About a-team Marketing Services
The knowledge platform for the financial technology industry

A-Team Insight Blogs

What the Regulator Wants to See as AI Governance Moves from Policy to Proof

Subscribe to our newsletter

Over the past 18 months, generative AI (GenAI) based solutions have progressed from pilots into mainstream investment and trading processes, including risk and compliance. With the exception of the prescriptive risk-based EU AI ACT, regulators across jurisdictions are relying on existing rule-books and adopting a principles-based approach, rather than publish AI specific regulations. To get a sense for the questions Chief Compliance Officers (CCOs) are facing when examiners encounter live GenAI deployments for the first time, RegTech Insight spoke with ACA Group President and former SEC regulator, Carlo di Florio.

“I meet with CCOs every day, including through roundtables and conferences. This issue wasn’t there with earlier advanced technologies – machine learning, natural language processing or relational analytics,” says Di Florio. “With generative AI, suddenly, they’re saying, ‘My firm is asking me to be the AI officer. What the hell do I know about AI?’.”

Examiners’ questions covers a range from the superficial – ‘Are you using AI?’, ‘How are you using it?’, ‘How are you controlling risk’, to a more rigorous 18 point examination that digs deep into the depth and completeness of firms’ controls. Di Florio describes these questions converging around  a set of core principles.

One of the earliest focus areas was dishonesty and false marketing claims. The final year of the Gensler-led SEC, saw a crackdown on misleading claims about advanced AI capabilities aka ‘AI Washing’. A sweep resulted in a number of enforcement actions against advisors. Despite the new administration’s more deregulatory tone, they’ve made it clear that dishonesty, fraud and misconduct will not be tolerated.

Policy

Di Florio describes five areas of the business where examiners are focusing. The first of these is the establishment of  authorised-use policies:

  • Who was involved in developing the policy and how did you land where you landed?
  • What choices did you make and why did you make those choices?

“That’s the cornerstone. If you want to use AI, you must follow this process before you can be allowed to use it. So that’s the first thing we see examiners look at, and that makes a lot of sense,” Di Florio says.

Governance

The next focus area is governance. “Who is responsible for it and who owns decision-making when the business comes and says, ‘we need to use AI for this to remain competitive’? Who is deciding what is or is not okay?” Some firms place the responsibility with an individual and some with a committee. Di Florio suggests regulators want to see technology experts sitting down with legal, compliance and business experts to evaluate opportunities and risks, and then deciding how authorised-use policy will be monitored and making sure people actually follow it.

Testing

From governance,  the focus moves to testing and evidence. Examiners want to understand the data going into each system, who owns it and how the firm checks the result. Di Florio sees examiners asking questions such as:

  • What are the data inputs that are going into these AI models at your firm and who is responsible for that data?
  • The next question is who tests outputs for hallucinations, bias and errors before anyone relies on them.

Firms should be able to produce the test, the result, the reviewer and the action taken when an output fails.

AI can help detect cyber security threats, but AI deployments can also expose new risks. “How have you evaluated the cyber risk around your use of AI? What are you doing to mitigate and manage that cyber risk?” asks Di Florio. Examiners will expect the assessment to reflect what the system can reach, who can use it and what happens if it is compromised.

Third-Party & Vendor

Examiners are focusing on Firms’ existing third-party risk management, in particular, the way providers build and operate AI. Investment managers already share substantial amounts of firm and client data with service providers. Examiners are asking “How do you know that your service providers are using AI responsibly? How do you know how they’re using your data?” says Di Florio.

The next round of examinations are likely to determine how firms are controlling agentic AI deployments. An agent may call another system, start a process or act on an output. Di Florio described the challenge as “more like treating an agent as an employee. It has an employee identification number. It has a supervisor, a human in the loop. You’re defining very specifically its mandate and what it can do, what it can’t do. It has access controls. It’s getting evaluated on a regular basis,” he says.

Governance agents may eventually test process agents and escalate exceptions, but a human will still need to own the design and the result.

The 2026 IMCT Survey conducted by the Investment Advisors Association (IAA), ACA Group, and Yuter Compliance Consulting, shows widespread AI adoption by advisors but raises a number of concerns over resourcing and coverage.

Of the 411 investment adviser firms surveyed, 80 per cent had formally adopted AI, 86 per cent had acceptable-use policies, and the same proportion maintained AI inventories. However, a governance committee was only established at 59 per cent of firms, and only 37 per cent had formal testing and validation procedures.

Human oversight is only marginally better with forty-eight per cent having formal human-in-the-loop procedures, while 3o per cent had policies covering third-party AI. Incident response is the thinnest area with a mere 14 per cent having comprehensive plans for an AI-related disruption.

These gaps sit within smaller teams where forty-five per cent of compliance programmes had two to five staff, and around 60 per cent of Chief Compliance Officers held a combined role as COO/CCO or CFO/CCO.

Firms can expect the next round of examinations to feature a deeper set of questions that challenge the comprehensiveness and budgetary commitment to ensuring advisors’ AI deployments are adequately managed, whether internally developed or provided by third-party service providers.

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: Sponsored by FundGuard: NAV Resilience Under DORA, A Year of Lessons Learned

The EU’s Digital Operational Resilience Act (DORA) came into force a year ago, and is reshaping how asset managers, asset owners and fund service providers think about operational risk. While DORA’s focus is squarely on ICT resilience and third-party dependencies, its implications extend deep into core operational processes that are critical to market integrity, investor...

BLOG

Trillium Surveyor Expands Into Prediction Markets as Capital Markets Interest Grows

Prediction markets are finding early adopters in capital markets across brokers, exchanges, market makers, and infrastructure providers. Activity is most visible on the sell side, where firms are building access points, data services, venue capacity, and liquidity provision. Tradeweb’s partnership and minority investment in Kalshi, Robinhood’s build-out of Rothera Exchange & Clearing with Susquehanna International...

EVENT

Buy AND Build: The Future of Capital Markets Technology

Buy AND Build: The Future of Capital Markets Technology London examines the latest changes and innovations in trading technology and explores how technology is being deployed to create an edge in sell side and buy side capital markets financial institutions.

GUIDE

AI in Capital Markets Handbook 2026

AI adoption in capital markets has moved into a more disciplined phase. The priority is now controlled deployment: where AI can be used safely, where it can deliver measurable value, and how outputs can be governed, monitored and evidenced. The 2026 edition of the AI in Capital Markets Handbook examines how AI is being applied...