Financial regulators across the US, UK and UAE are converging on a single message: firms do not need to wait for AI-specific rules before tightening their governance, because existing regulatory frameworks already apply to how AI is used.
According to ACA Group, in the US, the Securities and Exchange Commission’s 2026 Examination Priorities have embedded AI oversight across information security, operational resiliency and emerging financial technology categories.
ACA Group recently delved into how AI governance is becoming a global examination priority.
The Financial Industry Regulatory Authority’s 2026 Annual Regulatory Oversight Report went further, adding a dedicated section on generative AI and asking member firms to show evidence of testing, supervision, governance, vendor diligence and recordkeeping for AI tools. Examiners will expect this regardless of whether a firm actively markets AI-powered strategies.
The UK’s Financial Conduct Authority has taken a different route, opting against additional AI-specific regulation in favour of a principles-based, outcomes-focused model. Initiatives including the FCA’s AI Lab, AI Live Testing and the Mills Review, launched in January 2026, all point firms towards adapting existing governance rather than waiting on bespoke rules.
In the UAE, the Dubai Financial Services Authority issued a circular to senior executive officers at every authorised firm in the DIFC, outlining expectations across four pillars: governance and accountability, risk management, operational risk and third-party arrangements. Regulators there stressed the guidance is not designed to slow adoption, but to ensure innovation and governance progress together.
Compliance chiefs are being told that senior management must genuinely understand AI-related risks rather than delegate oversight to technology teams, and must be ready to discuss data integrity, model limitations and the implications of desktop tools such as Claude and ChatGPT.
Third-party accountability also remains firmly with the firm, even where AI software is procured externally, while recordkeeping obligations extend to AI-enabled communications.
A recent ACA survey of more than 200 compliance and operations professionals, 62% of them CCOs, found 84% of respondents use desktop AI tools at work, yet the average firm applies AI in fewer than two of 20 surveyed functions. That gap between widespread adoption and limited, inconsistent governance is precisely why regulators are stepping up scrutiny.
ACA notes that firms able to demonstrate proportionate governance, effective oversight and clear accountability will be best positioned, irrespective of whether they are supervised in New York, London or Dubai. Independent assessments, the firm suggests, can help benchmark governance against regulatory expectations before gaps become examination findings.
Read the full ACA Group post here.
Copyright © 2026 FinTech Global









