From Regulation to Implementation: A Critical Evaluation of LLM-Assisted Regulatory Compliance in Industry

2026-08-21Artificial Intelligence

Artificial Intelligence
AI summary

The authors looked at how using large language models (LLMs) helps create documents needed to follow European Union rules on sustainability and privacy. They focused on two types of documents: Digital Product Passports, which need strict formats, and Data Protection Impact Assessments, which have looser formats and require expert knowledge. Their study showed that LLMs do better with strict formats even if the instructions are simpler, but for looser formats, LLMs need more detailed guidance to be accurate and complete. They also found that strict formats can cause LLMs to make more mistakes or add false information.

European UnionEcodesign for Sustainable Products Regulation (ESPR)Digital Product Passports (DPP)General Data Protection Regulation (GDPR)Data Protection Impact Assessments (DPIA)Large Language Models (LLMs)Regulatory complianceData extractionPrompt engineeringDocument standardization
Authors
Adriana Watson, Marco Bücheler, Grant Richards
Abstract
The European Union (EU) has emerged as a leading regulatory body in the development of sustainability and privacy regulations. While new regulation requirements vary, many include a documentation artifact to ensure compliance. Notably, the Ecodesign for Sustainable Products Regulation (ESPR) introduces Digital Product Passports (DPPs) for life cycle transparency, while the General Data Protection Regulation (GDPR) mandates Data Protection Impact Assessments (DPIAs) to mitigate privacy risks. Creating these compliance artifacts, however, is challenging. Industrial data, which often exists in heterogeneous formats and is scattered across company and supplier systems, is required for DPPs and can be difficult to extract into compliant DPP formatting. Furthermore, DPIA documents require interdisciplinary expertise and follow no standardized format, making development difficult for novel systems. To address the particular complexity of compliance artifact creation for both regulations, researchers have proposed the use of LLMs in the generation process; however, the impact of the aforementioned problems on the output of these systems is largely unaddressed. This work investigates the existing research gap by exploring how data extraction instructions and regulatory vagueness impact the quality and consistency of LLM-produced compliance artifacts. The resulting artifacts are evaluated by benchmarking different models against manually created ground-truth schemas. The results reveal that less strict guidelines, such as DPIA formatting, require higher context prompts to maintain consistency and completeness. Stricter guidelines, such as formatting for Digital Battery Passports (DBP), result in consistent results regardless of prompt context, but may lead to more hallucinations in the output