Every California operator I talk to is somewhere on the same curve: someone on the team is already pasting questions into ChatGPT, someone else wants to “build a bot for our SOPs,” and ownership is wondering whether any of this is safe in an industry where a records mistake can cost you a license. Having spent the past two years building AI systems inside my own law practice, here’s the honest framework I give clients (including the parts some AI vendors won’t tell you).
Start with an uncomfortable truth: AI amplifies whatever compliance posture you already have
AI systems are only as good as the data underneath it. Point one at clean, current, verified SOPs and it makes your team faster and more consistent. Point one at a 2020 binder, tribal knowledge, and unreconciled METRC habits and it will confidently distribute your mistakes at scale, with a friendly tone. That’s why “incorporate AI” is really a two-part project: get your compliance data verified first, then build on it. Skipping the first step doesn’t just waste the tool; it manufactures liability.
Step 1 — Verify what you have
Before any AI touches your compliance program, you need to know what’s true in it:
- Inventory your SOPs. Which exist, which are actually followed, and when each was last revised. If you can’t produce this list, that is your first finding.
- Map your records. What records exist, where they live, in what format, and how long they’re kept. (Your recordkeeping is also, quietly, the raw material for everything AI will do for you later.)
- Check currency. Procedures written before the recent federal changes may be answering yesterday’s questions.
Whether this verification takes the form of a full audit, a focused gap review, or an attorney second opinion on a self-audit you’ve already done, the question it must answer is the same: if my team follows our written procedures exactly, are we compliant today? If you don’t know, that’s the place to start rather than worrying about AI.
Step 2 — Build on verified content only
Once your procedures are verified, the AI layer is genuinely simple: your SOPs, license conditions, recordkeeping calendars, and incident playbooks become the knowledge base for an AI system. Questions are answered according to your actual procedure, cited to the actual document, instead of a guess or a Slack thread.
Three design rules separate a safe deployment from a liability machine:
- Cite or escalate. The AI system answers only from your verified materials, cites the source, and says “not covered — escalate” rather than improvising. An AI that guesses about compliance is worse than no AI.
- Route legal questions to counsel. “How long do we keep delivery manifests?” is operational — fair game. “Is it legal for us to…” is a legal question, and a properly built AI system refuses it and points to the escalation chain. This line matters for your protection and for professional-responsibility reasons on our side.
- Coach documentation, don’t editorialize. When staff write incident logs, the AI system should coach them to record facts — what happened, when, who, what was done — not conclusions like “this was our fault.” What your team writes in a log can be read back to you later; your AI should know that.
Step 3 — Plan for staleness, because it’s coming
The most dangerous compliance AI system is one that was right last year. Rules change; an AI serving outdated procedures doesn’t just fail to help — it actively spreads the old rule with confidence. Every file in your AI system should carry a “last verified” date, and someone — realistically, your counsel — needs to own the loop: watch the regulatory landscape, and push updated, reviewed content into the AI system when something material moves. If nobody owns that loop, set a calendar reminder to turn the AI system off in twelve months, because that’s roughly when it starts lying to your staff.
What AI should not do in your compliance program
Worth saying plainly: don’t let AI file things with regulators unreviewed, don’t let it communicate with the DCC or inspectors, don’t let it make judgment calls on reportable events, and don’t treat its output as legal advice no matter how confident it sounds. The pattern that works is AI doing the reading, retrieving, and drafting, with humans — your compliance lead and your counsel — doing the deciding. That division of labor is what makes the whole thing defensible if a regulator ever asks how your program works.
The five questions to ask before you start
- If my team followed our written SOPs exactly, would we be compliant today?
- Can I produce a current list of every record we’re required to keep, and where it lives?
- Who verified the content my AI tool would be built on — and when?
- Where does my data physically go when my team uses the tool?
- Who owns keeping it current when the rules change?
If you can answer all five, you’re ready to build. If you can’t, the answers are cheaper to get than the consequences of guessing, and getting them is exactly the kind of fixed-fee project that takes a week, not a quarter.
Kocot Law helps California operators verify their compliance programs and build AI systems on top of them — attorney-reviewed, running in your environment, kept current as the rules change. Learn about the Kocot Law Compliance Operating System or call/text (916) 572-6445.
Attorney advertising. This article is general information, not legal advice, and reading it does not create an attorney-client relationship. Rules change — confirm current requirements with counsel before relying on any statement here.

