Skip to content
Regulayer™Human Control for AI
Book a live demo

Research library · Sectors

Financial Services and Capital Markets: AI Rules, Enforcement and Litigation

Covers how US, EU and UK financial regulators apply existing and new rules to AI as of May 2026, including SEC "AI-washing" enforcement, SEC and FINRA examination expectations, MiFID II, the EU AI Act, DORA, the FCA's approach, and AI-related securities litigation.

Compiled from public sources, May 2026. Information, not legal advice.

1. United States Securities and Exchange Commission (SEC) Regulatory Landscape

1.1 Enforcement Actions Against AI Misrepresentation ("AI-Washing")

The SEC brought its first dedicated "AI-washing" enforcement actions in 2024 and continued to bring AI-related misrepresentation cases through 2025.

1.1.1 SEC v. Delphia (USA) Inc. and Global Predictions Inc. (2024). On March 18, 2024, the SEC announced settled charges against Delphia (USA) Inc. and Global Predictions Inc., marking the Commission's first dedicated "AI-washing" enforcement actions (SEC.gov) (Mayer Brown). Delphia, a Toronto-based investment adviser, said it collected data from its clients, "through social media, banking, credit card, online purchases, etc.", as inputs into its algorithms (Baker Botts). The SEC found that Delphia did not have the AI and machine learning capabilities it claimed (SEC.gov). The SEC examined Delphia's AI claims in July 2021, and afterwards, despite telling the SEC it would review and correct its disclosures, Delphia made further false and misleading statements in investor emails, social media posts and a press release (Baker Botts) (The Harvard Law School Forum on Corporate Governance).

Global Predictions Inc., a San Francisco-based investment adviser, falsely claimed to be the "first regulated AI financial advisor" and misrepresented that its platform provided "[e]xpert AI-driven forecasts", in claims made in 2023 on its website and on social media (SEC.gov). It offered advisory services through an interactive online platform, a chatbot, which did not generate any recommendations (Baker Botts).

Case detail Delphia (USA) Inc. Global Predictions Inc.
Date of action March 18, 2024 (SEC.gov) March 18, 2024 (SEC.gov)
Primary violations Sections 206(2) and 206(4) of the Advisers Act; Rules 206(4)-1 (Marketing Rule) and 206(4)-7 (Compliance Rule) (Harvard Law School Forum) Sections 206(2) and 206(4) of the Advisers Act; Rules 206(4)-1 and 206(4)-7; impermissible liability hedge clause (SEC.gov)
Civil penalty $225,000 (SEC.gov) $175,000 (SEC.gov)
Additional sanctions Censure; cease-and-desist order Censure; cease-and-desist order; undertaking to retain a compliance consultant to review its marketing and training materials (Harvard Law School Forum)
Status GREEN: settled GREEN: settled

The combined civil penalties were $400,000 (SEC.gov). SEC Chair Gary Gensler said: "We've seen time and again that when new technologies come along, they can create buzz from investors as well as false claims by those purporting to use those new technologies", and "Investment advisers should not mislead the public by saying they are using an AI model when they are not. Such AI washing hurts investors." Gurbir S. Grewal, Director of the Division of Enforcement, said that "if you claim to use AI in your investment processes, you need to ensure that your representations are not false or misleading" (SEC.gov).

1.1.2 Penalty structure and settlement terms. Both firms consented to the orders without admitting or denying the SEC's findings (SEC.gov).

In February 2025 the SEC launched its Cyber and Emerging Technologies Unit (CETU) (SEC.gov). On April 9, 2025, the SEC charged the founder and former CEO of Nate, Inc. with fraudulently raising more than $42 million through false and misleading statements about the company's use of artificial intelligence (SEC.gov). The civil case, SEC v. Saniger, No. 1:25-cv-02937 (S.D.N.Y.), and the parallel criminal case, No. 25-cr-00157 (S.D.N.Y.), allege that Nate's shopping app, marketed as using AI to complete purchases, relied in large part on overseas contract workers who entered orders manually, and that the founder staged transactions to give investors a false impression of the app (SEC.gov) (JD Supra) (DLA Piper). The criminal case charges one count each of securities fraud and wire fraud, showing that AI misrepresentations can lead to criminal charges as well as SEC action (DLA Piper).

On October 10, 2024, the SEC announced settled charges against Rimar Capital USA, Inc., its parent Rimar Capital, LLC and two executives for false claims that Rimar had an AI-driven platform for trading securities; the respondents raised nearly $4 million from 45 investors (SEC.gov). On August 27, 2024, the SEC charged a foreign investment adviser and its CEO in the U.S. District Court for the District of South Dakota over claims that its AI technology could generate above-market returns while protecting "100%" of client funds (Holland & Knight).

Enforcement action Date Jurisdiction Penalty or amount Nature of violation Status
SEC v. Delphia (USA) Inc. March 18, 2024 United States (SEC administrative) $225,000 civil penalty False claims about using client data in its AI GREEN: settled (SEC.gov)
SEC v. Global Predictions Inc. March 18, 2024 United States (SEC administrative) $175,000 civil penalty False "first regulated AI financial advisor" and "AI-driven forecasts" claims GREEN: settled (SEC.gov)
SEC v. foreign investment adviser and its CEO August 27, 2024 United States (D.S.D.) Not specified Claims that its AI could generate above-market returns while protecting "100%" of client funds Charges filed (Holland & Knight)
SEC: Rimar Capital USA, Inc., Rimar Capital, LLC and two executives October 10, 2024 United States (SEC administrative) $310,000 combined civil penalties, plus disgorgement and prejudgment interest from one executive False claims of an AI-driven trading platform GREEN: settled (SEC.gov)
SEC v. Saniger and parallel criminal case April 9, 2025 United States (S.D.N.Y.) More than $42 million raised (alleged) AI automation claimed; purchases largely completed manually Charges filed (SEC.gov) (JD Supra)

1.1.3 Nature of violations: false and misleading statements about AI capabilities. The SEC's enforcement theory distinguishes three categories of AI-related misrepresentation. First, capability misrepresentation involves claiming AI functionality that does not exist or is materially overstated, such as Global Predictions' "first regulated AI financial advisor" claim or assertions of "expert AI-driven forecasts" when processes are conventional (JD Supra). Second, process misrepresentation occurs when firms describe investment processes as built on proprietary AI engines when portfolio decisions remain predominantly human-driven or use simple screens. Third, autonomy misrepresentation involves implying fully autonomous, self-learning systems where human judgment still dominates, creating false impressions of scalability and edge (JD Supra).

The gap between represented and actual AI capabilities has become an enforcement trigger. The SEC's application of traditional antifraud provisions to AI claims, rather than creating AI-specific rules, means that all firms making any claims about AI involvement in their services face immediate compliance obligations under existing law.

1.2 Examination Priorities and Regulatory Scrutiny

Beyond enforcement, the SEC has embedded AI into its examination program.

1.2.1 SEC 2026 Examination Priorities: AI governance and representation. The SEC's Fiscal Year 2026 Examination Priorities, released in late 2025, state that the Division of Examinations "will review for accuracy registrant representations regarding their AI capabilities or AI" and will assess whether firms have adequate policies and procedures to monitor and/or supervise their use of AI technologies, including for tasks related to fraud prevention and detection, back-office operations, anti-money laundering (AML), and trading functions. The priorities also cover training and security controls to identify and mitigate new risks associated with "artificial intelligence (AI) and polymorphic malware attacks" (SEC.gov) (JD Supra).

In a speech on February 3, 2026, Brian Daly, Director of the SEC's Division of Investment Management, said that intelligent use of AI "can, should, and will catalyze a transformation of the technology of investment management", and told firms with concerns about how existing rules constrain their deployment of new technologies to "please reach out" (SEC.gov).

1.2.2 Scrutiny of AI use across operational functions. Examiners will review firms' policies and procedures for supervising AI used in four functions: fraud prevention and detection; back-office operations; anti-money laundering; and trading functions (SEC.gov). This functional breadth extends scrutiny beyond client-facing communications.

The SEC's Cyber and Emerging Technologies Unit (CETU), launched February 2025, complements this examination focus with dedicated enforcement capacity. Its remit covers misconduct relating to securities transactions involving blockchain technology, AI, account takeovers, cybersecurity and other areas (SEC.gov). At the Securities Enforcement Forum West on May 15, 2025, SEC enforcement and CETU officials said that "rooting out" fraud schemes related to AI washing is an immediate priority, and a CETU enforcement attorney said staff were scrutinizing how both public companies and startups describe their AI capabilities to customers and investors (DLA Piper).

1.2.3 Integration of regulatory technology (RegTech) expectations. The 2026 examination priorities say reviews "will also consider firm integration of regulatory technology to automate internal processes and optimize efficiencies" (SEC.gov). Theta Lake, a compliance technology vendor, advises compliance leaders to be prepared to demonstrate "a robust and defensible approach" to AI oversight (Theta Lake).

The SEC's practical message is that AI needs to be built into the same governance, risk, and compliance framework that applies to other important systems, with senior managers and boards knowing which AI tools the firm is using and who is accountable for them, regular testing to detect model drift, bias, or errors, and maintenance of evidence regarding tests conducted, problems found, and remediation implemented (JD Supra).

1.3 Proposed and Pending Regulatory Frameworks

1.3.1 Proposed rules on predictive data analytics (2023). On July 26, 2023, the SEC proposed rules under the Securities Exchange Act and the Investment Advisers Act that would regulate the use of predictive data analytics (PDA) and similar technologies, including AI, in broker-dealer and investment adviser interactions with investors (SEC.gov) (JD Supra). The proposal, including proposed Rule 211(h)(2)-4, would have required firms to "eliminate, or neutralize the effect of" conflicts of interest associated with covered technologies (SEC.gov). The proposal also included amendments to Exchange Act Rules 17a-3 and 17a-4 and Advisers Act Rule 204-2 that would have required books and records including disclosures to investors of the use of covered technologies, documentation of conflict evaluation and resolution, testing, and instances in which a covered technology was overridden (JD Supra).

1.3.2 Status of finalized AI-specific attestation requirements. On June 12, 2025, the Commission formally withdrew this proposal as part of a broader retraction of fourteen outstanding rulemakings from the prior administration (JD Supra). Any future action in this area would require a fresh proposal and comment process.

Regulatory development Date Status Implication
Predictive data analytics conflict-of-interest rules Proposed 2023; withdrawn June 12, 2025 RED: withdrawn, no replacement timeline No current mandatory attestation requirement from this rulemaking (JD Supra)
SEC Investor Advisory Committee AI disclosure recommendation Approved December 4, 2025 AMBER: recommendation, not Commission action Potential future materiality-based disclosure guidance (JD Supra)
Potential new proposal on AI conflicts Unknown RED: no confirmed timeline Uncertain; any rule would require new proposal and comment period (JD Supra)

Status: RED. No finalized AI-specific attestation requirements exist at the SEC. The Commission continues to apply existing antifraud and disclosure frameworks to AI-related conduct. However, the cumulative effect of enforcement actions, examination priorities, and staff guidance creates de facto compliance expectations.

1.4 Record-Keeping and Audit Trail Obligations

1.4.1 Model risk management guidance. SR 11-7, the Federal Reserve's 2011 Guidance on Model Risk Management for banking organizations, was superseded on April 17, 2026 by SR 26-2, revised model risk management guidance issued jointly by the Federal Reserve, the OCC and the FDIC. The revised guidance keeps the pillars of model development and use, validation and ongoing monitoring, and governance and controls, with a risk-based approach tailored to each banking organization's model risk profile (Federal Reserve).

1.4.2 Documentation to support AI claims. DLA Piper advises organizations to consider memorializing the technical architecture of AI systems so that it can support statements about the systems' capabilities in marketing materials, investor pitch decks or public filings, with documentation also covering data sources, model governance, human-in-the-loop processes and limitations (DLA Piper). Such documentation helps substantiate marketing claims and withstand AI-washing scrutiny.

2. Financial Industry Regulatory Authority (FINRA) Compliance Requirements

2.1 Core Rule Applicability to AI-Generated Content

FINRA applies its existing rules to AI in broker-dealer operations on a technology-neutral basis, supplemented by specific guidance addressing generative AI.

2.1.1 FINRA Rule 2210: communications with the public (technology-neutral application). FINRA Rule 2210 governs broker-dealer communications with the public, which it divides into correspondence, retail communications and institutional communications. A registered principal must approve each retail communication before the earlier of its use or filing; correspondence is subject to the supervision and review requirements of Rule 3110(b); and firms must have written procedures for reviewing institutional communications. All communications "must be based on principles of fair dealing and good faith, must be fair and balanced, and must provide a sound basis for evaluating the facts" (FINRA Rule 2210). FINRA Regulatory Notice 24-09, published June 27, 2024, reminded member firms that FINRA rules, "intended to be technology neutral", and the securities laws "continue to apply when member firms use Gen AI or similar technologies in the course of their businesses, just as they apply when member firms use any other technology or tool" (FINRA).

The technology-neutral principle has critical implications: AI-generated content receives no regulatory safe harbor or reduced scrutiny. Firms must implement the same supervisory infrastructure for AI-generated research reports, client communications, and marketing materials as for human-generated content. This creates substantial operational burden.

2.1.2 FINRA Rule 3110: supervision of AI-generated communications. FINRA Rule 3110 requires each member to "establish and maintain a system to supervise the activities of each associated person that is reasonably designed to achieve compliance with applicable securities laws and regulations, and with applicable FINRA rules" (FINRA Rule 3110). FINRA rules apply whether firms develop Gen AI tools for their own use or leverage a third party's technology, including features embedded in existing third-party products (FINRA).

2.1.3 FINRA Regulatory Notice 24-09 (June 2024): explicit AI reminder to member firms. Regulatory Notice 24-09 notes that, depending on how a firm uses it, Gen AI "could implicate virtually every area of a member firm's regulatory obligations". It gives supervision as an example: under Rule 3110 a firm must have a reasonably designed supervisory system, and if it uses Gen AI tools as part of that system, its policies and procedures should address technology governance, including model risk management, data privacy and integrity, and reliability and accuracy of the AI model (FINRA).

FINRA rule or guidance AI application Compliance requirement Source
Rule 2210 (Communications) AI-generated public communications Principal pre-approval of retail communications; Rule 3110(b) review of correspondence; written procedures for institutional communications; fair and balanced content FINRA Rule 2210; Reg Notice 24-09
Rule 3110 (Supervision) Supervision of AI use, including Gen AI tools used in supervision Reasonably designed supervisory system; where Gen AI is used in supervision, policies addressing technology governance FINRA Rule 3110; Reg Notice 24-09
Recordkeeping AI prompts and outputs FINRA's 2026 report says GenAI may implicate recordkeeping rules and describes maintaining prompt and output logs as a monitoring practice Debevoise & Plimpton

2.2 Examination and Enforcement Posture

2.2.1 FINRA 2026 Annual Regulatory Oversight Report: GenAI supervision expectations. FINRA's 2026 Annual Regulatory Oversight Report, released December 9, 2025, includes standalone guidance on generative AI (Secretariat) (FINRA). This guidance contains key factors for firms to consider when testing and deploying GenAI tools, including: establishment of an appropriate governance model; assessment and mitigation of risks such as hallucinations and bias; and implementation of robust testing and ongoing monitoring processes (Secretariat). The report also examines emerging risks and challenges that AI agents may present to investors and the overall market, and specifically encourages firms to have conversations with third-party vendors to understand how they are using AI tools, as this area is often overlooked (Secretariat).

Ncontracts, a compliance vendor, expects examiners to ask advisers to inventory AI use across the firm, including by affiliates and service providers, and to show that governance policies are followed in practice, not just written down (Ncontracts). The 2026 report says GenAI may implicate rules relating to supervision, communications, recordkeeping, and fair dealing (Debevoise & Plimpton).

2.2.2 Ongoing monitoring of prompts, outputs, and model performance. The ongoing monitoring practices described in FINRA's 2026 report include reviewing prompts, responses and outputs over time, "maintaining prompt and output logs for accountability and troubleshooting", tracking which model version was used and when, and confirming that deployed solutions continue to perform as expected (Debevoise & Plimpton).

2.3 Practical Compliance Implications

2.3.1 Pre-approval requirements for AI-generated client communications. Under FINRA Rule 2210, a registered principal must approve each retail communication, AI-generated or not, before the earlier of its use or filing; correspondence is reviewed under Rule 3110(b) rather than pre-approved (FINRA Rule 2210). Applied identically to AI and human content, principal approval of retail communications creates operational scaling challenges as AI-generated content volume increases.

2.3.2 Accuracy, fair dealing, and balanced presentation standards. AI-generated content must meet the same substantive standards as human-generated content: communications must be based on principles of fair dealing and good faith, must be fair and balanced, and must provide a sound basis for evaluating the facts (FINRA Rule 2210). The SEC's AI-washing enforcement demonstrates that accuracy standards for AI claims are actively enforced.

2.3.3 Data capture and archiving for supervisory review. FINRA's 2026 report says GenAI may implicate recordkeeping rules, and describes maintaining prompt and output logs as part of ongoing monitoring (Debevoise & Plimpton).

3. European Union: MiFID II and EU AI Act Intersection

3.1 MiFID II Obligations for AI-Generated Investment Recommendations

The Markets in Financial Instruments Directive II (MiFID II) establishes foundational requirements for investment services that apply comprehensively to AI-generated recommendations, creating layered compliance obligations with the EU AI Act.

3.1.1 ESMA Public Statement on AI in retail investment services (2024). On 30 May 2024 the European Securities and Markets Authority (ESMA) issued a Public Statement on the use of Artificial Intelligence in the provision of retail investment services, giving initial guidance on firms' key obligations under MiFID II (ESMA). It expects firms to: (1) act in clients' best interests and be transparent about the role of AI, disclosing its use in client interactions; (2) ensure management body oversight so that AI tools align with the firm's strategy, risk tolerance and compliance framework; (3) implement effective AI-specific risk management, including regular testing; (4) ensure input data is "relevant, sufficient, and representative", with rigorous oversight of training and validation; (5) align AI tools with product governance and suitability requirements through quality assurance and periodic stress testing; (6) apply MiFID II outsourcing requirements, including due diligence, to third-party providers; (7) adhere to data protection requirements; and (8) keep records on the use of AI, including decision-making processes, data sources, algorithms and modifications (ESMA).

ESMA expects investment firms "to maintain comprehensive records on AI utilisation and on any related clients' and potential clients' complaints", and says these records "should encompass aspects of AI deployment, including the decision-making processes, data sources used, algorithms implemented, and any modifications made over time" (ESMA).

Further specificity emerges from Taylor Wessing's analysis of key regulatory considerations for EU investment firms, which notes that ESMA expects firms "to maintain comprehensive records of information about the use of the AI in the provision of the regulated service or key back-office functions," including information about "the way in which AI was used in the decision-making processes, what were the data sources and how were they analysed" (Taylor Wessing). This granular documentation expectation extends beyond mere binary disclosure (AI used or not used) toward a more nuanced record of AI involvement.

3.1.2 Record-keeping requirements: decision-making, data sources, algorithm documentation. MiFID II Article 16(6) requires investment firms to keep records of all services, activities and transactions they undertake, sufficient to enable the competent authority to carry out its supervisory tasks (MiFID II, EUR-Lex). For AI, ESMA expects these records to cover the decision-making processes, data sources used, algorithms implemented and any modifications made over time (ESMA).

In "AI governance after MiFID II: beyond (mere) technological neutrality?" (ERA Forum, February 2026), Alessio Azzutti writes that MiFID II's communication standards apply to every form of communication, "whether produced by a human adviser, an automated report generator, or a chatbot integrated into a trading app", and that AI-generated content "must therefore be intelligible both to clients and to internal compliance functions capable of verifying its factual accuracy and compliance with MiFID II's communication standards" (Springer). For generative AI tools, particularly large language models producing dynamic or personalized content, firms face heightened challenges in ensuring outputs "remain explainable, auditable, and consistent with information provided through other delivery channels" (Springer).

3.1.3 Human oversight and quality assurance process mandates. MiFID II's organizational requirements under Article 16 and Commission Delegated Regulation (EU) 2017/565 mandate that investment firms implement adequate policies and procedures to ensure compliance, including effective procedures for risk management. ESMA's 2024 statement calls for robust ex-ante controls on the accuracy of information supplied to and used by AI systems, and sufficiently frequent ex-post controls on any process that delivers information through AI (ESMA).

Azzutti reads ESMA's 2023 Briefing on the Definition of Investment Advice as confirming that "machines cannot hold this legal status" of investment adviser and that "responsibility remains with the authorised firm and its human management" (Springer). The 2024 ESMA Public Statement says that firms using AI for client interactions, such as chatbots, "should transparently disclose to clients the use of such technology during these interactions" (ESMA).

3.1.4 Product governance and suitability alignment requirements. MiFID II's product governance obligations (Articles 16(3) and 24(2) of the Directive, and Articles 9 and 10 of Delegated Directive (EU) 2017/593) require investment firms to ensure financial instruments are designed for, and distributed to, identified target markets. ESMA expects robust controls so that AI systems are designed and monitored, for example in product governance to align the distribution of products to the target market, and in suitability assessments to align recommendations with the client's financial situation, investment objectives, and knowledge and experience (ESMA).

3.2 EU AI Act Classification of Financial Services AI

The EU AI Act creates a risk-tiered regulatory framework with specific obligations for high-risk AI systems in financial services. Rules for high-risk systems in Annex III areas were originally to apply from August 2, 2026; under the AI Omnibus, on which political agreement was reached on 7 May 2026 and which entered into force on 27 July 2026, they apply from December 2, 2027 (European Commission).

3.2.1 Annex III, Points 5(b) and 5(c): credit scoring and life and health insurance pricing as high-risk. The EU AI Act classifies as high-risk AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score, except systems used to detect financial fraud (Annex III, point 5(b)), and AI systems intended for risk assessment and pricing in relation to natural persons in life and health insurance (point 5(c)) (The Artificial Intelligence Act). This classification triggers comprehensive obligations including: risk management systems throughout the AI lifecycle; data governance and training data quality requirements; technical documentation and record-keeping; transparency and provision of information to users; human oversight; accuracy, robustness, and cybersecurity; and quality management system implementation. The high-risk classification applies regardless of whether the AI system is developed in-house or procured from third-party vendors, and extends to EU-established financial entities as well as non-EU entities whose AI system outputs are used within the European Union (Goodwin Procter).

The European Banking Authority (EBA) has confirmed that in the banking and payment sector, "the use of AI systems to evaluate the creditworthiness or to establish the credit score of natural persons is classified as 'high-risk'" (European Banking Authority). This classification is functionally determined rather than technology-dependent: the same underlying AI model may be minimal risk when deployed for customer service chatbot purposes but becomes high-risk when applied to credit scoring or insurance risk assessment (Aurora Trust).

Risk category Financial services application Application date Maximum penalty
Prohibited AI (Article 5) Social scoring, subliminal manipulation February 2, 2025 (GREEN) €35 million or 7% global turnover (Article 99)
High-Risk AI (Annex III, points 5(b) and 5(c)) Credit scoring; life and health insurance risk assessment and pricing December 2, 2027, moved from August 2, 2026 by the AI Omnibus (AMBER) (European Commission) €15 million or 3% global turnover (Article 99)
Transparency obligations (Article 50) Chatbots, AI-generated customer communications August 2, 2026 (AMBER) (European Commission) €15 million or 3% global turnover (Article 99)
General Purpose AI Models Foundation models used in financial applications Obligations from August 2, 2025; Commission fines from August 2, 2026 (AMBER) (Article 113) €15 million or 3% global turnover (Article 101)

The prohibition on social scoring in Article 5(1)(c) is not limited to public authorities (The Artificial Intelligence Act). Under Article 111(2), high-risk AI systems already placed on the market or put into service before the application date are covered only if they are subject to significant changes in their design from that date, although providers and deployers of high-risk systems intended for use by public authorities must comply by 2 August 2030 (The Artificial Intelligence Act). The Digital Omnibus proposal, introduced in November 2025, delayed the Annex III high-risk provisions to December 2, 2027; it was adopted and entered into force on 27 July 2026 (European Commission).

3.2.2 Article 14: human oversight requirements for high-risk AI systems. Article 14 of the EU AI Act imposes detailed human oversight obligations. The article mandates that high-risk AI systems "shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which they are in use" (The Artificial Intelligence Act).

Article 14(4) specifies that high-risk AI systems must enable natural persons assigned to oversight to: properly understand the system's capacities and limitations; remain aware of automation bias tendencies; correctly interpret the system's output; decide not to use the system or override its output; and intervene or interrupt system operation through a "stop" button or similar procedure (The Artificial Intelligence Act) (Cambridge University Press & Assessment).

For financial services deployers, Article 26(2) requires deployers to "assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support" (The Artificial Intelligence Act). Osborne Clarke's summary of the European Parliament's resolution of 25 November 2025 reads: "Effective human oversight must be maintained, with ex ante and ex post controls over decisions affecting consumers' rights and finances" (Osborne Clarke).

ESMA's February 2026 report on AI adoption trends found that 77% of AI use cases in surveyed firms operated with low or no autonomy, meaning human approval was required or the AI system only provided suggestions. By ESMA's count, 19% of all use cases, and 27% of agentic AI use cases, had a high or medium degree of autonomy. GenAI was the most widely used technology, characterising 571 of the reported use cases (71% of the 807 for which technology was reported, with multiple choices possible), followed by natural language processing at 227 use cases (28%) and agentic AI systems at 141 use cases (17%) (European Securities and Markets Authority).

Article 14 requirement Practical implementation for financial services
Understand system capabilities and limitations Role-specific training beyond basic system usage; system architecture overview for non-technical users
Monitor operation and detect anomalies Real-time dashboards with confidence indicators, deviation alerts, input quality warnings
Avoid automation bias Critical thinking training, independent judgment exercises, awareness of over-reliance risks
Interpret output correctly Explanations in domain language, similar historical cases, feature importance highlighting
Override or reverse output Technical capability to disregard AI recommendations, documented escalation procedures
Interrupt system operation Stop button or similar procedure, tested interruption protocols

3.2.3 Article 50: transparency obligations and machine-readable marking of AI-generated content. Article 50 of the EU AI Act establishes transparency obligations. Article 50(2) requires providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content to ensure that outputs are "marked in a machine-readable format and detectable as artificially generated or manipulated", with technical solutions that are "effective, interoperable, robust and reliable as far as this is technically feasible" (The Artificial Intelligence Act) (Legalithm).

On 20 July 2026 the European Commission published guidelines on the transparency obligations of providers and deployers under Article 50, connected to the Code of Practice on marking and labelling of AI-generated content. The guidelines aim at "ensuring compliance with the transparency obligations under Article 50 of the AI Act in a consistent, effective, proportionate and uniform manner" (European Commission).

The intersection of Article 50 with high-risk AI systems in financial services creates layered compliance requirements. A customer interacting with a bank's conversational AI to understand loan eligibility triggers both high-risk obligations (if the AI influences creditworthiness assessment) and transparency obligations (for the chatbot interaction itself) (Rasa). The conversation interface does not change the underlying high-risk classification: what matters is the function the AI performs and the data it processes (Rasa).

Article 50 paragraph Obligation Financial services application Effective date
Article 50(1) Disclosure of AI interaction Chatbots, robo-advisors, automated customer service August 2, 2026
Article 50(2) Machine-readable marking of synthetic content AI-generated marketing materials, investment research summaries August 2, 2026
Article 50(3) Notification of emotion recognition or biometric categorization Behavioral biometrics in fraud detection, sentiment analysis August 2, 2026
Article 50(4) Deepfake disclosure Synthetic media in marketing, training materials August 2, 2026

Dates: European Commission.

Osborne Clarke's summary of the European Parliament's November 2025 resolution includes, under "Financial education and transparency": "Clarity is required on the role of AI in retail services and the provision of understandable disclosures, to support informed decisions and financial education" (Osborne Clarke).

3.3 Overlay and Cumulative Compliance Burden

3.3.1 Dual compliance: MiFID II record-keeping plus EU AI Act risk management. The EU AI Act does not replace existing financial services regulation but layers on top of it, with explicit reference to existing EU financial services laws containing internal governance and risk management requirements (eyreact, EU AI Act Compliance Platform). Under Article 74 of the AI Act, where high-risk AI systems are placed on the market, put into service or used by financial institutions regulated by Union financial services law, the market surveillance authority is the national authority responsible for the financial supervision of those institutions (The Artificial Intelligence Act).

Osborne Clarke's summary of the European Parliament's resolution says: "Rigorous testing, model registers, and risk assessments are required. Explainability should be proportionate to the impact on the customer" (Osborne Clarke).

3.3.2 ESMA expectations for comprehensive AI usage documentation. For investment firms specifically, the MiFID II record-keeping requirements for algorithmic trading and investment decision-making processes must now be supplemented with EU AI Act-mandated technical documentation, risk management system documentation, and human oversight records where AI systems are high-risk. The ESMA Public Statement on AI in retail investment services (May 2024) set expectations for records documenting the use of AI across the provision of investment services (ESMA) (Schellenberg Wittmer).

3.3.3 Periodic stress testing and algorithm outcome validation requirements. Both MiFID II and the EU AI Act require ongoing validation of algorithmic systems. ESMA expects firms to run periodic stress tests of AI systems used in investment services (ESMA). Article 9 of the EU AI Act requires a risk management system for high-risk AI systems, "understood as a continuous iterative process planned and run throughout the entire lifecycle" (The Artificial Intelligence Act). Separately, Article 26 of DORA requires certain financial entities to carry out threat-led penetration testing at least every three years (DORA, EUR-Lex).

4. Digital Operational Resilience Act (DORA) AI Governance Obligations

4.1 Enforcement Framework and Timeline

4.1.1 Enforcement date: January 17, 2025 (GREEN status). The Digital Operational Resilience Act (Regulation (EU) 2022/2554, "DORA") entered into force on January 16, 2023, and applies from January 17, 2025 (DORA, EUR-Lex). As of the report date (May 11, 2026), DORA is fully applicable across EU financial entities.

DORA's Article 2(1) lists 20 categories of financial entity, including credit institutions, payment institutions, account information service providers, electronic money institutions, investment firms, crypto-asset service providers, central securities depositories, central counterparties, trade repositories, insurance and reinsurance undertakings, crowdfunding service providers and securitisation repositories; it also applies to ICT third-party service providers (DORA, EUR-Lex). AI deployment in EU financial services that relies on ICT systems and services falls within this framework.

4.1.2 Penalty structure. DORA does not itself set fine amounts for financial entities. Article 50 requires Member States to lay down rules establishing appropriate administrative penalties and remedial measures for breaches, which must be "effective, proportionate and dissuasive". For critical ICT third-party service providers, the Lead Overseer may impose periodic penalty payments of up to 1% of the provider's average daily worldwide turnover in the preceding business year, on a daily basis for no more than six months (Article 35) (DORA, EUR-Lex).

4.2 Specific AI-Related Obligations

4.2.1 ICT risk management framework requirements (Article 6). DORA Article 6 requires financial entities to have "a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system"; Articles 8 to 13 then set requirements on identification, protection and prevention, detection, response and recovery, and learning and evolving (DORA, EUR-Lex). AI systems used by financial entities fall within this framework as ICT assets.

4.2.2 Incident classification and reporting (Articles 17 to 19). Articles 17 to 19 establish management, classification and reporting requirements for ICT-related incidents. Article 18 classifies incidents by criteria including the number of clients affected and reputational impact, duration and service downtime, geographical spread, data losses, criticality of services affected, and economic impact. Major incidents must be reported to competent authorities through an initial notification, intermediate reports and a final report, within time limits set under Article 20 (DORA, EUR-Lex).

4.2.3 Digital operational resilience testing (Articles 24 to 26). Article 24 requires a digital operational resilience testing programme, and Article 25 lists appropriate tests including vulnerability assessments and scans, scenario-based tests and penetration testing. Article 26 requires advanced testing by means of threat-led penetration testing (TLPT) at least every three years for identified financial entities (DORA, EUR-Lex).

4.2.4 Third-party ICT risk management for AI vendors (Article 28). Article 28 establishes third-party ICT risk management requirements that apply to AI vendors providing ICT services. Financial entities must: maintain a register of information on all contractual arrangements for the use of ICT services; assess risks including ICT concentration risk; exercise access, inspection and audit rights; and put in place exit strategies for ICT services supporting critical or important functions (DORA, EUR-Lex). For AI providers, this creates downstream compliance obligations: financial institution customers will require AI vendors to demonstrate operational resilience, incident response capability, and documentation standards.

4.3 AI Systems as Critical ICT Services

4.3.1 AI within DORA scope. DORA does not mention AI expressly; AI systems and AI services are covered as ICT systems and ICT services. The European Supervisory Authorities (ESAs), through their Joint Committee, may designate ICT third-party service providers as critical, based on criteria including systemic impact, the systemic character of the financial entities relying on the provider, reliance on the provider for critical or important functions, and substitutability (Article 31) (DORA, EUR-Lex). AI providers that serve multiple significant financial institutions could be designated as critical ICT third-party providers, subjecting them to direct oversight by the ESAs and enhanced resilience requirements.

4.3.2 Third-party risk management for AI providers. Under Article 30, contracts with ICT third-party service providers must include, among other terms, a clear description of the services, the locations where services are provided and data processed, assistance in ICT incidents, cooperation with competent authorities and termination rights; for services supporting critical or important functions, they must also include service levels, participation in threat-led penetration testing, unrestricted rights of access, inspection and audit, and exit strategies (DORA, EUR-Lex).

The Register of Information (RoI) requirement under DORA mandates that financial entities maintain records of all contractual arrangements with ICT third-party providers; the second annual submission was due in March 2026, and 46 percent of institutions cite the RoI as their biggest compliance challenge (digital-chiefs.de).

5. United Kingdom Financial Conduct Authority (FCA) Regulatory Framework

5.1 Guidance on AI Use in Financial Advice and Client Communications

The UK Financial Conduct Authority has adopted a principles-based approach to AI regulation in financial services. It does "not plan to introduce extra regulations for AI", relying instead on existing frameworks, specifically the Consumer Duty and the Senior Managers and Certification Regime (SM&CR) (Financial Conduct Authority) (Freshfields Bruckhaus Deringer). The regulators explored the approach in the joint Discussion Paper DP5/22 ("Artificial Intelligence and Machine Learning", October 2022) with the Bank of England and the Prudential Regulation Authority, and in the joint feedback statement published on 26 October 2023 (Bank of England).

On September 9, 2025, the FCA launched a dedicated webpage entitled "AI and the FCA: our approach", consolidating its position on safe and responsible AI adoption in UK financial markets (Freshfields Bruckhaus Deringer). The webpage serves as a hub for resources including: the FCA's AI Lab; AI-related research and collaboration activities; and the FCA's AI Live Testing program, with the first cohort of firms due to begin testing in October 2025 (Freshfields Bruckhaus Deringer).

5.1.1 COBS 9.4 requirements for AI-generated suitability reports. The FCA's Conduct of Business Sourcebook (COBS) 9.4 sets out what suitability reports must contain, including the client's demands and needs and an explanation of why the recommendation is suitable. Aveni, an AI vendor, notes that AI-generated suitability reports must meet the same FCA standards as manually created documentation, and that no formal requirement currently exists to notify the FCA of AI use for suitability reports (Aveni).

5.1.2 Consumer Duty obligations: clarity and fairness standards. The FCA's Consumer Duty came into force on 31 July 2023 for open products. Its three cross-cutting rules require firms to act in good faith toward customers, avoid causing foreseeable harm, and enable and support customers to pursue their financial objectives (Financial Conduct Authority).

In a 2024 update on its approach to AI, the FCA said that "firms using AI technologies in a way that embeds or amplifies bias, leading to worse outcomes for some groups of consumers, might not be acting in good faith for their consumers, unless differences in outcome can be justified objectively" (Pinsent Masons). This position creates litigation risk and examination risk.

5.1.3 Treating Customers Fairly principles applied to AI outputs. The FCA's Treating Customers Fairly (TCF) principles require that firms pay due regard to the interests of customers and treat them fairly. The FCA's research series on AI bias, including a literature review on bias in supervised machine learning and a pilot study into bias in natural language processing used in chatbots, robo-advice, and analysis of financial documents, demonstrates active regulatory attention to AI system characteristics (Pinsent Masons).

5.2 Human Oversight and Accountability Requirements

5.2.1 Senior Managers and Certification Regime (SM&CR) accountability for AI governance. The SM&CR allocates personal accountability for AI governance to senior individuals, with potential personal liability for failures in AI system oversight. Individuals in scope must be able to demonstrate that they have taken reasonable steps to ensure that the business for which they are responsible complies with regulatory requirements. The UK Parliament's Treasury Committee has recommended more FCA guidance on how consumer protection and individual accountability rules apply to firms' use of AI (Linklaters, Financial Regulation Insights).

5.3 Enforcement Actions and Examination Focus

5.3.1 UK Parliament recommendations for enhanced FCA AI oversight. The UK Parliament's Treasury Committee published a report on January 20, 2026, recommending that the FCA give comprehensive and practical guidance on the application of consumer protection and individual accountability rules to firms' use of AI by the end of 2026 (Linklaters, Financial Regulation Insights). The Committee also recommended AI-specific stress testing by the FCA and Bank of England, and designation by HM Treasury of major AI and cloud service providers under the critical third parties regime before the end of the year (Linklaters, Financial Regulation Insights). These recommendations, if implemented, would expand specific AI governance requirements.

5.3.2 Status of FCA approach. The UK does not yet impose AI-specific regulation on financial services firms; according to the Treasury Committee, this "wait-and-see approach" exposes consumers and the financial system to potentially serious harm, while the FCA has argued that its existing rulebook is flexible enough to apply to AI (Linklaters, Financial Regulation Insights).

6. Litigation Landscape: US and UK Cases Involving AI-Generated Financial Content

6.1 Securities Class Actions and AI-Washing Allegations

6.1.1 Trends in AI-related securities class actions through 2025. The litigation environment surrounding AI in financial services has evolved rapidly, with AI-related securities class actions emerging as a distinct and growing category. According to Broadridge Financial Solutions' seventh Global Class Action Annual Report, released February 19, 2026, global securities class actions delivered "more than $4 billion in investor recoveries in 2025", with "a growing wave of securities class actions centered on AI disclosures", growing interest in opt-in and collective actions, and continued growth in ESG-related litigation (Broadridge).

AI-related securities cases more than doubled between 2023 and 2024, with sustained elevation through 2025:

Year AI-related securities cases Trend Primary allegations
2021-2023 6-8 annually (Bloomberg Law News) Baseline Early AI-washing claims; capability misrepresentations
2024 15 (Bloomberg Law News) 100%+ increase AI-washing; efficiency overstatements; rebranding claims
H1 2025 12 (Bloomberg Law News) Sustained elevation Concealed licensing issues; integration feasibility; algorithm failures (Secretariat)

Broadridge counted nine mega settlements over $100 million in 2025 (Broadridge). While AI-related cases represent a subset, the growth trajectory indicates increasing materiality. Cornerstone Research identified 161 new securities class actions filed in federal and state courts through September 30, 2025, and Skadden describes new filings as shifting toward AI-related claims (Skadden, Arps, Slate, Meagher & Flom LLP).

6.1.2 Allegations of misrepresented AI capabilities in financial services marketing. AI-washing allegations in securities litigation follow patterns established by SEC enforcement. Plaintiffs allege: companies overstated AI-driven efficiencies; misleadingly rebranded legacy technology as AI; concealed licensing or performance issues; and exaggerated the pace and feasibility of AI integration (Skadden, Arps, Slate, Meagher & Flom LLP). Financial services defendants face particular exposure where AI claims relate to investment performance, risk management capabilities, or operational efficiency.

The Federal Trade Commission's "Operation AI Comply" has brought at least a dozen AI-washing cases targeting companies that overstate what their AI does or mislead consumers about AI-powered earnings and performance claims (Internet Lawyer Blog). In August 2025, the FTC sued Air AI, alleging deceptive claims that its agentic AI could fully replace human sales reps and deliver unrealistic business results (Internet Lawyer Blog).

6.2 Material AI Content Disputes

6.2.1 Case identification: named parties, jurisdictions, and disputed amounts. The following table summarizes confirmed enforcement actions and litigation with named parties and amounts:

Case Jurisdiction Date Alleged conduct Status or outcome Amount
SEC v. Delphia (USA) Inc. US (SEC administrative) March 2024 False claims about using client data in its AI Settled $225,000 civil penalty (SEC.gov)
SEC v. Global Predictions Inc. US (SEC administrative) March 2024 False "first regulated AI financial advisor" and "AI-driven forecasts" claims Settled $175,000 civil penalty (SEC.gov)
SEC v. foreign investment adviser and its CEO US (D.S.D.) August 2024 Claims that its AI could generate above-market returns while protecting "100%" of client funds Charges filed Not specified (Holland & Knight)
SEC: Rimar Capital USA, Inc., Rimar Capital, LLC and two executives US (SEC administrative) October 2024 False claims of an AI-driven trading platform Settled $310,000 combined civil penalties (SEC.gov)
SEC v. Saniger and parallel criminal case US (S.D.N.Y.) April 2025 AI automation claimed; purchases largely completed manually Charges filed More than $42 million raised (alleged) (SEC.gov)
Joonko founder charges (SEC and DOJ) US June 2024 Investor fraud using "artificial intelligence" and "automation" claims Charged (civil and criminal) At least $21 million (alleged) (SEC.gov)

The Nate, Inc. case illustrates the enforcement pattern: the founder raised over $42 million by claiming the company's shopping app used AI to complete purchases, when, according to the SEC, Nate relied in large part on contract employees to manually input orders placed by users on the app (SEC.gov). The SEC charged securities fraud under general antifraud provisions, demonstrating applicability to AI misrepresentations across industries.

The discovery implications of AI-generated content have created new litigation dynamics. In The New York Times v. OpenAI/Microsoft, Magistrate Judge Ona Wang in November 2025 ordered OpenAI to produce some 20 million ChatGPT logs, a reminder that product logs can become discoverable evidence in AI litigation (Internet Lawyer Blog).

The settlement of Bartz v. Anthropic on the eve of trial in September 2025, for a reported $1.5 billion, underscored the stakes of training-data decisions (Internet Lawyer Blog).

6.2.2 Outcomes and precedential value. The SEC settlement outcomes signal the SEC's position on: (1) the materiality of AI capability representations to investment decisions; (2) the falsity or misleading character of specific representations about AI involvement; and (3) scienter or negligence regarding the accuracy of those representations.

Courts have begun developing standards for AI-related securities claims. In In re Upstart Holdings, Inc. Securities Litigation (S.D. Ohio, September 2023), the court held that statements calling an AI model "fairly magical" were inactionable because they were "loosely optimistic statements that cannot be objectively verified", but that statements about the model's "significant advantage" over "traditional FICO-based models" and its ability to "respond very dynamically" to macroeconomic changes were actionable material misstatements (Bloomberg Law News). This distinction, between general enthusiasm and specific, verifiable claims, creates litigation risk that depends on documentation quality.

7. Cross-Jurisdictional Synthesis

7.1 Regulatory Convergence Patterns

Analysis across the US, EU, and UK jurisdictions reveals substantial convergence on core AI governance principles, despite significant divergence in regulatory methodology and specificity.

7.1.1 Common themes: human oversight, audit trails, transparency. Three common themes emerge across all jurisdictions:

Convergent theme US implementation EU implementation UK implementation
Human oversight SEC examination priorities: adequate policies and procedures to supervise AI (SEC.gov); FINRA supervision under Rule 3110 (FINRA) EU AI Act Article 14: mandatory human oversight with intervention capability (The Artificial Intelligence Act); ESMA management body oversight (ESMA) SM&CR accountability; Consumer Duty good outcomes (Linklaters, Financial Regulation Insights)
Audit trails FINRA 2026 report: prompt and output logs as a monitoring practice; GenAI may implicate recordkeeping rules (Debevoise & Plimpton) EU AI Act Article 12: automatic recording of events (logs) (The Artificial Intelligence Act); MiFID II Article 16(6) record-keeping; ESMA records on AI use (ESMA); DORA incident reporting SYSC 9 record-keeping
Transparency SEC AI-washing enforcement; Marketing Rule accuracy requirements (SEC.gov) EU AI Act Article 50: machine-readable marking (The Artificial Intelligence Act); ESMA disclosure of AI use in client interactions (ESMA) Consumer Duty clarity and consumer understanding (Aveni)

The EU AI Act's Article 14 human oversight requirements for high-risk AI systems and the FCA's reliance on SM&CR individual accountability both centre on human involvement in AI-augmented processes (The Artificial Intelligence Act) (Linklaters, Financial Regulation Insights).

The EU AI Act's Article 50 machine-readable marking requirement (The Artificial Intelligence Act) creates an explicit technical specification that is not yet matched by US or UK prescriptive rules. The SEC's enforcement actions demonstrate that accuracy in AI capability claims is actively enforced (SEC.gov), while the FCA's Consumer Duty creates implicit transparency obligations for AI-generated client communications (Aveni).

7.1.2 Divergence across jurisdictions. Despite thematic convergence, significant divergence persists in implementation specificity:

Dimension EU US UK
Regulatory approach Prescriptive: detailed technical requirements, defined compliance deadlines, specified penalty structures Enforcement-driven: technology-neutral rules applied through examination and enforcement Principles-based: outcomes-focused, flexible implementation, evolving guidance
Enforcement timeline Hard deadline: December 2, 2027 for Annex III high-risk AI systems, after the AI Omnibus (European Commission) Continuous: ongoing examination and enforcement Emerging: Treasury Committee asked for FCA guidance by the end of 2026 (Linklaters, Financial Regulation Insights)
Penalty certainty High: specified percentages of global turnover Moderate: case-by-case determination, escalating pattern Uncertain: principles-based, enforcement history limited

This divergence creates complexity for global firms.