Compliance has spent two decades becoming excellent at paperwork about harm. Incident registers, case files, audit trails, disclosure reports: the machinery of recording failure has never been more sophisticated, more audited, or more expensive.
The outcomes tell a different story, and privacy tells it most cleanly. European regulators now receive personal data breach notifications at an average of 443 per day, up 22% in a year, and cumulative GDPR fines have passed €7.1 billion, with over 60% of that imposed since January 2023 (DLA Piper, January 2026). The notification machinery has never run better; the thing being notified about keeps growing. Trade compliance has the same shape. Screening programmes generate more alerts than ever, and the penalties keep setting records, with BIS's $252.5 million Applied Materials settlement in February 2026 the second-largest in the agency's history.
Even safety, the domain with the longest recording tradition and the best headline trend, makes the point once the numbers are split. US recordable injury rates have fallen by nearly half since 2006; the fatal injury rate fell by roughly a fifth. The metric the recording system optimises improved more than twice as fast as the outcome that matters most. Globally, the International Labour Organization estimates around 2.93 million people die from work-related causes each year, the large majority from occupational disease rather than sudden accidents, and those slow harms appear in no incident log at all.
The recording trap
The gap is not hypocrisy. It is an honest consequence of what compliance systems were built to do. A recording system improves the things recording improves: classification, timeliness of reports, completeness of files, defensibility in hindsight. Those went up, measurably.
But recording is downstream of the event. Every record begins its life after the thing it exists to prevent has already happened. An apparatus built entirely of downstream tools can refine its description of failure forever without once arriving earlier than the failure.
The pattern repeats across every compliance domain. Regulatory teams maintain registers that describe obligations after they change. Trade teams clear screening alerts after the transaction is flagged. Auditors sample controls months after the control operated. Ethics teams analyse hotline cases after someone was harmed enough to call. Different domains, one grammar: the past tense.
What the upstream version looks like
Each of those functions has an upstream twin, and the data to power it usually already exists inside the downstream records:
- The observations, permits and near-misses that precede a serious incident, assembled into a prediction rather than a monthly count.
- The regulatory change detected on publication and mapped to the procedures it touches, rather than discovered at the annual review.
- The ownership structures traversed before the sanctioned party appears in a transaction, rather than after the alert fires.
- The control that is monitored continuously, so drift is detected in days rather than sampled into visibility a quarter later.
- The pattern of retaliation risk and reporting decay read from the case data, before it becomes next year's headline.
The registers are not waste. They are training data. The failure is leaving them as filing cabinets when they could be predictors.
Prediction alone is not the destination
One caution, learned the hard way in safety. An upstream number can be as hollow as a downstream one. A risk score nobody acts on is a recorded prediction, which is to say, another record. The point of predicting is the decision it enables: a named owner, a threshold that triggers action, an intervention whose outcome is tracked, and honesty about what the data cannot support.
That is why the shift is properly described as compliance becoming a decision discipline, not compliance buying a forecasting feature. The question the function should be judged on changes from "can we evidence what happened?" to "did we see it coming, and did acting on that foresight change the outcome?" Evidence of the past remains the floor. It stops being the ceiling.
This conviction is the reason the Prophesee Compliance Suite exists. Nine compliance domains on one decision layer that predicts, detects, explains and intervenes rather than stopping at the record. Built with and proven inside global enterprises. See it on your own data. Start here.