AI Compliance for Financial Services
Financial Services is addressed by 50 regulatory updates across 9 jurisdictions and 4 frameworks. This page tracks how regulators worldwide are approaching financial services in the context of artificial intelligence.
Framework Requirements for Financial Services
Regulations Covering Financial Services
US Federal(24)
SEC announces internal AI task force
The SEC announced an internal AI task force on 1 August 2025 to coordinate responsible AI adoption across the agency; the announcement does not introduce a new external compliance obligation.
FTC AI enforcement and policy hub
The FTC’s AI hub consolidates recent AI enforcement and policy actions, reinforcing that deceptive or unsubstantiated AI capability claims remain an active Section 5 enforcement risk for vendors and deployers.
Congressional AI bills and resolutions introduced in 119th Congress
Multiple 119th Congress measures listed on Congress.gov, including AI-adjacent resolutions and bills, were introduced or advanced in 2025 but do not yet create binding federal AI obligations.
SEC charges advisers with false AI claims
The SEC charged two investment advisers for making false and misleading statements about their use of artificial intelligence, confirming that AI-wash in financial marketing and disclosures is an enforcement priority.
SEC creates AI Task Force to coordinate agency AI oversight
On 2025-08-01, the SEC created an AI Task Force to coordinate innovation and efficiency across the agency, signaling more structured internal oversight of AI-related supervisory and enforcement activity.
European Union(6)
EBA, EIOPA and ESMA call for enhanced governance over frontier AI ICT risks in EU financial services
On 2026-07-31, the EU supervisory authorities called for stronger governance and consistent supervision to mitigate ICT risks from frontier AI models in the financial sector, signaling that firms should tighten controls now rather than wait for formal rule changes.
ESA call for enhanced governance and consistent supervision of frontier AI ICT risks
On 2026-07-31, EBA, EIOPA and ESMA called on EU financial-sector firms and supervisors to tighten governance and supervision of frontier AI-related ICT risks, signaling immediate expectations for stronger control frameworks under existing resilience obligations.
ESAs call for stronger governance over frontier AI ICT risks in EU finance
On 2026-07-31, the EBA, EIOPA and ESMA issued a joint statement urging a cross-sector, risk-based and consistent supervisory approach for frontier AI models because their ICT risks are now a live supervisory concern in the EU financial sector.
ESRB Warning on systemic cyber risks from frontier AI models
The ESRB warned that frontier AI models can collapse defensive time buffers and materially increase systemic cyber risk for EU financial institutions, and it specifically points to ECB-requested action plans due by 31 October 2026 as the near-term trigger for supervisory attention.
ESAs support ESRB warning on systemic cyber risks from frontier AI models
On 2026-07-07, the European Supervisory Authorities backed the ESRB’s warning that frontier AI models can create systemic cyber risks for financial markets, elevating AI cyber resilience as a supervisory priority.
United Kingdom(5)
FCA confirms no new AI-specific rules for financial services
The FCA says it is not planning AI-specific regulation and will rely on existing frameworks such as Consumer Duty and SM&CR, so firms should focus on fitting AI governance into current control regimes rather than waiting for a new rulebook.
FCA, Bank of England and Treasury joint statement on frontier AI models and cyber resilience
The FCA, Bank of England, and HM Treasury said firms must be able to identify, monitor, and manage external AI-related applications, libraries, and services integrated into their networks, raising the bar for cyber and third-party resilience.
FCA Mills Review on how AI will reshape retail financial services
The FCA launched a review of advanced AI’s impact on retail financial services, with feedback due 24 February 2026 and recommendations expected for the FCA Board in summer 2026.
FCA, Bank of England and Treasury issue frontier AI cyber resilience statement
UK authorities issued a joint statement on frontier AI model cyber resilience, so regulated firms and FMIs should now align AI governance with existing operational resilience and cyber controls.
FCA AI live testing and innovation support
The FCA’s planned AI live testing service, with rollout targeted for September 2025, means financial firms should prepare to evidence model behavior, controls, and testing assumptions before engaging the regulator.
Switzerland(5)
FINMA sets governance and risk-management expectations for AI use in Swiss financial institutions
FINMA’s 2024 guidance states that Swiss financial institutions using AI must identify, limit, control, and monitor AI-related risks within their existing supervisory framework, so firms should immediately test whether their governance and model-risk controls are adequate.
FINMA guidance on governance and risk management when using artificial intelligence
FINMA’s 18 December 2024 guidance says supervised institutions must adapt governance and controls to the materiality and probability of AI risks, including operational, model, data, IT/cyber, third-party, legal, and reputational risks.
FINMA guidance on AI governance and risk management
FINMA’s AI guidance highlights operational, model, cyber, data-quality, third-party, legal, and reputational risks, so Swiss financial institutions should formalize AI governance and oversight now.
FINMA Guidance on Governance and Risk Management When Using Artificial Intelligence
FINMA published AI governance guidance on December 18, 2024, making governance, model risk, data quality, cyber risk, third-party dependence, and legal/reputational risk explicit supervisory priorities for Swiss financial institutions using AI.
FINMA Guidance on AI Governance and Risk Management
FINMA’s AI supervisory guidance highlights operational, model, data, cyber, third-party, legal, and reputational risks, so Swiss financial institutions should treat AI governance as an immediate supervisory issue.
Colorado(4)
Colorado SB189 Automated Decision-Making Technology
Colorado SB189 was introduced in the Senate on 2026-05-01, adding another state-level automated decision-making proposal that could expand obligations for organizations using AI in consequential decisions.
Bryan Dorsey v. Robert T. Jones
The state court listing gives no substantive outcome, so there is no actionable compliance change in the provided record.
State v. Bailey
The state court listing is caption-only and does not identify any operative holding, so no regulatory action is evident from the supplied text.
Bryan v. Child Support Enforcement Agency
The state court listing is caption-only and does not disclose an operative ruling, so there is no compliance delta in the supplied text.
New York(2)
New York automated lending decision tools bill advances
New York A00773 advanced to third reading on 2026-04-30, signaling imminent scrutiny of automated lending tools and the need to prepare consent/opt-out and governance controls now.
New York automated lending decision-making bills advance
New York’s automated lending decision-making bills advanced on 2026-04-30, moving consent and opt-out requirements for banks closer to enactment and increasing near-term compliance planning pressure for lenders using automated tools.
International(2)
ESAs Spring 2026 Risk Update
The ESAs’ spring 2026 risk update flags heightened geopolitical and private-finance risks, signaling supervisors expect firms to reassess enterprise risk exposure and preparedness now rather than waiting for a formal deadline.
ESMA Supervisory Briefing on Algorithmic Trading
ESMA issued a supervisory briefing on algorithmic trading on 2026-02-26, giving market participants a fresh supervisory signal on expectations for controls, governance, and monitoring of trading algorithms.
Germany(1)
Weekly digest
Leave your email to get each issue in your inbox. Free, no account required.
We use your email only for the digest. Privacy policy