Why AI is testing the limits of financial crime controls

Why AI is testing the limits of financial crime controls

The rapid adoption of generative and agentic AI is forcing financial services firms to reconsider whether traditional information barriers remain effective in a world where machines can access, analyse and distribute sensitive data in seconds.

According to analysis from RegTech provider ACA, firms must assess whether their existing market abuse controls are equipped for AI-driven workflows, as the technology introduces new risks around inside information, data access and accountability. While AI does not change the definition of inside information under UK Market Abuse Regulation (UK MAR), it can accelerate how restricted information is accessed, combined and shared, creating new challenges for compliance teams.

The FCA’s inside information guidance, refreshed on 22 May 2026, outlines the systems and controls firms should maintain to identify, manage and disclose inside information. The regulation prohibits insider dealing, unlawful disclosure and market manipulation, defining inside information as precise, non-public information relating to issuers or financial instruments that could significantly affect prices if released.

The challenge for firms is not that AI creates a new category of regulatory risk, but that it can amplify existing weaknesses. A document previously held within a restricted deal folder can now be uploaded into an AI tool and summarised instantly. An analyst could use a model to generate client communications based on sensitive information, potentially extending access beyond approved recipients.

Agentic AI systems introduce further complexity. Autonomous tools capable of completing tasks across connected systems may retrieve restricted information, generate materials or share outputs without sufficient oversight if permissions, monitoring and approval processes are not properly designed.

The FCA has indicated it does not intend to create separate AI-specific market abuse rules. Instead, existing regulatory expectations around governance, accountability and risk management will continue to apply. This means firms remain responsible for ensuring AI systems operate within established controls, with clear ownership across compliance, legal, technology and business teams.

Recent enforcement activity demonstrates the regulator’s continued focus on weak information controls, poor governance and failures to identify suspicious activity. While cases such as Dinosaur Merchant Bank and Sigma Broking pre-date the widespread use of AI, they highlight the risks that can emerge when firms lack effective oversight of data flows, monitoring processes and reporting obligations.

As firms introduce AI into compliance, investment and client-facing workflows, they must evaluate whether their existing frameworks can manage AI-related risks. Key considerations include understanding where inside information originates, controlling which AI tools can access sensitive data, monitoring permissions, maintaining audit trails of prompts and outputs, and ensuring AI activity can be reviewed during regulatory investigations.

ACA argues that firms do not need a separate market abuse framework for AI, but they do need confidence that existing controls remain effective in AI-enabled environments. This includes reviewing AI governance, information barriers, access controls, data loss prevention measures, surveillance capabilities, recordkeeping, policies, training and assurance testing.

As financial institutions continue adopting generative and agentic AI, the ability to integrate the technology without weakening market abuse protections will become a critical compliance challenge. Firms that fail to adapt their controls risk creating new pathways for sensitive information to move beyond intended boundaries.

Read the full ACA analysis here.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.