Every company that adopted generative AI over the past two years made, without quite realizing it, the same bet: that fluency in the answer would be enough. An employee asks about a sick-leave rule, a termination clause, a reimbursement criterion, and the AI answers instantly, confidently, in polished prose. No one stops to ask where that came from, because the answer sounds right. The problem is that sounding right and being defensible are two different things, and that gap is exactly the size of the risk most companies are carrying without knowing it.
This isn't just a Legal problem. HR, Finance, Compliance — any area that uses AI to support answers to employees is exposed to the same risk, just under different names. For Legal, it's a labor-law clause misapplied. For HR, it's a benefit explained in a way that doesn't match the policy actually in force. The symptom changes; the cause is always the same: no one can say, with confidence, what the AI actually based its answer on.
The regulator has already started asking
Brazil's data protection authority, the ANPD, didn't wait for Congress to pass the AI legal framework before acting. In December 2025, it published its Map of Priority Themes for 2026-2027, placing artificial intelligence as one of four central pillars of enforcement, with 75 planned activities over that period. The AI pillar evaluates transparency, bias mitigation, and — above all — compliance with Article 20 of Brazil's data protection law (LGPD), which grants data subjects the right to contest automated decisions.
That applies even when the AI merely suggests an answer for a human to review. The regulator's question isn't who clicked "send" — it's what source backed up that guidance. And that's exactly where most generative AI tools in corporate use fall short: they answer from the model's general knowledge, with no declared link to the specific regulation or internal policy of that particular company.
Convincing is different from auditable
No company would accept a junior analyst giving a labor-risk opinion from memory, having never opened the actual labor code. No HR team would accept an intern explaining a health plan based on what they think they remember from the last meeting. And yet that's exactly what most AI tools do every day, and no one questions it, because the answer sounds convincing enough not to be checked.
A language model is trained to produce fluent text, not to refuse to answer when it doesn't have the right source at hand. It answers regardless, with the same confidence, whether it's right or not. Making sure an answer is backed by documentation can't depend on the model's goodwill — it has to be built into the process before the answer ever reaches the person who will use it. That design, more than the model's raw intelligence, is what separates an exposed company from a protected one: forcing the AI to consult a source defined by the team itself first — be it the labor code for labor questions, or the benefits policy for HR — and only then suggest an answer. That's the path AskLisa has been building: no answer should go out without someone being able to point to where it came from.
Day to day
Every month, an HR team receives hundreds of repeated questions about benefits and leave, and much of the response comes from institutional memory or a rushed search through a document that may be outdated. A labor-relations team lives the same routine with questions about working hours and terminations, answering off the top of their head what should be answered with the labor code open beside them. In both cases, the specialist does two jobs at once: answering, and making sure the answer is correct. The second job is the one that suffers most when the schedule gets tight.
The result is predictable: inconsistent answers between colleagues in the same team, dependence on whoever's memory happens to be freshest, and no trail to show, if questioned later, what that guidance was based on. It's not a lack of technology — it's a process that was never designed to leave a trace.
The cost
The regulatory pressure of 2026 isn't going away, and it won't spare anyone who treats their AI — or even their manual processes — as a convenient black box. Every department that supports decisions about people is, in practice, betting that no one will ask where the answer came from. That bet has gotten riskier in recent weeks, and it will keep getting riskier as the AI legal framework moves through Brazil's Chamber of Deputies and the ANPD executes its enforcement calendar.
The choice facing the leaders of these areas isn't whether to use AI or not — that discussion is already over.
It's between continuing to answer fast and without a paper trail, or building a process that can always say which source it relied on. The difference only shows up on the day someone asks — and by then, it's too late to improvise.

