Durham University Business School has published a study calling for a dedicated regulatory framework to govern the use of artificial intelligence within financial services.
The research concludes that a bespoke set of rules is needed to limit the risks AI poses to consumers and to strengthen oversight across the sector. It finds that current approaches to AI regulation are inconsistent from one jurisdiction to another, leaving gaps that could expose customers and institutions to harm.
According to the study, some regions, including the European Union and China, have already put AI-specific legislation in place, while others, such as the UK and the US, continue to rely on a more relaxed, principles-based approach. Professor Habib Ahmed of the university’s Department of Finance contends that financial services should not be governed by generic AI rules, and instead need a model built around the sector’s particular risks. He points to the EU’s AI Act as a possible template for such a framework.
The study sets out several risk areas tied to AI adoption in finance, among them the mishandling of personal data, biased outcomes in automated decision-making, overreliance on external technology suppliers, and exposure to cyber threats. It warns that these issues could undermine core regulatory goals such as safeguarding consumers, preserving financial stability and maintaining market integrity, with consequences that could ripple outward from individual users to the broader financial system.
To build his proposed framework, Professor Ahmed first mapped the main risks financial institutions face when deploying AI, then assessed existing governance models, drawing heavily on the EU AI Act’s approach to risk management and oversight. The resulting framework sorts AI use into four tiers. Systems considered unacceptable, such as unauthorised harvesting of facial data or manipulative applications, would be banned outright.
High-risk systems, including those affecting access to essential services, would face strict regulation. Limited-risk uses, such as AI-generated video or text, would require transparency so users know they are engaging with AI. Minimal-risk applications, like spam filters or gaming AI, would fall outside the framework entirely.
Looking ahead, the study anticipates that AI will play a far larger role in financial services, making robust regulation increasingly urgent. Professor Ahmed suggests that policymakers should look to adapt existing models, such as the EU AI Act, for the finance sector specifically, arguing this would let institutions capture the benefits of AI while limiting consumer risk and preserving trust in the financial system.
Copyright © 2026 FinTech Global









