ARR/Field Notes/Accounting
Field notes · Regulatory & compliance

Which version of the policy did your AI just apply?

An employee asked your AI assistant a compliance question. It answered clearly, cited the policy, and applied a rule that was replaced in March. Six months later an auditor asks which version it used, and nobody can say.

For compliance officers, risk teams & internal audit · 6 min read
Two versions of a Gifts and Hospitality Policy. The superseded 2024 version allows gifts up to $150 and is the one the AI quotes. The current version, effective 1 March 2026, lowered the limit to $100 and never reached the AI. An auditor later asks which version was applied, and there is no record.
Click to open full size
The story

A $120 dinner. A $20 problem.

A supplier invites one of your account managers to dinner. Estimated cost: $120 a head. Before accepting, the employee does the right thing and asks the company AI assistant whether it's allowed.

AI answer
"Yes. Under §3.2, gifts and hospitality up to $150 can be accepted without approval."
confident · cited · superseded

On 1 March 2026 your Gifts & Hospitality Policy was updated to version 5, and the limit dropped to $100. The old version 4 is still sitting on the intranet, in last year's training deck and in a shared folder. The AI found one of those. The employee followed the advice in good faith, and an approval that should have been required never happened.

The dinner is minor. The question that follows isn't: how many other answers came from superseded versions, and can you show which version each one used?

Why it happens

Relevance isn't authority.

AI assistants answer from the passages that best match the question. An old policy that happens to be worded like the question will beat the current one, and nothing in the process checks effective dates, superseded status or approval state. A superseded rule and a current rule look exactly alike once they've been turned into an answer.

That's a governance problem as much as a technical one. Regulators increasingly expect an AI decision record to show exactly which policy and which version was relied on, not just "the gifts policy" (CX Today, Velt). If the assistant can't tell versions apart, nothing downstream can record the difference.

01

Someone asks

"Can I accept a $120 dinner from a supplier?"

02 · where it breaks

The old version matches best

The superseded policy is picked because its wording fits the question, not because it's current.

03

A compliant-sounding answer

Clear, cited, applied in good faith. Against a rule that no longer exists.

Five signs, five fixes

Every answer cites a policy. Not every policy is current.

01
The superseded rule

A rule that has already changed

Your AI applies the version it read earlier, after the policy was updated.

✓ With ARR

Your AI is told when a rule it read has changed since, so it re-checks before answering.

02
The lookalike versions

v4 and v5 read almost the same

Your AI treats two versions of a policy as identical and answers from whichever it found first.

✓ With ARR

The versions are paired and you see exactly what differs, such as the limit dropping from $150 to $100.

03
The missing history

An auditor asks what changed

There's no change log for half your policies, so your AI can only guess what was edited and when.

✓ With ARR

ARR shows what changed between documents, even with no history or backup to compare against.

04
The dropped exception

A requirement with an exemption beside it

Your AI states the requirement and leaves out the exemption written on the next line, or the reverse.

✓ With ARR

When a requirement and its exception sit together, your AI is handed both, so neither arrives alone.

05
The unverifiable evidence

References that stop matching

The section numbers in your evidence pack drift as policies are revised, and nobody can prove what the AI actually saw.

✓ With ARR

Every reference carries a fingerprint of the exact text, so a reviewer can confirm what was relied on (in shared setups).

Why a policy library isn't enough

Your portal has one version. Your organisation has ten.

A well-run policy management system keeps one approved, current version. That's the right foundation. But copies escape it: exported files, attachments in old emails, last year's training slides, a team's own summary on the wiki. An AI assistant that can read across your organisation will find those too, and it has no reason to prefer the official one.

ARR doesn't replace your policy system or your judgment. It changes what the AI is handed: the current rule with its exceptions, a clear signal when two versions disagree, and a warning when something it relied on has changed.

A fair caveat

ARR helps your AI tell versions apart and notice when they change. It isn't an audit-trail system by itself; recording which version each answer used is still the job of your logging and governance tools. We've measured these abilities in our own benchmark on code and text, not yet on policy documents, so treat this as how ARR is built to work here. That's what early access is for.

Try this tomorrow

The effective-date test

  1. Pick a policy whose rule changed this year, such as a limit, threshold or approval step.
  2. Ask your AI assistant a question where the old and new answers differ.
  3. Check which version it applied, and whether it mentioned the effective date at all.

If it applied the old rule, or can't say which version it used, that's the gap ARR was built to close.

Early access

Be one of the first compliance teams to test ARR on real policies.

We're opening ARR to a small group first. Tell us how your policies are managed and we'll be in touch when your place is ready. No payment required.

More in ARUKAS Field Notes:
Your AI is answering from an old document
When legal AI gets the clause wrong
Chunking breaks meaning
Why AI coding agents break things three files away
Running parallel coding agents without them overwriting each other
AI citation errors start before the AI writes anything
Duplicate files, duplicate totals: where AI reconciliation goes wrong
What AI prior-art search doesn't tell you it missed
How ARR works →