
AI has been a major part of the conversation at Archer® Summit 2026, but by Day 3, the conversation had moved beyond what AI can do. The bigger question was what it takes to put that capability to work in a way that organizations can actually trust, govern and defend.
That shift was reflected in the customer sessions throughout the day. After two days of announcements and discussion around the future of GRC, customers brought the conversation back to something hands-on: what does modernization look like when it moves from an idea to the work organizations have to do every day?
The answer, in many of those conversations, was surprisingly simple. Modernization is not always about adding something new. Sometimes it is about figuring out what can finally be removed.
From AI Capability to AI You Can Govern
The first two days of Archer Summit established the foundation for that conversation.
Archer introduced Archer Evolv™ Foundation and Archer Evolv™ Workplace, bringing a governed digital workforce into the GRC environment. Foundation serves as the shared AI intelligence layer beneath that workforce, using the organization’s existing GRC context, records and relationships to give AI the information it needs to do meaningful work. Workplace is the marketplace where customers can select governed AI Operators and assign them to their teams. Each Operator is designed for a specific GRC job, works within a defined scope and remains under the supervision of a named person.
Then came Archer Evolv™ AI Compliance, which extends that same approach into the AI runtime itself. Regulations and company policies can become enforceable controls through native AWS Bedrock Guardrails, so prompts from employees or agents can be evaluated before the model responds. The resulting control and violation evidence remains connected to the GRC system of record.
Taken together, the three announcements point to a broader idea: enterprise AI needs more than the ability to generate an answer or take an action. It needs context, boundaries, accountability and evidence.
That distinction became especially clear as Summit moved into its customer sessions.
The Hard Part Is Proving the Work
The conversation around AI often starts with speed. How quickly can a model read a regulation? How fast can it identify a control, summarize a finding or draft a response?
Those capabilities matter, but they are only part of the equation. In GRC, the harder question comes later, when an auditor, examiner or risk leader needs to understand why something happened and whether the organization can stand behind the decision.
An AI system may be able to generate an obligation library in a fraction of the time it once took an analyst to build one. An AI Operator can analyze records, identify patterns and recommend a finding or mapping. An employee or another agent can submit a prompt and receive a response in seconds.
But if something goes wrong, speed does not answer the question that matters most: Why was this allowed?
That is where the architecture behind Archer Evolv becomes important. Foundation provides the shared intelligence layer and GRC-specific environment for AI Operators to work with the organization’s existing records and context. Its data-readiness capabilities help ensure that the information AI relies on is usable and trustworthy, while the GRC harness keeps Operators within defined boundaries and connected to the system of record.
Workplace builds on that foundation by giving organizations a practical way to put those Operators to work. Instead of treating AI as another application sitting outside the GRC program, teams can select purpose-built digital workers for specific jobs and assign them to the people already responsible for that work. Operators gather information, analyze it and generate recommendations, while a named human remains responsible for reviewing and approving the result.
Archer Evolv AI Compliance takes the same principle one step further by putting controls directly into the path of AI activity. Instead of discovering a policy violation after the fact, organizations can enforce approved controls before the model is invoked and retain evidence of what happened.
The goal is not simply to make AI faster. It is to make the work more useful without losing the ability to understand, control and prove what happened.
SMBC’s discussion of internal audit modernization brought that idea down to earth. The focus was not on replacing auditors with AI or making broad claims about what technology might eventually do. It was on improving the work itself by standardizing evidence formats, reducing manual reconciliation and creating a stronger connection between a finding and the evidence supporting it.
That is what modernization looks like when it has to work in the real world. The technology matters, but the discipline around the technology matters just as much.
Modernization Is Mostly Subtraction
That same idea came through in several of the other customer conversations at Summit, even when AI was not the subject.
EY described moving a heavily customized, on-premises environment with more than 1 million legacy accounts and roughly 2 terabytes of data to SaaS in less than a year. The technical migration was a significant undertaking, but the harder part was deciding what actually needed to come along.
Years of customization had created fields, workflows and workarounds that had made sense when they were introduced. Over time, however, some had become difficult to explain and even harder to justify. Modernization meant taking a close look at that accumulated complexity and deciding what still earned its place.
Zions Bank took a different approach, using an incremental rollout of new Archer capabilities rather than trying to make the entire transition in one move. Each step could be validated before the next one was introduced, creating a more deliberate path forward instead of treating modernization as a single event.
Blue Cross Blue Shield described another side of the same challenge. Individual customizations had made sense when they were added, but over time, the accumulation of those decisions had created a system that was increasingly difficult to change and adopt. What started as flexibility had eventually become its own source of friction.
The organizations approached modernization differently, but the underlying lesson was consistent: sometimes the biggest improvement comes from removing the things that have accumulated around the work.
Fewer manual steps. Fewer workarounds. Less duplication. Less maintenance. Less complexity.
That is an important lesson for AI, too.
The natural reaction to every new technology is to add another tool, another model or another application. But if AI simply creates another system for GRC teams to maintain, the organization has added capability without necessarily removing any of the work.
The opportunity with Archer Evolv is different. Foundation, Workplace and AI Compliance are designed to extend the GRC environment rather than create another disconnected layer around it. Foundation provides the intelligence and context, Workplace puts purpose-built Operators to work under human supervision, and AI Compliance brings regulatory and policy controls into the AI runtime.
In other words, the goal is not to create more places for GRC teams to manage AI. It is to make the environment they already trust capable of doing more.
What Legacy GRC Can Teach Us About AI
Conversations about GRC modernization and AI governance may seem like two separate topics.
One is about migrations, customization and legacy systems. The other is about AI, agents and runtime controls.
But the customer conversations at Summit made the connection easier to see.
A GRC environment that has accumulated years of unnecessary customization and an AI system that can produce decisions without enough context or oversight have a similar underlying problem. In both cases, technology can become difficult to govern when organizations keep adding to it without taking the time to reconsider what should stay, what should change and what needs to be controlled.
For a legacy GRC program, that complexity can eventually show up as difficult maintenance, poor adoption or a migration that takes longer than expected.
For AI, the consequences can appear when someone asks what the system did, what information it used, which policy applied or who approved the result.
Those answers cannot always be reconstructed later from a collection of disconnected logs. They need to be part of the process.
That is why the GRC system of record matters in an AI environment. The value is not simply having a place to store the final answer. It is having the context, obligations, controls, evidence and ownership connected to the work as it happens.
That is also where the role of the AI Operator becomes different from a general-purpose AI assistant. An Operator is built for a specific GRC job, operates within a defined scope, works with the records and context it is authorized to access, and leaves a traceable record of its work. A named human remains responsible for reviewing and approving the outcome before it is written back into Archer.
The result is not AI working around GRC.
It is AI working within GRC.
The First Generation Was About Capability. The Next Is About Proof.
The first generation of enterprise AI was largely about proving that the technology could do the work.
- Could it read a document?
- Summarize a regulation?
- Identify a risk?
- Draft a response?
Those questions have largely been answered.
The next questions are more fundamental to GRC.
- Can the organization show where an answer came from?
- Can it identify the obligation or policy that governed an action?
- Can it show what the AI was allowed to access or change?
- Was a person responsible for reviewing the result?
- Was a control enforced before the model responded, rather than discovering a violation afterward?
These are not simply AI questions. They are GRC questions.
A general-purpose model can generate an answer, but a GRC Operator needs to perform a defined piece of work within a controlled environment. A basic prompt filter can block certain content, but a compliance control needs to connect that decision to the regulation or policy behind it. A repository can store a policy, but a GRC system needs to connect that policy to obligations, controls, evidence, owners and decisions.
That is the difference between adding AI to GRC and building GRC for the age of AI.
What Modernization Looks Like Now
The customer conversations at Archer Summit were not stories about organizations that had somehow finished modernization. In many ways, that was what made them more valuable.
SMBC talked about the practical work required to make AI-assisted audit processes more trustworthy. EY described the work involved in separating what was still useful from years of accumulated customization. Zions Bank showed how modernization can happen incrementally rather than through one massive transition. Blue Cross Blue Shield demonstrated how well-intentioned customization can eventually become an obstacle to change.
None of those stories suggested that modernization is easy.
They showed something more useful: modernization becomes possible when organizations are willing to question the way work has always been done.
That means asking what still serves a purpose, what can be automated, what can be removed and what needs stronger controls. It means making better use of the data and systems already in place instead of continually adding another layer around them.
The same thinking applies to AI.
The value of AI will not come simply from having more models or more agents. It will come from putting that capability into an environment where the organization can control it, understand it and prove what it did.
That is the direction Archer Evolv is designed to take GRC.
- Archer Evolv Foundation provides the intelligence layer and governed environment.
- Archer Evolv Workplace gives teams access to purpose-built AI Operators that can take on defined GRC work.
- Archer Evolv AI Compliance extends governance into the AI runtime, turning regulations and policies into controls that can be enforced before a model is invoked.
The three announcements are part of the same larger shift: from AI that can do something to AI that an enterprise can responsibly put to work.
And that brings the conversation back to what customers were talking about on Day 3.
Modernization is not about adding technology for the sake of adding technology. It is about making the work easier to manage, easier to understand and easier to defend.
Sometimes that means introducing something new.
Just as often, it means finally getting rid of something that no longer needs to be there.
The next era of GRC modernization will be defined not only by what organizations add, but by what they can remove while still maintaining the control, context and evidence they need to trust the work.
Frequently asked questions
Archer’s GRC keeps the world’s most regulated enterprises ahead of constant regulatory change. More than 1,300 organizations run on Archer, including half the Fortune 500 and 37 of the top 50 global banks.
Archer introduced two new products, Archer Evolv Foundation, Archer Evolv Workplace, and Archer Evolv AI Compliance, which put a governed agent workforce to work inside the GRC system of record. Archer also extended that same discipline to runtime enforcement, turning regulations and company policies into controls that are enforced before an AI model responds.
Because AI capability is no longer the hard part; making that capability trustworthy, controlled and defensible is. Without traceability, an AI system can generate a mistake as easily as an answer, and there is no way to show an examiner or auditor why a decision was reasonable when it was made.
Based on customer sessions at Archer Summit 2026, it means clearing away accumulated workarounds and legacy customization rather than stacking on more tools, models or workflows, so systems can do more while requiring less manual work and remaining explainable.










