Why compliance teams can’t wait for AI-specific regulation

AI

Financial regulators across the US, UK and UAE are converging on a single message: existing rules already apply to artificial intelligence, and firms cannot wait for AI-specific legislation before tightening their governance.

According to ACA Group, the SEC’s 2026 Examination Priorities have embedded AI oversight across information security, operational resiliency and emerging financial technology categories, signalling that AI governance will matter to examiners regardless of whether a firm actively markets AI-powered strategies.

ACA Group recently delved into how AI governance is becoming a global examination priority.

FINRA’s 2026 Annual Regulatory Oversight Report went further still, adding a dedicated generative AI section and demanding that member firms evidence testing, supervision, vendor diligence and recordkeeping.

In the UK, the FCA has confirmed it will not introduce standalone AI rules, instead maintaining its principles-based approach. Initiatives including the AI Lab, AI Live Testing and the Mills Review, launched in January 2026, reinforce the expectation that firms adapt existing risk frameworks rather than wait for new regulation.

The DFSA has taken a similarly firm stance in the Dubai International Financial Centre, issuing a circular to senior executive officers at every authorised firm. Its guidance rests on four pillars: governance and accountability, risk management, operational risk, and third-party arrangements, with regulators keen to stress that oversight and innovation should progress together rather than one constraining the other.

Across all three jurisdictions, the practical implication is the same. Senior management must understand AI-related risks well enough to provide genuine oversight, third-party AI vendors fall under existing outsourcing accountability, and AI-enabled communications must be captured within books and records.

Yet an ACA survey of more than 200 compliance and operations professionals, 62% of them CCOs, found a widening gap between adoption and governance. While 84% of respondents said they use desktop AI tools at work, the average firm applies AI in fewer than two of 20 surveyed business functions. Adoption is broad but shallow, and governance maturity is not keeping pace.

For compliance teams, the takeaway is that policies must match practice, vendors must be overseen, and AI use must be defensible under examination, whether that examination happens in New York, London or Dubai.

Read the full ACA Group post here. 

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.