Chris Stapenhurst
Director, Product Management
5 Surveillance Lessons from XLoD NY
Being on the ground at XLoD New York this year, one reality was immediately apparent across every session that the conversation is no longer about whether financial institutions and regulated firms can use AI. Instead, the focus has pivoted to how we govern it, set enforceable guardrails, and maintain accountability when automated models are deeply embedded in surveillance and risk detection pipelines. Here are the five critical takeaways that defined XLoD New York:
1. The next frontier for surveillance is human-to-AI and AI-to-AI interaction
As employees increasingly use enterprise AI assistants, and Agentic AI systems begin interacting with other systems, a new category of communications and conduct risk is emerging. Firms are looking to regulators for greater clarity on expectations, but regulatory uncertainty should not become a reason to wait. The focus should remain on understanding and reducing underlying risks — not simply building controls to satisfy the next regulatory requirement. Firms need to start considering what should be monitored, what constitutes a record, and how existing surveillance frameworks will need to evolve as more activity takes place between people and machines, and increasingly between machines themselves.
2. AI is moving into the control environment
The question is increasingly less about whether firms will use AI and more about how they will govern it. For surveillance and risk functions, that means clear ownership, appropriate controls, and the ability to understand and challenge the output.
3. Good surveillance still starts with good data
Technology can improve surveillance, but it cannot fix poor inputs. Fragmented data, inconsistent taxonomies and unclear ownership continue to make effective monitoring harder than it needs to be. And this is of paramount importance as firms begin to incorporate more and more AI across the 3 lines.
4. The Three Lines need clearer boundaries
And speaking of the 3 lines, there remains a continued focus on reducing duplication across the 1st, 2nd and 3rd Lines while keeping accountability clear. For the 2nd Line in particular, that means spending less time on repetitive activity and more time on oversight, challenge and emerging risks.
5. Surveillance needs to keep pace with the risk
Market abuse and communications surveillance continue to become more complex as firms use more channels and generate more data. The opportunity is not simply to monitor more, but to make surveillance more focused, risk-based and effective.
Let’s Continue the Conversation
The transition from AI adoption to AI governance is the defining challenge of 2026. If your team is navigating these same questions around audit trails, data boundaries, or AI oversight, I'd love to connect and share how we're approaching it at Arctera.