The U.K. financial regulator is expanding its remit and planning to deploy AI to manage its increased workload. This is part of a global trend and has significant compliance implications.
The Financial Conduct Authorityโs (FCAโs) 2026-27 work program, published on March 27, included two important compliance takeaways. First, the regulator is becoming the only anti-money-laundering (AML) supervisor for professional services, bringing around 60,000 more firms under its auspices.
Second, to manage this increased workload and achieve aims including innovation, stronger standards, and better customer outcomes, it intends to make greater use of AI. This may affect how companies interact with the regulator and introduce new compliance risks.
The FCA plans to integrate AI into regulatory workflows to enable it to detect harm more effectively and speed up regulatory decision-making. It will also use generative AI to review documents received from firms to support faster decisions.
Nikhil Rathi, chief executive of the FCA, explained: โThis yearโs program builds on our ongoing drive towards smarter, more data-driven regulation, helping us identify risks sooner, make faster, more consistent decisions and reduce unnecessary burdens on firms.โ
Global trends
Adam Gilbert, global senior regulatory advisor in financial services risk and regulatory at PwC, said compliance teams worldwide must adapt to AI supervision.
โThe FCAโs integration of AI in its 2026-27 strategy is a clear signal of where supervision is heading globally,โ he warned.
He pointed to two key compliance issues. First, while the FCA has been transparent about its use of AI, some U.S. regulators, including the U.S. Securities and Exchange Commission (SEC), are already using AI internally for document review, analysis, and supervisory efficiency, although they have not all stated this publicly.
Others, like the Federal Reserve, are exploring โhow AI can enhance supervision โ improving examiner training and helping analyze large volumes of public data โ while emphasizing that expert judgment remains central to decision-making,โ he said.
โIn that sense, the FCAโs plans are an early and more visible example of a broader shift toward transparent, data-driven, and technology-enabled supervision. That shift will require firms to enhance their compliance capabilities, particularly in areas such as data quality, governance, and their own internal use of AI,โ Gilbert explained.
The second issue for compliance is that this is a step-change in regulatory capability, particularly in terms of speed, consistency, and continuity. Gilbert said the FCAโs use of AI to review firm submissions, combined with the integration of automated data feeds into supervision, will make oversight faster, more consistent, and more data-driven.
โIn practice, inconsistencies across policies, submissions, and controls that may previously have gone unnoticed are more likely to be identified quickly,โ he said. โAutomated data feeds will also make it harder for firms to control the flow of information to regulators, compared with a model where specific information is formally submitted.โ
To meet these evolving demands, Gilbert advised compliance teams to:
- Expect greater scrutiny of consistency. AI allows regulators to compare policies, filings, and controls across the enterprise and over time, increasing the likelihood that gaps or contradictions are identified.
- Use AI internally for quality assurance. Applying similar tools to review submissions, test alignment across governance documents, and identify unsupported statements can help firms address issues before regulators do.
- Strengthen governance and documentation. As regulators gain the ability to analyze larger and less structured datasets, including transaction data, customer interactions, and elements of code, firms will need clearer documentation of assumptions, model changes, and control frameworks.
- Prepare for more continuous supervision. The move toward automated data feeds suggests supervision will become less episodic and more ongoing, reducing the ability to curate regulatory interactions.
โThe FCAโs strategy signals a move toward a more proactive, technology-enabled supervisory model that leaves less room for inconsistency or delay,โ he summarized. โFirms that invest now in data quality, governance, and AI-enabled compliance will be better positioned to keep pace as this model becomes the global standard.โ
Underlying expectations
Ted Datta, head of the financial crime and compliance practice for Europe and Africa at Moodyโs, agreed AI is changing the speed, scale, and persistence of regulatory oversightย โ but not the underlying expectations.
โRegulators using AI can review far more information simultaneously and seek toย identifyย potential risks earlier, but firmsย remainย fully accountable for the quality and defensibility of their decisions,โ he warned.
Datta pointed out that 79 percent ofย risk and complianceย professionals believe new regulations governing the use of AI in compliance are important. โMore than half of organizations say they are already using or trialing AI in risk and compliance, up from roughly 30 percent two years earlier, meaning supervisors are increasingly overseeing AIโassisted activity in live environments rather than pilots,โ he explained.
However, he warned that one of the biggest constraints on effective AI adoption is trust in outputs. Compliance teams consistently point to challenges around data quality, explainability, and governance.
โTo address this, firms need to shift focus from AI tools alone to the context and intelligence layer that sits underneath them,โ he advised. โIn regulated environments, AI outputs must be explainable, auditable, and defensible. While 84 percent of risk and compliance professionals agree AI offers significant advantages, many have only seen a moderate impact so far. Governance, safeguards, and operating model readiness matter as much as the technology itself.โ
He advised that โintelligence that isย decisionโgrade โ curated,ย structuredย and fully traceableโ is critical now that AI systems are embedded in risk and compliance workflows.
Opacity is a complianceย risk.ย โAs AI supports more regulatory activity, firms become vulnerable if they cannot explain or evidence AIโassisted decisions under scrutiny.โ
Compliance teams can mitigate this by embedding governance, clear sourcing, lineage, and audit trails into AIโenabled workflows, with responsibility remaining firmly with people rather than systems, he said.ย Purposeโbuilt AIย toolsย being developedย canย produceย trusted, auditable outputs at the scale and speed regulated institutions demand.
Continuous scrutiny
Compliance teams should expect regulators’ use of AI to lead to more continuous, data-led scrutiny, instead of periodic reviews, warned Scott Bridgen, general manager for risk and audit at Diligent.
โFor firms, that raises the bar on their own systems and controls,โ he said. โYou need to be confident that the data you submit is accurate, timely, and wellโgoverned.โ
They must be able toย demonstrateย how processes are controlled, the checks and reconciliations in place, how AI tools areย monitored, and who is accountable. โWithout that, responding to regulatory queries is going to get much harder,โ he said.
This will be a challenge for organizations still dealing with fragmented data and limited visibility, especially where AI implementation and usageโฏsitsโฏwith third-party providers.
โAs AI-enabled adversaries have increased attacks byโฏ89 percent year-on-year,โฏthe risks tied to poorly governed systems and external dependencies are growing.ย That lack of oversight becomes more visible when regulators are using AI toโฏidentifyโฏpatterns or anomalies atโฏscale,โ he said.
โExplainability is critical,โ he added. If a regulator flags an issue based on AI analysis, firms must respond with evidence showing how a decision was made, the data and models used, and theย level of human oversight.
โThere is a real danger inย overโrelianceย on automated signals โ on both sides โ if neither party fully understands how those outputs are reached,โ he warned.
Brigden advised that firms that invest in data quality, strong governance, and clear accountability for AI (including model inventories, testing for drift and bias, and robust thirdโparty oversight) will be better able to meet regulatorsโ demands, because they will have the same capabilities to spot issues.
โThey will be able to demonstrate that their control environment can stand up to that level of scrutiny,โ he said.


