Perly Consulting │ Beck Eco

The State of Play

A living index of AI adoption across industries — where established practice meets the bleeding edge
UPDATED DAILY

The AI landscape doesn't move in one direction — it lurches. Some techniques leap from experiment to table stakes in a single quarter; others stall against regulatory walls, technical ceilings, or organisational inertia that no amount of hype can dislodge. Knowing which is which is the hard part. The State of Play cuts through the noise with a rigorously maintained index of AI techniques across every major business domain — classified by maturity, evidenced by real-world adoption, and updated daily so you always know where you stand relative to the field. Stop guessing. Start knowing.

The Daily Dispatch

A daily newsletter distilling the past two weeks of movement in a domain or two — delivered to your inbox while the index updates in the background.

AI Maturity by Domain

Each dot marks the weighted maturity of practices within a domain — hover for a brief summary, click for more detail

DOMAIN
BLEEDING EDGEESTABLISHED

⚖️ Legal, Compliance & Risk

AI for managing contracts, regulation, governance, and organisational risk. Contract review and e-discovery are good practice with proven ROI; regulatory monitoring and due diligence are advancing steadily. Most of the domain sits at leading-edge — adoption is constrained by liability concerns and the need for domain-expert validation rather than by tooling gaps.

21 practices: 9 good practice, 11 leading edge, 1 bleeding edge

Legal, Compliance & Risk — Biweekly Brief

The headline: Europe's AI rules went live on August 2. Three-quarters of companies believe they could pass an AI audit today; barely a quarter actually could.

The Picture

The question here is no longer whether AI can do legal and compliance work well enough. It is whether you can prove, on demand and in writing, that it did. Most large organizations cannot: half say they could not assemble a complete record of what their AI systems accessed within one business day. A small group built the evidence layer first, and the payoff shows up in an unexpected place — companies with mature governance are roughly four times more likely to have AI running in real production, not less. If you have named an owner for AI but never written down what your systems are and are not allowed to do, you are in the exposed middle with almost everyone else.

This Fortnight

  • The EU AI Act's first enforcement wave landed on August 2. Regulators can now demand unredacted access to your AI risk framework within five business days, with penalties running to €35M or 7% of global revenue, and a new EU channel lets employees report AI governance violations directly. Ask your team the blunt question: if that request arrived tomorrow, what could we actually hand over?

  • Governance stopped looking like a tax and started looking like the enabler. A survey of 639 senior AI leaders found organizations with fully integrated governance were 3.9 times more likely to have AI agents — software that acts on its own without being prompted — running in genuine production. Four other independent studies this fortnight pointed the same way. This changes the budget argument: controls are no longer what slows the program down, they are what lets it ship.

  • Regulators moved from "did you get the alert" to "prove the alert became a working control." Examiner analysis of a $140M penalty against USAA shows supervisors now testing whether a flagged regulatory change actually changed something, and US Customs and Border Protection issued the first formal American guidance requiring human-in-the-loop review — a person signing off each output — for AI-assisted trade compliance decisions. Detection is assumed; evidence of follow-through is what gets examined.

  • A fabricated AI output is now alleged to have moved a nine-figure contract. A lawsuit in the US Court of Federal Claims alleges AI errors tainted the evaluation of a $450M Army award by assigning false weaknesses to one bidder and inflating a rival's strengths. Court records of AI hallucinations — when a tool confidently makes things up — now number around 1,500 worldwide. The cost has moved well beyond embarrassing footnotes.

Coming Up

  • The harder EU obligations arrive in December 2027, but the record-keeping starts now. The deferred high-risk rules require a documented history of how each system was built and monitored — evidence you cannot retrofit after the fact. Get an inventory of which AI systems touch regulated decisions, and start logging against it this quarter.

  • Banking supervisors are formalizing "AI monitoring AI." The Financial Stability Board, the global body that sets banking standards, has defined six mandatory oversight capabilities on the premise that human review cannot keep pace with automated systems, with the framework going to G20 finance ministers in October. In financial services, expect continuous automated monitoring of your AI to become an examination expectation rather than a nice-to-have.

  • Vendor economics are turning against buyers who committed early. Privacy platform customers report renewal price increases of ten to thirty times, contract platform switching costs run into the hundreds of thousands, and analysts expect a large share of AI agent projects to be cancelled by 2027 on cost and unclear returns. Negotiate exit terms and the right to export your own audit records before your next renewal, not during it.

What's Hard About This

  • The averages sell the tool; the exceptions create the liability. Independent academic benchmarking puts contract review error rates at 6–13% on standard agreements but 15–22% on specialized and cross-border work — precisely the deals where mistakes are expensive. Tools trained mostly on US contracts also misread European and Asian legal concepts, a failure that looks like a confident correct answer.

  • Double-checking breaks down exactly when you need it. Analysis of one major law firm's failed filing found both safeguards — firm policy and a second reviewer — collapsed simultaneously under deadline pressure. And when both sides of a negotiation use the same AI, the usual protection of an opposing party catching your error stops working. Verification has to be mechanical, not advisory.

  • Owning the platform is not the same as having the control. A lawsuit against the NFL documented a consent system correctly installed while 186 third-party trackers kept firing after users opted out. More than half of organizations that bought contract management software report it does not meet their needs. Budget for the implementation and the proof, not the license.


Go deeper: the full Legal, Compliance & Risk briefing — the longer analytical write-up, plus every practice we track in this domain with its maturity rating, the tools to consider, and the evidence behind our assessment.