AI Governance Is Becoming a Global Examination Priority

Key Takeaways

  • Financial regulators across the U.S., the UK, and the UAE are converging on AI governance expectations
  • Existing regulatory frameworks already apply to AI-enabled activities
  • AI-related governance and controls are receiving increased attention in examination priorities and supervisory guidance
  • Governance, vendor oversight, and recordkeeping are emerging as common regulatory priorities
  • Firms should strengthen AI governance before AI-specific rules are introduced

Although financial regulators have taken different approaches to AI, a clear pattern is emerging: Existing regulatory frameworks continue to apply when firms use AI, and AI-related controls are receiving greater supervisory attention.

That convergence is significant because firms do not need to wait for AI-specific rules before strengthening their governance. Although the SEC, FINRA, FCA, and DFSA have taken different approaches, each has emphasized that existing regulatory obligations already apply when firms use AI.

AI governance is moving from a future compliance discussion to a present examination priority.

U.S. Regulators Are Embedding AI Governance into Examinations

If you manage a compliance program for an investment adviser or broker-dealer, the SEC’s 2026 Examination Priorities deserve close attention. The Division of Examinations embedded AI oversight across multiple examination categories, including information security, operational resiliency, and emerging financial technology.

The practical implication is that AI governance will be an increasingly important factor in regulatory examinations for all firms, not just for those that are actively marketing AI-powered strategies. FINRA’s 2026 Annual Regulatory Oversight Report went further, introducing a dedicated section on generative AI and calling on member firms to demonstrate testing, supervision, governance, vendor diligence, and recordkeeping practices for AI tools.

The message from both regulators is clear: Existing regulatory obligations apply to AI, even in the absence of AI-specific rules. Examiners will expect firms to demonstrate effective governance.

The FCA Expects Existing Regulatory Frameworks to Apply to AI

In the UK, the FCA has stated that it does not plan to introduce additional AI-specific regulations. Instead, it continues to favor a principles-based, outcomes-focused approach that allows firms to innovate while remaining accountable under existing regulatory frameworks.

Initiatives such as the FCA’s AI Lab, AI Live Testing, and the long-term Mills Review, launched in January 2026, reinforce the expectation that firms should adapt existing governance and risk management arrangements for AI rather than wait for AI-specific regulation.

The DFSA Is Reinforcing AI Governance Expectations

Earlier this year, the DFSA issued a formal circular to the senior executive officers of every authorized firm in the DIFC, setting out expectations for AI risk management. The guidance focuses on four pillars: governance and accountability, risk management, operational risk, and third-party arrangements.

Notably, the UAE’s regulatory approach is not intended to slow AI adoption. Instead, regulators are signaling that innovation and strong governance should develop together. Firms are encouraged to embrace AI where it delivers value, provided they can demonstrate appropriate human oversight, clear accountability, effective risk management, and robust governance arrangements.

Together with developments in the U.S. and the UK, this reinforces an emerging global expectation that AI should be governed within existing regulatory and risk management frameworks.

What “Existing Frameworks Apply” Means in Practice

AI does not create a separate compliance regime. Instead, it changes how firms demonstrate that existing governance, risk management, and compliance frameworks remain effective when AI becomes part of everyday business processes.

In practice, AI governance refers to the policies, controls, oversight arrangements, accountability, and risk management processes that enable firms to use AI safely, transparently, and in line with regulatory expectations.

For compliance teams, the phrase “existing frameworks apply” can sound deceptively simple.

From a governance perspective, the SEC has been direct about its expectation that AI use remains comprehensible and defensible under examination. Regulators in the UK and the UAE reinforce the same expectation: Senior management must have sufficient understanding of AI-related risks to provide meaningful oversight, not simply delegating to technology teams.

CCOs should be prepared to discuss data integrity risks, model limitations, and the compliance implications of desktop AI tools such as Claude and ChatGPT, as well as AI-enabled software applications used across the business.

When it comes to third-party risk, SEC examination priorities and FINRA guidance indicate that firms should consider AI-related risks arising from their use of third-party vendors. An investment adviser that uses AI-powered software remains fully accountable for the outputs and the controls in place, even if the software and models were procured externally. The DFSA and FCA have the same expectation within their existing outsourcing and third-party risk frameworks.

Regarding recordkeeping and disclosure, the SEC and FINRA have flagged the importance of capturing AI-enabled communications within firm books and records and ensuring that representations made to investors about AI tools are accurate and consistent with actual practices.

Firms Should Strengthen AI Governance Before Examinations

The regulatory message is increasingly consistent across jurisdictions. Firms do not need to wait for AI-specific regulation before reviewing how AI is governed. Instead, compliance teams should assess whether existing governance frameworks remain effective when AI is introduced into business processes.

Firms should be able to demonstrate:

    • Clear governance and accountability for AI-enabled activities
    • Regular risk assessments and appropriate oversight for higher-risk AI use cases
    • Effective third-party governance for AI vendors and service providers
    • Appropriate recordkeeping and monitoring for AI-assisted decisions and communications
    • Regular training and periodic reviews to ensure governance keeps pace with AI use

The objective is not to build an entirely new compliance framework. It is to demonstrate that existing governance, risk management, and control frameworks continue to operate effectively when AI becomes part of everyday business processes.

Most Firms Are Still Early in Their AI Governance Journey

ACA recently surveyed more than 200 compliance and operations professionals, 62% of whom are CCOs, across asset management, private markets, wealth management, hedge funds, and broker-dealers.

The findings help explain why regulators are increasingly focused on AI governance. While 84% of respondents said they use desktop AI tools at work in some capacity, the average firm reported using AI in fewer than two of the 20 functions surveyed. In other words, AI use is common, but it remains limited across business functions and is often inconsistent or ad hoc.

The findings highlight a growing disconnect. AI adoption is becoming widespread, but governance maturity is not keeping pace. That gap helps explain why AI governance is becoming a greater focus of supervisory activity.

These broad but inconsistent adoption patterns matter in today’s regulatory environment. Firms that use desktop AI tools often lack formal governance, testing, and controls around those tools. The question is not whether your firm uses AI. The question is whether your policies match your practices, whether your vendors are appropriately overseen, and whether a compliance professional can explain and defend how AI is being used in your workflows.

Regulators are not waiting for new AI-specific rules. They are applying longstanding governance, risk management, and compliance frameworks to rapidly evolving technology.  Firms that can demonstrate proportionate governance, effective oversight, and clear accountability will be best positioned, regardless of whether they are supervised in New York, London, or Dubai.

For many organizations, the challenge is no longer recognizing the need for stronger AI governance. It is determining whether existing controls remain fit for purpose. An independent review can help firms benchmark their governance arrangements, identify gaps, and assess whether AI-related risks are being managed in line with evolving regulatory expectations before they become examination findings.

AI Governance Assessments Help Firms Prepare for Regulatory Examinations

As AI adoption accelerates, many firms are finding that existing governance frameworks were not designed for AI-enabled processes. Independent assessments can help benchmark governance arrangements against evolving regulatory expectations, validate existing controls, identify potential gaps, and prioritize practical improvements before they become examination findings.

ACA helps regulated firms strengthen AI governance through practical, risk-based advisory services tailored to the financial services sector. Our specialists support firms with AI governance assessments, governance framework and policy development, AI risk assessments, third-party AI due diligence, governance operating model design, and independent reviews of compliance controls to determine whether they remain effective in an AI-enabled environment.

Working alongside compliance, legal, risk, technology, and business teams, we help firms build proportionate governance frameworks that support innovation while meeting evolving regulatory expectations across jurisdictions.

Find out how an independent AI governance assessment can help your firm prepare for evolving regulatory expectations.

Related Reading

AI Governance FAQs for Regulated Firms

AI governance refers to the policies, controls, oversight, accountability, and risk management processes that help organizations deploy AI safely, responsibly, and in line with regulatory expectations.

Financial regulators increasingly recognize that AI can affect operational resilience, customer outcomes, recordkeeping, third-party risk, and decision-making. Rather than introducing entirely new AI rules, many regulators expect firms to demonstrate that existing governance frameworks remain effective when AI is used.

Regulators across multiple jurisdictions, including the SEC, FINRA, FCA, and DFSA, have all made it clear that firms are expected to govern AI responsibly under existing regulatory frameworks, even where AI-specific rules do not exist.

Not always. In many cases, firms can build on existing governance, operational resilience, outsourcing, and compliance frameworks. The key is ensuring that those frameworks appropriately address AI-related risks.

Firms should understand where AI is being used, assign clear accountability, assess AI risks, review third-party AI providers, maintain appropriate records, and regularly review whether existing governance arrangements remain fit for purpose.

Yes. Existing regulatory obligations may apply when employees use general-purpose AI tools such as ChatGPT or Claude for regulated business activities. Firms should understand those uses and apply controls that are appropriate to the associated risks.