Skip to Content
Financial Regulatory Developments Focus

Filters
The following posts provide a snapshot of selected UK, EU and global financial regulatory developments of interest to banks, investment firms, broker-dealers, market infrastructures, asset managers and corporates.
  • Delegated Regulation on market risk prudential requirements for EU banks published in OJ
    11 September 2026

    Commission Delegated Regulation (EU) 2026/1221 was published in the Official Journal of the European Union (OJ). The Regulation makes targeted amendments to the EU prudential framework for banks' market risk, specifically the Fundamental Review of the Trading Book (FRTB) under the Capital Requirements Regulation (CRR).

    While most Basel III reforms have applied since 1 January 2025, the FRTB has been deferred on several occasions, most recently to 1 January 2027 in response to uncertainty around implementation timelines and potential deviations from the Basel standards in other major jurisdictions.

    This Delegated Regulation sets out amendments intended to support a level playing field for EU banks competing internationally in trading activities by offsetting the negative capital impact of the FRTB for a period of three years – until 31 December 2029, in aspects of the framework where deviations in other jurisdictions have been identified or are likely, including:

    • The profit and loss attribution test (PLAT): to allow banks to calculate the PLAT only for monitoring purposes during the three-year period, with no direct impact on the own funds requirements.
    • The non-modellable risk factors (NMRFs) framework: to modify the conditions on the number of verifiable price observations needed for a risk factor to be considered modellable and hence be capitalised under the expected shortfall calculation.
    • Internal default risk model requirements: applying a multiplier equal to 0 to the probability of default of issuers/obligors that attract a 0 % risk-weight under the alternative standardised approach (allowing banks under the internal model approach to treat exposures to those issuers identically to how those exposures would be treated under the alternative standardised approach).
    • The expected shortfall risk measure and the stress scenario risk measure calculations: allowing banks under the alternative internal model approach to temporarily calculate and disclose the values of the regulatory expected shortfall risk measure and stress scenario risk measure on a weekly rather than daily basis.
    • Exposures to Collective Investment Undertakings: allowing and specifying thresholds for a partial look-through, while requiring a more conservative treatment for the part that cannot be looked through.
    • The residual risk add-on (RRAO): applying multipliers for instruments that have future realised volatility as an underlying, that are options that can be exercised on a finite number of dates, or that are options on the difference between two constant maturity swap rates denominated in the same currency, where those instruments attract an RRAO charge only for those reasons.
    • Default risk under the alternative standardised approach: recognising economic hedges between an equity derivative and a cash position of the same underlying.
    • The output floor: limiting the phase-in of the own funds requirements for market risk under the alternative standardised approach, and allowing banks that apply the simplified standardised approach to similarly benefit from the phase-in.
    • Additional proportionality for banks with small trading book businesses: allowing use of the simplified standardised approach for their non-trading book positions subject to foreign exchange risk and commodity risk.
    • Limiting capital impacts: allowing credit institutions adversely impacted by the implementation of the new market risk rules, even after applying the targeted amendments, to limit that capital impact for the three-year period.

    The Regulation entered into force on 12 September, with the amendments applying from 1 January 2027.

  • UK FCA findings on frontier AI and cyber resilience
    2 September 2026

    The UK Financial Conduct Authority (FCA) has published its findings from a multi-firm review examining how firms are using, testing and preparing for frontier AI models with cyber capabilities. The FCA notes that while these models can help firms identify and analyse cyber vulnerabilities more quickly, they can also, if used maliciously, amplify cyber threats to firms' safety and soundness, customers, market integrity and financial stability. The publication does not introduce new rules, guidance or regulatory expectations but summarises observations reported by firms during the FCA's engagement.

    The review identified five key themes:

    • Vulnerability discovery is accelerating faster than firms' ability to respond, increasing pressure on remediation processes.
    • Frontier AI is becoming a test of organisational resilience, not just a tool, with organisational readiness identified as the primary challenge.
    • The value of frontier AI depends on the firm's operating environment, including its governance, tooling, controls and human oversight.
    • Frontier AI is making cyber and operational resilience more important as it exposes weaknesses in vulnerability management practices, access management controls, dependency mapping and remediation processes.
    • Effective governance and human judgement remain critical, with senior leaders needing greater visibility of how AI affects remediation capacity, operational resilience and risk.

    The FCA expects firms to consider whether: (i) their use of frontier AI is supported by clear ownership, appropriate guardrails, access to system information and specialist review; (ii) their vulnerability management and change processes are effective if the volume and speed of model-driven discovery increases; and (iii) their people, systems and processes can operate under greater pressure.

  • FSB letter to G20 finance ministers on financial stability risks
    31 August 2026

    The Financial Stability Board (FSB) has published a letter (dated 28 August) from its Chair, Andrew Bailey, to G20 Finance Ministers and Central Bank Governors, on the current risks to financial stability. While the financial system has continued to absorb the supply shock from the conflict in the Middle East, global markets remain vulnerable to a disorderly correction amid sovereign debt market fragilities, vulnerabilities in private credit and stretched asset valuations, particularly those linked to AI investments. The letter highlights concern that increasing leverage in equity markets, combined with high valuations, market concentration and AI-related cross-investment, could amplify future market stress. Mr Bailey also identifies frontier AI models as an emerging financial stability risk, particularly due to their potential impact on cyber resilience, and calls on authorities to support the safe and responsible release and deployment of such models. He further stresses the importance of robust response and recovery capabilities within financial institutions and resilience among critical third-party technology and service providers. He concludes that the FSB remains focused on identifying emerging vulnerabilities, strengthening resilience and ensuring that innovation is consistent with financial stability.

  • UK FCA wealth management survey report
    18 August 2026

    The UK Financial Conduct Authority (FCA) has published its latest wealth management survey report for 2026, focusing on discretionary portfolio management. The report shares data and insights to help firms understand the market, compare their approach and raise standards. Drawing on survey data from around 400 wealth management firms, as well as regulatory returns and other FCA and public data sources, the FCA highlights both progress and persistent weaknesses across the sector.

    Key findings are set out below in the following areas:

    • AI adoption—13% of firms currently use AI tools and 45% are using or considering AI, but the FCA warns that firms must use these tools responsibly and understand associated risks around fraud, cyber security and client harm.
    • Outsourcing—92% of firms outsource part of their business, with the FCA emphasising that firms remain responsible for the services they provide and must ensure strong oversight, so clients receive consistent outcomes.
    • Financial crime controls—some firms still do not refresh Know Your Client checks for higher-risk clients after a trigger event or at least annually; 26% do not collect expected transaction frequency; around 6% do not screen for politically exposed persons; and around 7% do not carry out sanctions screening.
    • Fair value—the FCA's Financial Lives 2024 survey found that 17% of clients using a named wealth management firm were concerned that fees were high, hidden or complex, indicating pricing is not always clear or consistently applied.
    • Consumer vulnerability—83% of firms now identify at least one client with characteristics of vulnerability (up from 68% in the first survey), yet practices remain inconsistent and firms are urged not to treat vulnerability as a one-off assessment.

    The FCA confirmed it will not repeat the full survey this year but intends to issue a shorter version in 2027, focused on portfolio management activity. The FCA will continue to look for smarter ways to use data and engage with the sector.

  • ESAs statement on mitigating ICT risks from frontier AI models
    31 July 2026

    The European Supervisory Authorities (ESAs, comprising the European Banking Authority, the European Securities and Markets Authority and the European Insurance and Occupational Pensions Authority) have published a joint statement toward a consistent and risk-based approach for information and communication technology (ICT) risks from frontier AI models. The statement builds on the European Commission's action plan on cybersecurity and AI, the ESRB's warning on systemic cyber risks from frontier AI models, and the ECB's letter to significant institutions on AI-related cybersecurity threats.

    While noting that existing frameworks, including the Digital Operational Resilience Act and the EU AI Act, provide a strong foundation for managing these risks, the ESAs emphasise that the speed at which vulnerabilities can be identified and exploited requires financial institutions to take a proactive approach. The ESAs encourage firms to strengthen their ICT risk management processes through three key risk mitigation strategies: prevention; detection, moving to continuous vulnerability monitoring; and management.

    Examples of risk mitigation strategies and actions are set out in the accompanying annex. The ESAs state that in all cases and without delay, financial entities should establish governance structures that support effective management of frontier AI-related risk, with clear accountability frameworks, timely response plans and sufficient internal investment dedicated to strengthening cyber resilience. Separately, the ESAs as lead overseers have initiated targeted engagement with relevant critical third-party providers to understand how they identify and manage these risks.

  • UK Modernising payment services regulation
    14 July 2026

    HM Treasury (HMT) has published a consultation on modernising the UK's payment services and electronic money regulatory framework. Given the pace of innovation in new technologies, the government wants to ensure the existing framework under the Payment Services Regulations 2017 (PSRs) and Electronic Money Regulations 2011 (EMRs) can facilitate new forms of payment safely and securely. The Cross Border Payments Regulation and the SEPA Regulation are also within scope of the reforms while the Interchange Fee Regulation 2015 and the Payment Card Interchange Fee Regulations 2015 are out of scope, reflecting ongoing work on card fees.

    The consultation considers updates to the PSRs and EMRs, including the extent to which responsibility for setting firm-facing requirements should be delegated to the UK Financial Conduct Authority (FCA). Having found that strong customer authentication standards (SCA), while reducing fraud, created burdensome customer friction, the government has already committed to revoking the SCA-related authentication provisions in the PSRs so that the FCA can adopt more outcomes-based authentication rules. The consultation also sets out the government's approach to the long-term regulatory framework for open banking.

    The deadline for responses is 6 October.

  • Financial services AI adoption plan
    14 July 2026

    HM Treasury (HMT) has published the financial services AI adoption plan, setting out next steps to accelerate safe AI adoption and innovation in the sector. The plan describes the UK's existing regulatory framework as a major asset and strong foundation for AI adoption but identifies that the core challenge now is not the absence of regulatory support, but its accessibility, consistency and practical application across the sector. The priority is therefore to establish a clear, authoritative single source of cross-regulator guidance, enabling firms to navigate requirements confidently and scale adoption consistently.

    The plan sets out ten recommendations to unlock near-term scaling, support consistent adoption and manage systemic risk and competitiveness. They include:

    • A comprehensive review of the consumer, competition and wider impacts of financial guidance and advice-like outputs generated by general purpose large language models.
    • Consistent consumer disclosure for AI-driven services.
    • Voluntary AI incident and "near-miss" sharing across the UK financial sector.
    • Exploring the development of a sector-wide financial services AI skills plan.
    • Leveraging the HMT consultation on modernising payment services to establish a "trust framework" to support agentic payments protocol.

    The plan also sets out broader considerations for the government to address cross-sector barriers that impact financial services, such as AI sovereignty and resilience.

  • HMT report on cyber resilience
    8 July 2026

    HM Treasury has published a report setting out evidence on the economic and financial value of operational resilience in financial services, with a particular focus on cybersecurity.

    The report highlights the growing challenges facing organisations and markets as cyber risk intensifies, identifying an increase in the severity of cyber-attacks and the scale of their consequences. It warns that a small number of severe incidents can lead to disproportionate financial losses, with losses for large firms potentially approaching GBP466 million, significantly exceeding the cost of day-to-day incident activity. The consequences of such losses are becoming larger and more persistent, with potentially lasting effects on affected firms. Beyond financial loss, the impact can extend to customer trust, reputation, and investor confidence, highlighting the importance of resilience.

    The report also encourages firms to reframe operational resilience as a source of growth, rather than merely as a compliance obligation or cost. HM Treasury suggests that more resilient firms are better positioned for growth and performance, as they can recover faster and sustain operational momentum. The report cites evidence that more resilient firms outperform their peers in areas such as revenue growth and profitability.

    Furthermore, the report notes that, as digital technologies evolve, the scale and severity of cyber threats are likely to increase. Organisations with stronger resilience will be better equipped to modernise systems and adopt new technologies with less disruption. The report also notes that only 10% of organisations report being prepared for AI-augmented cyber threats and that 77% lack essential data and AI security practices.

    The report concludes that operational resilience and cybersecurity should be treated as strategic capabilities that support financial, operational and reputational growth. It emphasises the significant value of improving resilience in order to protect firms against increasingly sophisticated cyber threats, including those augmented by AI.

  • ECB calls significant institutions to draft an action plan against AI related cybersecurity threats
    7 July 2026

    The European Central Bank (ECB) has published an open letter to CEOs of significant institutions on AI related cybersecurity threats. The ECB warns that advances in AI are accelerating vulnerability discovery and exploitation, marking a long-term shift in the cyber threat landscape rather than a temporary or tool-specific risk. The letter identifies bank management bodies as primarily responsible for responding to the evolving cyber risk, suggesting they may need to revisit ICT investments, resource allocation and bank information and communication technology (ICT) risk-tolerance frameworks, and strengthen governance and control systems where necessary.

    The ECB expects significant institutions to assess the impact of the evolving threat landscape and to develop a comprehensive action plan to strengthen relevant controls. The plan should build on existing cyber-risk strategies, cover short- and longer-term measures, allocate resources, assign responsibilities and set implementation timelines. The action plan must be submitted to the respective joint supervisory team (JST) by 31 October after which the JST will discuss the plan with the bank and monitor progress.

    In the short term, the ECB expects banks to prioritise vulnerability and patch management, monitoring and detection, AI-enabled defensive capabilities, third-party ICT risk management, and protection of perimeter technologies and externally exposed ICT assets. Longer-term measures should include reinforcing defence-in-depth and cyber hygiene, modernising legacy or unsupported technology, and strengthening response, recovery, crisis-management and information-sharing arrangements.

    The ECB also urges banks to remediate outstanding ICT-related supervisory findings without delay, noting that unresolved weaknesses identified through prior supervisory activity may become increasingly material in the evolving threat landscape.

    The ECB confirms that DORA requirements remain highly relevant and that it will extend the deadline for the annual IT Risk Questionnaire from September 2026 to February 2027.  The ECB also notes that the responsible CERT (Computer Emergency Response Team) / CSIRT (Computer Security Incident Response Team) authorities may provide additional guidance. For more information, you may like to read our client bulletin titled "ECB requires significant institutions to address AI-enabled cybersecurity threats".

  • Mills Review sets out recommendations to the FCA on AI and the future of retail financial services
    6 July 2026

    The UK Financial Conduct Authority (FCA) has published The Mills Review report, based on an independent review led by Sheldon Mills, Executive Director, Consumers and Competition at the FCA, examining the potential impact of AI on retail financial services by 2030 and beyond. The review concludes that AI is likely to drive a transition from human-led financial activity to increasingly AI-enabled and delegated services, with firms embedding AI across a wide range of functions and consumers making greater use of AI tools and agents to manage their finances. The review identifies four key systemic shifts arising from AI adoption: the transformation of AI becoming core to firms; the emergence of AI-led consumer journeys; changes to competition and market power; and the amplification of financial crime and cyber risks.

    While it considers the UK's existing outcomes-based regulatory framework, including the consumer duty, senior managers and certification regime and operational resilience requirements, to be broadly fit for purpose, it highlights the need for them to evolve to keep pace with AI developments.

    To support the FCA, the review sets out seven priority recommendations for consideration, including:

    • Securing and adapting the regulatory perimeter.
    • Strengthening system-wide coordination and oversight.
    • Monitoring the transition to autonomous models and adapting regulatory frameworks.
    • Scaling up the FCA's AI Lab to support AI models and system innovation in financial services.
    • Enabling the foundations for agentic finance.
    • Building and adopting an AI-enabled agentic supervisory model.
    • Developing a trusted public-interest AI-enabled financial capability service.
  • UK DRCF call for input on authentication and trust in digital services
    25 June 2026

    The Digital Regulation Cooperation Forum (DRCF) has issued a call for input under its Thematic Innovation Hub on the theme of "authentication and trust", exploring how regulators can help innovators achieve public trust in new technologies and systems. The Hub enables regulators to better understand emerging risks and opportunities and to engage earlier with innovators developing complex new technologies.  The call focuses on the opportunities and challenges associated with two key sub-themes: (i) digital verification, including where these services may support or intersect with open finance and wider smart data frameworks. The DRCF makes clear that this term refers solely to private-sector use cases and focuses exclusively on the verification of identity attributes, rather than the government's ongoing work on digital identity; and (ii) synthetic media and deepfakes, including AI-generated content that may pose risks to authentication, consumer trust and intellectual property rights. Responses are intended to merely inform the DRCF's future cross-regulatory work, and the DRCF does not intend to provide advice or guidance in response to questions raised through the call for input. The deadline for input is 14 August. The DRCF may engage further with respondents through webinars and/or roundtables.

  • FSB consults on sound practices for responsible adoption of AI
    10 June 2026

    The Financial Stability Board (FSB) has published a consultation report on sound practices for responsible adoption of AI. The report sets out 12 sound practices aimed at supporting financial institutions in managing AI-related risks while enabling innovation. The proposed practices are structured around three core areas: (i) organisation-wide AI governance (practices 1–4); (ii) risk management and mitigation across the lifecycle of AI development and deployment (practices 5–10); and (iii) management of AI-related cyber, information and communication technology, and third-party risks (practices 11–12).

    The practices are intended to complement existing international standards and promote cross-border coordination and information-sharing, rather than impose prescriptive requirements or create new regulatory obligations. Financial institutions' boards and senior management are encouraged to consider these practices when shaping strategy, technology adoption and risk management. The deadline for feedback is 22 July, with a final report expected in October.
  • Chancellor speech at the AI Adoption Summit
    9 June 2026

    HM Treasury (HMT) has published a speech delivered by chancellor Rachel Reeves at the AI Adoption Summit. The speech sets out how the government is implementing its strategy to accelerate AI adoption and outlines next steps. In particular, the chancellor confirmed the upcoming publication of a financial services AI adoption plan on 14 July, when she delivers her Mansion House speech.

    During the speech, the chancellor confirmed the launch of the Advisory AI Growth Lab, a forum which will bring together regulators to provide practical guidance on how current rules apply to emerging AI applications, with an initial focus on legal services. She also announced the introduction of the AI Economics Institute, a research organisation of HM Treasury and the Department for Science, Innovation and Technology. Later this month, the National Cyber Action Plan is due to be published. The chancellor further confirmed that legislation would be brought forward in the autumn to better provide for and enable the safe testing of innovative products and services.

    Read more.
  • CMORG guidance on frontier AI and cyber resilience
    4 June 2026

    The Cross Market Operational Resilience Group (CMORG) has published guidance on frontier AI and cyber resilience for financial institutions. The guidance highlights that advanced AI systems are accelerating the speed, scale and sophistication of cyber-attacks, significantly compressing the time between vulnerability discovery and exploitation. This creates an immediate challenge for firms to adapt now to maintain resilience.

    CMORG indicates that remediation timelines may need to compress from weeks to days, and in some cases hours, requiring firms to operate with greater urgency, coordination and discipline. Financial institutions are advised to place stronger emphasis on rapid patch deployment, balanced against potential impacts such as service availability. An effective response will also require coordinated action across governance and leadership, operating models, technology architecture, detection and response capabilities, and the management of supply chain and ecosystem risk.

    Given the pace of development in frontier AI, this guidance is expected to evolve over time. It is intended to provide a practical and actionable baseline for firms to assess their current capabilities and accelerate their response.
  • UK DRCF call for input on consumer interest and AI
    3 June 2026


    The Digital Regulation Cooperation Forum (DRCF) has published a call for input under its "consumer interest and AI" project, project, seeking views on consumer attitudes to, and the management of risks arising from, generative and agentic AI. The call for input is structured in two phases. The first phase focuses on consumer attitudes to the risks associated with generative and agentic AI adoption, including what risks consumers feel they may be exposed to, and to what extent they are, and are not, prepared to tolerate risks in exchange for benefits of AI adoption. The deadline for responses on the first phase is 3 July. The second phase focuses on the tools, governance frameworks and regulatory approaches available to policymakers, regulators and firms to mitigate AI-related harms and deliver effective consumer protection. The deadline for responses on the second phase is 2 September. The DRCF states that responses will inform its ongoing policy work and broader engagement, including future workshops and its Responsible AI Forum, with a view to shaping the debate on proportionate, outcomes-focused regulation of AI across sectors. It does not plan to provide advice or guidance.

  • IOSCO publishes final report on AI supervisory toolkit
    25 May 2026

    The International Organization of Securities Commissions (IOSCO) has published its final report on a Supervisory Toolkit for AI Use in Capital Markets. The report is based on IOSCO's previous work, and provides supervisors with a practical, multi-phased approach to monitoring ongoing advancements in AI, the concentration and dependency on AI service providers, and AI's expanding range of applications and risks in capital markets. The report is designed to complement, not replace, national frameworks, and to offer a common foundation for supervisory dialogue between authorities and firms.

    The report sets out three complementary layers to support supervisory oversight:
    • Areas of supervisory consideration: the first layer outlines areas of supervisory consideration, building on the work conducted for previous IOSCO reports on AI.
    • Tools for supervisory oversight of key areas: the second layer provides supervisors with more detailed tools to support evaluation across four areas of focus: (i) governance and risk management; (ii) third-party and outsourcing risk management; (iii) disclosure; and (iv) recordkeeping and reporting. It also includes practical examples of questions that supervisory authorities may find helpful when planning examinations of supervised firms' AI use.
    • Indicators and data sources: the third layer provides supervisors with suggested indicators for monitoring AI adoption and use, alongside a range of engagement methods to gather relevant information.

    Read more.
  • BoE, FCA and HMT joint statement on AI frontier models and cyber resilience
    15 May 2026

    The Bank of England, UK Financial Conduct Authority (FCA) and HM Treasury have published a joint statement on frontier AI models and cyber resilience, addressed to regulated firms and financial market infrastructures. The statement notes that frontier AI models already exceed the capabilities of skilled practitioners and can amplify cyber threats to firms' safety and soundness, customers, market integrity and financial stability. This is particularly true in cases where firms have not invested sufficiently in core cyber security.

    The joint statement calls on firms to mitigate risks proactively in relation to the following:
    • Governance and strategy: ensuring boards and senior management sufficiently understand frontier AI risks to set strategic direction and oversee how control functions manage risks. Firms should also consider whether they have appropriate insurance in place.
    • Identification and risk management of vulnerabilities: being able to triage, prioritise, risk assess, and remediate vulnerabilities more quickly, more frequently, and at scale, including through automation where appropriate, while mitigating the operational risks from doing so.
    • Managing risks from third parties: effectively managing AI-related cyber risks arising from third parties, supply chains and open-source software, including the capability to monitor and remediate external vulnerabilities.

    Read more.
  • UK FCA re-opens AI input zone to gather views on AI practices
    14 May 2026

    The UK Financial Conduct Authority (FCA) has published an updated webpage confirming the re-opening of its AI input zone. This forms part of the FCA's AI Lab, which supports the safe and responsible use of AI in financial services. The FCA is seeking views and examples to inform a publication on good and poor practices later this year. In particular, it is keen to understand what stakeholders consider "good" practice in terms of safe and responsible AI development, and what can be learned from and improved upon. The deadline for responses is 19 June.
  • UK FCA speech on the next phase of fintech innovation
    21 April 2026

    The UK Financial Conduct Authority (FCA) has published a speech by Jessica Rusu, chief data, information and intelligence officer, setting out how the FCA intends to support fintech firms in the next phase of innovation amid rapid advances in AI and the emergence of "agentic commerce".

    The FCA highlighted its principles-led, outcomes focused approach to AI regulation and announced the next phase of its AI Lab, including: (i) an extended partnership with NVIDIA and NayaOne; (ii) a second cohort of firms entering AI Live Testing, which will conclude by the end of the year, with an evaluation report expected in Q1 2027; (iii) the scaling of the Supercharged Sandbox, giving more UK fintechs access to data and Nvidia compute to build their products, with a second intake opening on 5 May; and (iv) confirmation that the FCA will not introduce new AI specific rules at this stage, but will instead publish examples of good and poor practice later in the year. In parallel, the FCA emphasised the role of its recently published open finance roadmap and announced that its Scale Up Unit is now open for expressions of interest from solo regulated firms to support them in scaling and entering new markets.
  • UK FOS response to FCA on the long-term impact of AI on retail financial services
    2 April 2026

    The UK Financial Ombudsman Service (FOS) has published its response (dated February) to the FCA's Mills Review on the long‑term impact of AI on retail financial services. The response focuses on two areas: the increasing use of AI by consumers and professional representatives in complaint submissions; and financial firms' use of AI.

    The FOS observes an increase in consumers using AI, noting that AI can help consumers organise complaints, overcome language barriers and present clearer cases—especially consumers who are vulnerable and have difficulty expressing themselves in writing. However, there are also concerns where generative AI is used excessively or inaccurately, leading to lengthy, incoherent submissions and "hallucinations". The FOS reports early indications from a small sample analysis that AI may have contributed to around 35% of responses to initial assessments, which can lead to a disproportionate amount of time spent on verifying accuracy. The FOS welcomes the FCA's focus on AI in retail financial services and calls for consistent guidance to firms and consumers as AI use evolves in the complaint process, offering to provide its own insights to support this work.

    Read more.
  • DRCF paper on the future of agentic AI
    1 April 2026

    The Digital Regulation Cooperation Forum (DRCF, comprising the UK Competition and Markets Authority, the UK Financial Conduct Authority, Information Commissioner's Office and Ofcom) has published a paper on the future of agentic AI and exploring how UK regulatory frameworks can help realise the opportunities of this technology in a responsible and safe way. The DRCF defines agentic AI as an agent that acts on behalf of users. Unlike standard generative AI, which responds to queries and creates outputs, agentic systems can assess goals, plan workflows and execute actions autonomously to impact real-world environments and interact with people or other agents.

    While recognising that agentic AI could deliver significant benefits to consumers, the paper highlights that it can also amplify existing risks and introduce new ones, particularly in relation to data protection, consumer protection, online safety and cybersecurity. It considers potential future developments and sets out early views on cross regulatory implications across four key areas: (i) governance; (ii) data protection and cybersecurity; (iii) consumer rights and interests; and (iv) market dynamics and competition. The DRCF emphasises that agentic AI does not fall outside existing legal frameworks and that obligations on transparency, fairness, accountability and consumer outcomes continue to apply. The DRCF emphasises that organisational responsibility for legal compliance remains unchanged notwithstanding the autonomy of agentic AI, and that regulators will continue to work collectively and individually to support a clear and coherent regulatory approach enabling safe and responsible adoption.
  • BoE and PRA response on AI in financial services
    1 April 2025

    The Bank of England (BoE) has published a joint letter from the BoE and the UK Prudential Regulation Authority (PRA) to the chancellor of the exchequer and relevant secretaries of state, setting out their approach to enabling the safe and responsible adoption of AI in the UK financial sector. The letter responds to a request of 28 January to publish a plan explaining how the authorities will help enable safe AI driven innovation as well as to report annually on how their supervisory and regulatory approach supports AI driven innovation and growth.

    Planned work for this year includes:
    • Embedding AI as a supervisory priority for 2026, with increased focus on AI‑related risks and practices through supervisory dialogue with firms.
    • Conducting the next edition of the biennial survey of AI adoption across Bank‑ and FCA‑regulated firms.
    • A report from the AI consortium on its work, including on generative AI and emerging trends such as the rise of agentic AI.

    Read more.
  • FPC record of March meeting
    1 April 2026

    The Bank of England (BoE) has published the record of the Financial Policy Committee's (FPC) meeting held on 27 March to identify risks to financial stability and agree policy actions aimed at safeguarding the resilience of the UK financial system. The FPC assesses that the conflict in the Middle East has triggered a substantial negative supply shock, leading to significant market moves (including higher and more volatile energy prices and higher government bond yields). While the financial system has been resilient so far, the shock is expected to weigh on growth, increase inflation and tighten financial conditions. The FPC highlights that these developments could interact with existing vulnerabilities it has previously identified in sovereign debt markets, risky asset valuations and risky credit markets (notably private credit), increasing the likelihood that multiple vulnerabilities could crystallise at the same time and amplify risks to financial stability. The FPC emphasises the need for timely and active risk management by market participants, including stress testing and liquidity preparedness that incorporate scenarios involving further sudden and significant price adjustments.

    Read more.
  • UK FCA annual work programme 2026/27
    26 March 2026

    The UK Financial Conduct Authority (FCA) has published its annual work programme for 2026/27 setting out its planned activity for the second year of its five-year strategy. The programme is structured around the following four strategic priorities:
    • Being a smarter regulator: to improve regulatory efficiency and proportionality, the FCA will continue to invest in digital, data and AI capabilities, reduce administrative burdens by simplifying rules and streamlining data returns (including removing three regular returns in April), and improve the authorisation process by further reducing authorisation timelines and continuing to report against new, shorter voluntary targets. In a press release published on the same day, the FCA announced it is developing a new internal AI-enabled authorisation tool, integrated into its existing systems. The FCA will also use generative AI to review documents received from firms, which, following successful testing, it will begin rolling out more widely across authorisations and supervision.

    Read more.
  • IOSCO 2026 work programme
    9 February 2026

    The International Organization of Securities Commissions (IOSCO) has published its 2026 work programme , setting out its five strategic priorities for the year:
    • Strengthening financial resilience and market effectiveness – new key initiatives in this field for 2026 include: (i) addressing over-the-counter derivatives reporting fragmentation; (ii) working on the impact of market microstructures on liquidity and of extended trading hours on equity trading venues; (iii) contributing to the Financial Stability Board's (FSB) work on issues of non-bank data availability, use and quality; and (iv) contributing, as necessary, to follow-up work on the issue of leverage in non-bank financial intermediation (NBFI). IOSCO will also continue to develop work to strengthen the operational resilience of financial market infrastructures (FMIs).
    • Enhancing investor protection – IOSCO will launch a new TechSprint in partnership with the UK Financial Conduct Authority's AI Lab and will explore products such as cryptoasset funds, private credit vehicles and retail-facing derivatives. IOSCO will also continue to engage with platform providers to advocate for restrictions on harmful or fraudulent content and to promote the use of its I-SCAN tool (its Enhanced Investor Alerts Portal).
    • The evolution of public and private markets – key initiatives in this field include assessing the growing interconnectedness between private equity activities and the audit sector, contributing to the FSB's deep dive on private credit and researching the functioning of public equity markets.

    Read more.
  • FSB 2026 work programme
    3 February 2026

    The Financial Stability Board (FSB) has published its 2026 work programme. The FSB states it will continue its mission to promote global financial stability by addressing systemic financial risks and fostering international cooperation. Key priorities for the year include:
    • Vulnerabilities assessments – the FSB will complete a report on private credit and will begin new work on vulnerabilities, possibly including work on foreign exchange derivative markets or private finance.
    • Non-bank financial intermediation (NBFI) – the FSB will work to improve its methodologies to assess vulnerabilities in the non-bank sector as well as work on non-bank leverage and over-the-counter derivatives.
    • Cross-border payments – the FSB will continue to coordinate the implementation of the G20 cross-border payments roadmap by helping jurisdictions with the development of their voluntary, specific and time-bound action plans.
    • Digital innovation and AI – the FSB will continue to monitor developments regarding cryptoassets and will examine issues related to possible stablecoin vulnerabilities. It will also undertake work on sound practices for AI adoption, use and innovation by financial institutions, in close coordination with the standard-setting bodies.

    Read more.
  • UK FCA second cohort of AI live testing applications now open
    30 January 2026

    The UK Financial Conduct Authority (FCA) has published a blog on its AI live testing service. The service is voluntary and open to firms that have developed AI proofs of concept and are active in UK financial markets, subject to competitive selection criteria. The initiative aims to support safe and responsible AI deployment through a collaborative, real-world testing environment and complements the FCA's Supercharged Sandbox. The blog sets out: (i) what the FCA is testing; (ii) how the testing operates in practice; and (iii) what the FCA aims to learn from the process. The first cohort joined in October 2025. The FCA confirms it has opened a second application window and is now inviting applications until 2 March. The FCA has provided Terms of Reference with further detail and confirms that successful applicants will be notified by mid-March. The testing is due to commence from April.
  • EBA draft single programming document
    29 January 2026

    The European Banking Authority (EBA) has published its draft single programming document (SPD) for 2027–2029, outlining its strategic priorities and resource needs over the three‑year period. The EBA confirms it will focus on implementing new mandates for banking and payments including its oversight role under the Digital Operational Resilience Act, supervision of significant issuers of asset referenced and e money tokens under the Markets in Crypto-Assets Regulation and validation of initial margin models under the amended European Market Infrastructure Regulation (EMIR 3). The EBA will also focus on addressing emerging risks arising from geopolitical instability. This will require new approaches to risk assessment, financial stability monitoring and consumer protection. Supporting EU co legislators also remains central for the EBA as the SPD reflects the priorities for the financial sector and aims to keep the financial system strong while also ensuring it can fund the European economy.

    Against this backdrop, the EBA identifies three strategic priorities for 2027–2029: (i) evolving and simplifying the Single Rulebook for banking and financial services; (ii) carrying out risk assessments to support effective risk analysis, supervision and oversight; and (iii) embracing innovation to enhance technological capacity across the sector. The EBA notes that close cooperation with relevant EU and third-country authorities will be required to meet its objectives.
  • UK FCA call for input on the long-term impact of AI on retail financial services
    27 January 2026

    The UK Financial Conduct Authority (FCA) has announced the launch of "The Mills Review", led by Sheldon Mills, the Executive Director of the FCA, looking at how advanced AI, including generative and agentic systems, could influence consumers, retail financial markets and firms by 2030. Accompanying the press release, the FCA has published a call for input seeking views on four areas: (i) the future evolution of AI technologies, including the development of more autonomous and agentic systems; (ii) the future impact on markets and firms, including the changes to competition and market structure and UK competitiveness; (iii) the impact for consumers, including how consumers will be influenced by AI but also influence financial markets through new expectations; and (iv) how regulators may need to evolve to ensure that retail financial markets continue to work well. While wholesale markets and broader societal markets remain out of scope, any relevant indirect influences to retail financial services will be considered. Feedback will inform recommendations to the FCA Board in the summer, ahead of an external publication. The deadline for comments is 24 February.
  • UK Treasury Committee report expresses concern over current approach to AI in financial services
    20 January 2026

    The UK Treasury Select Committee has published a report on AI in financial services. The report expresses concerns that the Bank of England, the UK Financial Conduct Authority (FCA) and HM Treasury (HMT) are exposing consumers and the wider financial system to potentially serious harm by maintaining a "wait‑and‑see" approach to AI in financial services. With over 75% of UK financial services firms now using AI, particularly insurers and international banks, the Committee acknowledges the potential benefits to consumers but concludes that regulators are not doing enough to mitigate emerging risks.

    The report recommends that: (i) the Bank of England and the FCA undertake AI‑specific stress testing to build firms' readiness for AI-driven market shocks; (ii) the FCA publishes comprehensive practical AI guidance for firms by year‑end covering: (a) how existing consumer protection rules apply to their use of AI and (b) accountability and the level of assurance expected from senior managers under the Senior Managers and Certification Regime for harm caused through the use of AI; and (iii) by year-end, HMT must designate the major AI and cloud providers as critical third parties for the purposes of the Critical Third Parties Regime. The Committee states it is unclear why HMT has been slow to use the new powers at its disposal, noting that the regime was established over a year ago. It further recommends that the Bank of England's Financial Policy Committee should monitor the regime's progress and, if needed, use its power of recommendation to HMT to ensure swift implementation.
  • EBA and AMLA complete handover of AML/CTF mandates
    19 January 2026

    The European Banking Authority (EBA) has announced it has completed the transfer of all anti‑money laundering and counter‑terrorist financing (AML/CTF) mandates to the new Authority for Anti‑Money Laundering and Countering the Financing of Terrorism (AMLA) on 1 January. This transition, part of the EU's broader AML/CTF reform package, ends the EBA's stand‑alone AML/CFT mandate established in 2020 and places AMLA at the centre of a unified European supervisory framework. Key EBA tools and expertise, including the EuReCa database, supervisory insights and risk assessments, have been handed over, with all existing EBA AML/CTF guidelines and standards remaining in force until replaced by AMLA. Under the new regime, AMLA will complete the EU's Single Rulebook, advance supervisory convergence, coordinate the work of financial intelligence units and directly supervise 40 of the most complex financial institutions or groups in the EU. The EBA will continue to address money laundering risk through prudential regulation. The EBA has also published a fact sheet explaining the transition. A formal ESAs–AMLA Memorandum of Understanding was signed in June 2025, which underpins ongoing cooperation and information‑sharing between the authorities.
  • EBA letter on outcome of EBA's EU AI Act mapping exercise against EU banking and payments regulation
    17 December 2025

    The European Banking Authority (EBA) has published a letter sent to the European Commission (EC) with the outcome of its EU AI Act mapping exercise. In January 2025, the EBA established a dedicated workstream to map the requirements on high-risk AI systems under the EU AI Act against relevant provisions in EU banking and payments regulation, with a focus on the use of AI for creditworthiness and credit scoring. The EBA confirms that, although the EU AI Act identifies overlaps between some requirements on high-risk AI systems and EU financial sector law and envisages targeted derogations and other ways to address this (such as integration or combination of requirements), it does not envisage such derogations for other requirements on high-risk AI systems (e.g. human oversight, data governance, cybersecurity) which are already widely regulated under EU financial services law.

    The EBA highlights that the Digital Operational Resilience Act framework extensively covers the cybersecurity and business continuity requirements set out in the EU AI Act and that the Capital Requirements Regulation and Capital Requirements Directive IV requirements already provide a comprehensive and technology-neutral governance and risk management framework that can be applied to supervising the use of AI tools. The EBA sets out in an annex to its letter, a table identifying how EU financial services law already addresses relevant EU AI Act requirements. The EBA believes the table will be useful to the EC when producing the guidelines under Article 96(1)(e) of the EU AI Act on the interplay between the EU AI Act and EU financial services law and managing any regulatory overlaps.
  • UK FCA second cohort of AI Live Testing applications to open in January 2026
    3 December 2025

    The UK Financial Conduct Authority (FCA) has published an update on its AI Live Testing service. The service aims to promote the safe and responsible adoption of AI in UK financial services through a collaborative, real-world testing environment. The live testing service is voluntary and open to firms that have developed AI proofs of concept and are active in UK financial markets, subject to competitive selection criteria. The initiative complements the FCA's Supercharged Sandbox and follows its September feedback statement on AI benefits and risks. Applications for the first AI Live Testing cohort closed on 15 September. The application window for the second cohort will open in January 2026, with testing commencing in April 2026.
  • EP resolution on impact of AI on the financial sector
    25 November 2025

    The European Parliament (EP) has adopted a resolution on the impact of AI on the financial sector. This follows the final report published by the EP's Committee on Economic and Monetary Affairs (ECON) earlier in November. The press release confirms that the resolution highlights AI's potential benefits to the financial sector, including through fraud detection, personalised advice, transaction monitoring and environmental, social and governance (ESG) data analysis. However, it also warns of risks such as data bias, model opacity, cybersecurity threats and over-reliance on major tech providers. MEPs call for human oversight, robust data governance and updates to supervisory tools — emphasising that no new legislation is needed; instead, existing rules should be clarified and streamlined to foster innovation without compromising consumer protection or financial stability. The resolution urges the European Commission and supervisors to provide proportionate guidance and to enhance cross-border cooperation and support initiatives such as setting up AI-specific regulatory sandboxes, increasing AI literacy, researching AI's environmental impact, and reducing regulatory barriers for AI-based financial firms.
  • EBA factsheet on implications of EU AI Act for banking and payments sector
    21 November 2025

    The European Banking Authority (EBA) has published a fact sheet summarising the findings from its 2025 mapping exercise on the interaction between the EU AI Act (Regulation EU 2024/1689) and existing banking and payments legislation. This includes the Capital Requirements Regulation (575/2013), the Consumer Credit Directive (2008/48/EC), the Mortgage Credit Directive (2014/17/EU) and the Payment Services Directive ((EU) 2015/2366). The EBA's key findings include: (i) no significant contradictions have been found between the AI Act and EU banking and payment legislation; (ii) the AI Act is complementary to EU banking and payment sector legislation, which already provides a comprehensive framework to manage risks. However, some efforts may be required by banks and other financial institutions to integrate the two frameworks effectively; and (iii) the co-existence of multiple authorities supervising financial entities' compliance highlights the importance of supervisory cooperation to ensure effective implementation of the AI Act.

    The EBA also concludes that no immediate changes to its guidelines or new EBA guidelines are planned. Instead, the EBA will follow up with actions to contribute to a common supervisory approach to supervisory cooperation and implementation of sectoral requirements alongside AI Act requirements. The EBA will undertake specific activities in 2026–2027 to support the implementation of the AI Act in the EU banking and payments sector by: promoting common supervisory approaches and cooperation among national competent authorities responsible for financial sector supervision and market surveillance authorities; and providing input to the AI office, as appropriate, and participating in discussions of the AI Board Subgroup on Financial Services.
  • EC adopts Digital Omnibus Package and launches consultation
    19 November 2025

    The European Commission (EC) has adopted its Digital Omnibus Package with a set of proposals which seek to simplify rules on AI, data and cybersecurity. This forms part of the EC's broader digital initiative to help EU businesses innovate, scale and save on administrative costs. At the core of the package is the proposal for a regulation on simplification of the digital legislation which introduces technical amendments to a large range of digital laws.

    Key measures include:
    • AI – providing clarifications and practical measures to ensure smooth application of AI rules, including provisions for regulatory sandboxes and SME-friendly compliance pathways. Further targeted amendments to the EU AI Act are made through a separate legal proposal within the package.
    • Cybersecurity – establishing a single-entry reporting mechanism that consolidates mandatory obligations under, among others, the NIS2 Directive, the General Data Protection Regulation (GDPR) and the Digital Operational Resilience Act (DORA). In a second stage, sector-specific rules in areas such as energy and aviation will also be integrated into this single-entry point.

    Read more.
  • Joint UK—Singapore report on tokenised assets and announcements on collaborative partnerships
    12 November 2025

    The Investment Association and the Investment Management Association of Singapore, in partnership with the UK Financial Conduct Authority (FCA) and Monetary Authority of Singapore (MAS), have released a joint report on challenges and opportunities in tokenised asset markets across the UK and Singapore. The report highlights an "adoption gap" between innovation in digital assets and investor requirements. It introduces a practical operational readiness checklist in section 4, to guide market participants looking to design and launch tokenised financial products.

    Read more.
  • ECON report on impact of AI on the financial sector
    11 November 2025

    The European Parliament's Committee on Economic and Monetary Affairs (ECON) has adopted its final report on the impact of AI on the financial sector. This follows the draft report published in May, which highlighted concerns around regulatory overlaps and legal uncertainty, and set out recommendations to encourage responsible use of AI in financial services. This final report builds on those recommendations, reinforcing the need for clarity on how existing financial and other regulations interact with the EU AI Act. It advocates for proportional supervisory approaches and supporting measures, such as the issuance of clear and practical guidance by the European Commission, to foster innovation while safeguarding market integrity. Further, the report emphasises that current sectoral legislation on AI is sufficient to cover AI deployment in its present form but highlights the importance of continuous monitoring to identify any duplications or gaps in the current financial services legislation applicable to AI deployment, especially with a view to safeguarding consumer rights and the right to privacy.
  • HMT commissions report on AI, disruptive technologies and skills needs
    5 November 2025

    The Economic Secretary to HM Treasury (HMT) has published a letter confirming it has commissioned the Financial Services Skills Commission to produce a comprehensive report on the impact of AI and other disruptive technologies on the UK financial services sector. The research, aligned with the Financial Services Growth and Competitiveness Strategy, will examine emerging technologies, their effect on the sector's growth at both national and regional levels and on implications for customers. It will also identify the skills required for successful adoption and deployment of the technologies and set out a clear plan with actionable steps for employers, employees, education providers and government on how to build the skills required over the next decade. The final report is scheduled for mid-2027.
  • UK DSIT plans to establish a new AI Growth Lab
    21 October 2025

    The UK Department for Science, Innovation and Technology (DSIT) has announced its plans to establish an AI Growth Lab, a new blueprint for AI regulation. This regulatory sandbox is designed to support responsible AI innovation by allowing firms to pilot AI technologies in real-world conditions, under temporary and closely supervised environments. The Lab would operate issue specific sandboxes, focusing on sectors where there is opportunity for innovation and adoption, but where regulatory modification may be needed and existing regulatory sandboxes are not in place. Within the Lab, certain regulations may be temporarily "switched off" or adjusted for a limited period to enable experimentation.

    Target sectors include professional services, healthcare, transport and advanced manufacturing. DSIT has issued a call for views to help shape the Lab's operating model. The proposals cover its design (including whether it should be centrally operated by the government or relevant regulator-led on a sandbox-by-sandbox approach), application criteria, necessary safeguards and the length of the sandbox. DSIT is also considering powers for government to make permanent responsible regulatory modifications, validated through Lab testing, by secondary legislation. This would be subject to appropriate parliamentary scrutiny. If adopted, this mechanism would mean that the Lab is not only a safe and controlled way to trial responsible AI, but also a driver for dynamic regulatory reform. The deadline for responses is 2 January 2026. During the response window, DSIT will organise roundtables for stakeholder and public engagement.
  • BoE publishes approach to responsible innovation in AI, DLT and quantum computing
    15 October 2025

    The Bank of England (BoE) has published its approach to supporting responsible innovation across artificial intelligence (AI), distributed ledger technology (DLT) and quantum computing. Recognising these as potentially transformative technologies, the BoE emphasises its role in enabling safe adoption while safeguarding monetary and financial stability. The BoE acknowledges that these technologies will significantly impact the work it does, from setting interest rates, to maintaining financial stability, to operating the UK's core payments infrastructure. It also highlights its responsibility to understand and manage the risks and opportunities these innovations present.

    To foster a resilient and innovation-friendly environment, the BoE sets out the following three key regulatory levers.

    Read more.
  • FSB publishes report on monitoring AI adoption and related vulnerabilities in the financial sector
    10 October 2025

    The Financial Stability Board (FSB) has published a report examining how financial authorities can monitor the adoption of AI and assess related vulnerabilities. Building on its 2024 report and drawing on insights from a member survey on AI monitoring approaches, alongside other sources, the FSB highlights that while AI presents potential benefits such as enhanced efficiency, improved regulatory compliance, advanced data analytics and more personalised financial products, many financial authorities are still in an early stage of monitoring AI-related vulnerabilities. Several data collection challenges remain, including lack of agreed definitions for AI, data gaps and difficulties in assessing the criticality of AI services.

    In addition, as AI adoption in the financial sector is still evolving, mapping indicators to specific vulnerabilities, ensuring regular data collection, and addressing gaps in monitoring critical areas such as third-party dependencies, market correlations, and cyber risks will help to enhance monitoring initiatives. The report also includes a range of direct and proxy indicators to support monitoring activities, as well as a case study on generative AI (GenAI). It highlights how financial institutions are exploring new use cases, and how GenAI deployment often relies on the critical role of third-party service providers which could lead to operational vulnerabilities and critical dependencies within the AI supply chain.

    Read more.
  • BIS publishes report on the use of AI for policy purposes
    10 October 2025

    The Bank for International Settlements (BIS) has published a report examining how central banks, financial regulators and supervisory authorities are increasingly leveraging AI, including generative AI and large language models, for policy purposes. The report outlines the transformative impact of AI on managing large datasets and complex decision-making processes, with real-world examples illustrating how big data and machine learning are transforming key areas of work across monetary and financial stability functions. It also identifies key challenges such as data governance, investment in human capital and the need for robust IT infrastructure. To overcome challenges, collaboration is emphasised, forming a "community of practice" to share knowledge, data, best practices and AI tools emerges as a promising a way forward.
  • UK DRCF launches new Thematic Innovation Hub and publishes call for views on agentic AI
    10 October 2025

    The Digital Regulation Cooperation Forum (DRCF) has announced the launch of its new Thematic Innovation Hub. Building on the success of the AI and Digital Hub pilot, the Thematic Hub will provide tailored regulatory advice on priority topics, with its first thematic focus centred on agentic AI – AI systems capable of autonomous decision-making and initiating actions without direct human prompts. As part of this new approach, the DRCF has also published a "call for views" seeking input on the regulatory challenges and opportunities associated with agentic AI. The call for views consists of six questions that stakeholders may choose to respond to or share other insights that they believe are relevant.

    The deadline for submissions is 6 November. The DRCF clarifies that it does not intend to issue advice or guidance in response to submissions; the aim is to gather insights to inform future thematic work. Accompanying the launch, the DRCF has published an insights paper that shares learnings from the pilot phase of its AI and Digital Hub.
  • G7 Cyber Expert Group issues statement on AI and cybersecurity in the financial sector
    6 October 2025

    HM Treasury has published a statement from the G7 Cyber Expert Group (CEG) on AI and cybersecurity, aiming to raise awareness of the cybersecurity implications of AI and outlining key considerations for financial institutions, amongst others, to strengthen resilience and security in the financial sector. It highlights how AI can enhance cyber resilience, including through improved anomaly and fraud detection, while also amplifying existing risks, such as AI-driven phishing and increased effectiveness of attacks.

    The statement sets out financial sector-specific considerations and recommendations which include strengthening internal capabilities to understand specific AI risks, integrating AI-related risks in existing risk management processes, encouraging strong governance and leadership engagement and fostering cross-sector collaboration to monitor evolving AI capabilities, opportunities and risks. Looking ahead, as AI becomes more embedded in financial systems, the CEG encourages stakeholders to explore AI's potential to enhance cyber defence, update risk frameworks accordingly and engage in collaborative research and dialogue. The statement concludes with a list of reference materials that financial institutions may find useful for further guidance.
  • UK FCA publishes new webpage on its approach to AI
    9 September 2025

    The UK Financial Conduct Authority (FCA) has published a new webpage to support the safe and responsible adoption of AI in UK financial markets. The FCA confirms it does not intend to introduce new AI-specific regulations, opting instead to rely on existing frameworks which mitigate many of the risks associated with AI. The webpage outlines the requirements already in place that are relevant for using AI safely: the consumer duty and the accountability and governance requirements under the senior managers and certification regime. Firms are encouraged to visit the FCA's AI Lab for support on developing AI models and solutions safely and responsibly. The FCA confirms that it is leveraging AI tools, including predictive models and large language models, to enhance supervisory efficiency and consumer engagement. The webpage also highlights ongoing collaboration with domestic and international partners, including co-chairing the AI consortium with the Bank of England and signposting links to research the FCA has been involved in. In parallel, the FCA has confirmed on the same day that it intends to proceed with AI live testing.
  • UK FCA publishes feedback statement on AI live testing service
    9 September 2025

    The UK Financial Conduct Authority (FCA) has published feedback statement FS25/5, summarising responses to its April engagement paper on AI live testing. The AI live testing service aims to promote the safe and responsible adoption of AI in UK financial services through a collaborative, real-world testing environment. The live testing service is voluntary and open to firms that have developed AI proofs of concept and are active in UK financial markets, subject to competitive selection criteria. The FCA has made it clear that the feedback statement does not set out its policy position or views on AI use in financial markets. The feedback reveals strong industry support for the proposal, with respondents recognising the potential of AI live testing.

    Read more.
  • BIS Innovation Hub launches Project Noor to explain AI models for financial supervision
    18 August 2025

    The BIS Innovation Hub has announced the launch of Project Noor, a collaborative initiative with the Hong Kong Monetary Authority and the UK Financial Conduct Authority aimed at enhancing the transparency and accountability of AI models used by banks and other financial institutions. AI is increasingly shaping decisions in digital finance, from mortgage approvals to fraud detection. Yet as these models grow more complex, the press release states that regulators and consumers alike face challenges in interpreting how decisions are made. Project Noor seeks to address this by prototyping explainable AI (XAI) tools that translate complex model logic into human-readable explanations and intuitive visuals. The initiative intends to support compliance with emerging regulations requiring high-risk financial AI systems to be auditable and explainable, without prescribing fixed standards. It empowers supervisors to assess fairness, robustness, and consistency in AI-driven decisions, while preserving privacy and promoting responsible innovation. Importantly, Project Noor does not seek to override existing practices or impose mandatory frameworks. Rather, its purpose is to support supervisors by offering tools and reference points to help them develop their own well-informed judgments. Financial institutions will remain responsible for model explainability.
  • EBA issues opinion on money laundering and terrorist financing risks across the EU
    28 July 2025

    The European Banking Authority (EBA) has published its fifth opinion on money laundering and terrorist financing (ML/TF) risks. In the report, the EBA highlights the growing vulnerabilities in the EU financial sector arising from the growth of technologies, new financial products such as crypto-assets, and the increasing interconnection of financial products and services across sectors. The EBA states that while tools such as RegTech and AI offer potential for enhanced compliance, their improper implementation (often due to lack of expertise and oversight) has led to serious compliance failures. Competent authorities have reported high or rising ML/TF risks in Fintech firms and crypto-asset service providers linked to weak AML/CFT controls and governance. Additionally, the use of AI by criminals to automate laundering and forge documents is outpacing institutional defences. The EBA notes that supervisory engagement has improved the capability of some sectors to fight financial crime. The EBA emphasises the importance for consistent application of the new EU AML/CFT legal framework.
  • FCA announces launch of Supercharged Sandbox
    9 June 2025

    The UK Financial Conduct Authority (FCA) has announced the launch of its Supercharged Sandbox, developed in collaboration with NVIDIA, as part of its AI Lab and in line with the FCA's strategy to foster economic growth. This upgraded sandbox builds on the FCA's existing digital sandbox structure, offering firms access to NVIDIA's accelerated computing and AI enterprise software. This sandbox complements the FCA's AI Live Testing service, which alternately assists those that are further along in development and ready for implementation. By enhancing technical resources, data access and regulatory support, the sandbox aims to foster responsible AI innovation without introducing new regulations, relying instead on existing frameworks. Applications for the Supercharged Sandbox have opened and will close on 11 August. The programme will run for three months, from 30 September to 9 January 2026. Full details, including eligibility criteria and application guidance, are included in the official participation pack.
View All (500+)