News

CBP Selects Tru Identity

Voices·Jul 22, 2026

Defining and Implementing Responsible AI

By Hugo Pakula

Trade enforcement grew 520% in the seven years leading up to 2024. From 2025 until present day, the number of CF-28s and CF-29s are increasing rapidly. And CBP has committed another $3.5 billion through 2029, earmarked specifically for artificial intelligence and machine learning, layered on 30 years of ACE data that can now be used as a dataset to target non-compliance.

Cindy Allen, who ran the ACE Business Office inside CBP's Office of Trade, estimates the private sector now runs five to seven years behind the agency's capabilities. This asymmetry has ended the debate about whether AI belongs in trade compliance. The question now is how to use it without trading one kind of risk for another.

The result of rampant fraud is a demand for technology to keep pace. CBP is now very comfortable and familiar with the capabilities and benefits that Responsible AI can bring - and is setting the tone for the logistics industry.

What is AI?

Start with what AI is: a tool—in the same lineage as ABI, ACE, and Excel. Tools make professionals more effective; they don't absorb their obligations. The responsibility for the outcome of an entry still belongs to the customs broker or the importer.

CBP has confirmed this directly. HQ Ruling H350722, issued in January 2026, established that AI cannot conduct customs business independently: software can't classify to ten digits on a live entry, and, to many people's surprise, even OCR of entry documents crossed the line. Our read is that the ruling went further than expected on specifics like OCR, and CBP's outreach since suggests clarification may come. The core is not moving: a technology company can't act as a customs broker, and the licensed broker remains the responsible party under 19 CFR § 111.

What is Responsible AI in trade?

Responsible AI is artificial intelligence that has been specifically crafted to meet the demands of compliance, of scrutiny, and for responsible supervision. Responsible AI reduces to a working definition:

  • A qualified human reviews outputs through a documented, risk-based process
  • Every determination can be explained and defended when a CF-28 lands
  • The licensed professional remains the decision-maker, in fact and on paper
  • You can articulate exactly where AI is and isn't involved in your workflow

When CBP evaluates responsible supervision and control, the standard is the totality of circumstances. No single control proves compliance; the whole documented process does.

Where AI belongs in the workflow

Talk to enough brokerages and the same math appears:

One high-volume e-commerce broker manually reviews about 30% of products before filing deadlines. Another, processing 36 million transactions a month, reviews roughly 2%. All while another has 100,000 new products arrive monthly, many without so much as a unique product identifier. A mid-market brokerage clocks classification at 20 to 30 minutes per product, with 90% of the incoming products being net-new.

The work is more than ever before - it’s simply unsustainable. It is inevitable that a new generation of tools are ushered in.

Even simply “working harder” doesn’t solve the problem. That volume problem is where AI earns its place, in three operating modes:

  • In the background. Continuously screening, scoring, and flagging so your team only sees what's worth reviewing. In one deployment, 9,770 products produced 779 flags; 719 resolved automatically with better data, 60 went to a broker for judgment. That's a review any team can actually perform.
  • On patrol. Watching HTS revisions, 99-code changes, and AD/CVD scope updates, and surfacing which of your products are affected before your client asks, instead of a master spreadsheet maintained by hand. Used this way, AI is surfacing the most relevant, consequential compliance opportunities and risks while you focus on delivering excellent service.
  • On demand. Drafting an HTS classification with the full GRI citation chain, modeling a tariff impact, or prepping a CF-28 response for your licensed broker to sign off on rather than building from scratch.

Every mode carries the same requirement: confidence scoring that routes low-confidence items to human review. If you can't see how certain the system is, you can't manage its risk. None of this displaces judgment. It decides where judgment gets spent.

Where AI doesn't belong

The sharper test of a responsible program is what you refuse to automate.

Final determinations without a “Human in the Loop”. Classification, valuation, and admissibility decisions on formal entries are customs business. Under H350722, that work requires a licensed broker's oversight. An AI recommendation can inform the decision. It cannot be the decision.

General-purpose chatbots doing trade compliance. A consumer LLM hallucinates, doesn't know your HTS codes, and can't see your entry data. Further, its training data ages while regulations move. It isn't purpose-built for the workflow, or for the high accuracy standard that exists in this industry, so its output is often plausible yet indefensible…the worst combination in an audit. "Our AI said so" won’t satisfy a CBP auditor.

Deterministic logic. Chapter 99 stacking and sequencing is not something you can guess, or in the case of an LLM - predict. There is one right answer, and it must be the same answer every time. That belongs in hard-coded rules, not in a probabilistic model that is correct most of the time. Part of running a responsible program is knowing which problems are AI problems and which are not.

The client relationship. The recent executive order pushes brokers to police their customers — without the tools or the authority to compel answers from them. What brokers do have is the relationship: knowing the client's products, their data, their second- and third-tier suppliers. That knowledge is what differentiates a real service provider from a data pusher.

There's an unspoken risk here too: expertise atrophies when staff stop questioning outputs and thinking critically. The fix here is structural. Position AI to feed questions to experts, not to sneak conclusions past them.

What to demand — from vendors and from yourself

Three questions separate vendors who understand trade from ones who don't:

  • "Where does your regulatory data come from?" If the answer is "the model's training data," the conversation is over. Training data doesn't update; regulations do.
  • "How is a determination built?" A viable vendor walks you through the citations, the GRIs, and the audit trail, built on controlled, verified sources.
  • "What happens at low confidence?" A viable answer routes the case to a human for final review and determination.

One more demand most evaluations skip is multi-layered audit. AI checks human output, humans check AI output, continuously.

What will enable you to grow as a brokerage is the ability to fine-tune these controls for sensitivity and for compliance so that you’re only reviewing what is really necessary, without overdoing it and creating unnecessary work for your team.

The same discipline applies internally. Start with the problem, not the technology.

For example, clean data that just needs to reach CBP, data scattered across procurement and legal, or handwritten supplier invoices. Define success across your own organization before evaluating anyone, and don't get distracted by shiny objects. Then document everything: what the AI does, who reviews what, and why. When scrutiny comes, the record is the defense.

What good looks like

Deployed this way, the results are measurable:

  • A customs brokerage cut classification review during client onboarding from 1–1.5 hours to under 10 minutes, then turned that review into a billable compliance service. AI made their licensed expertise more valuable, not less.
  • A cross-border fulfillment provider moving high volumes has run with zero customs stoppages: messy data in, cleaned up using compliance APIs, and all exceptions caught before filing.

The pattern holds in every case: a licensed professional still makes the call. What changed is how many calls they can make, how fast, and how defensibly.

The standard is proof

Trade compliance has always run on one question: can you support what you filed? AI doesn't change the question. AI raises the stakes, because CBP can now find what you can't prove, faster than ever. The test worth applying to your program: if CBP audited you tomorrow, could you reconstruct every determination your AI made alongside your team?

At Tru's entire design philosophy is constructed around this reality:

  • AI where it adds accuracy and speed
  • Hard rules where determinism is required
  • Humans where judgment lives
  • Documentation everywhere

The right AI scales with your team and doesnt replace them. Not because that makes a better pitch, but because it's the only version of AI that survives contact with 19 CFR.

Compliance has only ever moved one way. I can't think of a government this century that decided to ask importers and brokers for less. So the brokerages that pull ahead won't be the ones running the most AI. They'll be the ones who can show, entry by entry, that they used it responsibly.

Put responsible AI into practice

Defining responsible AI is the easy part. Proving it takes a framework. For this, the Using AI in Customs Brokerage guide turns principles into practice with a complete Responsible AI toolkit including the full set of questions to ask any vendor, the red flags that should end a demo early, and a side-by-side scorecard for choosing a partner you can actually defend.

Get the guide →