Perly Consulting │ Beck Eco

The State of Play

A living index of AI adoption across industries — where established practice meets the bleeding edge
UPDATED DAILY

The AI landscape doesn't move in one direction — it lurches. Some techniques leap from experiment to table stakes in a single quarter; others stall against regulatory walls, technical ceilings, or organisational inertia that no amount of hype can dislodge. Knowing which is which is the hard part. The State of Play cuts through the noise with a rigorously maintained index of AI techniques across every major business domain — classified by maturity, evidenced by real-world adoption, and updated daily so you always know where you stand relative to the field. Stop guessing. Start knowing.

The Daily Dispatch

A daily newsletter distilling the past two weeks of movement in a domain or two — delivered to your inbox while the index updates in the background.

AI Maturity by Domain

Each dot marks the weighted maturity of practices within a domain — hover for a brief summary, click for more detail

DOMAIN
BLEEDING EDGEESTABLISHED

Whistleblower report analysis & triage

LEADING EDGE

TRAJECTORY

Stalled

AI that analyses incoming whistleblower reports, triages them by severity and credibility, and routes them for investigation. Includes automated classification and priority scoring; distinct from general ticket triage which handles customer rather than compliance reports.

OVERVIEW

AI-powered whistleblower report triage has crossed from experimental to production-proven, but the technology's deployment is surfacing hidden costs. A handful of major platforms process millions of reports annually, automating severity classification, credibility scoring, and investigator routing at scale. The technology works at the triage layer. Yet paradoxically, NAVEX's 2026 data now shows that case closure times are lengthening, possibly because AI tool integration adds procedural overhead that slows rather than accelerates investigation workflows. The defining tension has shifted: it is no longer whether the technology works -- production deployments at Control Risks and others confirm capability maturity -- but whether AI-assisted triage creates net positive investigation outcomes when procedural complexity is included. Investigation capacity, organisational maturity (only 61% maintain a reporting channel), and now AI integration architecture emerge as the binding constraints. The research gap also persists: AI classification systems systematically diverge from human judgment on rule violations, and base-rate effects generate thousands of false positives per million communications, straining already-thin investigation teams.

CURRENT LANDSCAPE

The vendor ecosystem has consolidated around a small number of integrated GRC platforms. NAVEX leads with 2.15 million reports across 4,000+ organisations; Diligent (which acquired Vault Platform) and EQS Integrity Line (14,000+ global customers as of April 2026) compete on AI-assisted classification, anonymisation, and multi-channel intake. Consolidation continues: Case IQ acquired WhistleBlower Security in late 2025, and specialised entrants like LegalIntel target law firms with AI case intelligence. NAVEX's February 2026 launch of Quick Insights and incident benchmarking reflects a market shifting from basic triage automation toward comparative analytics and programme-level performance measurement. Production-scale deployments demonstrate capability: Control Risks used Relativity aiR to analyse 275,000 multilingual whistleblower documents in parallel, completing within one week of a two-week deadline—language-barrier elimination and accelerated document triage at scale. SAI360's deployment at ABB shows multinational enterprise adoption of 30+-language AI translation and automatic case routing with zero-IP-tracking anonymity. Document analysis at scale is now proven: consulting firms deploying LLM-powered platforms achieve 80% time reduction on qualitative document processing and risk theme identification.

Regulatory pressure is accelerating demand. Japan criminalised whistleblower retaliation in 2025; the UAE and Netherlands expanded protections; California's Transparency in Frontier AI Act now mandates whistleblower safeguards for frontier AI companies. The DOJ's updated Evaluation of Corporate Compliance Programs explicitly instructs prosecutors to assess whistleblower protection and anonymity safeguards, formalising what was previously best practice into a compliance expectation. These drivers explain rising reporting volumes -- Europe's rate jumped from 0.49 to 0.67 per 100 employees -- but they are surfacing AI integration trade-offs. NAVEX's 2026 analysis reveals that case closure times are lengthening, potentially because AI tool integration adds procedural overhead. The compliance field is beginning to recognize that orchestrating AI into investigation workflows is not a pure acceleration; it can introduce friction. Seventy percent of US workers express comfort with AI-driven reporting tools, yet only 32% of organisations have formal AI governance programmes in place. Board-level governance visibility (tracking disclosure types, triage times, and systemic issues) remains rare despite regulatory expectations. The false-positive problem persists: base-rate effects in misconduct detection generate thousands of alerts per million communications, straining already-thin investigation teams. A complementary risk emerges: whistleblowers using mainstream consumer LLM tools face identity verification barriers and data-sharing risks that undermine anonymity protection—a distinct concern from enterprise deployment overhead. The critical question is no longer adoption feasibility but integration architecture: when to automate, when to preserve human judgment, and how to avoid both AI-added overhead and whistleblower exposure from inadvertent mainstream AI tool use.

TIER HISTORY

ResearchJan-2022 → Jul-2022
Bleeding EdgeJul-2022 → Jan-2025
Leading EdgeJan-2025 → present

EVIDENCE (59)

— ALSP deployed AI to triage 200+ discrimination complaints in Q3 2024 with severity assessment and legal exposure flagging. Intake triage methodology (automated analysis, priority scoring, intelligent routing) directly applicable to whistleblower hotline report triage workflows.

— elsai AI platform automated risk theme identification and chronology sequencing from investigation documents for global advisory firm, reducing manual timeline work from 15-20 days to minutes while maintaining audit-trail evidence linking.

— Simform deployed LLM-powered document analysis platform using GPT-4o and RAG on Azure for fintech consultancy. 80% time reduction, 5x faster insight generation, 100% data coverage from unstructured document volumes—methodology directly transferable to whistleblower report triage workflows.

— Critical assessment of privacy and identity risks when whistleblowers use mainstream LLM tools, highlighting adoption barriers: mainstream AI providers require identity verification creating unacceptable risk for anonymous reporters, and corporate data sharing introduces uncompensated whistleblower exposure.

Secure Whistleblower Hotline - SAI360Product Launches

— SAI360 GRC platform with AI translation (30+ languages), automatic case creation and routing, and zero IP-tracking anonymity architecture. Named customer ABB reports deployment across multinational operations managing retaliation risk.

— Compliance counsel (Debevoise & Plimpton) citing NAVEX 2026 data documenting that case closure times are lengthening, potentially due to growing integration of AI tools into case management adding procedural steps. Recommends policy updates for agentic AI risks in whistleblower contexts.

— EQS Integrity Line serving 14,000+ organizations with AI-powered case routing, automated transcription, anonymization, and multi-language support. Human oversight built into every AI decision; positioned as eliminating low-value tasks to preserve expert investigation time.

— AICD governance guide citing ASIC's examination of whistleblower processes across 134 companies. Establishes board-level governance benchmarks: tracking disclosure volume and types, average triage time, escalation paths, and de-identified systemic issue analysis.

HISTORY

  • 2022-H1: NAVEX demonstrated large-scale whistleblower report analysis deployment across thousands of organisations in three continents, processing hundreds of thousands of reports annually. Evidence showed both capability maturity and emerging challenges: substantiation rates stable at 43%, but retaliation claims doubled year-over-year, and investigation times increased despite faster report escalation.
  • 2022-H2: Regulatory drivers (EU Whistleblowing Directive) and competitive pressure accelerated adoption across multiple vendors (NAVEX, Vault Platform). New AI features emerged (deduplication for psychological safety). However, compliance professional surveys revealed organizational maturity gap: only 40% of programs self-rated mature despite widespread technology availability, indicating implementation barriers.
  • 2023-H1: Ecosystem consolidation accelerated—Diligent acquired Vault Platform in May, signaling vendor belief in scaling whistleblower analysis. NAVEX continued multi-vendor benchmarking at scale (1.3M+ reports). Critical research emerged: MIT published findings that ML models designed to classify rule violations systematically diverge from human judgment, directly challenging the fairness of fully automated triage systems. Organizational maturity remained a barrier despite technology advancement.
  • 2023-H2: Product maturity continued advancing with Vault Platform's Integrity Intelligence AI analytics going live, enabling customizable severity classification and resolution tracking. Independent journalism documented operational deployment benefits: organizations using advanced platforms reported 70% increase in internal complaint volume and 50% reduction in resolution time. Simultaneously, compliance experts reinforced critical limitations: AI systems cannot replace human judgment in fairness-sensitive decisions, and vendors bear no responsibility for inadequate adoption or implementation. The capability gap narrowed while the organizational maturity barrier remained firm.
  • 2024-Q1: Adoption metrics continued climbing—NAVEX's 2024 benchmark covered 1.8M+ reports globally; independent analysis showed reporting volume increased to 1.57 per 100 employees (from 1.47 in 2022) with substantiation rates at 45% (up from 41%). New product capabilities launched (Vault's VaultTalk AI-enhanced phone intake system claiming 50% faster investigations). Research advanced on whistleblower protection: academic paper demonstrated AI-powered text sanitization reducing re-identification risk from 98.81% to 31.22% authorship attribution accuracy. Broader AI hype cycle generated skepticism (Acemoglu warning of 2024 disappointment), reflecting continuing tension between capability maturity and organizational readiness. Market consolidation continued with Vault Platform's Fast Company recognition and strong market positioning. Challenge remains: growing adoption and capability advancement coexist with persistent organizational implementation barriers and AI fairness concerns in automated classification.
  • 2024-Q2: NAVEX's official 2024 report on 3,784 organizations confirmed continued adoption momentum: median 1.57 reports per 100 employees with 45% substantiation rate marking an 11-year high, and 50% substantiation for identified reporters indicating sustained organizational trust. Notably, regulatory attention to AI whistleblower issues (SEC and DOJ enforcement focus) and industry discussions about whistleblower protections for AI workers highlighted emerging meta-concern about AI governance—though not directly impacting whistleblower report triage systems themselves. The capability ecosystem remained mature and consolidating, with post-acquisition integration (Diligent-Vault) proceeding and continued emphasis on AI-assisted classification and deduplication.
  • 2024-Q3: Vendor product evolution continued: EQS Group's Integrity Line platform released new AI features for automated transcription and anonymization of whistleblower reports (August). However, adoption metrics remained concerning—NAVEX's July 2024 survey of compliance professionals showed only 61% of organizations maintain a whistleblower hotline or internal reporting channel and just 55% have non-retaliation policies, revealing persistent gaps in foundational infrastructure despite widespread technology availability. Regulatory drivers intensified: DOJ's September 2024 update to its Evaluation of Corporate Compliance Programs (ECCP) now explicitly instructs prosecutors to assess whistleblower protection, anonymity safeguards, and anti-retaliation enforcement—formalizing whistleblower infrastructure as a compliance expectation. The contradiction remained stark: technology platforms mature and feature-rich, but organizational readiness and investigation capacity lagging.
  • 2024-Q4: Vendor packaging and integration accelerated: NAVEX and Gartner analyst coverage (October) confirmed continued ecosystem consolidation around major platforms offering integrated whistleblower & incident management. EQS Integrity Line reported 4,000 global customers, signaling competitive multi-vendor deployment beyond NAVEX's dominant position. However, broader AI governance surveys (Deloitte, Smarsh) in December revealed persistent implementation gaps: 58% of organizations adopted generative AI for compliance, but only 32% established formal governance programs—illustrating the core barrier to effective whistleblower AI deployment. By year-end 2024, the ecosystem remained in the tension state from prior quarters: capability maturity and regulatory pressure had advanced, but organizational implementation infrastructure and investigation capacity continued to lag, limiting the impact of increasingly sophisticated AI triage and anonymization tools.
  • 2025-Q1: NAVEX's March 2025 benchmark reaffirmed sustained large-scale adoption: 2.15 million reports from 4,000+ organizations at record 1.57 reports per 100 employees and highest substantiation rates. Vendor ecosystem remained competitive (Vault, EQS) with continued AI feature launches. Law firms (A&O Shearman, January) articulated growing organizational need to integrate AI thoughtfully into whistleblower programs amid evolving regulatory complexity. Practitioner analyses emphasized hybrid human-AI approaches and rapid investigation workflows. However, organizational maturity barriers persisted: the fundamental gap remained between technology capability and genuine organizational commitment to effective whistleblower protection and investigation infrastructure.
  • 2025-Q2: Regional adoption data showed geographic acceleration (Europe's reporting rate jumped from 0.49 to 0.67 per 100 employees), with investigation closure times ranging 19-69 days and anonymous reporting rates 52-70% across regions. Vault Platform and EQS Integrity Line continued product feature evolution (multi-channel engagement, AI summarization, anonymization). Vendor data showed 30% engagement boost and 66% faster resolution times for AI-enabled multi-channel systems. Practitioner analyses emphasized AI applications in anonymity protection, real-time prioritization, and pattern detection. The core organizational maturity gap remained the binding constraint on effectiveness despite continued capability advancement.
  • 2025-Q3: Employee perception survey (Case IQ) showed 70% US worker acceptance of AI-driven whistleblowing tools alongside 20% expressing privacy and fairness concerns. NAVEX's September guidance explicitly identified cultural resistance and governance concerns as primary adoption barriers, positioning AI as complementary to human judgment rather than autonomous. EQS continued platform feature evolution (transcription, anonymization). Vendor ecosystem remained mature with normalized AI-assisted triage, but organizational implementation gaps (investigation capacity, retaliation prevention, AI governance policies) remained the binding constraint on effectiveness.
  • 2025-Q4: Ecosystem consolidation accelerated with Case IQ's acquisition of WhistleBlower Security (December), combining reporter-centric hotline intake with investigator-centric AI case management for end-to-end workflows. Diligent's Vault Switch Kit promotion signaled continued vendor investment in migration tooling and AI-enhanced report management. Employee adoption signals strengthened: Case IQ's 2025 study confirmed 81% of employees witnessed misconduct with 72.7% reporting, and AI chatbots/voicebots ranked among top three preferred intake channels. By year-end 2025, organizational maturity barriers remained the primary constraint; technology capability and vendor competition continued advancing, but investigation resource capacity, retaliation prevention infrastructure, and formal AI governance adoption remained lagging indicators.
  • 2026-Jan: Regulatory acceleration and vendor consolidation continued through early 2026. New regulatory requirements in Japan, UAE, Netherlands, and California (Transparency in Frontier AI Act) explicitly mandated whistleblower protections, driving organizational demand for faster AI-assisted triage systems. EQS and Diligent-Vault completed ecosystem consolidation, with multiple law firms and compliance platforms (LegalIntel, EQS, Vault) offering AI-powered case intelligence features at production scale. Independent market analysis confirmed competitive multi-vendor ecosystem with matured AI capabilities including automated classification, pattern detection, and anonymization. However, organizational maturity barriers and investigation resource constraints remained the binding constraint on effectiveness.
  • 2026-Feb: NAVEX released new AI-driven analytics features (Quick Insights dashboard, incident benchmarking) expanding real-time trend detection and program comparison capabilities at scale. However, critical analysis of AI accuracy claims in compliance revealed persistent false positive challenges: 94% of financial services firms deploying AI misconduct detection tools, but base rate effects cause 10,000+ false alarms per 1M communications, undermining investigation efficiency and reviewer attention. Vendor consolidation and product evolution continued, but AI reliability concerns remained a binding constraint on effectiveness.
  • 2026-Apr: Production-scale capability continued to be confirmed: Control Risks deployed Relativity aiR to process 275,000 multilingual documents ahead of deadline; elsai automated risk-theme identification and investigation chronology sequencing for a global advisory firm, cutting timeline work from 15-20 days to minutes; and LLM-powered document analysis platforms are now achieving 80% time reductions with full coverage of unstructured document volumes. EQS Integrity Line reached 14,000+ organisations and SAI360 demonstrated 30+-language AI routing at ABB. Against this, compliance counsel at Debevoise & Plimpton cited NAVEX 2026 data showing case closure times are lengthening — a documented signal that AI tool integration is adding procedural overhead rather than net acceleration — and ASIC's examination of 134 companies prompted AICD to publish board-level governance benchmarks for triage times and systemic issue tracking. A distinct risk surfaced for whistleblowers using consumer LLM tools: mainstream AI providers' identity-verification requirements and data-sharing practices create anonymity exposure, highlighting a gap between enterprise-grade triage infrastructure and the ad-hoc tools individual reporters may turn to.