Sprggun

Mobile Navigation Menu

"Compliance as growth" was never about compliance. Governance is business.

22 July 2026

Emma Di iorio | CEO & Co-founder, Spriggun

Something has curdled. A year ago, "compliance as growth" was a real argument. Today it is the industry line, and it means something narrower: buy a better governance platform, appoint a champion, draft another policy, add compliance to the slide deck. The operating model that produced the problem is left exactly where it was.

My argument in Shaping AI Without the Hype was never that compliance itself is growth. It was that governance done properly - embedded in how the business decides what to do with its data, AI and cyber, owned by named executive leadership, inseparable from the strategic work - is what turns regulatory readiness into competitive advantage. What has changed is the distance between what that requires and what much of the market has actually built.

Governance done properly is one with business strategy. Where it sits as a separate function - a folder of policies, a committee that meets and disperses, a work stream nobody at the top has actually named as theirs - it isn't governance. It is decoration. Decoration doesn't deliver ROI on the AI you've bought; it doesn't make compliance quick or defensible; it doesn't earn trust from customers, investors, regulators or staff. It harms the business it's meant to protect: risks nobody weighed, deals nobody can credibly close, decisions made in the absence of a settled position. This is the state much of the market is living inside, and the response has been to buy tools. It is not being solved by tools; it cannot be.

"Compliance as growth" was reaching for governance embedded in strategy - the two doing the same job. Embedded is the board and executive taking their own position on what the business will and won't do with its data and AI, with the same weight as the calls they take on markets, hiring or pricing. Bolted alongside is that position is expected to emerge from a governance function's review of decisions already taken elsewhere. The mistake is not that governance was ignored, but that companies did the second and called it the first.

What running the business now involves

Every company sells, makes, hires, prices, targets and delivers through data and technology; there is no part of the business that runs without them. The strategic questions of the last decade - what markets, what products, what risks - now sit on top of a set of questions the board and executive cannot delegate. What the business will and won't do with its data and AI, which use cases it will approve, which it will refuse. Whether the underlying data is fit for the ambition someone has already promised the market, or whether it will take months and millions to get there. These are not compliance questions; they are not questions a legal or IT function can settle. They are the calls the business exists to make, and the answers set the direction that everything downstream runs against.

The failure looks different in each domain but is the same failure. In AI, ROI that never lands because the data underneath cannot support the use case. In privacy, decisions the business cannot defend because the data map is out of date. On the web estate - the visible layer of how customer data actually flows - an estate leaking data through vendors nobody has mapped. In cyber, an attack surface nobody knows they own. Different symptoms, one question underneath.

Few companies have made them cleanly. The strategic layer is either missing or held informally by whoever is loudest in the room. What sits below is a function - legal, compliance, sometimes IT - being asked to defend a position the top has never taken, on data nobody is sure about, for a use case someone has already committed to. That isn't compliance failing. It is compliance being asked to do a job that sits with the executive and the board.

Why decoration doesn't work

When governance is a folder rather than an operating reality, the effect on people is uneven and mostly damaging. Without change management, and without a settled position they can point to, staff are left to guess. Some freeze - unsure what is allowed, they don't use the tools the business is paying for at all, and the promised value never lands. Others go the other way - unsure what is allowed and under pressure to move, they use whatever they can get their hands on, including shadow AI: tools reached for outside the sanctioned enterprise stack, unapproved, unmapped, running on data nobody has traced. Fear drives both. A due diligence request comes back with three different answers depending on who was asked.

Regulators, courts, customers and investors now want assurance rather than assertion. Not "do you have a policy," but "show me this actually happening"; and behind that, "show me you know what you are doing." The retention schedule that lists what the business intended to do with data, rather than what it actually does, is not that answer; the record that reconciles the two, and that has been kept current, is. Decoration cannot answer the questions, nor can a governance platform. Only a business that has done the work can.

The regulatory pressure has hardened while this has happened. In the UK, the maximum fine for a cookie or direct-marketing breach went from £500,000 to £17.5 million or 4% of global turnover, in force since February - a thirty-five-fold jump on a control most businesses file under marketing. In the EU, the Digital Omnibus has reopened GDPR, ePrivacy and the AI Act at once, and courts are already penalising algorithmic decisions under consumer law that never needed the Act to bite. The binding constraint isn't the regulation. It is that most companies cannot say clearly what they have decided to do, and are asking compliance to defend a position nobody has taken.

Know Your Data. Know Your AI.

The baseline that gives real governance somewhere to stand, in Spriggun's frame, is Know Your Data (KYD) and Know Your AI (KYAI). There is no AI without data, so data comes first. Any board should be able to ask what data the business holds, where it came from, and what can lawfully be done with it - and hear an answer, not a scramble.

Done properly, this baseline compounds across regimes. The record European privacy law has required for years is much of the foundational information the EU AI Act now demands for a high-risk system; the same record tells the security team what actually needs protecting. One piece of work, three jobs, none starting from scratch. The next use case, the next audit, the next deal are answered from a settled position rather than a blank page.

The brilliant boring basics of compliance sit inside this and remain non-negotiable - record-keeping, technical documentation, working consent, incident reporting. Doing them well is the floor. What they will not tell you is whether the AI you just bought works, whether the data behind it can be trusted, or whether the third party holding it can keep it safe. A business can meet every requirement on record and still not know what it has - which is not compliance dressed up as strategy, or even compliance.

What tells you governance is real

The test of whether governance is real, or decoration, is not the number of policies or the platform choice, but five core elements. Whether a named executive owns the work, sitting on the leadership team rather than one layer down. Whether there is a strategic plan for data, AI and technology - not a policy library, an actual roadmap the exec owns and the board has approved, with sequencing, dependencies and the resource behind it - against which decisions are being made. Whether the governance work happens inside the strategic decisions the business is making, or alongside them, as a parallel process nobody at the top has authority over. Whether the policies and thresholds reflect the realities of the company as the board has strategically assessed them, or have been lifted from a template. Whether everyone who touches data, technology or customers has enough fluency to make sound calls in the moment, within limits the exec and board have set clearly enough that people know where they stand - a defined playing field, not a guessing game.

Where these hold, everything else follows; committees convene because they have decisions to reach, training is tailored to role and level because the roles have been thought about, compliance moves quickly because the direction is already set. Where they don't, everything else is theatre.

Who has to own it

Legal and IT have been asked to carry all of this alone for years - to make the strategic calls, build the framework and hit compliance - often without the business scope, executive backing or organisational fluency the job requires. It was never a fair ask. Nobody enjoys telling the board that the tools it is buying cannot work until the strategic layer is settled and the underlying data has undergone significant data cleansing and rectification. That conversation is exactly the one the board needs to hear.

The top has to send down a settled position: a roadmap the exec owns with board approval, policies that reflect it, and change management honest enough to name that the technology is coming and to say how the business will help people get there. Fear people feel but leadership will not name is what produces the shadow AI above; the two are the same failure mode from opposite ends. Tailored training belongs here too - not a compliance video, but an ongoing programme, differentiated by role - alongside an enterprise stack good enough that shadow AI isn't the only place to reach.

The upward question matters as much as the downward direction. Executive leadership has to be willing to ask, and hear the answer to, whether the data actually supports the ambition someone has already promised the market. That question travels across privacy (does what we hold justify what we've told customers we do with it), cyber (do we know what we hold well enough to protect it) and web (do we know what our own site is doing with customer data), not only AI. If the answer is that the data doesn't support the ambition, the choice is cleaning what exists, buying what doesn't, or rescoping - not deploying anyway. That single conversation saves companies from significant spend on outcomes that cannot arrive.

From the bottom: engaging with training on the understanding that the technology is coming either way; noticing when a call is bigger than the caller's remit and passing it up; refusing shadow AI where it matters - specifically, not putting personal or commercially sensitive data into public tools nobody has approved. This is not compliance literacy, it is engagement over autopilot.

Where either direction of that contract is missing - where the top has not settled its position, or where the bottom has not been given the tools, training or clarity to act on it - governance is theatre. The harm that follows is not a compliance problem. It is a business one.

What good looks like

An organisation that has done this work moves differently. It gets to yes on a new use case in days rather than months, because the position the business has taken on its data is already settled and does not need to be relitigated for every deal. That yes holds - defensible six months later, to a regulator or a customer, as the same answer. Procurement and investors are already asking what regulators ask; the businesses that have done the work are winning contracts, closing rounds and entering markets the others cannot credibly reach. The models return, because they run on data someone can vouch for. Trust is what happens when a business can show its working.

The stakes have moved; the argument hasn't. Governance embedded in how the business decides is what running the business now involves; platforms, folders and functions bolted on the side are not. Done properly, this is what unlocks value. Done properly, this is what earns trust. Done properly, this is what "compliance as growth" was reaching for before the market flattened it into something you could buy off the shelf.


Emma Di Iorio is Co-Founder and CEO of Spriggun, a UK-based RegTech and AI governance advisory firm. A qualified solicitor with senior in-house and advisory experience, she writes and speaks internationally on AI, data, privacy, and web compliance. Her chapter in _Shaping AI Without the Hype: How Women Turn Technology Into Real-World Impact (2025) explores holistic data strategy as the foundation for responsible AI and digital transformation._