EU’s AI Act could model finance-specific rules, study finds

AI

Durham University Business School has found that financial institutions need a dedicated regulatory framework for AI to cut risks and strengthen consumer protection.

The research shows that AI regulation around the world remains patchy. Some jurisdictions, including the European Union and China, have already put dedicated AI legislation in place, whereas others, such as the UK and the US, have taken a softer regulatory stance.

Professor Habib Ahmed of the university’s Department of Finance contends that finance needs its own purpose-built rules to tackle the sector-specific risks that AI creates, and points to the European Union’s AI Act as a possible template for a finance-focused equivalent.

The research sets out several risks tied to the expanding use of AI across financial services. These span the improper handling of personal data, biased outcomes in automated decisions, over-reliance on outside technology providers, and vulnerability to cyberattacks.

According to the study, these issues could undermine core regulatory goals such as safeguarding consumers, preserving financial stability and upholding market integrity. As AI adoption deepens across the industry, the paper cautions that weak oversight could ripple outward, moving beyond individual customers to affect the broader economy and global financial markets.

To build the proposed framework, Professor Ahmed began by mapping the principal risks financial institutions face when deploying AI, before reviewing existing approaches to AI governance, drawing heavily on the European Union’s AI Act and its provisions on risk management, governance and supervision.

The resulting model sorts AI applications into four risk bands. Systems judged unacceptable, such as the unauthorised scraping and use of people’s facial imagery, or tools that manipulate or exploit users, would be barred outright from use by financial institutions.

High-risk systems, including those affecting access to essential services or data, would need close regulation and careful handling given their potential impact on people’s rights, health or security. Limited-risk applications, such as AI-generated text or video content, would require providers to be upfront with users about when they are engaging with AI. Minimal-risk uses, such as spam filters or video games, would fall outside the framework altogether.

The study concludes that AI’s role in financial services will only grow, making robust regulation increasingly critical. Professor Ahmed argues that policymakers and regulators should look at adapting existing models, such as the EU AI Act, for the finance sector specifically, a move he suggests would let financial institutions capture the benefits of AI while limiting risks to consumers and preserving trust in the financial system.

Read the daily RegTech news 

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.