Artificial intelligence is no longer limited to automating simple, repetitive compliance and risk tasks. Across financial services, firms are increasingly using AI to conduct risk assessments, prioritise alerts and recommend decisions, but the closer AI gets to the decision itself, the harder questions become around explainability, accountability and trust.
For years, the promise of AI in financial services was largely about doing more with less. Machines could sift through thousands of transactions, scan regulatory updates or review customer documents faster than a human analyst could ever hope to.
That promise is now evolving. AI is moving into the assessment layer itself, identifying patterns, assigning risk scores, suggesting materiality classifications and determining which cases warrant human attention. In some areas, particularly fraud, financial crime and regulatory change management, AI is already helping to form the views behind a risk decision.
Automation speeds up the existing process, while decision support means the system begins to interpret information and form a judgement.
“The distinction worth drawing is that automation makes an existing task faster, whereas risk assessment means the system forms a view,” said Abhishek Bali, CEO and co-founder of ZIGRAM.
For many financial institutions that does not yet mean handing over the final decision. Instead, AI is increasingly becoming the first analyst in the chain, with a human responsible for the final call.
Vall Herard, CEO of Saifr, said firms are already experimenting with delegating lower-risk decisions to AI, but the technology hasn’t yet reached the point where organisations are comfortable handing over high-risk decisions entirely.
“Some firms are starting to do this, delegating low-risk decisions to AI, but we’re not there yet for high-risk decisions,” Herard said.
From automation to assessment
The shift is most visible in areas where financial institutions are dealing with vast amounts of structured or semi-structured data.
In third-party risk, AI can bring together fragmented information, check it against set criteria, identify gaps and suggest a materiality or criticality classification for a human reviewer.
Bakas said this is already decision support because the system is forming a view rather than simply completing a task.
“In third-party risk we see it mapping messy source data into a required schema, checking entries against controlled taxonomies, flagging gaps, and putting forward a suggested materiality or criticality classification for someone to confirm,” Bakas said.
“That last step counts as decision support in the ordinary sense. The system forms a view and a person carries it.”
Regulatory compliance is another area where this is developing.
James Mackonochie, global executive head of product at CUBE, said AI agents can now take the first pass at regulatory changes by identifying the obligations and controls affected, flagging potential gaps and drafting an assessment.
“It has already happened for bounded, evidenced work. Agents now do the first pass: read a regulatory change, map it to the obligations and controls it touches, flag what looks non-compliant and draft the assessment,” Mackonochie said.
“A named human still signs it off. That is decision support in production today, not a pilot.”
Mackonochie said better data, rather than simply more advanced AI models, has been important to this development.
“What unlocked it was not smarter models but better data,” he said.
“Assessment requires knowing which rule applies to which entity, in which jurisdiction, and what changed since last week. Without structured, connected regulatory data underneath, an agent produces confident prose with no evidence behind it.”
Regulatory change management is now one of the areas seeing the strongest impact from AI-driven risk tools.
Mackonochie said teams are using agents to build and rationalise control inventories, map controls to regulatory obligations and identify gaps and duplication.
Financial crime is another major area of adoption.
“Fraud detection is unambiguously leading adoption, and it is leading for a simple reason: the adversary evolves weekly,” Bali said.
Fraud models can assess transaction behaviour, customer activity, relationships between accounts and other signals at the same time.
“Static rules cannot keep pace with that,” Bali said.
AI is also being used in adverse media screening, due diligence and transaction monitoring, helping investigators identify potentially relevant risk signals and reduce the amount of manual review.
The human remains responsible
As AI takes on more of the assessment process, the question for financial firms is where responsibility should sit.
For now, the answer remains with a human.
Bali said most applications remain decision support rather than fully autonomous decision-making.
“The important caveat is that almost all of this sits in the decision support category rather than autonomous decision-making,” Bali said.
“That is not a technology limitation. It is a design choice, driven by regulatory expectation and, frankly, by good sense. The system forms a view. A person still owns the outcome.”
This is particularly important for decisions that can have a direct impact on customers.
Credit and underwriting are therefore likely to progress more cautiously than areas such as fraud detection, while investment advice and suitability decisions remain particularly sensitive.
Herard said firms are continuing to keep humans involved in AI-driven decisions because of both accountability and concerns around fully autonomous systems.
“AI governance continues to be an area of focus for firms, especially related to explainability,” Herard said.
“As part of the governance process, firms continue to ensure there is a human in the loop to oversee AI use, partly to ensure accountability, and partly because financial firms do not yet have a level of comfort with fully autonomous AI decision making.”
This means explainability is becoming a key requirement as AI is given greater responsibility.
Mackonochie said firms need to be able to show how an AI system reached a conclusion.
“The firms getting this right treat explainability as a product feature rather than a report written afterwards,” he said.
“Every output carries its source, the version of the rule it was based on, and the path the agent took to get there. If you cannot evidence it, you cannot delegate it.”
He said firms are also moving towards continuous testing rather than treating governance as something that happens only before deployment.
“Governance is shifting from a launch gate to a continuous test,” Mackonochie said.
“Leading teams write evaluation sets before an agent goes anywhere near a customer and rerun them on every change, the same discipline software engineers apply to regression testing. That is what makes speed and control compatible instead of opposed.”
AI creates another risk
AI is also creating a new consideration for financial firms: the technology itself can become a third-party risk.
COPLA’s CEO Aurimas Bakas said firms need to consider AI systems as dependencies that require their own oversight.
“The point that tends to get missed is that the AI system is itself a third party,” Bakas said.
“Under the EU’s DORA, an AI tool supporting a critical or important function is an ICT third-party arrangement. It belongs in the register of information, carries the same contractual and exit obligations as any other critical provider, and counts toward concentration exposure.”
For UK firms, the issue is increasingly linked to operational resilience and third-party risk requirements.
“A firm buying AI into its risk function is taking on a dependency it has to govern and, increasingly, to report,” Bakas said.
“Governance of AI decisions and governance of AI vendors turn out to be one piece of work.”
Model changes are another concern.
If an external provider changes its model, the firm’s control environment can change without the institution deliberately making that change.
“A vendor updates its model and a firm’s control environment has shifted without passing through any change process,” Bakas said.
“We have noticed contractual notification rights and a defined revalidation step becoming part of how firms procure this, and it is usually a provision that gets added after someone has been surprised once.”
The issue becomes more important as firms experiment with agent-to-agent systems.
Herard warned that autonomous systems could create new risks if they are deployed without sufficient safeguards.
“From a technical standpoint, firms are experimenting with agent-to-agent frameworks that could help them save time and money. However, without the proper safety mechanisms, these autonomous agent-to-agent (A2A) systems could create an operational loop that escalates risk,” Herard said.
“Transparency, explainability, and governance are still key factors in building trustworthy agent systems.”
Data and explainability remain barriers
Despite the growing use of AI in risk management, firms still face barriers before they can give the technology responsibility for more critical decisions.
Data quality is one of the biggest.
Bakas said an AI system cannot provide a reliable assessment if the information which it is working from is incomplete.
“Data readiness comes first,” Bakas said.
“A model operating on an incomplete vendor inventory produces confident output about a partial picture. Firms see that clearly and hold back accordingly.”
Mackonochie said data lineage is another problem, particularly in regulatory compliance.
“Data lineage, not model performance,” is the key barrier, he said.
“Most firms cannot trace a regulatory obligation back through their own systems to the source text and the date it changed. Until that is fixed, no amount of model accuracy will satisfy an audit.”
Explainability is also limiting adoption.
“The explainability gap is the number one blocker, and I do not think that is close,” Bali said.
“Model capability has advanced very quickly, particularly with large language models, but the ability of these systems to give a clean, auditable account of their own reasoning has not advanced at the same rate.”
Rather than explaining every technical element of an AI model, firms need to be able to understand why a particular assessment was produced.
“The practical resolution the industry has landed on is to surface the reasoning rather than the mechanism: risk scores, the specific features that drove the score, supporting statistics, the entity relationships that triggered attention,” Bali said.
“That gives a compliance officer something defensible to work with.”
Accountability also remains a concern.
“Firms are reasonably cautious about automating a determination someone will personally defend in a supervisory conversation,” Bakas said.
External vendor dependence adds another layer of risk.
“Handing critical risk decisions to an external model deepens reliance on a provider whose roadmap the firm does not control,” the CEO said.
“What happens when the provider changes the model, changes its pricing, or leaves the market has become part of the buying conversation rather than an afterthought.”
AI could become a necessity
There is also a case for financial firms to continue adopting AI despite these risks.
The same technology is increasingly being used by fraudsters to create synthetic identities, generate convincing documents and coordinate activity across networks.
Bali said this means firms cannot look at AI only as a way to reduce costs.
“So AI in risk management is not simply an efficiency play,” Bali said.
“For a growing set of typologies, it is the only realistic defence.”
That changes the question for financial institutions.
Rather than asking whether AI should be involved in risk decisions, firms increasingly need to determine how much responsibility they can give the technology while maintaining appropriate oversight.
For now, AI is taking on more of the work behind risk decisions, while humans remain responsible for the final outcome.
As the technology develops, that division is likely to change.
The firms that benefit most may not be those that give AI the most control, but those that can expand its role while maintaining clear accountability.
Copyright © 2026 RegTech Analyst





