidance after more than a decade of change in modelling practice. Governance documents and vendor materials still referencing only SR 11-7 are describing a superseded instrument.
The European Union codifies the same concern for AI systems specifically. Article 14(4)(b) of the AI Act requires oversight to enable the responsible person to remain aware of the tendency to over-rely on system output — automation bias — and flags the risk particularly where the system produces information or recommendations for human decisions. That is a regulator describing the saturated reviewer, and requiring the system's design to work against the condition rather than assume it away.
The Answer Other Sectors Reached: Move Review Upstream
The solution that has emerged across regulated industries is not more reviewers. It is a change in what gets reviewed: instead of examining every output, the regulator and the operator agree in advance on an envelope of behaviour that may proceed without individual review, and reserve human attention for what falls outside it.
The clearest expression is the FDA's final guidance of 4 December 2024 on Predetermined Change Control Plans for AI-enabled device software functions. A manufacturer specifies, in the original marketing submission, which modifications it anticipates, the protocol by which they will be made and validated, and an assessment of their impact. Modifications falling within that pre-authorised plan may then be implemented without a new marketing submission. The review did not disappear; it moved to the boundary and happened once, at high intensity, instead of repeatedly at low intensity.
That inversion is the transferable idea. Reviewing each output is the intuitive design and it scales worst. Reviewing the envelope — what the system may conclude on its own, on what evidence, and what it must escalate — scales, and it concentrates scarce expert attention where judgement is genuinely required.
What an Envelope Looks Like in Trade Documentation
Translated to shipment work, the envelope is a set of standing decisions taken deliberately rather than by drift. Which determinations may stand on machine preparation alone? Typically the mechanical ones: a field-level reconciliation where two documents agree exactly, a deadline computed from a date on the face of a transport document, a rate lookup where one instrument is unambiguously in force.
Which must always escalate? The ones where the law itself allocates judgement — a classification that is not a repeat of an established position, a first shipment on a new lane, a determination resting on a document that is absent or internally inconsistent, anything where the governing instrument changed inside the shipment window.
And what must the escalation carry? This is where preparation quality converts directly into review capacity. A reviewer given a determination plus its rule, its source documents, its reconciliation and an explicit list of what could not be resolved can exercise real judgement in minutes. The same reviewer given a confident answer and a folder of PDFs cannot exercise judgement at all, only trust. Escalation volume is a design variable; escalation quality is what decides whether the human hours spent are worth anything.
The Honest Position
An organisation deploying automated preparation into trade compliance should size its review capacity before its throughput, and should treat a falling override rate as a warning rather than a success metric. The question to put to any programme is not how much it produced, but what proportion of its output received genuine effective challenge — and whether the answer is knowable from the record at all.
TradeWatch is built for that arithmetic: preparation runs at machine depth, unresolved evidence is surfaced explicitly rather than resolved away, and what reaches the reviewer-of-record arrives already cited and already reconciled, so the scarce resource is spent on judgement rather than on assembly. Kanan Labs prepares a readiness packet. It does not file Shipping Bills and holds no customs credentials — your licensed CHA files.
- Interagency Supervisory Guidance on Model Risk Management (SR 26-2, April 2026), replacing SR 11-7 (2011)
- FDA — Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions (final guidance, 4 December 2024)
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act)