Compliance teams have spent three years waiting for an AI rulebook for financial services. In 2026 it has become reasonably clear that, in both the UK and the US, no such document is coming — at least not in the form people expected.
The two jurisdictions reached this position by opposite routes, and the difference in route matters enormously for how a firm should actually build its programme.
*This article discusses regulatory frameworks in general terms and is not legal advice.*
The UK: Deliberate Non-Legislation
The UK position has been consistent since 2023 and was restated repeatedly through 2026: AI in financial services will be overseen through existing frameworks rather than bespoke AI rules.
The FCA has said it does not currently plan to introduce AI-specific rules. Its stated approach points firms to the instruments that already apply — the Consumer Duty, the Senior Managers and Certification Regime, the systems and controls requirements in SYSC, and operational resilience rules. Alongside this it runs an AI Lab to support firms developing use cases and co-chairs an AI consortium with the Bank of England.
This is not passivity, and 2026 has made that clear.
In January 2026, the House of Commons Treasury Committee published a report on AI in financial services that was pointedly critical, warning that regulators were not doing enough to manage the risks. Its recommendations included that the FCA publish comprehensive, practical guidance by the end of 2026 on how existing consumer protection rules apply to AI — and specifically on what level of assurance is expected from senior managers under SM&CR for harm caused through AI; that the FCA and Bank of England conduct AI-specific stress testing; and that HM Treasury designate major AI and cloud providers under the Critical Third Parties regime.
That third recommendation is the one with the largest structural consequence. Designating major AI providers as critical third parties would bring the largest model providers inside the Bank of England's operational resilience perimeter — regulating the supply chain rather than the individual firm's use. It is a genuinely different regulatory theory from anything the US is currently pursuing.
Also in January 2026, the FCA launched a long-term review into how AI could reshape retail financial services, while acknowledging that existing supervisory frameworks may need to evolve as AI systems become more capable and autonomous. Its March 2026 perimeter report flagged growth in unregulated AI-driven financial guidance tools, particularly chatbots offering advice without oversight — a reasonably clear signal of where an enforcement line may eventually be drawn.
Industry has broadly supported the UK approach, partly on the argument that AI-specific standards would overlap awkwardly with the Consumer Duty and SM&CR, and that firms would end up treating any new guidelines as de facto rules anyway.
The US: Carve-Out at Federal Level, Patchwork at State Level
The US arrived at "no AI rulebook" by a different mechanism, and the result is considerably messier.
In banking, SR 26-2 — the revised interagency model risk guidance issued on 17 April 2026 — explicitly excludes generative and agentic AI from its scope, describing the technologies as novel and rapidly evolving. The guidance states that a bank's existing risk management principles should govern systems outside its scope, and the Federal Reserve has been seeking input on appropriate governance approaches.
In insurance, there is no federal prudential regulator at all, and the NAIC has moved into the space decisively. The Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted in December 2023, is not a model law and is not self-executing — it takes effect in a state only when that state's insurance department adopts it. By mid-2026, more than half of US jurisdictions had done so, with counts running from the mid-twenties to around thirty depending on whether substantially-similar guidance is included, and further adoption expected.
Where adopted, the bulletin requires a written AI Systems Program covering: an inventory of AI tools in use; documented risk controls and testing for bias and errors; senior management and board accountability; a defined evaluation process before deployment; oversight of third-party AI including contractual audit rights; and consumer notification where AI systems are in use. Regulators have signalled they will look through vendor relationships during examinations — an insurer cannot outsource its way out of responsibility.
The NAIC has also been piloting an AI Systems Evaluation Tool, a structured framework for examiners reviewing insurer AI governance during market conduct examinations, with a subset of states participating.
Four large markets sit outside the bulletin count and have their own frameworks: California, Colorado, New York and Texas. Colorado's regime for life insurers using external consumer data and predictive models is the most substantive, establishing outcomes-based testing requirements, with an enforceability provision activating in June 2026.
Layered on top is genuine legal uncertainty about the division of authority between federal and state government over AI regulation, which is currently the subject of both executive action and litigation. That dispute is unresolved and politically contested; firms should plan on the assumption that state insurance requirements remain live while it plays out, because they are the ones being examined against today.
The Practical Comparison
| United Kingdom | United States | |
|---|---|---|
| AI-specific rules | None planned; existing frameworks apply | Banking: AI carved out of MRM guidance. Insurance: state-adopted NAIC bulletin |
| Primary instruments | Consumer Duty, SM&CR, SYSC, operational resilience | SR 26-2 (banks, non-binding); NAIC AI Systems Program (adopting states) |
| Individual accountability | Named senior manager, personal exposure | Board and senior management collectively; named accountability in insurance |
| Explainability trigger | Consumer Duty + UK GDPR Art. 22 automated decision rights | State unfair discrimination law; adverse action requirements |
| Third-party AI | Critical Third Parties regime (designation pending) | Contractual audit rights; regulators look through vendors |
| Examination apparatus | Supervisory engagement, thematic review | NAIC AI Systems Evaluation Tool pilot; market conduct exams |
| Uniformity | Single national regime | Fragmented by state; large markets outside the model |
What This Means for a Firm Operating in Both
Five practical conclusions.
1. The absence of AI rules increases the documentation burden, it does not reduce it. When a rulebook exists, compliance means demonstrating you followed it. When it does not, compliance means demonstrating your judgement was reasonable — which requires recording the judgement, the alternatives, and the basis for choosing. That is more work, not less.
2. Build to the NAIC AI Systems Program specification globally. It is currently the most concrete AI governance specification either jurisdiction has produced — inventory, testing, senior accountability, third-party oversight, consumer notification. A firm that meets it is well positioned for FCA guidance whenever it arrives, because the substantive expectations overlap heavily.
3. Consumer notification is the widest gap in most programmes. Adopting-state expectations include telling consumers when AI systems are in use. Very few firms operating cross-border have systematically implemented this, and it cannot be retrofitted quickly because it touches customer journeys rather than back-office process.
4. Vendor contracts are the binding constraint. Both jurisdictions expect the firm to remain responsible for third-party AI behaviour. If your contracts lack audit rights, regulatory cooperation clauses and material-change notification, you cannot meet the expectation regardless of how good your internal governance is. Contract remediation has a long lead time; start it now.
5. Watch the critical third parties development closely. If the UK designates major AI providers under the CTP regime, the compliance question shifts from "how do we govern our use of this model" to "what does our provider's designated status require of us." That is a different programme, and firms with concentrated dependence on one or two providers will feel it first.
The Honest Summary
Neither jurisdiction has decided AI is low risk. Both have decided that writing AI-specific rules would either duplicate existing obligations or freeze a moving target.
The consequence for firms is uncomfortable but clear: you are being asked to construct a defensible governance position without a specification to build to, and to be able to justify it under examination. The firms that treat the current period as a waiting room will be the ones with the least evidence when guidance lands — because guidance, when it comes, will be applied to systems that are already in production.
Key Takeaways
- The UK has declined to write AI-specific financial services rules, relying on the Consumer Duty, SM&CR, SYSC and operational resilience requirements.
- The January 2026 Treasury Committee report pressed for practical FCA guidance by end-2026, AI stress testing, and designation of major AI providers as critical third parties.
- US banking guidance SR 26-2 explicitly carved generative and agentic AI out of scope; existing risk management principles still apply.
- The NAIC Model Bulletin binds only through state adoption, now covering more than half of US jurisdictions, with California, Colorado, New York and Texas operating separate frameworks.
- Absence of a rulebook raises the documentation burden: firms must evidence the reasonableness of their judgement, not compliance with a specification.
Frequently Asked Questions
Does the UK have AI-specific regulation for financial services? No. The FCA has stated it does not currently plan to introduce AI-specific rules, expecting firms to govern AI under existing frameworks including the Consumer Duty, SM&CR, SYSC and operational resilience requirements. Practical guidance on how those rules apply to AI has been recommended for publication by the end of 2026.
Is the NAIC AI Model Bulletin legally binding on insurers? Not by itself. It is principles-based guidance that takes effect only where a state insurance department adopts it, and adopted text can vary between states. Where adopted, it is enforced through market conduct examination, and insurers writing across multiple states may be subject to it in some jurisdictions and not others.
What is an AI Systems Program under the NAIC bulletin? A written programme governing AI used in underwriting, rating, claims, fraud detection and marketing. It typically requires a documented AI inventory, risk controls and testing for bias and errors, senior management and board accountability, a pre-deployment evaluation process, third-party AI oversight with audit rights, and consumer notification where AI systems are in use.
Related reading
See also Regulatory Compliance and Model Risk, or review qualifications.
About the author
Jonas Osman Abdelghafour is an actuary and risk expert advising insurers, banks and pension funds on model risk, regulatory compliance, financial crime and enterprise risk management across UK, EU and US regimes. He writes on where quantitative actuarial practice meets the governance, risk and compliance frameworks regulators expect boards to evidence. See qualifications and services, or get in touch to discuss an engagement.
Frequently asked questions
What should risk leaders know about the UK: Deliberate Non-Legislation?
The UK position has been consistent since 2023 and was restated repeatedly through 2026: AI in financial services will be overseen through existing frameworks rather than bespoke AI rules.
What should risk leaders know about the US: Carve-Out at Federal Level, Patchwork at State Level?
The US arrived at "no AI rulebook" by a different mechanism, and the result is considerably messier.
What should risk leaders know about the Practical Comparison?
| | **United Kingdom** | **United States** | |---|---|---| | **AI-specific rules** | None planned; existing frameworks apply | Banking: AI carved out of MRM guidance. Insurance: state-adopted NAIC bulletin | | **Primary instruments** | Consumer Duty, SM&CR, SYSC, operational resilience | SR 26-2 (banks, non-binding); NAIC AI Systems Program (adopting states) | | **Individual accountability** | Named senior manager, personal exposure | Board and senior management collectively; named accountabi...
What should risk leaders know about the Honest Summary?
Neither jurisdiction has decided AI is low risk. Both have decided that writing AI-specific rules would either duplicate existing obligations or freeze a moving target.
What should risk leaders know about frequently Asked Questions?
**Does the UK have AI-specific regulation for financial services?** No. The FCA has stated it does not currently plan to introduce AI-specific rules, expecting firms to govern AI under existing frameworks including the Consumer Duty, SM&CR, SYSC and operational resilience requirements. Practical guidance on how those rules apply to AI has been recommended for publication by the end of 2026.