Blog & Insights
ACA 2026: What Compliance Leaders Should Take Away from This Year’s Conference
ACA’s Annual Convention showcased the challenges and opportunities shaping the future of the ARM industry. Topics ranged from leadership and innovation to operational efficiency.
But this was the theme that stood out the most to me: Artificial intelligence is not a future consideration. It’s a present reality.
The conversation has evolved beyond whether organizations should use AI. The more important question is: How can organizations use AI responsibly while maintaining compliance, transparency, and consumer trust?
From legal and regulatory developments to practical AI governance strategies, here are my key takeaways from ACA 2026.
AI Is Becoming Essential, but Governance Matters
AI has the potential to help our industry modernize operations, improve efficiency, and address longstanding challenges. This year’s Innovation Stage was filled with solutions focused on everything from modern collections strategies and digital communications to self-service tools and operational automation.
That said, speakers repeatedly emphasized that AI should not be adopted simply because it’s available.
AI creates value only when it solves real business problems. Organizations should resist the temptation to deploy technology for technology's sake and instead focus on solutions that improve outcomes for consumers, clients, and employees.
Just as importantly, AI must be implemented with caution, oversight, and accountability. The recurring themes throughout the conference were:
- Transparency
- Accountability
- Responsible governance
- Consumer trust
- Human oversight
In other words, successful AI programs are not built solely by technologists. These programs require compliance, legal, operational, and business stakeholders working together.
Your Employees Are Already Using AI
One of the most practical messages shared during AI discussions was simple: Your employees will use AI whether you formally authorize it or not.
Ignoring AI usage is not a strategy. Instead, organizations should establish clear governance frameworks that define:
- Which AI tools may be used
- Who may use them
- Acceptable business purposes
- Required approvals
- Data handling requirements
- Monitoring and oversight procedures
Rather than providing open access, organizations should consider role-based permissions and clearly defined use cases. Employees need guidance, not just access.
AI Doesn't Replace Existing Compliance Obligations
A critical reminder throughout the conference was that AI does not lessen regulatory requirements. If anything, it introduces additional responsibilities.
Organizations remain responsible for complying with existing consumer protection, collections, privacy, security, employment, and communications laws, regardless of whether a process is performed by a human or an AI-enabled tool.
Simply put: AI changes how work gets done. It does not change the legal requirements governing that work.
Compliance programs must evaluate AI-enabled processes using the same regulatory lens applied to existing operations while also addressing new risks unique to AI technologies.
Vendor Oversight Is More Important Than Ever
Many organizations are adopting AI through third-party vendors rather than developing solutions internally. While this approach can accelerate implementation, it does not eliminate accountability.
A recurring theme throughout the conference was the importance of robust vendor oversight programs. Regulators increasingly expect organizations to understand how their vendors operate, manage risk, and make decisions.
If a vendor's technology creates compliance issues, the organization using that technology may still be held responsible.
Organizations should ensure their vendor management programs include:
- Due diligence reviews
- Ongoing monitoring
- Contractual controls
- Testing and validation requirements
- Security and privacy assessments
- AI-specific governance evaluations
Trusting a vendor is not the same as validating a vendor.
Ask the Right Questions Before You Commit
Transparency and Accountability Continue to Be Key Expectations
Conference discussions frequently returned to the importance of transparency.
Consumers increasingly expect to know when AI is involved in interactions or decision-making processes. And depending on the state law, organizations may be required to provide AI disclosures. Organizations should carefully evaluate where disclosures may be appropriate and how to communicate AI usage clearly and accurately.
Accountability remains essential. Organizations should be prepared to explain:
- How AI systems are being used
- What data is being utilized
- How outcomes are monitored
- What controls exist to mitigate risk
- How concerns are investigated and resolved
Transparency helps build trust. Accountability helps sustain it.
The NIST AI Risk Management Framework Remains a Strong Foundation
For organizations still developing their AI governance programs, the NIST AI Risk Management Framework (2023) was repeatedly referenced as a practical starting point. The framework emphasizes governance, risk identification, measurement, and management throughout the AI lifecycle.
While it is not industry-specific, its principles align well with emerging regulatory expectations surrounding responsible AI deployment.
Organizations don't need to start from scratch. Existing frameworks can help create structure around AI risk management efforts.
Legal Developments Continue to Shape Operations
Beyond AI, legal and regulatory updates highlighted several developments that may impact industry operations. Among the notable discussion points:
- Agencies cannot simply rely on clients to ensure compliance. Agencies remain responsible for understanding and following applicable laws.
- TCPA litigation continues to evolve, including ongoing legal questions surrounding the treatment of text messages under certain provisions.
- Delivery of required notices through digital channels remains an active area of scrutiny, with effectiveness and ease of consumer access playing important roles.
- Consent remains foundational to compliant communication strategies.
As always, organizations should work closely with legal counsel when evaluating operational impacts from new court decisions and evolving regulatory interpretations.
Final Thoughts
The most important lesson I took away from ACA 2026 is that AI and compliance are not separate conversations. The industry's future will be shaped by organizations that can balance innovation with responsible governance.
AI offers tremendous opportunities to improve efficiency, enhance consumer experiences, and support business growth. But achieving those benefits requires thoughtful implementation, clear accountability, strong vendor oversight, robust data governance, and unwavering commitment to compliance.
Technology may continue to evolve rapidly, but the fundamentals remain the same:
Be transparent. Be accountable. Protect consumers. Build trust.
Those principles will continue to guide successful organizations long after the latest AI tool arrives.
Finding the Right Path Forward with AI
As AI adoption accelerates, organizations face a practical challenge: identifying where AI can create value while maintaining accountability and oversight. Download the guide to explore a more deliberate approach to AI adoption, and how Finvi can help you apply AI in ways that align with your operational and compliance goals.