Are CX leaders relying too heavily on the reputation of major AI models to protect them from legal compliance risk?
In this CX Today interview, Nicole Willing speaks with Nadia Kadhim, Executive Director at Aithos, about research that raises serious questions for organizations deploying AI agents across customer support, sales, onboarding and digital engagement.
Aithos, the European non-profit AI research foundation behind LARA, a legal compliance testing tool for AI systems, tested leading AI models against European regulations, including GDPR and the EU AI Act. The results were stark: every major model tested failed compliance checks across realistic workplace scenarios.
For Kadhim, the most surprising finding was not one isolated failure. It was the consistency of non-compliance across the board. Even frontier models, which many organizations may assume are safer or more reliable, broke legal provisions in multiple scenarios. In some cases, the models also violated banned practices under Article 5 of the EU AI Act, which covers practices Europe considers especially harmful to safety, health and human rights.
“So newer and more capable does not necessarily mean more compliant, and that was the most surprising.”
That point matters for customer experience leaders because many businesses are deploying AI agents quickly, often with a focus on whether the system completes the task, answers questions, sounds human or uses the right tone of voice. But Kadhim argues that organizations are less likely to test whether those same systems are violating legal provisions while doing the job they were designed to do.



